If you advise expat and cross-border clients — a firm established in Dubai or Singapore with clients scattered across the EU, the UK, the Gulf and Asia — you have a problem a purely domestic adviser does not. The moment you put an AI tool anywhere near client data or client-facing output, you are answering five or six regulators’ questions, and they are not the same questions.

The picture in mid-2026 is more navigable than the headlines suggest. Most financial regulators have converged on the same expectations: know what AI you use, keep a human accountable for it, control the data that feeds it, and do not let it say things you cannot stand behind. The differences are in enforcement style and timing. What follows is a working map, jurisdiction by jurisdiction, then the conclusion I keep arriving at with international firms: run one governance baseline, set to the strictest regime that touches you, rather than a per-jurisdiction patchwork.

The European Union: the anchor regime, with a moving timeline

The EU AI Act remains the world’s most comprehensive AI statute, and for most international advisory firms it is the regime that ends up setting the ceiling. But its timeline moved significantly in the past year.

Obligations on providers of general-purpose AI models (the foundation models behind most adviser-facing tools) took effect on 2 August 2025, supported by the voluntary General-Purpose AI Code of Practice, with Commission enforcement powers following from August 2026 [1]. The high-risk obligations — originally due 2 August 2026 — were deferred by the “Digital Omnibus on AI”, provisionally agreed by EU legislators on 7 May 2026: standalone high-risk systems under Annex III (which includes creditworthiness assessment and certain insurance pricing uses) now attach from December 2027, and AI embedded in regulated products under Annex I from August 2028. Crucially, the Article 50 transparency obligations — telling people when they are interacting with an AI system, and disclosing AI-generated content — were not deferred and apply from 2 August 2026.

For a typical advisory firm using AI for research, drafting, meeting notes and client communications, most tools will not be “high-risk” under the Act at all — the transparency obligations, the prohibited-practices list (in force since February 2025) and the deployer-side duty of AI literacy are the parts most likely to touch day-to-day work.

Two other EU instruments matter as much as the AI Act for financial firms. GDPR applies in full to any processing of EU-resident client data — and its reach does not stop at the EU border, a point I return to below. And DORA, in application since January 2025, treats AI vendors as ICT third-party service providers: they belong in your register of information, your contracts and your exit planning like any other critical supplier [2]. The European supervisory authorities designated their first critical ICT third-party providers in late 2025 — dominated by the cloud platforms on which most AI tooling runs.

The United States: no single statute, but active supervision

The US still has no federal AI law, and the state-level picture has, if anything, retreated. Colorado’s pioneering AI Act — the first comprehensive state statute aimed at algorithmic discrimination — was delayed from February to June 2026, then substantially revised and pushed to January 2027 by a replacement bill signed in May 2026, with enforcement of the original law also tangled in litigation. Firms that built plans around a hardening US state patchwork should re-check those assumptions.

What fills the gap is supervision through existing securities law. The SEC’s examination priorities for fiscal 2026 put adviser use of AI squarely in scope: examiners will look at whether firms have policies and procedures to monitor and supervise their AI use, whether staff are trained, and — pointedly — whether representations about AI capabilities are accurate [3]. That last item reflects the SEC’s continuing “AI washing” enforcement line, which began in March 2024 with charges against two investment advisers for false and misleading statements about their use of AI [4]. For broker-dealers, FINRA’s 2026 Regulatory Oversight Report devotes a section to generative AI: assess compliance obligations before deployment, establish governance over usage, address hallucination and bias, and keep humans monitoring outputs — with early attention to autonomous AI agents [5].

On the framework side, the NIST AI Risk Management Framework remains voluntary but is the de facto US reference for AI governance [6]; in February 2026 the US Treasury, with the Cyber Risk Institute, released a Financial Services AI Risk Management Framework mapping NIST’s structure into sector-specific control objectives. Neither is law; both are what a US examiner will recognise as good practice.

Singapore: from principles to supervisory expectations

Singapore has run the longest arc from soft principles to formal expectations. MAS published its FEAT principles — fairness, ethics, accountability, transparency — back in 2018; in November 2025 it consulted on Guidelines on Artificial Intelligence Risk Management applying across financial institutions, including capital markets intermediaries and advisory firms [7]. The consultation closed at the end of January 2026, with a 12-month transition period once the guidelines are finalised.

