In July 2026, ESMA fined Moody’s Germany EUR 2,145,000 for misreporting under MiFID II[1]. The fine was not for fraud. It was for data errors in a reporting process: automated, systematic, and apparently undetected until regulators caught it. That is the kind of failure that keeps compliance officers awake, and it is exactly the category of risk that grows when AI-assisted workflows sit between your firm’s data and its regulatory submissions.

This is the context in which the EU AI Act’s requirements for high-risk AI systems are now being enforced. And if your firm uses AI to inform, draft, route, or flag decisions in client-facing or compliance-sensitive processes, parts of that regulatory framework already apply to you.

What the EU AI Act actually requires of financial services firms

The EU AI Act classifies AI systems used in financial services, credit assessment, and certain client-facing decisions as high-risk[2]. High-risk designation carries concrete obligations: human oversight mechanisms, documented risk management systems, data governance requirements, and logging of system outputs sufficient to enable post-hoc audit.

The practical implication is this: if your firm uses an AI model to help with suitability assessment, AML screening, credit decisions, or document classification for regulatory purposes, you cannot treat that system as a black box. You need to be able to explain what it did, why it did it, and who reviewed its output before it influenced a regulated decision. The “black-box” nature of many AI systems is precisely what regulators are targeting, because it makes that explanation impossible[3].

The Act is not asking you to ban AI from these processes. It is asking you to govern them.

Why financial services has the highest AI production deployment rate and the highest exposure

Financial services firms adopted AI faster than most sectors. Production deployment of AI agents in financial services runs at 21%, the highest of any industry, driven by early investment in document processing and compliance automation[4]. That adoption rate is commercially rational. AI can reduce document review time dramatically. NTT Data cut one operational process from 30 minutes to near-instant completion using AI automation[5].

But the same deployment rate that creates competitive advantage also creates regulatory exposure. Moody’s misreporting fine illustrates the basic principle: the output of an automated system is still your firm’s output. Regulators do not accept “the system did it” as an explanation. They accept accountability from a named individual, which under SMCR means a named senior manager.

The question is not whether AI makes your decisions faster. It is whether you can explain those decisions to a regulator, and who signs their name to that explanation.

The ECB has flagged customer-facing AI in financial services as presenting substantial discrimination risk where systems lack robust validation[6]. BaFin has identified AI-driven financial data processes as a source of systemic cyber risk[7]. The regulatory direction is not ambiguous. These bodies are watching the gap between what firms claim their AI systems do and what those systems actually do.

What the ‘glass box’ approach means in practice

The emerging framework for governing AI in regulated environments is sometimes called the glass box approach: every model decision should be observable, testable, and modifiable by a human staff member before it produces a regulated output[3]. This is not a technology requirement in the first instance. It is a process design requirement.

In practice, glass box governance means three things:

First, map every AI-assisted process that touches a regulated output. This does not need to be a formal project. It needs to be honest. Walk through your firm’s workflows for suitability letters, client onboarding, AML checks, and regulatory reporting. At each stage, note where an AI system flags, sorts, drafts, or recommends. That map is the foundation of your EU AI Act compliance position.

Second, define and document the human review step for each of those processes. The AI flags a transaction as potentially suspicious. Who sees that flag? What decision do they make? What is logged? If the answer is “the system routes it to a queue and someone looks at it eventually,” that is not governance. Governance means a named person, a defined decision, and a record. Under SMCR, that named person carries accountability.

Third, check your vendor agreements. If you are using a third-party AI tool in a high-risk process, your vendor’s EU AI Act compliance posture is your problem too. Procurement due diligence now includes asking whether the tool is documented as required for high-risk deployment, what audit logging it provides, and what indemnity it carries for system failures. Anthropic’s USD 1.5 billion copyright settlement[8] is a recent reminder that AI vendors carry legal risk that can transfer to customers if contracts are not structured carefully.

What to do if your firm is in this position

Most IFA and wealth management firms sit somewhere on a spectrum between “we have used AI for a year and never thought about any of this” and “we have a compliance team reviewing AI outputs weekly.” Neither extreme is the norm. The majority are somewhere in the middle: AI tools in use, some awareness of regulatory expectations, limited formal governance.

Here is a practical starting point:

1. Identify your high-risk AI processes. Using the EU AI Act’s definition: AI in suitability decisions, credit, AML, or client-facing advice processes is likely high-risk. AI used for internal scheduling or drafting marketing copy is not. The distinction matters. Focus your governance effort on the high-risk category first.

2. Audit your logging. Can you reconstruct what your AI system recommended or flagged for any given client interaction, and when? If not, that is the first gap to close. Logging is the minimum condition for post-hoc regulatory audit.

3. Name the accountable person. For each high-risk AI process, there should be a named senior manager under SMCR who is accountable for the governance of that process. This is not a technicality. It is the mechanism by which the regulator holds a firm to account when something goes wrong.

4. Review your vendor agreements now, not after a review. Ask your AI vendors directly whether their tools are documented as high-risk AI systems under the EU AI Act, and what compliance evidence they can provide. If they cannot answer the question, treat that as a risk.

Financial services showed the highest AI production deployment rate precisely because AI delivers measurable value in document-heavy, compliance-sensitive processes[4]. That value is real and worth protecting. The way to protect it is not to pull back from AI deployment, but to govern it well enough that when a regulator looks at your processes, the accountability is clear.

The Moody’s fine was EUR 2.1 million for data errors in a reporting process[1]: for a smaller firm, the proportionate equivalent would be smaller in absolute terms and potentially firm-ending in relative ones. The EU AI Act gives you a framework for avoiding that outcome. The question is whether you use it before or after a regulator makes the point for you.

If you want to think through where your firm’s current AI processes sit relative to these requirements, a discovery call with Cordrey Consulting is a reasonable place to start.


This article is for informational purposes only and does not constitute regulated financial advice or a compliance opinion. Consult a qualified compliance professional for advice specific to your firm.


Sources

[1] ESMA, ‘Moody’s Germany fined EUR 2,145,000 for misreporting’, European Securities and Markets Authority, July 2026. Available at: https://www.esma.europa.eu/press-news/esma-news/moodys-germany-fined-eur-2145000-misreporting-esma

[2] European Parliament and Council, ‘Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)’, Official Journal of the European Union, 12 July 2024. Available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX

[3] a16z, ‘The Glass Box Approach to Enterprise AI’, Andreessen Horowitz, 31 July 2026. [Industry commentary on observable, auditable AI design in regulated environments.]

[4] van Riel, Z. (2026) ‘Why 78% of AI Agent Pilots Never Reach Production’, AI Engineer Blog. Available at: https://zenvanriel.com/ai-engineer-blog/ai-agent-scaling-gap-pilot-production-2026/

[5] OpenAI, ‘NTT Data’, OpenAI, 2026. Available at: https://openai.com/index/ntt-data

[6] European Central Bank (2024) ‘Report on AI in customer-facing financial services’, European Central Bank. [Cited for customer discrimination risk finding.]

[7] BaFin (2026) ‘Industry report on AI-driven financial data intermediation and systemic cyber risk’. [Cited for systemic cyber risk finding attributed to AI-driven financial data intermediation.]

[8] Digital Applied, ‘Anthropic’s $1.5B Settlement: What Fair Use Now Costs’, Digital Applied, 25 July 2026. Available at: https://www.digitalapplied.com/blog/anthropic-1-5b-copyright-settlement-approved-content-ip