2026 is the year AI regulation for financial services stops being a policy briefing and becomes an operating obligation. The EU AI Act's high-risk regime goes live on 2 August 2026, and parallel rulemaking in the UK, US, Singapore, Hong Kong, Australia and the Gulf has tightened around the same core duties: model inventory, human oversight, documented impact assessment, transparency and auditable evidence. This article maps the regimes that bear on a private capital fund, the deep-dive points by vertical, and the single operating model that satisfies all of them at once.
It complements the The Regulated Fund whitepaper, the AI governance for private capital guide, and the EU AI Act compliance checklist.
Figure 1 · Regional AI regimes most relevant to private capital. Sources: Regulation (EU) 2024/1689 (OJ L, 12 July 2024); FCA DP5/22; PRA SS1/23; SEC Investment Advisers Act 1940 and Marketing Rule (Rule 206(4)-1); NYDFS Insurance Circular Letter No. 7 (2024); MAS FEAT Principles (2018) and Veritas Toolkit; HKMA generative AI principles (2024); ASIC Report 798 (2024); ADGM and DFSA AI guidance.
Why 2026 is the inflection year
Regulation (EU) 2024/1689, the EU Artificial Intelligence Act, entered into force on 1 August 2024 and is phased. The Article 5 prohibitions applied from 2 February 2025. The general-purpose AI (GPAI) obligations applied from 2 August 2025. The Annex III high-risk regime applies in full from 2 August 2026. Annex I product-embedded high-risk obligations follow on 2 August 2027. The August 2026 milestone is the moment the regime stops being prospective and starts being supervised.
Parallel rulemaking has moved on a similar clock. In the UK, the FCA continues to operate Discussion Paper DP5/22 alongside the Consumer Duty (PS22/9), and the PRA's Supervisory Statement SS1/23 on model risk management remains the model-governance backbone. In the US, the SEC withdrew its 2023 predictive data analytics proposal (Release No. 34-97990) in June 2025, but the Investment Advisers Act of 1940 fiduciary duty and the Marketing Rule (Rule 206(4)-1) continue to apply to AI-assisted advice and performance claims; state-level rules including NYDFS Insurance Circular Letter No. 7 (2024) and the Colorado Artificial Intelligence Act add overlays. In Asia-Pacific, MAS's Veritas Toolkit and FEAT Principles, HKMA's generative AI principles (2024), and ASIC Report 798 (October 2024) define supervisory expectations. The Gulf has ADGM and DFSA AI guidance.
The European stack
For European-active funds, Regulation (EU) 2024/1689 does not arrive alone. It sits alongside AIFMD II, the Sustainable Finance Disclosure Regulation (SFDR), MiFID II where in-scope distribution applies, and the GDPR. The practical effect is that decisions, portfolio data and AI usage all need to be captured in a single auditable layer, because the same evidence answers multiple regimes.
The EU AI Act articles that bear most directly on a fund acting as a deployer are Article 5 (prohibited practices), Article 9 (risk management), Article 10 (data and data governance), Article 13 (transparency to deployers), Article 14 (human oversight), Article 15 (accuracy, robustness and cybersecurity), Article 17 (quality management), Article 26 (deployer obligations including log retention), Article 27 (Fundamental Rights Impact Assessment, FRIA), Article 50 (transparency for AI-generated content), Article 72 (post-market monitoring) and Article 73 (serious incident reporting). Penalties are graduated under Article 99: up to EUR 35 million or 7% of worldwide annual turnover for Article 5 breaches (Article 99(3)); up to EUR 15 million or 3% for high-risk obligations breaches (Article 99(4)); up to EUR 7.5 million or 1% for incorrect information to authorities (Article 99(5)); a "lower of" rule for SMEs and start-ups (Article 99(6)); and separate Commission fines on GPAI providers under Article 101.
See your AI compliance evidence in one platform
Walk through the model register, the FRIA workflow, the AI disclosure badges and the human oversight log on live fund data.
Book a governance walkthroughUnited Kingdom
The FCA has chosen a principles-based path. Discussion Paper DP5/22, published jointly with the Bank of England and PRA in October 2022, set the supervisory direction on AI and machine learning in financial services. The Consumer Duty (Policy Statement PS22/9) applies where AI affects retail outcomes, and is increasingly read across to professional client outcomes by analogy. PRA Supervisory Statement SS1/23 on model risk management is the model-governance backbone for banks and is directly relevant to private credit and venture-debt funds with banking counterparties. ICO guidance on AI and data protection sits on top, harmonising the UK GDPR overlay.