The substance previews where other regulators are heading: board-level accountability for AI, an enterprise-wide inventory of all AI systems in use or planned, risk-materiality assessment for each, lifecycle controls from development through monitoring, and demonstrable capability to operate what you deploy. The inventory requirement in particular — you cannot govern what you have not identified — is quietly becoming the common denominator of every serious AI supervisory framework.

UAE and the DIFC: accountability without a bespoke rulebook

The DFSA, regulating firms in the Dubai International Financial Centre, has so far chosen expectations over new rules. In June 2026 it issued a “Dear SEO” letter setting out its regulatory expectations on AI risk management in the DIFC: firms remain fully accountable for their use of AI, and senior management are expected to exercise appropriate oversight and ensure AI is operated in a controlled and responsible manner.

The context is rapid adoption — the DFSA’s 2025 AI survey found generative AI use in the DIFC nearly tripling year on year, with governance maturing more slowly than uptake [8]. For advisory firms headquartered in the DIFC with clients in Europe and Asia — a common shape among international advisers — the DFSA expects governance, but the detailed content of that governance will usually be set by the stricter regimes their client base drags in.

Hong Kong: early, specific guidance on generative AI

Hong Kong’s SFC was among the first securities regulators to issue dedicated generative AI guidance, in a circular to licensed corporations of November 2024. It applies a risk-based lens: uses classed as high-risk — notably generating investment recommendations or advice to clients — attract stronger expectations around senior management responsibility, model testing, output review and third-party vendor risk [9]. The HKMA issued parallel guidance for banks on consumer-protection aspects of generative AI in August 2024, alongside a sandbox for supervised experimentation. The result is one of the clearer supervisory positions in Asia: no new statute, but specific written expectations that examiners can hold firms to.

The UK, briefly

The UK sits closest to the DIFC model: the FCA has explicitly ruled out new AI-specific rules, relying on existing frameworks — the Consumer Duty, the Senior Managers and Certification Regime, established governance expectations — while running an AI Lab and a live AI testing service for firms deploying consumer-facing models [10][11]. I cover the UK position in full in a companion piece, AI governance for UK financial advisers — the short version is that “no new rules” does not mean “no expectations”.

Three trap cases

Each jurisdiction above is manageable in isolation; cross-border firms get caught in the seams. Three patterns recur.

  • The adviser outside the EU using AI on EU-resident client data. A Dubai or Singapore entity advising a client resident in France is very likely within GDPR’s extraterritorial reach, and feeding that client’s data into an AI tool is processing like any other — requiring a lawful basis, a processor agreement, and a lawful transfer mechanism if the data leaves the EEA. The EU–US Data Privacy Framework still stands but is under sustained legal challenge; prudent firms keep standard contractual clauses and transfer impact assessments in place rather than relying on the adequacy decision alone.
  • AI-generated marketing that crosses borders. Financial promotion rules attach where material is received, not where it was generated. One AI-drafted market commentary sent to a mailing list spanning the EU, UK, UAE and US can simultaneously engage EU transparency obligations for AI-generated content (from August 2026), the FCA’s financial promotions regime, and — if it overstates what your AI does — the SEC’s AI-washing enforcement line. Generated content needs the same sign-off discipline as human-written content, plus disclosure where a regime requires it.
  • Vendor tools trained and hosted in the US. Most advisory AI tooling ultimately runs on US-headquartered model providers and cloud platforms. That single fact pulls in GDPR transfer rules (for EU client data), DORA-style third-party registers (for EU-regulated entities), MAS’s proposed inventory expectations, and the vendor due diligence the SFC and FINRA both spell out. Every regulator in this map places responsibility for third-party AI squarely on the regulated firm, not the vendor.

One baseline, not six rulebooks

Here is where the map converges. Maintaining a separate AI governance regime for each jurisdiction your clients touch would drown you in version control — and the regimes overlap far more than they conflict. Every framework above wants roughly the same artefacts: an inventory of AI systems, a named accountable owner, risk classification, human review of client-facing output, vendor due diligence, data-handling controls, and records that prove all of it.

So the recommendation is simple: run one governance baseline, set to the strictest regime that plausibly applies to you — in practice usually the EU AI Act’s transparency and literacy obligations plus GDPR’s data rules — and treat everything else as a delta check. A baseline built to EU standards, with MAS-style inventory discipline and SEC-style substantiation of any AI claims in your marketing, satisfies the DFSA’s accountability expectations and the SFC’s circular almost by construction. The reverse is not true.

