Global artificial intelligence agent regulation in financial services
Global artificial intelligence agent regulation in financial services: non-functional requirement obligations and low-code citizen-development controls
- The EU AI Act already makes AI systems used for creditworthiness evaluation, credit scoring, and life and health insurance risk assessment and pricing high-risk, which means those systems cannot lawfully be deployed without documented risk management, logging, technical documentation, human oversight, robustness, cybersecurity, and conformity-assessment controlsEU (2024)European (n.d.)
- A regulated institution using a low-code platform to configure an agent for a high-risk financial use case remains at least a deployer under the EU AI Act and may also become a provider through own-branding or substantial modification, so low-code assembly does not reduce operator obligationsEU (2024)Microsoft (n.d.)
- APRA has not published a standalone AI prudential standard for financial services, but its existing information-security and operational-risk framework would require AI used in material processes to sit inside classified information-asset inventories, lifecycle security controls, board reporting, incident response, and material service-provider oversightAPRA (2019)APRA (2024)
- NZ already imposes a real legal floor on AI deployments through privacy, misleading-conduct, and directors' duties law, and the Office of the Privacy Commissioner adds official expectations for leadership approval, Privacy Impact Assessment, transparency, human review, and controls over retention and disclosurePrivacy (2020)Legislation (n.d.)Companies (1993)Office (n.d.)
- RBNZ and FMA have moved AI into active supervisory attention by naming AI-driven errors, privacy and cyber harms, market distortions, concentration risk, and conduct challenges as current concerns, even though they have not yet converted those concerns into a dedicated finance-specific AI rulebookRBNZ (n.d.)FMA (n.d.)
- The strongest current US obligations for AI in regulated financial decisions come from model-risk governance and adverse-action explainability, because SR 11-7 requires documented validation and board governance while CFPB says creditors may not use opaque models if they cannot provide specific and accurate reasons for denialsFederal (n.d.)CFPB (2022)
- The UK is unlikely in the near term to create a separate financial-services AI code equivalent to the EU AI Act, because the supervisory direction remains to clarify and coordinate existing principles-based regimes rather than replace them with a new sector-specific AI statuteBankofengland (n.d.)FCA (n.d.)DRCF (2023)
- A defensible minimum control set for business-built AI agents in regulated workflows includes a central approval gate with risk classification, named accountability, approved data sources, validation and testing, logging, human review, incident handling, vendor due diligence, and restricted publishing, because platform guardrails alone do not satisfy the underlying legal dutiesMicrosoft (n.d.)Office (n.d.)Federal (n.d.)Github (n.d.)
Research Question
What regulatory obligations do financial-services regulators globally, including the European Union (EU), Australia, New Zealand (NZ), the United States (US), and the United Kingdom (UK), impose on Artificial Intelligence (AI) agents and agentic systems used in regulated processes such as credit, insurance, payments, and advice, what cross-cutting control requirements such as explainability, auditability, robustness, and human oversight do those obligations mandate, and how do those requirements apply when business users create and deploy agents using low-code platforms such as Microsoft Copilot Studio?
Findings
Executive Summary
- Financial institutions already face enforceable obligations when they deploy AI agents in regulated workflows, because the EU AI Act imposes explicit high-risk controls for some finance use cases while the US, Australia, NZ, and the UK already apply model-risk, privacy, conduct, operational-risk, and governance rules to the same underlying activities.
- Compared with the jurisdictions reviewed outside the EU, the EU is the most prescriptive regime in scope, because creditworthiness and life and health insurance risk-assessment uses are treated as high-risk and must meet risk management, logging, documentation, human-oversight, robustness, and conformity-assessment duties.
- Outside the EU, regulators mostly rely on technology-neutral frameworks, but those frameworks still require secure information handling, accountable governance, validation, resilience, vendor oversight, and human review for consequential AI uses.
- Low-code citizen development does not shift accountability away from the institution, so business-built agents in regulated processes must still pass central approval, testing, logging, documentation, and oversight gates before deployment.
Key Findings
- High confidence. The EU AI Act already makes AI systems used for creditworthiness evaluation, credit scoring, and life and health insurance risk assessment and pricing high-risk, which means those systems cannot lawfully be deployed without documented risk management, logging, technical documentation, human oversight, robustness, cybersecurity, and conformity-assessment controls.
- High confidence. A regulated institution using a low-code platform to configure an agent for a high-risk financial use case remains at least a deployer under the EU AI Act and may also become a provider through own-branding or substantial modification, so low-code assembly does not reduce operator obligations.
- Medium confidence. APRA has not published a standalone AI prudential standard for financial services, but its existing information-security and operational-risk framework would require AI used in material processes to sit inside classified information-asset inventories, lifecycle security controls, board reporting, incident response, and material service-provider oversight.
- High confidence. NZ already imposes a real legal floor on AI deployments through privacy, misleading-conduct, and directors' duties law, and the Office of the Privacy Commissioner adds official expectations for leadership approval, Privacy Impact Assessment, transparency, human review, and controls over retention and disclosure.
- High confidence. RBNZ and FMA have moved AI into active supervisory attention by naming AI-driven errors, privacy and cyber harms, market distortions, concentration risk, and conduct challenges as current concerns, even though they have not yet converted those concerns into a dedicated finance-specific AI rulebook.
- High confidence. The strongest current US obligations for AI in regulated financial decisions come from model-risk governance and adverse-action explainability, because SR 11-7 requires documented validation and board governance while CFPB says creditors may not use opaque models if they cannot provide specific and accurate reasons for denials.
- Medium confidence. The UK is unlikely in the near term to create a separate financial-services AI code equivalent to the EU AI Act, because the supervisory direction remains to clarify and coordinate existing principles-based regimes rather than replace them with a new sector-specific AI statute.
