Last week, the UK government published its AI Adoption Plan for financial services, based on ten recommendations from Lloyds' head of AI, Rohit Dhawan PhD and Starling CIO, Harriet Rees. As a little bit of background, the pair were named AI champions in January, reporting to Economic Secretary to the Treasury Lucy Rigby, with a mandate to find where adoption could move faster and where barriers were holding firms back. It covers the regulatory perimeter, consumer disclosure standards for AI-driven services, rollout of the Critical Third-Party regime for AI and cloud providers, and a voluntary framework for sharing AI incidents across the sector. The plan takes a different approach from the EU AI Act, as, rather than adopting a standalone AI law, the UK is folding AI oversight into existing regimes such as consumer duty, SMCR, and operational resilience. There's no new rulebook, just more interpretation, as compliance and governance functions map AI use cases onto obligations written before agentic systems existed. Millions of people are already using general-purpose AI tools to shape financial decisions without ever consulting a regulated adviser. That is why the plan calls for a Financial Conduct Authority review. Where that regulatory boundary ultimately sits, however, remains fluid and likely will for some time. The Critical Third-Party regime is where this plan gets some teeth on big tech. It doesn't attempt a broad AI conduct regime; instead, it targets systemic risk in financial services specifically, which is narrower than the EU's approach but also more enforceable within its scope. But that will remain to be seen… The plan is betting that flexibility produces better outcomes than prescription. And after all, if you’ve ever heard me talk, it’s outcomes, not activity, that we should be focusing on. Whether that works will depend less on regulation than on whether firms invest now in governance, accountability and model assurance before regulators start defining those expectations for them. Here’s the full publication: https://lnkd.in/e3gXWfDj #AIAdoption #AIGovernance #FinancialServices #UKAIAdoption
UK AI Adoption Plan for Financial Services Published
More Relevant Posts
-
I've written a second book on the EU AI Act. "The EU AI Act Playbook for Boards" is out today. It follows April's playbook for funds and financial services, and it is book two in The AI Governance Playbook Series. The first book was for the people who have to implement AI governance. This one is for the Directors and Boards who have to answer for it. Because that is where this is heading. The EU AI Act is in force. The Digital Omnibus fixed the deadlines in law last month. High-risk obligations apply from December 2027. Transparency obligations already apply. That is the legal timetable. But the first test of a board's AI governance will not be a deadline. It will be the next query, assessment, examination, or audit — from a regulator, an investor, an auditor, or a D&O insurer. And most boards, asked to produce evidence of their AI governance, could not. Not because they are careless. Because nobody has told them what evidence looks like. So the book gives them it. The ten questions every director should be asking management. The decisions only the board can make. The evidence file, laid out. What personal exposure actually looks like for directors of EU entities. Why "we are monitoring the situation" fails an inspection. Fully updated for the final Digital Omnibus text — Regulation (EU) 2026/1744, in force since 27 July — and the Commission's draft high-risk classification guidelines. Concise, and written to be read before a board meeting rather than after an inspection. If you sit on a board — or you report to one — this is the conversation coming down the track at you. More to come in the series over the next 12 months: non-EU managers with European exposure, and governing AI agents. #EUAIAct #AIGovernance #CorporateGovernance Links in the comments. If you cannot produce it, you have a problem. Start now.
