The rapid adoption of generative and agentic AI is forcing financial services firms to reconsider whether traditional information barriers remain effective in a world where machines can access, analyse and distribute sensitive data in seconds.
According to analysis from RegTech provider ACA, firms must assess whether their existing market abuse controls are equipped for AI-driven workflows, as the technology introduces new risks around inside information, data access and accountability. While AI does not change the definition of inside information under UK Market Abuse Regulation (UK MAR), it can accelerate how restricted information is accessed, combined and shared, creating new challenges for compliance teams.
The FCA’s inside information guidance, refreshed on 22 May 2026, outlines the systems and controls firms should maintain to identify, manage and disclose inside information. The regulation prohibits insider dealing, unlawful disclosure and market manipulation, defining inside information as precise, non-public information relating to issuers or financial instruments that could significantly affect prices if released.
The challenge for firms is not that AI creates a new category of regulatory risk, but that it can amplify existing weaknesses. A document previously held within a restricted deal folder can now be uploaded into an AI tool and summarised instantly. An analyst could use a model to generate client communications based on sensitive information, potentially extending access beyond approved recipients.
Agentic AI systems introduce further complexity. Autonomous tools capable of completing tasks across connected systems may retrieve restricted information, generate materials or share outputs without sufficient oversight if permissions, monitoring and approval processes are not properly designed.
The FCA has indicated it does not intend to create separate AI-specific market abuse rules. Instead, existing regulatory expectations around governance, accountability and risk management will continue to apply. This means firms remain responsible for ensuring AI systems operate within established controls, with clear ownership across compliance, legal, technology and business teams.
Recent enforcement activity demonstrates the regulator’s continued focus on weak information controls, poor governance and failures to identify suspicious activity. While cases such as Dinosaur Merchant Bank and Sigma Broking pre-date the widespread use of AI, they highlight the risks that can emerge when firms lack effective oversight of data flows, monitoring processes and reporting obligations.
As firms introduce AI into compliance, investment and client-facing workflows, they must evaluate whether their existing frameworks can manage AI-related risks. Key considerations include understanding where inside information originates, controlling which AI tools can access sensitive data, monitoring permissions, maintaining audit trails of prompts and outputs, and ensuring AI activity can be reviewed during regulatory investigations.
ACA argues that firms do not need a separate market abuse framework for AI, but they do need confidence that existing controls remain effective in AI-enabled environments. This includes reviewing AI governance, information barriers, access controls, data loss prevention measures, surveillance capabilities, recordkeeping, policies, training and assurance testing.
As financial institutions continue adopting generative and agentic AI, the ability to integrate the technology without weakening market abuse protections will become a critical compliance challenge. Firms that fail to adapt their controls risk creating new pathways for sensitive information to move beyond intended boundaries.
Copyright © 2026 FinTech Global
Facts Only
* Generative and agentic AI adoption is forcing financial services firms to reconsider traditional information barriers.
* Firms must assess if existing market abuse controls are equipped for AI-driven workflows due to risks concerning inside information, data access, and accountability.
* AI does not change the definition of inside information under UK Market Abuse Regulation (UK MAR).
* The FCA's inside information guidance outlines systems and controls for managing inside information.
* AI can accelerate how restricted information is accessed, combined, and shared, creating new compliance challenges.
* Agentic AI introduces complexity through autonomous tools that may retrieve data or share outputs without sufficient oversight if permissions are not designed correctly.
* Firms must evaluate existing frameworks to manage AI-related risks when integrating the technology into compliance, investment, and client workflows.
* Key considerations for AI integration include understanding information origin, controlling tool access, monitoring permissions, tracking prompts and outputs, and ensuring review during investigations.
* ACA argues firms need confidence that existing controls remain effective in AI-enabled environments through reviewing governance, barriers, access controls, surveillance, recordkeeping, and training.
Executive Summary
The rapid adoption of generative and agentic AI is compelling financial services firms to re-evaluate the effectiveness of traditional information barriers, given machines' ability to process sensitive data quickly. RegTech provider ACA suggests firms must assess if existing market abuse controls adequately cover AI-driven workflows due to new risks involving inside information, data access, and accountability. Although AI does not alter the definition of inside information under UK MAR, it accelerates the combination and sharing of restricted information, creating compliance challenges for teams.
The FCA's inside information guidance outlines the necessary systems and controls for managing inside information disclosure. The core challenge is that AI can amplify existing weaknesses; for example, sensitive documents can be instantly summarized or client communications generated from data access, potentially bypassing approval processes if agentic systems are not properly monitored. Agentic AI introduces further complexity as autonomous tools may retrieve restricted data or share outputs without adequate oversight if permissions and approval mechanisms are deficient.
The regulator intends to maintain existing regulatory expectations regarding governance, accountability, and risk management rather than creating separate AI-specific rules. Firms remain responsible for ensuring AI systems adhere to established controls, requiring clear ownership across compliance, legal, technology, and business functions. Recent enforcement activity confirms the focus on weak information controls, underscoring the need to evaluate frameworks against AI integration.
Full Take
The narrative centers on the tension between technological acceleration and regulatory inertia regarding information control. The core implication is that the mechanism of risk has shifted from the act of disclosure itself to the uncontrolled flow and synthesis of data via automated systems. Existing legal definitions remain stable, but the operational context for insider dealing and market abuse is being fundamentally altered by AI's speed and scope.
The pattern observed is a framing that positions regulatory oversight as reactive rather than proactive; established controls are presented as potentially insufficient against novel, rapidly evolving technical capabilities. This sets up an urgency predicated on the fear of uncontrolled information leakage facilitated by sophisticated tools. The transition from human-mediated data flow to machine-mediated data synthesis introduces accountability gaps where traditional governance structures may fail.
The unstated assumption is that existing systemic controls are robust enough to govern emergent AI behaviors. This shifts the focus from specific prohibited acts (like insider dealing) to broader failures in system architecture and oversight—governance, access control, and auditability. The real challenge lies in establishing novel accountability mechanisms for autonomous decision-making within compliance frameworks, moving beyond simple human responsibility onto the design of the AI systems themselves.
Bridge questions: What specific governance metrics should regulators mandate for assessing the risk associated with agentic systems? How can firms establish effective audit trails for prompts and outputs that satisfy both regulatory requirements and technical traceability? If existing controls are insufficient, what concrete mechanisms must be established to bridge the gap between policy and machine execution?
Sentinel — Human
The text presents a coherent analysis connecting emerging AI capabilities to established financial regulations, functioning as a synthesized industry risk assessment based on documented regulatory language.
