The Regulation Didn't Break Your Operating Model. It Found It
(09)
Overview
The EU AI Act didn't create your operating model problem. It just made it visible.
Year
2026
Industry
Capital Markets / Operating Model

Challenge
Regulation (EU) 2024/1689 entered into force in August 2024. For financial institutions deploying AI in credit scoring, fraud detection, or automated decisioning, the high-risk compliance deadline is August 2, 2026. That's not abstract. It applies to systems already running inside your organisation. The compliance conversation has mostly focused on what the regulation requires, documentation, human oversight, bias assessment, technical logging. That's the right conversation for your legal team. It's the wrong conversation for your COO. The COO question is different: who owns the AI system end-to-end across jurisdictions, and does that person have the authority to make it one thing? The EU AI Act requires human oversight. DORA requires operational resilience. FINMA Circular 2023/1 on operational risks and resilience requires institutions to document and govern the systems driving critical functions, AI included. Each regulation is asking a version of the same question. Most institutions are answering it three different ways, in three different teams, with three different process owners who have never been in a room together. That's not a compliance gap. That's an operating model that was never designed to work across sovereign boundaries.

Impact
The institutions that will clear August 2026 without a crisis aren't the ones with the best lawyers. They're the ones that decided, before the regulation arrived, who owns the process, what governed looks like across jurisdictions, and what happens when the rules conflict. Most didn't. The deadline is the stress test. The operating model was always the problem.