Different Approaches to AI Governance Across the Globe 

Fortune Global Tech Forum 2019

Financial regulators from the United States, United Kingdom, and United Arab Emirates are showing that firms do not need to wait for AI-specific rules before tightening their governance, because regulatory frameworks for how artificial intelligence (AI) is used already exist. 

Regulating AI and its Use Cases 

ACA Group, a leading governance, risk, and compliance advisor and technology provider for many financial services firms in the U.S., looked into how AI governance is becoming a global examination priority. 

In its recent report titled the Financial Industry Regulatory Authority’s 2026 Annual Regulatory Oversight Report, a dedicated section was added that talks about generative AI. 

Member firms are now expected to demonstrate evidence of testing, supervision, governance, vendor due diligence, and recordkeeping for AI tools. Importantly, examiners will expect this even from firms that do not actively promote AI-driven strategies. 

The UK’s Financial Conduct Authority approached it in a different way. Instead of additional AI-specific regulations, the UK FCA’s stance is that AI should be governed through existing principles, with firms being responsible for showing that their governance produces fair, safe, and accountable outcomes. This contrasts with how the US is approaching AI oversight. 

The U.S. Securities and Exchange Commission’s 2026 examination priorities include AI oversight throughout information security, operational resiliency, and emerging financial technology categories.   

UAE: Balancing AI Adoption and Governance 

On the other part of the world, in the U.A.E., the Dubai Financial Services Authority’s intent is not to slow down AI adoption, but to make sure that firms advance innovation together with governance. 

This is to make sure that the rapid deployment of AI tools will not outpace the safeguards needed to protect markets and consumers. They also issued a circular for senior executive officers of every authorized firm under the Dubai International Financial Centre (DIFC). 

Compliance chiefs are being told that senior management should understand AI-related risks and should not simply delegate AI oversight to the technology teams. Leaders should also be able to discuss issues such as data integrity, model limitations, and the implications of widely used desktop tools such as Claude and ChatGPT. 

AI Adoption vs. Governance Gap 

In a recent ACA survey of more than 200 compliance and operations professionals, 84% of respondents reported using desktop AI tools at work, while 62% of them were chief compliance officers. 

The average firm applies AI in only around 2 of the 20 functions surveyed. This shows the gap between widespread adoption and limited, inconsistent governance, which has also heightened regulatory scrutiny. 

ACA emphasizes that firms demonstrating proper governance, effective oversight, and clear accountability will be best positioned, whether supervised in New York, London or Dubai. The firm also notes that independent assessments can help benchmark governance against regulatory expectations before gaps surface during an examination or testing. 

Sign up for our Newsletter

Click edit button to change this text. Lorem ipsum dolor sit amet, consectetur adipiscing elit