Last Updated on August 24, 2026 by TMB
According to a study by Durham University, specific regulations need to be put in place to govern the use of AI in the financial sector. As AI becomes a much bigger part of our everyday lives, our finances are no exception.
But as the study also claims, some countries are more on top of this than others. China and EU member states were noted as already having such measures, while the US and the UK are lagging behind.
What New AI Laws Are Needed
The report stated that the use of AI comes with unique challenges and risks for consumers, and that having laws in place will help mitigate some of them. This harm reduction, however, is hampered by inconsistent AI-related laws across regions, creating gaps.

Some of the biggest issues identified include the mishandling of consumer data, which is already causing concern beyond financial services. Then there are possible errors in automated decision-making. Many finance sector businesses now use AI for decision-making, such as approving claims and loans. But with no concrete laws to guide these use cases, unfair denials could occur or unsuitable approvals. Cybersecurity threats are also a major concern as AI use creates another layer of exposure for businesses.
Professor Habib Ahmed of Durham’s Department of Finance also noted that the current EU AI laws could serve as a template for other countries. The US and the UK were highlighted as currently relying on a principles-based approach, which will be unsuitable moving forward.
The Solution Proposed
Professor Ahmend analyzed the existing risks associated with AI, as well as the governance models already in place, and developed a framework suitable for broad application. This framework divides AI use into four tiers:
- Minimal Risk Applications such as spam filters
- Limited Risk Applications such as text and image generation, which would require transparency and disclaimers for users that engage with it
- High Risk Applications, which affect access to essential services, would face heavy government regulation
- Unacceptable Applications, such as unauthorized data harvesting, would be outside of the framework and banned
While the AI space has evolved and will continue to evolve, the laws that govern it must do so as well. This framework offers a baseline categorization that allows both governments and individuals to assess the risk of various applications and respond accordingly. Hopefully, we will see the US, UK, and other countries apply more specific laws to protect consumers at scale.


