Big Tech’s AI Gatekeepers Could Draw Regulatory Scrutiny
Legal experts highlight emerging regulatory scrutiny on Big Tech gatekeepers and liability attribution for autonomous AI agents.
Open sourceCompare legislation, supervisory expectations and policy development across financial centres. Every position is dated, classified by legal force and linked to the regulator’s own evidence.
Regulatory change desk
Recent source-linked developments from the live OneBench corpus. The jurisdiction tracker below remains the authoritative statement of current position.
Legal experts highlight emerging regulatory scrutiny on Big Tech gatekeepers and liability attribution for autonomous AI agents.
Open sourceArXiv paper proposes a framework for enterprise AI agents to selectively unlearn obsolete policies, regulations, and workflow rules.
Open sourceJurisdiction tracker
Filter by geography, legal force, implementation stage or control topic. Open a profile for the factual position, practical implications and primary instruments.
Global bodies are converging on board accountability, lifecycle controls, third-party concentration and system-wide monitoring, but do not create directly binding firm obligations.
FSB consultation closed on 22 July 2026; monitor publication of the final sound practices.
The EU combines horizontal AI legislation with existing financial-services rules. Creditworthiness and access-to-service uses can be high-risk, while DORA governs operational resilience and critical technology dependencies.
High-risk Annex III requirements are scheduled for 2 December 2027 following the 2026 AI Omnibus changes.
UK financial regulators currently apply technology-neutral rules rather than a new AI rulebook. Consumer Duty, SM&CR, governance and model-risk expectations remain the main control anchors.
Monitor the FCA’s promised publication of good and poor practice from its 2026 engagement and testing work.
US oversight remains sectoral and use-case based. Banking agencies revised model-risk guidance in 2026, while fair-lending, adverse-action, privacy and consumer-protection laws continue to apply to algorithmic decisions.
Monitor the planned interagency request for information on AI, including generative and agentic systems.
OSFI has finalised an enterprise-wide, risk-based model-risk guideline that expressly includes AI and machine-learning models across federally regulated financial institutions.
Guideline E-23 takes effect on 1 May 2027.
Australia is applying existing prudential and conduct obligations while supervisors press firms to close a widening gap between AI adoption and governance maturity.
Regulated entities should expect supervisory follow-up on the weaknesses APRA identified in its 2026 targeted review.
MAS is moving from principles and industry toolkits towards detailed, proportionate AI risk-management expectations for all financial institutions, including GenAI and agents.
Consultation closed on 31 January 2026; final guidelines and the proposed transition period remain to be confirmed.
HKMA combines current high-level AI and consumer-protection principles with supervised experimentation through an expanded GenAI sandbox.
Sandbox++ launched in March 2026; monitor resulting good practice and any follow-on supervisory circulars.
Japan’s FSA is taking a technology-neutral, dialogue-led approach that recognises both AI risk and the ‘risk of not taking action’ in financial services.
Version 1.1 was published in March 2026; monitor policy clarifications arising from the public-private forum.
RBI’s FREE-AI framework sets a financial-sector direction for responsible and ethical adoption, intended to balance innovation, inclusion and risk management.
Monitor the conversion of FREE-AI recommendations into formal directions and sector-specific supervisory expectations.
FINMA uses technology-neutral supervision and expects institutions to identify, limit and monitor AI risk through governance and risk-management systems proportionate to materiality.
FINMA continues risk-based supervisory exchanges and asks institutions to engage early on critical AI processes or regulatory-parameter use.
The UAE now combines cross-authority enabling-technology guidance with a 2026 CBUAE consumer-protection note specific to responsible AI and machine learning in licensed financial institutions.
Monitor supervisory implementation of the February 2026 consumer-protection guidance and any sector-specific follow-on rules.
South African financial supervisors are developing a joint regulatory approach after surveying adoption and finding weaknesses in fairness testing, third-party model risk and board oversight.
Prudential Authority and FSCA are preparing a discussion paper setting out their regulatory approach.
Brazil’s central bank is studying AI use, risks and impacts across regulated institutions as part of its 2025–2026 regulatory priorities; no AI-specific financial rule is yet represented here.
Monitor publication of the central bank’s policy conclusions and any resulting consultation or rulemaking.
Control convergence
An explicit-coverage map—not a score. It shows which control topics appear in the regulatory position tracked for each jurisdiction.
| Jurisdiction | Governance & accountability | Model risk & validation | Customer & conduct | Fairness & explainability | Data & privacy | Third party & resilience | Monitoring & reporting | GenAI & agents |
|---|---|---|---|---|---|---|---|---|
| EU | Explicitly covered |
Implementation horizon
Only milestones with a confirmed date in primary-source material appear here. Undated policy intentions remain visible in the tracker without a fabricated deadline.
Guideline E-23 takes effect on 1 May 2027.
High-risk Annex III requirements are scheduled for 2 December 2027 following the 2026 AI Omnibus changes.
Regulatory intelligence, not legal advice. OneBench records what the official source says, when it was reviewed and whether it is law, supervisory expectation, guidance, consultation or monitoring.
Regulator, central-bank and official legislative material is the evidence base.
Legal force and implementation stage are classified separately.
Practical implications are labelled and never replace the source position.
Research identifies security risks in integrating LLMs as AI components due to overlooked traditional software supply chain lessons.
Research demonstrates Tabular Foundation Models achieve strong in-context learning transfer via self-supervised pre-training on a single real table.
Open sourceResearch demonstrates debate-based adversarial fine-tuning reduces reward hacking in RLAIF when aligned using automated LLM judges.
Open sourceAudit reveals leading multi-hop RAG benchmarks rely on non-commercially licensed models like NV-Embed-v2 (CC-BY-NC-4.0), masking commercial IP risks.
Open source| Explicitly covered |
| Explicitly covered |
| Explicitly covered |
| Explicitly covered |
| Explicitly covered |
| Explicitly covered |
| UK | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered | Not explicit | Explicitly covered | Explicitly covered | Explicitly covered |
|---|
| US | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered | Not explicit | Explicitly covered | Explicitly covered | Explicitly covered |
|---|
| Canada | Explicitly covered | Explicitly covered | Not explicit | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered |
|---|
| Australia | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered | Not explicit | Explicitly covered | Explicitly covered | Explicitly covered |
|---|
| Singapore | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered |
|---|
| Hong Kong | Explicitly covered | Not explicit | Explicitly covered | Explicitly covered | Explicitly covered | Not explicit | Explicitly covered | Explicitly covered |
|---|
| Japan | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered | Not explicit | Not explicit | Explicitly covered |
|---|
| India | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered |
|---|
| Switzerland | Explicitly covered | Explicitly covered | Not explicit | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered | Not explicit |
|---|
| UAE | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered |
|---|
| South Africa | Explicitly covered | Explicitly covered | Not explicit | Explicitly covered | Explicitly covered | Explicitly covered | Explicitly covered | Not explicit |
|---|
| Brazil | Explicitly covered | Explicitly covered | Explicitly covered | Not explicit | Explicitly covered | Explicitly covered | Explicitly covered | Not explicit |
|---|
© 2026 OneBench: AI Insights. All rights reserved.
Evidence before opinion