To view or add a comment, sign in
-
We've been tracking this deadline since May. It arrived yesterday. And it arrived as a disclosure requirement. The EU AI Act went into enforcement on August 2, 2026. The world's first comprehensive AI governance framework is now live. The primary obligation it activated: chatbots must tell you they are AI. Deepfakes must be labeled. Fines up to €15 million or 3% of global turnover for non-compliance. That is the accountability architecture the world's most ambitious AI regulation produced on its enforcement date. The obligations that would have required something deeper, process accountability for AI systems making decisions in employment, healthcare, education, and credit, were deferred in May under the Digital Omnibus deal. Pushed to December 2027. Sixteen months later than originally scheduled. The third time the hard requirements have moved. What remained for August 2 is transparency at the output layer. The system must say what it is. The content must be labeled. The process that produced the decision, the inference chain that determined whether you got the job, the loan, the diagnosis, the admission, is still ungoverned. The enforcement infrastructure tells the rest of the story. A country-by-country tracker across the EU-27 now shows a 9/12/6 split. Nine member states have a national supervisory authority ready to enforce the law that went live yesterday. Twelve are partially prepared. Six have done nothing. The law is in force. The enforcement is not. This is the pattern Process-Centered Accountability has been documenting all year. The requirement arrives. The hard accountability obligations get deferred. What remains is disclosure, the output-layer mechanism that tells you what happened after the decision was made, in language the deploying institution chose, without a trace of the process that produced it. Disclosure is not accountability. It is the acknowledgment that accountability was needed, formatted for a regulator who wasn't present when the decision occurred. The deadline we've been watching since May is here. The framework it was supposed to deliver is sixteen months away, at minimum, in the countries that bother to build the enforcement infrastructure to require it. The window the UN said was open but closing is still open. The question is whether the institutions inside it will build process accountability before the next deferral is announced.
To view or add a comment, sign in
-
-
The EU just gave financial services institutions more time on the AI Act. That is not a reason to slow down on governance. It is a reason to use the time properly. On Monday, July 27 the EU AI Omnibus entered into force, pushing requirements for high-risk AI systems to December 2027 and product-embedded systems to August 2028. Regulatory sandboxes are being widened. Compliance requirements for smaller companies are being simplified. The deadline moved. The need for governance, documentation, and transparency did not. This is the pattern that keeps showing up across every major AI regulatory development. The timeline shifts. The underlying requirement stays the same. And the institutions that treat a deadline extension as breathing room rather than a building window arrive at the new deadline in exactly the same position they were in before. For financial services specifically the practical implication is straightforward. DORA is already live. The EU AI Act requirements for high-risk systems, which include credit decisioning, fraud detection, and regulatory reporting workflows, are now pushing toward end of 2027. That is eighteen months of runway that most institutions will either use to build governance infrastructure properly or spend waiting for more clarity that is not coming. The institutions that are ahead of this are not waiting for final regulatory guidance before they act. They are building explainability layers, audit trails, human oversight frameworks, and model risk documentation now, against the standard the regulation is clearly moving toward, because retrofitting governance into a production AI system is significantly more expensive than building it in from the start. The 1,100 current and former employees of OpenAI, Anthropic, Google DeepMind, and others who signed the Pacing the Frontier statement this week made the same point from a different angle. They are asking governments to build the brakes before they are needed, not after. The people closest to the most capable AI systems in the world are not asking for less governance. They are asking for it to be built in advance of the moment it becomes urgent. The EU just handed financial services institutions more time to do exactly that. The question is whether they will use it. P.S. "The deadline moved, not the need for governance." That is the only sentence that matters from the EU AI Omnibus announcement. Everything else is detail. #AIGovernance #FinancialServices #EnterpriseAI #AIStrategy #DigitalTransformation
To view or add a comment, sign in
-
