STANDARDS EXPLAINED

AI in financial services: what MiFID II, the EU AI Act, and US regulators actually require

Banks, wealth managers, and investment firms using AI face a layered compliance stack — EU AI Act, MiFID II, and US federal guidance all apply simultaneously. Here is what each framework actu

iDharma · July 23, 2026 · 7 min read
AI in financial services: what MiFID II, the EU AI Act, and US regulators actually require

Financial services firms deploying AI face one of the most demanding regulatory environments in any sector. The EU AI Act does not replace MiFID II — it sits on top of it. US federal and state regulators are issuing their own AI guidance. And no framework offers a complexity exemption: "our model is too sophisticated to explain" is not a defence that has succeeded in any enforcement action we have reviewed.

What the EU AI Act adds to existing financial regulation

The EU AI Act classifies AI systems used in financial services — particularly those making or influencing decisions on creditworthiness, insurance pricing, and investment suitability — as high-risk under Annex III. High-risk obligations include: a documented risk management system that runs throughout the system lifecycle, a technical file covering training data, accuracy benchmarks, and human oversight mechanisms, transparency obligations toward users and regulators, and a conformity assessment before deployment.

These obligations do not replace MiFID II suitability and best-execution requirements — they add a parallel compliance layer. A wealth management firm deploying AI-assisted portfolio recommendations must satisfy both the EU AI Act conformity assessment and MiFID II conduct-of-business obligations simultaneously.

What MiFID II requires of AI-assisted trading and advice

MiFID II has required algorithmic trading systems to be fully auditable since 2018. For AI-assisted or autonomous trading: the firm must be able to reconstruct every decision the algorithm made, demonstrate that it acted consistently with stated investment objectives, and show that human oversight mechanisms were effective (not merely documented). Regulators have penalised firms where "human oversight" existed on paper but the oversight personnel lacked the technical capability to actually intervene.

For AI-assisted investment advice, MiFID II suitability requirements mean the model must be able to explain, for each recommendation, why it was suitable for the specific client. A model that produces a recommendation it cannot explain fails MiFID II suitability standards regardless of how accurate it is in aggregate.

US federal guidance: where it stands

At the federal level, the US has not yet enacted comprehensive AI-specific financial services regulation. However, existing frameworks apply directly: the Equal Credit Opportunity Act and Fair Housing Act apply to any AI making or influencing credit or housing decisions; the Consumer Financial Protection Act applies to AI that causes consumer harm; and OCC, FDIC, and Federal Reserve guidance increasingly expects banks to document AI model risk management consistent with the 2011 Model Risk Management Guidance (SR 11-7), which regulators have confirmed applies to machine-learning models.

State-level: several states including New York (DFS Circular Letter No. 2024-5 on AI in insurance) and Colorado have enacted AI-specific financial services rules. The pace of state-level rulemaking is accelerating faster than federal harmonisation.

The overlap and where firms get it wrong

The most common pattern we see in financial services AI audits: firms treat the EU AI Act and MiFID II as separate workstreams handled by different teams. The result is documentation that satisfies neither. The EU AI Act conformity assessment requires technical documentation that the model governance team holds; MiFID II suitability requires customer-facing explanation capability that the compliance team is responsible for. When these teams do not share a unified technical specification, both programmes are weaker.

A second common pattern: treating model risk management (SR 11-7) as sufficient for AI Act compliance. Model risk management addresses validation and performance monitoring; the EU AI Act additionally requires fundamental rights impact assessments for high-risk systems, data governance documentation covering training data bias, and ongoing conformity monitoring at deployment. SR 11-7 compliance is necessary but not sufficient.

What iDharma maps against for financial services clients

Every iDharma audit in financial services maps simultaneously against the EU AI Act Annex III high-risk obligations, MiFID II conduct and suitability requirements where applicable, ISO/IEC 42001 AI management system requirements, and NIST AI RMF governance and measurement functions. We produce a single unified gap register — not three separate reports — so remediation can be prioritised against the frameworks that actually create legal exposure in your jurisdiction.

If you are not certain which frameworks apply to your specific AI deployment, the free Risk Snapshot is a twenty-minute assessment that produces a prioritised exposure summary. For a full audit, request a scoped engagement.

Wondering where your AI stands?