Financial sector needs AI-specific regulations to protect consumers, study finds
Financial institutions need a dedicated regulatory framework for the use of artificial intelligence (AI) to reduce risks and better protect consumers, according to new research from Durham University Business School.
The study found that existing AI regulation remains fragmented across the world. While jurisdictions such as the European Union and China have introduced AI legislation, countries including the UK and the United States have adopted a lighter regulatory approach.
Professor Habib Ahmed, from our Department of Finance, argues that the finance sector requires its own tailored framework to address the unique risks associated with AI. He suggests the European Union's AI Act could provide a foundation for a finance-specific model.
Consumer protection at the centre
The research highlights a range of risks linked to the growing use of AI in financial services. These include the misuse of personal data, bias in decision-making, reliance on third-party providers and cybersecurity threats.
The study found that these challenges have the potential to affect core regulatory objectives, including consumer protection, financial stability and financial integrity.
As AI becomes more widely embedded in financial services, the research warns that the potential consequences of poor oversight could extend from individual consumers to the wider economy and global financial markets.
A framework tailored to finance
To develop the framework, Professor Ahmed first identified the key risks facing financial institutions when implementing AI. He then examined existing approaches to AI governance, drawing particularly on the European Union's AI Act, which sets out measures for risk management, governance and oversight.
His framework assesses risks when it comes to AI, identifying them under one of four categories:
- Unacceptable: if an AI system is deemed unacceptable, it should be prohibited and not be used at all by finance institutions. This could include any AI usage that manipulates people's decisions or exploits them. Examples include the unauthorised scraping and use of facial imagery.
- High: these AI systems must be regulated and should be utilised with caution, as they can pose significant risks to people's health, rights or security, for example, access to vital services or data.
- Limited: for low-risk AI usage, the framework suggests that providers should be transparent and inform users when they are interacting with AI. For example, AI-generated text or video content.
- Minimal: AI usage here does not need to adhere to a framework, i.e. AI spam filters or video games.
Preparing for increased AI adoption
The study concludes that AI will play an increasingly significant role in the future of financial services, making effective regulation more important than ever.
Professor Ahmed argues that policymakers and regulators should consider adapting existing frameworks, such as the EU AI Act, to the finance sector. Doing so, he suggests, would help ensure that financial institutions can benefit from AI while reducing risks to consumers and maintaining trust in the financial system.
Find out more
- Learn more about Professor Habib Ahmed and his research at Durham University Business School.
- Read the study: “Regulatory framework for artificial intelligence (AI) in the financial sector: lessons from the European Union AI act”, published in Journal of Financial Regulation and Compliance.
- Our Department of Finance is part of a triple-accredited Business School ranked 58th globally in the Financial Times Masters in Finance 2025 and joint 61st globally in the QS Masters in Finance 2026. Visit our Finance webpages for more information on our undergraduate and postgraduate programmes.