Pair it with a one-page jurisdiction matrix, reviewed quarterly, answering five questions:

QuestionWhy it mattersRegimes it can trigger
Where is each advising entity established and licensed?Determines your primary supervisor and prudential regimeDFSA, MAS, FCA, SEC/FINRA, EU member-state regulators
Where are your clients resident?Client residence drags in data protection and conduct rules regardless of where you sitGDPR, EU AI Act transparency, local financial promotion rules
Where is client data processed and stored?Cross-border transfers need a lawful mechanismGDPR Chapter V, DPF/SCCs, local data protection laws
Where are your AI vendors established and their models hosted?Third-party AI is your regulatory responsibility, not the vendor’sDORA, MAS AIRG, FINRA/SFC vendor expectations
Where is AI-assisted marketing received?Promotion rules attach at the point of receiptFCA promotions regime, SEC Marketing Rule, EU Article 50

For each client segment, the matrix tells you which rules attach and therefore which parts of the baseline are load-bearing. When a new tool or client market arrives, you update one document, not six.

None of this needs to be heavyweight. A firm of twenty advisers can hold the whole thing — inventory, ownership, review rules, vendor list, matrix — in a handful of living documents, provided someone owns them. If you are starting from nothing, the sequencing in my simple guide to automation governance for regulated firms applies just as well to AI: start with what you have, classify it, and put a human name against every system before writing a single policy.

The map will keep shifting — the EU’s deferred high-risk dates, MAS’s final guidelines and the transatlantic transfer framework are all live in the second half of 2026. But the direction of travel is uniform, and firms that build the common core now will find each new rule lands as a delta, not a rebuild.

This article is for informational purposes only and does not constitute regulated financial advice, legal advice, or a compliance opinion. Consult a qualified compliance professional for advice specific to your firm.

Sources

[1] European Commission, ‘Timeline — Implementation of the EU AI Act’, accessed July 2026. Available at: https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act

[2] EIOPA, ‘Digital Operational Resilience Act (DORA)’, accessed July 2026. Available at: https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en

[3] US Securities and Exchange Commission, ‘SEC Division of Examinations Announces 2026 Priorities’, November 2025. Available at: https://www.sec.gov/newsroom/press-releases/2025-132-sec-division-examinations-announces-2026-priorities

[4] US Securities and Exchange Commission, ‘SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of Artificial Intelligence’, March 2024. Available at: https://www.sec.gov/newsroom/press-releases/2024-36

[5] FINRA, ‘2026 FINRA Annual Regulatory Oversight Report — GenAI: Continuing and Emerging Trends’, December 2025. Available at: https://www.finra.org/rules-guidance/guidance/reports/2026-finra-annual-regulatory-oversight-report/gen-ai

[6] NIST, ‘AI Risk Management Framework’, accessed July 2026. Available at: https://www.nist.gov/itl/ai-risk-management-framework

[7] Monetary Authority of Singapore, ‘Consultation Paper on Proposed Guidelines on Artificial Intelligence Risk Management for Financial Institutions’, 17 November 2025. Available at: https://www.mas.gov.sg/publications/consultations/2025/consultation-paper-on-guidelines-on-artificial-intelligence-risk-management

[8] Dubai Financial Services Authority, ‘New DFSA AI survey: Generative AI adoption has nearly tripled within the DIFC in last 12 months as governance continues to develop’, 2025. Available at: https://www.dfsa.ae/news/new-dfsa-ai-survey-generative-ai-adoption-has-nearly-tripled-within-difc-last-12-months-governance-continues-develop

[9] Securities and Futures Commission of Hong Kong, ‘Circular to licensed corporations — Use of generative AI language models’, 12 November 2024. Available at: https://apps.sfc.hk/edistributionWeb/gateway/EN/circular/openAppendix?refNo=24EC55&appendix=0

[10] Financial Conduct Authority, ‘AI and the FCA: our approach’, accessed July 2026. Available at: https://www.fca.org.uk/firms/innovation/ai-approach

[11] Financial Conduct Authority, ‘FCA set to launch live AI testing service’, 2025. Available at: https://www.fca.org.uk/news/press-releases/fca-set-launch-live-ai-testing-service