For a year, "August 2, 2026" was the date every company serving the EU market was bracing for. Last month, it moved. But not the way most headlines suggest — and reading it as "we got more time" is exactly the mistake that creates exposure. Here's what actually happened. The EU's Digital Omnibus, approved by the Parliament and Council in June, deferred the high-risk regime for stand-alone Annex III systems — hiring, credit scoring, education, access to essential services — from August 2, 2026 to December 2, 2027. AI embedded in regulated products moves to August 2028. That is real relief for one specific category. It is not a pause on the AI Act. What still lands on August 2, 2026: → The transparency obligations under Article 50. If your system generates or manipulates content, interacts with people as a chatbot, or produces deepfakes, you must disclose it. AI-generated content has to be marked as such. → The extraterritorial reach. The AI Act applies to any provider or deployer whose system's output is used in the EU — regardless of where the company sits. A Costa Rican company serving European clients is inside the scope, not outside it. → The direction of travel. "Delayed" is not "cancelled." The high-risk obligations are coming; the deadline is now December 2027. Every data inventory, consent record and human-oversight process you build now is work you won't be doing under deadline pressure later. The trap in a delay is that it feels like permission to wait. It isn't. It's a window to get ready without the penalty clock running. If your product touches the EU market and involves AI, the question isn't "are we high-risk yet?" It's "do we know which obligations already apply to us on August 2?" That's a 30-minute conversation. Worth having before the date, not after. Lic. Ricardo Castillo Castillo · Founder, AEGIS Legal Partners Educational content, not legal advice. #EUAIAct #AIGovernance #AICompliance #AILaw #CostaRica
To view or add a comment, sign in
-
The EU AI Act's high-risk deadline has moved from August 2026 to December 2027, giving organisations an extra sixteen months before standalone Annex III systems like credit scoring, employment and critical infrastructure tools need to comply. It is a meaningful extension, but it only changes the calendar. The risk based framework, the governance obligations and the penalties attached to them are exactly what they were before the delay was announced. That distinction matters because it decides how organisations end up using the extra time. Some will treat it as a genuine opportunity to build proper AI governance while there is room to do it properly, testing frameworks and closing gaps without the pressure of an imminent deadline. Others will read the extension as license to deprioritise the work altogether, and will find themselves in December 2027 facing the same requirements with far less runway to meet them. The regulators didn't ease the requirements. Instead, they have given organisations more time to meet them properly, and how that time gets spent will likely be the difference between organisations that walk into the deadline prepared and those still catching up.
To view or add a comment, sign in
-
-
𝗢𝗻 𝗦𝘂𝗻𝗱𝗮𝘆, 𝘁𝗵𝗲 𝗘𝗨 𝗔𝗜 𝗔𝗰𝘁 𝘀𝘁𝗼𝗽𝘀 𝗮𝘀𝗸𝗶𝗻𝗴 𝗻𝗶𝗰𝗲𝗹𝘆. On August 2, the grace period ends. The EU's AI Office moves from publishing rules to enforcing them. From that date, regulators can demand documentation, run their own technical evaluations of a model, order it pulled from the EU market, and levy fines up to 15 million euros or 3% of global turnover, whichever is higher. You have probably seen the other headline: the EU blinked. On Monday the Digital Omnibus entered into force and pushed the high-risk deadline out to December 2027. Sixteen months of runway, and a lot of businesses are reading that as permission to stop thinking about this. Read what it did not move. It did not move enforcement over the general-purpose models you already build on. And it did not move Article 50. Article 50 is the one that reaches you. From Sunday, if an AI system speaks to your customer, the customer has to be told. If you publish synthetic images, audio, or video, it has to be marked. Those duties sit on the business deploying the tool, not only the company that built it. Anything already live gets until December 2 for the machine-readable marking. Anything you launch from Sunday gets nothing. So the two things landing this weekend are the two things nobody delayed. The rules landed in 2025. Enforcement was held back twelve months so everyone could get ready. That window closes Sunday. The question is not whether the law reaches you. It is whether you used the year it gave you. If a regulator asked where AI touches your customer, and whether that customer knows, could your team answer in one sentence? That is the work we do at Lewis & Fields. #AIGovernance #ResponsibleAI
To view or add a comment, sign in
-
