R/00 // Field note · Compliance

The uncomfortable truth about AI compliance in retail brokers.

The common story in broker corridors is that regulators are behind on AI. They are not. This is the uncomfortable, honest picture of where broker AI compliance sits in 2026 — and what that means for anyone still hoping to ship without an envelope.

Abstract regulatory architecture, editorial illustration
Kasim Javed · Founder, KJ Capital12 min read

Every second broker AI conversation I have starts with a variation on the same theme: the regulator is behind, we have room, we can ship this. It is a comforting story. It is also wrong.

The regulator is not behind. The regulator is asking the exact right questions, and the firms that have not started answering them are the ones that will have to answer them under time pressure.

What supervisors are actually asking

In every supervisor conversation I have been read into over the last eighteen months, the questions have been the same. Who is accountable for this system under SM&CR? What is the policy layer? What sources does the retrieval span? What evaluation harness proves the system stays within the envelope? What is the reasoning trail behind an individual customer-facing decision?

These are not gotcha questions. They are the questions of a supervisor who has read the model risk management literature, the Consumer Duty guidance and the current AI governance discussion. They are the questions brokers should have been ready for two years ago.

Where the industry actually sits

Around 15% of retail brokers have a coherent answer. Another 30% have a partial answer. The rest have posture. That is not a sustainable distribution; the compliance envelope is going to become table stakes within twelve months, and firms that skip it will pay the difference in supervisor attention, remediation cost and reputational drag.

FAQ

Is the FCA about to publish AI-specific rules?

Rules will come from a combination of existing frameworks (Consumer Duty, SM&CR, model risk management) rather than a standalone AI rulebook. The direction is clear.

CySEC?

Similar direction, with an emphasis on governance and audit trail. Same architecture applies.

Can we retrofit compliance?

Retrofitting is expensive and often architecturally impossible. Designing the envelope first is the shortcut, not the tax.

What does 'coherent answer' look like?

A three-layer architecture — policy, retrieval, evals — with SMF accountability, per-decision reasoning trails and a live evaluation harness.

Cost?

The £15k Diagnostic produces the control map. The £75k+ Build implements it. Every subsequent AI system inside the envelope is cheaper and faster to ship.

Want this rigour applied inside your firm?

Start with the free 5-minute AI Readiness Score, or go straight to the £15k Financial AI Diagnostic — a two-week engagement that produces a costed build plan mapped to your regulator, your stack and your P&L.