
AI is already deeply embedded in everyday work across the financial services and insurance industry, and in some instances, employees are signalling their overreliance on AI and an inability to operate without it. Adoption, however, is moving much faster than compliance systems are designed to govern it, and clear compliance gaps are emerging that will prove to be a substantial risk for organisations.
Firms’ ability to effectively monitor and supervise AI-generated content and communications is also falling behind. Smarsh research shows that few UK financial services employees believe their organisation’s surveillance systems are fully equipped to detect risks in AI-generated content – and this concern is felt most acutely amongst younger professionals, the same group primarily driving AI usage.
The proliferation of AI is not slowing down, and firms will need to quickly adapt and create the right guardrails to manage employee usage and outputs.
AI is in the workflow, not just the toolbox
AI has already changed how financial services professionals work, and its implementation will only expand. Smarsh’s latest research, which surveyed 2,000 UK financial services and insurance professionals, found that 61% of professionals now use generative AI every day.
The same gap between adoption and understanding is visible in regulatory data. A joint Bank of England and FCA survey found that 75% of UK financial services firms were using AI, while only 34% said they had a complete understanding of the AI they used.
Importantly for compliance teams, nearly seven in ten (69%) say it has significantly increased the volume of content they produce. This content is not confined to the back office, it’s across briefing notes and call summaries (49%), client communications (40%), marketing and social media (38%) and, notably, compliance documentation (34%). The tools have moved well beyond administrative convenience, and the outputs they generate are landing in precisely the channels regulators care about.
Most compliance frameworks were built for a world of email, chat and traditional written communications. They were designed to capture, retain and supervise content that humans created, reviewed and sent. AI-generated content operates differently. It’s produced faster, at greater volume and often with less individual scrutiny before it’s published or shared. Fewer than half (41%) of professionals say they make significant edits to AI-generated outputs before use. Ultimately, it’s evidence that the infrastructure built to govern communications has not kept up with the way those communications are now being made.
The exposure nobody has quantified
The next compliance failure in financial services will not necessarily come from misconduct. It will likely come from firms’ inability to explain how AI-generated content was created, who checked it, what approval process it went through or how it was used. Without adapted compliance protocols, the evidence trail that regulators expect to find will simply not exist.
This is not primarily a behavioural problem on the part of employees; only 32% of financial services professionals believe their organisation’s surveillance systems are fully equipped to detect risk in AI-generated content. And 81% say they would feel more confident using AI for work-related tasks if they knew their organisation was monitoring outputs properly.
Employees are not resisting governance. The professionals most actively generating AI content, often younger workers between 25-34, are also the most aware of the compliance blind spots it creates. Framing AI risk as a generational problem misses the point, as 32% of 35-54 year olds and 28% of 55-64 year olds are using AI tools daily. It’s a structural gap between how people across organisations are working and what firms can monitor, evidence and defend.
Governance must adapt with innovation
AI adoption will not slow, and nor should it. Firms that attempt to restrict or reverse the use of AI tools will find themselves at a competitive disadvantage. The productivity gains are real, and professionals who have access to these tools will use them.
The answer is to build the governance infrastructure that makes AI adoption sustainable. That means clear policies on when and how AI tools can be used for regulated activities, extending capture and monitoring capabilities to cover AI-generated content across all relevant channels and supervision frameworks that can identify where AI outputs have been used without adequate review. Audit trails will be clearly defined to demonstrate oversight, and training is vital, helping employees to understand not just how to use AI, but what their responsibilities are when they do.
Regulators across the UK and Europe are watching this space. The FCA has already made clear that it doesn’t plan to create a separate rulebook for AI, but it will apply existing frameworks around Consumer Duty, accountability and governance. The FCA’s July 2026 Mills Review reinforced that position, describing existing frameworks such as Consumer Duty, the Senior Managers and Certification Regime (SM&CR) and operational resilience requirements as a flexible foundation, while acknowledging that the way those frameworks are applied may need to adapt to keep pace with AI.
In Europe, the EU AI Act points in the same direction. For firms within its scope, classified as high risk, traceability, documentation, human oversight and transparency will be baseline expectations. The Act may not monitor general-purpose AI use in communications, but it will expect firms to understand, document and govern how AI is being used inside the business. The principles that underpin existing communications oversight requirements do not pause because the content was generated by a machine.
The volume of AI-generated communications in financial services is only going to increase. Firms that build governance frameworks now, before a regulatory examination or a compliance failure forces the issue, will be better placed than those that treat oversight as a problem to be solved retrospectively. The gap between adoption and governance is already significant. The question is how long firms are prepared to let it grow.


