Regulation & Compliance

The AI Rulebook That Isn't: AI Regulation in Financial Services, UK vs USA

By Jonas Osman Abdelghafour · August 2026

As at August 2026. General commentary, not legal advice. This area is moving quickly on both sides of the Atlantic - verify the current position against the FCA, PRA, federal banking agencies, NAIC and state sources before relying on it.

AI regulation in financial services, UK vs USA, is best understood through a paradox: the jurisdiction with the most centralised regulatory machinery - the UK - has chosen to write almost no AI-specific rules, while the famously fragmented US system is generating AI-specific instruments at speed, just not federally. Firms looking for "the AI rulebook" in either country are looking for something that does not exist. What exists is two different strategies for governing AI without a dedicated rulebook - and they demand different compliance postures.

The UK: technology-neutral by design

The FCA's stated position is that it has no AI-specific rules and currently intends none, on the argument that existing frameworks - the Senior Managers regime, the Consumer Duty, systems-and-controls requirements - already bind outcomes regardless of the technology producing them. The strategy is engagement over rulemaking: an AI Lab and supervisory sandboxes, joint Bank of England work on AI in financial stability, and repeated signalling that firms should innovate within existing obligations.

Around that core position, the perimeter is being mapped rather than moved. An independent review of AI and regulation reporting in early 2026, parliamentary scrutiny of whether accountability regimes give adequate assurance against AI-driven consumer harm, and the FCA's perimeter reporting each probe the same question - whether technology-neutrality holds when the technology starts making consequential decisions. Meanwhile the Critical Third Parties regime quietly does AI-relevant work from the infrastructure side: where AI provision concentrates in a few systemic vendors, designation brings direct regulatory oversight of the supplier, not just the firms using it.

The UK compliance posture this demands: map AI use to existing obligations - Consumer Duty outcomes, SM&CR responsibilities, operational resilience - and evidence that mapping, because supervision will arrive through those doors rather than through an AI Act-style gateway. UK GDPR Article 22 adds the one genuinely AI-shaped hook: rights around solely automated decisions with significant effects, which bite on fully automated underwriting and claims decisions.

The USA: no federal rulebook, fifty-one experiments

Federally, the banking agencies' revised model risk guidance brings machine learning inside ordinary model risk management while explicitly deferring generative and agentic AI - a carve-out I examine in my SR 26-2 comparison piece. There is no federal AI statute for financial services; the substantive action is state-level and sectoral.

In insurance, the NAIC's model bulletin on insurers' use of AI systems (adopted December 2023) has been adopted in a substantial and growing majority of states, requiring written AI programmes, governance proportionate to risk, and vendor oversight, all anchored to existing unfair trade practice and unfair discrimination law. Around it, states diverge: Colorado's quantitative testing regime for life insurers' use of external consumer data, New York's circular on AI in underwriting and pricing, and separate frameworks emerging in California, Texas and elsewhere. The NAIC is piloting evaluation tooling for AI systems, and the relationship between state authority and any future federal action remains contested - a question this article deliberately describes rather than forecasts, because the positions are political and dated commentary ages badly.

The US posture this demands: a fifty-state compliance map for insurers, a written AI governance programme as the common denominator, and close tracking of the handful of states whose requirements are quantitative rather than procedural.

The comparison

Dimension UK USA
AI-specific rules None by design; existing frameworks apply None federally; NAIC bulletin + state frameworks in insurance
Anchor obligations Consumer Duty, SM&CR, UK GDPR Art. 22, operational resilience Unfair discrimination law, model risk guidance, state bulletins
Individual accountability Named senior managers Professional/actuarial standards; institutional enforcement
Vendor concentration Critical Third Parties regime Third-party risk guidance; NAIC vendor expectations
Direction of travel Perimeter reviews; guidance signalled State adoption spreading; federal/state boundary unresolved

The deeper symmetry: both systems have concluded, for now, that outcomes law - fair treatment, non-discrimination, accountability, resilience - can govern AI without technology-specific statute. The difference is that the UK enforces that conclusion through one regulator's coherent framework, while the US enforces it through many overlapping ones. For a group operating in both, the binding constraint is usually the strictest state on one side and the Consumer Duty's evidential expectations on the other.

The rulebook that isn't is still a rulebook. It is just assembled from parts - and the assembly, as at August 2026, is the compliance job.

Key Takeaways

Frequently Asked Questions

Does the FCA have AI-specific regulations? No. The FCA's position is that existing frameworks - the Consumer Duty, the Senior Managers regime, systems-and-controls rules - govern AI-driven outcomes without technology-specific rules, supported by engagement vehicles such as its AI Lab. Firms are expected to map AI use to those existing obligations and evidence compliance through them.

What regulates AI use by US insurers? Primarily state law: the NAIC's model bulletin on AI systems - adopted by a majority of states - requires written AI programmes, proportionate governance and vendor oversight, anchored to unfair trade practice and unfair discrimination statutes, with some states (such as Colorado and New York) imposing additional, more specific requirements.

Do UK firms need consent for automated underwriting decisions? Where a decision is solely automated with legal or similarly significant effects, UK GDPR Article 22 restricts it unless specific conditions are met, and requires safeguards including human review rights. In practice, fully automated underwriting and claims decisions need a lawful basis, meaningful human-intervention routes and explainable outcomes consistent with Consumer Duty expectations.

Related reading

About the author

Jonas Osman Abdelghafour is a UK-based actuary and financial engineer specialising in quantitative risk management, reinsurance pricing, catastrophe bond structuring and stochastic modelling. Learn more about Jonas or get in touch.