For private capital with UK exposure, the operational asks are familiar: documented model governance, named accountability under the Senior Managers and Certification Regime, evidence of human oversight, fair-outcome testing where retail or LP outcomes are touched, and incident reporting through existing supervisory channels.
United States
There is no federal AI law for financial services. The SEC's June 2025 withdrawal of its 2023 predictive data analytics proposal (Release No. 34-97990) did not retire the substantive concerns. The Investment Advisers Act of 1940 fiduciary duty and the Marketing Rule (Rule 206(4)-1) continue to bear on AI-assisted advice, conflicts disclosure and performance claims. The Division of Examinations continues to flag AI as a priority area for adviser examinations.
State-level rules are where the operational lift lives. NYDFS Insurance Circular Letter No. 7 (2024) sets governance, fairness, transparency and reporting expectations for AI use in insurance underwriting and pricing. The Colorado Artificial Intelligence Act (SB24-205, effective 2026) imposes risk-management obligations on developers and deployers of high-risk AI systems. New York City Local Law 144 covers automated employment decision tools, with read-across to executive screening. Sanctions and CFIUS overlays continue to expand in scope for cross-border deals.
Asia-Pacific
Singapore's MAS published the FEAT Principles (fairness, ethics, accountability, transparency) in 2018 and operationalised them through the Veritas Toolkit, which has been progressively extended to cover generative AI in investment management. Hong Kong's HKMA issued high-level principles on the use of generative AI in 2024 and continues to run a generative-AI sandbox; the SFC has issued circulars on AI use in licensed activities, including investment management. Japan's FSA operates AI principles broadly aligned with the OECD framework. Australia's ASIC published Report 798 "Beware the gap: Governance arrangements in the face of AI innovation" in October 2024, setting supervisory expectations on AI governance, model risk and human oversight for licensed financial firms; Australia's Privacy Act reform proceeds in parallel.
Data residency adds an additional layer in APAC. China's Personal Information Protection Law (PIPL), India's Digital Personal Data Protection Act 2023 (DPDP) and Indonesia's Personal Data Protection Law 2022 (PDP) impose localisation and cross-border transfer requirements that bear on how diligence data on local portfolio companies is processed when AI systems are hosted outside the jurisdiction.
Middle East
In the Gulf, ADGM has issued AI policy and guidance through its Financial Services Regulatory Authority, and the DFSA has published its AI ethics and governance framework. Saudi Arabia's SDAIA (Saudi Data and Artificial Intelligence Authority) operates AI ethics principles and a personal data protection regime. These frameworks do not confer EU adequacy and do not substitute for direct compliance with Regulation (EU) 2024/1689 where it applies, but they reduce friction for funds raising from regional sovereign wealth pools and family offices that increasingly expect Brussels-aligned governance.
Where Reuben AI users are exposed: vertical deep-dive
Private equity and venture capital
Most VC and PE firms are deployers under Article 3 of Regulation (EU) 2024/1689 wherever they have European LPs, European portfolio exposure or European operating teams. The classification analysis turns on use case. Annex III(4) (employment, worker management and access to self-employment) is the relevant category when AI is used to screen founders or executives in hiring contexts. Annex III(1) (biometrics) applies where biometric identification is in scope. Generic deal scoring at the fund level is not automatically high-risk, but the classification must be made and documented per model under Articles 9 and 17.
Private credit and direct lending
Annex III(5)(b) explicitly lists AI systems used to evaluate the creditworthiness or establish the credit score of natural persons as high-risk (with a fraud-detection carve-out). For credit funds touching natural-person counterparties, Article 27 FRIA, Article 14 oversight and Article 15 accuracy and robustness obligations apply directly. PRA SS1/23 and NYDFS Insurance Circular Letter No. 7 (2024) layer model-risk and governance expectations in the UK and New York respectively.
Family office and multi-family office
Family offices typically inherit obligations through cross-border LP positions and beneficial-owner data. GDPR Article 22 (automated individual decision-making) is often the live obligation alongside the EU AI Act Article 50 transparency duty. Where family offices invest into the Gulf or APAC, ADGM, DFSA, SDAIA, MAS and HKMA guidance applies in parallel. The operating model needs to evidence consistent governance across all of them from one record.
