
It is market lore that regulation – and the concomitant complexities of compliance – are an ever tightening ratchet. What is less known is that this accelerating complexity can be qualified and quantified: Following Basel 3, the volume of words that had to be consumed and processed to understand one single rule increased from 600 to more than 25,000 – a 4,000% increase. Similarly, over the course of a decade, the wordcount describing UK banking regulation almost doubled from 400,000 to 720,000 words.
Recently, regulators are observing that increasing verbosity and accelerating volumes of regulation can impede market growth – and indeed, put firms participating in those markets at risk. More to the point, they have begun to do something about it.
From April 2028, the FCA’s PS26/15 regulation removes wholesale FX derivatives from MiFIR reporting obligations.This is forecast to bring about some £108m/year in savings against a projected £148.8m one-off implementation cost. For those not intending to sit on their hands until 2028, there is an interim “flexible supervisory approach”. On the broader canvas, we can expect the industry to regard this as a lobbying “win” and to push for similar “descoping “ across other major jurisdictions.
Across venues
There is, however, a wrinkle that the descoping debate tends to skip over. A firm trading FX across venues surfaces two discrete obligations The first is statutory: MiFIR, EMIR, MAR, published by regulators, consulted on in the open, and increasingly available in something approaching structured form.
The second is contractual, comprising the rulebooks of every exchange and clearing house whose membership the firm holds. These are amended by circular, rarely preceded by consultation, issued frequently as an attachment rather than as a change to a consolidated text, and (often) absent an authoritative in-force version to point at. No regulator publishes them, no policy statement announces them.
When the FCA removes FX derivatives from MiFIR scope, this second corpus is untouched. As such, the lobbying “win” narrows the first source of obligation while the second carries on growing. In reality, member firms have rather less leverage over exchanges than a trade association has over its regulator.
At the same time, many firms are leaning into technological enhancements that enable compliance efficiencies. In the same reporting space, the ISDA-sponsored Digital Regulatory Reporting initiative (DRR) reports operational savings of up to 50% for adopters. Through sharing reporting IP, the industry is seeking to emerge with a common corpus of applied regulatory knowledge that can be applied systematically to any well-defined data input.
That being said, DRR is a long way from the operational reality of most firms and workflows. The real world is messy, unstructured and full of grey areas. That is precisely where LLMs are being proposed – naively – as a silver-bullet solution.

Challenge of compliance
The challenge of compliance is to understand which of the hundreds of rules, and new rules, apply in any given situation. Previously the domain of the SME, the greybeard, the person who knew where the skeletons were buried, the Keepers of the Context, AI holds the promise to reduce time to compliance, and time spent on compliance. AI also changes how regulation is captured and structured in the first place: the shift from a folder full of PDFs to an online data repository.
In concrete terms, this means that software can track the evolution of a proposal from draft form through to the new version of the regulation. It is feasible to redline the new draft against the existing regulation against the in-force version.
At a deeper level, tools can track the regulatory topics that a document touches.Technology can point us at Enhanced Due Diligence rules captured in myriad places – from rules to guidance to notices of fines. Specialised AI models can extract accurate text from PDFs, structure this semantically into comprehensive and comprehensible data structure, and decompose the text into “synthetic obligations”. These capture the intent of multiple sentences, rather than relying on the user to “read Art. 2(b)(iii) in conjunction with Art. 2(b)”. They form atomic units that conjoin a messy text library to the brave new world of databases and coded logic.
Decomposition may get you structured text. It does not, however, create a pathway to production code. The harder step is auto-formalisation – using an LLM to turn an obligation into machine-executable logic – not simply a better set of more usable documents.
Technologies exist to address this gap. Catala, for instance, the declarative legal-logic language is already running live tax calculations for the French state and one can expect to see this and other similar constructs being referenced by regulators.
Recent research backs up this direction of travel – GPT-4.1 produced syntactically valid code 88.8% of the time when translating regulatory text into Catala. This is powerful analysis, especially in a space as plagued by grey areas as tax law. It is not yet close enough, however, to the point that a firm might consider handing over to the LLM to run its filings.
At the same time as overarching rule parsing attempts to gain a foothold, more familiar techniques can also be uplifted. In-tool redlining is the same concept, just spread over more touchpoints. It looks like a simple system, but in reality it requires agentic coordination to find the target of the amendment and make the amendments precisely in the location required.
Establishing manually what is changed between draft and in-force text, then doing it again as the draft evolves, is expensive and inaccurate. Exchange circulars present an acute version of this. While a consultation paper arrives with a date and a policy statement attached; a circular can land on a Tuesday, amend a rulebook by reference, and leave no consolidated text behind it. Establishing what a venue’s rules said on the day a trade was booked, two years after the event, is reconstruction at its most difficult and expensive.

