As at August 2026. General commentary, not legal advice. This area is moving quickly on both sides of the Atlantic - verify the current position against the FCA, PRA, federal banking agencies, NAIC and state sources before relying on it.
AI regulation in financial services, UK vs USA, is best understood through a paradox: the jurisdiction with the most centralised regulatory machinery - the UK - has chosen to write almost no AI-specific rules, while the famously fragmented US system is generating AI-specific instruments at speed, just not federally. Firms looking for "the AI rulebook" in either country are looking for something that does not exist. What exists is two different strategies for governing AI without a dedicated rulebook - and they demand different compliance postures.
The UK: technology-neutral by design
The FCA's stated position is that it has no AI-specific rules and currently intends none, on the argument that existing frameworks - the Senior Managers regime, the Consumer Duty, systems-and-controls requirements - already bind outcomes regardless of the technology producing them. The strategy is engagement over rulemaking: an AI Lab and supervisory sandboxes, joint Bank of England work on AI in financial stability, and repeated signalling that firms should innovate within existing obligations.
Around that core position, the perimeter is being mapped rather than moved. An independent review of AI and regulation reporting in early 2026, parliamentary scrutiny of whether accountability regimes give adequate assurance against AI-driven consumer harm, and the FCA's perimeter reporting each probe the same question - whether technology-neutrality holds when the technology starts making consequential decisions. Meanwhile the Critical Third Parties regime quietly does AI-relevant work from the infrastructure side: where AI provision concentrates in a few systemic vendors, designation brings direct regulatory oversight of the supplier, not just the firms using it.
The UK compliance posture this demands: map AI use to existing obligations - Consumer Duty outcomes, SM&CR responsibilities, operational resilience - and evidence that mapping, because supervision will arrive through those doors rather than through an AI Act-style gateway. UK GDPR Article 22 adds the one genuinely AI-shaped hook: rights around solely automated decisions with significant effects, which bite on fully automated underwriting and claims decisions.
The USA: no federal rulebook, fifty-one experiments
Federally, the banking agencies' revised model risk guidance brings machine learning inside ordinary model risk management while explicitly deferring generative and agentic AI - a carve-out I examine in my SR 26-2 comparison piece. There is no federal AI statute for financial services; the substantive action is state-level and sectoral.
In insurance, the NAIC's model bulletin on insurers' use of AI systems (adopted December 2023) has been adopted in a substantial and growing majority of states, requiring written AI programmes, governance proportionate to risk, and vendor oversight, all anchored to existing unfair trade practice and unfair discrimination law. Around it, states diverge: Colorado's quantitative testing regime for life insurers' use of external consumer data, New York's circular on AI in underwriting and pricing, and separate frameworks emerging in California, Texas and elsewhere. The NAIC is piloting evaluation tooling for AI systems, and the relationship between state authority and any future federal action remains contested - a question this article deliberately describes rather than forecasts, because the positions are political and dated commentary ages badly.
The US posture this demands: a fifty-state compliance map for insurers, a written AI governance programme as the common denominator, and close tracking of the handful of states whose requirements are quantitative rather than procedural.
The comparison
| Dimension | UK | USA |
|---|---|---|
| AI-specific rules | None by design; existing frameworks apply | None federally; NAIC bulletin + state frameworks in insurance |
| Anchor obligations | Consumer Duty, SM&CR, UK GDPR Art. 22, operational resilience | Unfair discrimination law, model risk guidance, state bulletins |
| Individual accountability | Named senior managers | Professional/actuarial standards; institutional enforcement |
| Vendor concentration | Critical Third Parties regime | Third-party risk guidance; NAIC vendor expectations |
| Direction of travel | Perimeter reviews; guidance signalled | State adoption spreading; federal/state boundary unresolved |
The deeper symmetry: both systems have concluded, for now, that outcomes law - fair treatment, non-discrimination, accountability, resilience - can govern AI without technology-specific statute. The difference is that the UK enforces that conclusion through one regulator's coherent framework, while the US enforces it through many overlapping ones. For a group operating in both, the binding constraint is usually the strictest state on one side and the Consumer Duty's evidential expectations on the other.
The rulebook that isn't is still a rulebook. It is just assembled from parts - and the assembly, as at August 2026, is the compliance job.
Key Takeaways
- Neither the UK nor the US has an AI-specific financial services rulebook; both govern AI through existing outcome-based frameworks, assembled differently.
- The UK's technology-neutral stance routes AI supervision through the Consumer Duty, SM&CR and operational resilience, with UK GDPR Article 22 as the main AI-shaped hook, and CTP designation covering systemic AI vendors.
- The US action is state-level: the NAIC AI bulletin as common denominator, with quantitative outliers (notably Colorado) and an unresolved federal/state boundary; SR 26-2 defers GenAI/agentic AI.
- Compliance postures differ: obligation-mapping and evidence in the UK; a state-by-state map plus written AI programme in the US.
- As at August 2026 - this landscape is moving quarterly; verify against primary sources. Not legal advice.
Frequently Asked Questions
Does the FCA have AI-specific regulations? No. The FCA's position is that existing frameworks - the Consumer Duty, the Senior Managers regime, systems-and-controls rules - govern AI-driven outcomes without technology-specific rules, supported by engagement vehicles such as its AI Lab. Firms are expected to map AI use to those existing obligations and evidence compliance through them.
What regulates AI use by US insurers? Primarily state law: the NAIC's model bulletin on AI systems - adopted by a majority of states - requires written AI programmes, proportionate governance and vendor oversight, anchored to unfair trade practice and unfair discrimination statutes, with some states (such as Colorado and New York) imposing additional, more specific requirements.
Do UK firms need consent for automated underwriting decisions? Where a decision is solely automated with legal or similarly significant effects, UK GDPR Article 22 restricts it unless specific conditions are met, and requires safeguards including human review rights. In practice, fully automated underwriting and claims decisions need a lawful basis, meaningful human-intervention routes and explainable outcomes consistent with Consumer Duty expectations.