Fund of funds and secondaries
FOF and secondaries inherit compliance through the underlying GP. The DDQ flow-through has tightened materially: ILPA's DDQ template includes an AI Governance module covering oversight, model inventory, third-party AI use, training data, monitoring and incident reporting. Secondaries diligence on AI-assisted GPs requires the same evidence pack the GP itself would produce under Article 27 FRIA and Article 26 deployer obligations.
Real assets and infrastructure
Annex III(2) (management and operation of critical infrastructure) is the relevant category where AI systems are used in essential infrastructure decisioning. For infrastructure GPs, the operational lift sits at the portfolio-company layer rather than the fund layer, but the GP carries the deployer duty for any infrastructure decisions taken under its control.
See cross-jurisdictional AI compliance from one data layer
Model register, FRIA workflow, Article 14 oversight, AI disclosure badges and the audit trail on a single record for EU, UK, US, APAC and Gulf obligations.
Book a DemoThe operating model that satisfies all of them at once
The encouraging finding from mapping the regimes side by side is that the operational asks converge. A fund that holds five things together can answer LP DDQ, ILPA AI Governance modules and supervisor requests across the EU, UK, US, APAC and Gulf without re-engineering per jurisdiction.
Figure 2 · One data layer that satisfies Regulation (EU) 2024/1689 deployer duties (Articles 12, 14, 26, 27, 50) and the parallel UK, US, APAC and Gulf expectations from the same record.
The five non-negotiables, in order: (1) a model register listing every AI system in use, internal or vendor supplied, with provider, version, risk tier under Annex III of Regulation (EU) 2024/1689, named owner, last validation date and the workflow it informs; (2) an Article 27 FRIA per high-risk system, signed off by a competent person and refreshed on material change; (3) Article 14 human oversight evidence per high-risk decision, with reviewer, action, timestamp and rationale; (4) an Article 50 disclosure surface for AI-generated or AI-assisted content visible to LPs, founders and counterparties; (5) an immutable audit trail held under Article 12 and Article 26(6) for at least six months.
What Reuben AI does inside that operating model
Reuben AI operates the model register, the FRIA workflow, the Article 14 human oversight log, the AI disclosure badges, the sub-processor register and the immutable audit trail as first-class surfaces on a single data layer. The same record powers fund governance, audit trail, AI due diligence and IC memo automation.
For the workflow engine that wires Article 14 evidence into every deal stage, see deal workflow automation for private capital. For how triangulation captures dissent and confidence on AI-assisted IC decisions, see multi-expert triangulation in investment committees.
Primary sources
- European Parliament and Council, "Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)," Official Journal of the European Union, 12 July 2024. See in particular Articles 3, 5, 9, 10, 12, 13, 14, 15, 17, 26, 27, 50, 53, 72, 73, 99, 101 and Annexes I and III.
- European Securities and Markets Authority, "Union Strategic Supervisory Priorities and 2025 Annual Work Programme," 2025.
- Financial Conduct Authority, Bank of England and Prudential Regulation Authority, "Artificial Intelligence and Machine Learning," Discussion Paper DP5/22, October 2022.
- Prudential Regulation Authority, "Model risk management principles for banks," Supervisory Statement SS1/23, May 2023.
- U.S. Securities and Exchange Commission, "Conflicts of Interest Associated with the Use of Predictive Data Analytics by Broker-Dealers and Investment Advisers," Release No. 34-97990 (proposed July 2023; withdrawn June 2025); Investment Advisers Act of 1940; Rule 206(4)-1 (Marketing Rule).
- New York State Department of Financial Services, "Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and Pricing," Insurance Circular Letter No. 7 (2024).
- Colorado General Assembly, "Consumer Protections for Artificial Intelligence," SB24-205 (Colorado Artificial Intelligence Act), 2024.
- Monetary Authority of Singapore, "Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) in the Use of Artificial Intelligence and Data Analytics in Singapore's Financial Sector," 2018; Veritas Toolkit, subsequent iterations.
- Hong Kong Monetary Authority, high-level principles on the use of generative AI by authorised institutions, 2024; Securities and Futures Commission, circulars on the use of artificial intelligence and large language models in licensed activities.
- Australian Securities and Investments Commission, "Beware the gap: Governance arrangements in the face of AI innovation," Report 798, October 2024.
- ADGM Financial Services Regulatory Authority, AI policy and guidance; Dubai Financial Services Authority, AI ethics and governance framework; Saudi Data and Artificial Intelligence Authority, AI ethics principles.
Ready to operate AI compliance across every jurisdiction from one platform
See the model register, FRIA workflow, Article 14 oversight log, AI disclosure surfaces and audit trail running on live fund data.
Book a Demo