Rebuilding any audit trail two years after the event, when the Word document has been versioned multiple times and the analyst who did the work has long since moved on is a pain that all firms will recognise.
The Duty of Responsibility (per SMCR rules) holds Senior Managers responsible, accountable and potentially liable for what was reasonably knowable, not what was actually known. A dated record of what landed, and when, and what got decided is the cheapest insurance premium. Increasingly, AI agents can guide this process, gathering, classifying and prioritising evidence automatically for audit time.
Consider too the poor compliance advisory officer; the one with the large trade hanging over them on the basis of an in or out call. If you are the person who says hold on, this should be clearly referenced to be valuable: knowledge recall is one of the most valuable – and expensive -skills for a firm to acquire.
The ability to interrogate a frontier LLM is, of course, seductive. It is also fraught with danger. When using this new technology in the regulatory compliance space particularly one must consider that however an answer was reached, that answer must be owned. An LLM is an eloquent flatterer, and the chatbot interface rewards sustained interaction in the way the previous generation of social platforms did. It is designed to keep you talking, not to tell you no.
This (insincere) eloquence masks serious risks across data governance, source scope, source staleness, source poisoning, silent semantic failures, non-determinism and reproducibility. Each of these risks have mitigations of which firms and individuals should be aware.
A well designed agentic system moves beyond the current model available via your corporate chat LLM. In the compliance space, a comprehensive agent will incorporate independent layers of checks for citation faithfulness, consistency and staleness. The tool will be calibrated to the purpose. The source data corpus is controlled and versioned to ensure auditable traceability. A specialised “entailment” model verifies the extent to which the response meets the premise and gives a numerical grade. (Or in plain English – did it answer the question?)
Firms that successfully integrate well grounded compliance tooling with well-designed oversight dramatically decrease the number of decisions that need to travel up the chain, in turn decreasing cost and key-person risk, while adding decision auditability.
The method of getting to the answer may be changing, but the questions remain the same. Jessica Rusu, FCA’s Chief Data, Information and Intelligence Officer, told the Treasury Select Committee in late 2025 that it has no plans to introduce prescriptive AI rules, citing Consumer Duty legislation and the Senior Managers regime as the key pillars of outcome-based accountability. This necessarily requires FCA’s enforcement guidance to evolve since lack of access to explainability or controls is not a defence. Not knowing why your model did what it did does not get you off the hook.
To be clear, the regulator isn’t telling firms to avoid AI; it’s telling them to be ready to explain it, on demand, after the fact, to someone who wasn’t in the room when the model made the call.
The FCA isn’t alone in asking for this. Ask why buy-side desks moved away from basic slippage numbers and onto platforms like BestX or Tradefeedr’s Algo Forecasting, and you’ll hear roughly the same demand a regulator makes. Clients know that “the algo decided” doesn’t cut the mustard anymore: They want to know why an order got routed in a particular way, and what the model expected before the trade, compared to what happened after.
Again, this interesting parallel affirms the continuing relevance of that time honoured demand from school – “show me your workings”.

Surveillance and market abuse detection
Beyond regulation, surveillance is another key area in which AI and LLMs are making significant inroads. In January 2026, LSEG launched Trade Surveillance for FX, covering spot participants on its own dealing and matching platforms as well as third-party venues, and pairing conventional alert methodology with behavioural anomaly detection.
The FCA has run its own TechSprint on the use of AI to cut false positives in market abuse detection. JPMorgan says its internal LLM Suite passed 200,000 users in eight months, with surveillance among the uses it discusses publicly.
Customer demand for progress is easy to understand: Trade surveillance is primarily data driven and derived from communications sources and trade flows that a firm is already monitoring and using market data that they are already paying for. The output is an alert, not an interpretation or an answer – the firm still has to make the final decision on each alert – and processing fewer of them saves time and money.
It’s the same story for market abuse risk assessment. A MARA is a point-in-time document that captures how a firm traded on the day it was written. But strategies change, desks reorganise, expectations move and the document gradually stops describing the firm. Regulators aren’t looking for something completed last year. They want evidence that the risk is understood now.
Tooling appears to close that gap. Continuous re-scoring as the business profile shifts. Benchmarking against comparable firms rather than an abstract standard. Creating a logged trail of every assessment and every decision. Producing a single rating for a board or auditor. What none of this does is establish if the controls themselves are adequate. That judgment still comes from people who have seen enforcement from the other side.

Changing compliance function
All of this puts a spotlight on the key tension in snapshot compliance processesfor a world that has embraced 24/7 trading. A paper written for the New York Fed’s FX Committee in April made this point precisely for FX: existing governance assumes algorithm logic is stable enough to be documented and approved at a point in time, but retraining and vendor updates move behaviour between those points. The FX Global Code covers governance and post-trade controls, but it wasn’t drafted for models that may change their minds between approvals.
If you look at what your second line spends its week doing, you will start to understand where the value lies. A large part of compliance work is classification and retrieval: remembering the 2013 Market Watch that references indicators of order layering when assessing our internal controls in that same product, the hours spent going over how a currency pair should be expressed in an EMIR report or whether a forward booked as 2 legs should be reported the same way.
A portion of this time is judgment. Reading a grey area, understanding the risk appetite of the firm, forming a position and owning the final call.
If the retrieval half is where the removable cost sits, buying the tooling is the easy part. The harder question is whether the function is shaped to realise that saving or to absorb it. A team built around people who hold the context is a different team from one where the tool holds the context and people adjudicate. The roles change but the question remains the same.
The numbers say that adoption is both broad and thin. Some 81% of financial services firms report using AI at some level, with around 40% at the scaling or transformation stage (more than double the rate among their own regulators). Yet only 31.8% have deployed anything into production, and just 12.2% describe their strategy as well defined and resourced.
The question worth carrying into next year is not which AI tool answers best. It is which one you would want to be standing behind in three years, when the trade is old, the analyst has left, and someone asks how you knew.