- Medium confidence. A defensible minimum control set for business-built AI agents in regulated workflows includes a central approval gate with risk classification, named accountability, approved data sources, validation and testing, logging, human review, incident handling, vendor due diligence, and restricted publishing, because platform guardrails alone do not satisfy the underlying legal duties.
Assumptions
- Assumption: [assumption] The low-code scenarios considered here involve agents that influence or participate in regulated financial workflows rather than purely personal productivity tasks. Justification: [assumption] The research question is limited to credit, insurance, payments, advice, and related regulated processes, so the control analysis assumes consequential use rather than casual drafting.
Analysis
- The EU position required the least inference because the Act names the relevant finance use cases and the mandatory control categories directly.
- The other jurisdictions were evaluated by mapping AI agents onto pre-existing regulatory objects such as models, information assets, critical operations, and third-party arrangements, which is the correct analytical move where regulators remain technology-neutral.
- The conduct layer matters as much as the prudential layer because opaque or misleading outputs can breach law at the point they affect a consumer, even when the model build process itself appears controlled.
- That weighting leads to the practical conclusion that low-code governance succeeds only if the institution can prove who approved the use case, what data was allowed, how outputs were checked, and why the agent was safe to publish.
Risks, Gaps, and Uncertainties
- The RBNZ portion relies heavily on a single primary publication, so a future review should corroborate it with additional RBNZ material if more AI-specific speeches or supervisory statements are published.
- APRA may still publish more explicit AI material, but current public evidence does not yet amount to a dedicated AI prudential standard.
- UK coordination work is active and could harden into clearer assurance expectations, so the current principles-based reading should be treated as time-sensitive.
- Microsoft platform controls were assessed from public governance documentation rather than a tenant-level implementation test, so this item covers control availability and governance logic rather than implementation quality in a specific environment.
Open Questions
- How should NZ's Conduct of Financial Institutions regime be mapped explicitly onto AI-assisted financial-advice and sales workflows?
- Which US agencies are most likely to move next from general AI inquiry into finance-specific supervisory expectations for agentic workflows?
- Will the UK eventually turn DRCF coordination and DP5/22 themes into a more explicit assurance regime for high-impact financial AI systems?
Output
- Type: knowledge
- Description: Cross-jurisdiction regulatory baseline for deploying AI agents in regulated financial-services processes, with a specific control model for low-code citizen-development scenarios.
- Links:
sources
Starting points, papers, articles, and official documents.
- [x] EU AI Act full text (Regulation (EU) 2024/1689) — - primary legal text for high-risk classification, operator roles, and Title III obligations.
- [x] European Commission AI Act overview — - official summary of risk classes, high-risk obligations, and implementation timeline.
- [x] APRA CPG 234 Information Security (June 2019) — - APRA guidance on information-asset classification, lifecycle controls, reporting, and incident management.
- [x] APRA Annual Report 2024/25 — - current APRA statement of governance and operational-risk priorities.
- [x] APRA Chair John Lonsdale speech to Australian Banking Association Conference 2025 — - current APRA view on operational risk, cyber risk, third-party dependence, and proportionality.
- [x] RBNZ special topic, Rise of the machines: How could artificial intelligence impact financial stability? — - RBNZ statement of AI-related financial-stability risks.
- [x] FMA Understanding Artificial Intelligence in Financial Services — - FMA research and supervisory signal on AI use and risk management.
- [x] FMA Annual Report 2024/25 — - FMA conduct-regulation priorities, fair-dealing actions, and AI-related regulatory work.
- [x] Privacy Act 2020 — - NZ statutory privacy baseline.
- [x] Privacy Act 2020, information privacy principle 8 — - accuracy before use or disclosure.
- [x] Office of the Privacy Commissioner, Artificial intelligence and the Information Privacy Principles — - official AI guidance on human review, Privacy Impact Assessment, and accuracy.
- [x] Office of the Privacy Commissioner, Generative Artificial Intelligence expectations — - official expectations for leadership approval, transparency, human review, and retention controls.
- [x] Fair Trading Act 1986 — - NZ misleading and deceptive conduct baseline.
- [x] Fair Trading Act 1986, sections 9 to 12A — - direct text for misleading conduct in trade and services.
- [x] Companies Act 1993 — - NZ directors' duties baseline, including sections 131 and 137.
- [x] Federal Reserve SR 11-7, Guidance on Model Risk Management — - interagency model-risk guidance issued with the OCC.
- [x] Joint Request for Information on financial institutions' use of artificial intelligence — - official US interagency signal on AI benefits and risks.
- [x] CFPB newsroom guidance on credit denials by lenders using artificial intelligence — - CFPB statement of explainability and adverse-action expectations.
- [x] CFPB Circular 2022-03 — - official policy statement on complex algorithms and adverse-action notices.
- [x] Bank of England and PRA Discussion Paper DP5/22, Artificial Intelligence and Machine Learning — - UK supervisory discussion paper on AI in finance.
- [x] FCA Feedback Statement FS23/6, Artificial Intelligence and Machine Learning — - FCA summary of feedback and current policy direction.
- [x] DRCF Annual Report 2023/24 — - cross-regulator coordination on AI principles, algorithmic systems, and the AI and Digital Hub.
- [x] OSFI response to draft Guideline B-10 consultation feedback, Third-Party Risk Management — - official summary of final B-10 expectations.
- [x] OSFI final Guideline B-13 release letter — - official technology and cyber-risk expectations.
- [x] National Institute of Standards and Technology (NIST) Artificial Intelligence Risk Management Framework (AI RMF) 1.0 — - voluntary but influential framework for governance, transparency, and lifecycle controls.
- [x] Microsoft Copilot Studio security and governance — - platform governance controls relevant to low-code deployment.