Two developments over recent weeks point in the same direction. The JFSC's guidance on AI in Jersey's financial services sector sets out a risk-based, proportionate approach built on five principles and a materiality ladder. It creates no new requirements. It explains how existing obligations apply to AI and confirms that firms remain accountable for outcomes when they use AI, just as they do with any other technology. Low-impact productivity tools attract light-touch controls. Anything touching regulated activity, customer outcomes, confidential data or regulatory submissions attracts more. Article 50 of the EU AI Act became applicable. The Digital Omnibus deferred the high-risk regime to December 2027 and August 2028 but left the transparency obligations on their original schedule. Enforcement arrived the same day: fines of up to €15 million or 3% of worldwide turnover for breaches of provider and deployer obligations. The duty and the penalty landed together. Many offshore firms will assume the AI Act is not their concern. It reaches them where systems are placed on the EU market or where outputs are used in the EU, which captures more offshore arrangements than most firms have checked. The practical message across both is the same. Existing governance and accountability obligations already extend to AI use. The questions are less about which vendor supplied the technology and more about how the firm governs it. Who approved this use case? What is the model permitted to access? How is oversight evidenced? Those are answerable today. Having an AI policy is a good start. Being able to name the accountable owner for every material AI use case is a stronger demonstration of effective governance. Worth an hour before the next risk committee. #AIGovernance #Jersey #FinancialServices #AIAct #LegalTech
To view or add a comment, sign in
-
-
We published a version of this in early July that left something out. Here's the corrected one. Our obligation stack for the EU AI Act showed the next milestones as December 2027 and August 2028 — the high-risk dates, which were pushed back in the May Digital Omnibus. That much was accurate. What it left out is that 2 August 2026 was never empty. Two things applied that day, and one of them reaches ordinary business software: the Article 50 transparency obligations. If a system talks directly to people — a chatbot, an assistant, an agent — the people using it have to be told they're talking to an AI, at or before the first interaction, clearly. The corrected stack is attached. The three things most often missed: → A line in your terms and conditions is not a disclosure. It has to be perceivable in the interaction itself. → Open-source AI systems are not exempt from Article 50. The carve-out elsewhere in the Act doesn't carry over. → The voluntary Code of Practice on AI-generated content is aimed at marking and labelling. It doesn't cover the chatbot disclosure at all. The deferral of the high-risk dates made a lot of us read 2026 as a quiet year. It wasn't, and correcting that in public seemed better than quietly swapping the file. The long version → https://lnkd.in/dNr5u_5C Not legal advice. #EUAIAct #Compliance #EnterpriseAI #SovereignAI #DSGVO
To view or add a comment, sign in
-
The EU just delayed its high-risk AI rules by 16 months. If your board read that as relief, they read it wrong. What happened: on June 29 the Council gave its final green light to the AI Act simplification package. The high-risk obligations, covering AI in hiring, credit, insurance and healthcare, move from August 2, 2026 to December 2, 2027 (https://lnkd.in/erEaYdw8). What did not move: on August 2, 2026, ten days from now, the rest of the Act switches on anyway. Article 50 transparency obligations, the Commission's enforcement powers over general-purpose AI providers, national market surveillance (https://lnkd.in/eZCZvbzZ). Fines reach EUR 15M or 3% of global turnover for most violations. So the executive picture is precise: the conformity-assessment regime got breathing room. The enforcement machinery did not. I read the deferral differently than the headlines. It is 17 months of cheap time for the unglamorous work nobody wanted to fund: knowing what AI you actually run. In my experience most organizations cannot produce that list today, and the agents being shipped this quarter are making it longer. What I would do with the time: - Inventory every AI system in production, including agents and shadow tools. You cannot classify what you have not found. - Run a preliminary classification against the Act's high-risk categories now, while nobody is auditing and mistakes are free. - Give AI Act readiness a named owner and a date, not a committee and a mandate. Don't confuse deferred with cancelled: December 2027 arrives on schedule. And don't skip the August 2026 transparency duties because "high-risk moved." Could your organization produce its AI inventory this week if a regulator asked? 👇 #AI #EUAIAct #Governance #Compliance #DigitalTransformation
To view or add a comment, sign in
More from this author
Explore related topics
- AI Adoption Strategies for Financial Services
- How Financial Firms can Use AI
- How AI is Regulated in Finance
- How Governments Use AI to Combat Financial Crime
- AI Adoption Strategies for Superannuation Funds
- How Banks Are Adapting to AI Changes
- How to Use AI in Financial Crime Compliance
- AI Governance and Regulatory Compliance
- AI adoption in insurance since 2015
- Role of AI in regtech and insurtech
Explore content categories
- Career
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Technology
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Communication
- Engineering
- Hospitality & Tourism
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development
Head of Corporate Planning | Leading Corporate Strategy & Investor Relations | Global IR & English Disclosure
1moInteresting perspective. It feels like the conversation is shifting from AI capabilities to AI governance.