As the year progresses towards Autumn, compliance professionals face more than another wave of rules in the coming months. They face a regulatory landscape in which AI, data governance, financial crime, cyber resilience, sustainability and third-party risk increasingly collide. The EU is advancing broad, cross-sector frameworks, with AI Act transparency obligations already applying from August 2026. Meanwhile, the UK continues to favour a more flexible, regulator-led approach, while reassessing data regulation for an AI-intensive economy. For multinational businesses, regulatory divergence now exists alongside deep interdependence. The critical question is whether traditional compliance functions can evolve quickly enough when technology, risk and regulation are all accelerating simultaneously. What’s coming up?
AI: From Experimentation to Accountability, Liability and Human Oversight
By 2027, asking whether an organisation “governs AI” will sound increasingly inadequate. The harder question is who answers when AI recommends, shapes or independently executes a consequential decision. The EU AI Act is making that question operational. From 2 August 2026, Article 50 transparency rules require, among other measures, disclosure when people interact with certain AI systems and labelling in specified cases involving AI-generated or manipulated content.
The next challenge is agentic AI. Unlike a chatbot producing text, an AI agent might analyse a customer, select an action and trigger the next step across connected systems. That makes model inventories, testing, documentation, explainability and meaningful human oversight essential. Firms must also confront “shadow AI”, where staff quietly introduce unapproved tools into everyday workflows.
The UK remains less horizontally prescriptive. Its July 2026 call for evidence explicitly examines whether existing data regulation can accommodate agentic AI. For compliance teams, the practical shift is profound: audits may increasingly examine decisions jointly produced by employees, algorithms, vendors and autonomous agents, with accountability mapped across the entire chain.
Compliance Without Borders
The digital economy has developed a fundamental contradiction. Businesses want data, cloud services and AI to move seamlessly across borders, while governments want control over the infrastructure on which they depend. The EU’s 2026 technological sovereignty package makes that tension explicit, seeking greater European capacity in semiconductors, cloud, AI and open-source technologies. Meanwhile, the Data Act, applicable since September 2025, includes measures making switching between cloud providers easier.
The UK is taking a different route. Its Data (Use and Access) Act 2025 amends rather than replaces UK GDPR and the Data Protection Act 2018, with all its data-protection provisions now in force. For international businesses, this creates a difficult question: where does a dataset, algorithm or cloud service actually “operate” when data may originate in London, be processed in Frankfurt and train an AI model elsewhere?
Forward-looking compliance teams should build regulatory architecture maps tracing where data originates, travels, is processed and influences decisions. Such maps can expose transfer restrictions, cloud concentration risks and conflicting jurisdictional obligations before they become expensive surprises.
How AML, Sanctions and Financial Crime Compliance Are Being Reinvented
Financial crime is becoming harder to divide neatly into AML, fraud and sanctions. Crypto-assets, instant payments, digital identities, deepfakes and AI-assisted scams increasingly connect risks that traditional compliance teams still manage separately. In the EU, 2027 will be pivotal. AMLA will select up to 40 high-risk financial institutions for direct supervision from 2028, using common risk-assessment methods to strengthen consistency across member states.
Speed is changing the equation too. Since October 2025, euro-area payment providers have had to offer instant euro payments, allowing transfers within seconds, alongside verification of payee to help prevent mistakes and scams. A suspicious payment can therefore travel faster than a conventional investigation.
The UK is strengthening another weak point: corporate identity. Companies House identity verification became compulsory for new directors and people with significant control in November 2025, with millions of existing individuals transitioning through 2026 and into 2027.
For compliance leaders, the lesson is practical. Connecting AML alerts, sanctions screening, fraud intelligence, beneficial-ownership data and identity signals can reveal patterns that siloed teams miss. Financial-crime compliance is becoming an intelligence problem, not merely a checking exercise.
The Supply Chain Becomes a Compliance Chain
Tomorrow’s compliance map increasingly resembles a network, not an organisation chart. Cloud providers, outsourced processors, AI vendors and even fourth parties can now expose businesses to cyber, operational, human-rights and environmental risks far beyond their direct control.
DORA illustrates the shift. EU financial firms must manage ICT third-party risk, including concentration risk where critical services depend heavily on a small number of providers. In November 2025, European supervisors designated critical ICT providers for direct oversight. Cross-border cooperation followed in January 2026, when EU supervisors and the Bank of England, PRA and FCA agreed arrangements for sharing information and coordinating oversight of critical technology providers.
The lesson extends beyond finance. The EU’s 2026 Omnibus reforms substantially amended sustainability reporting and due-diligence requirements, showing that compliance teams must track regulatory simplification as carefully as expansion.
Practically, firms should map not merely suppliers but dependencies. Contracts with cloud, outsourced and AI providers should establish information rights, incident notification, audit access and exit arrangements. The crucial question is becoming not “Who supplies us?” but “Who could stop us operating, expose us legally or damage our reputation?”
From Rule-Follower to Regulatory Futurist
Traditional horizon scanning cannot remain a monthly email containing 40 regulatory updates nobody finishes. As 2027 approaches, leading compliance functions need something closer to strategic intelligence. AI-assisted monitoring can identify emerging rules, while regulatory heat maps, scenario analysis and interconnected obligation libraries can show which products, controls and executives will actually be affected.
The UK’s May 2026 Regulatory Initiatives Grid offers a useful model, mapping significant financial-services initiatives across the next 24 months and indicating their expected impact. Businesses can go further by searching for “weak signals” and using predictive analytics to anticipate regulatory direction.
This supports regulatory optionality. A multinational, for example, might design an AI governance process that can accommodate diverging EU and UK requirements without rebuilding its controls each time rules change.
Crucially, horizon scanning must also detect regulation moving backwards. The European Commission’s simplification programme had produced twelve Omnibus proposals by June 2026, targeting billions in administrative savings. Tomorrow’s compliance professional therefore resembles a strategic intelligence analyst, asking not only “What must we do?” but “What is changing next?”
2027 Will Reward the Compliance Functions That See Around Corners
As 2027 approaches, successful compliance will be defined less by rule-following and more by regulatory intelligence. Human decisions are becoming human-machine decisions, company risk is becoming ecosystem risk, and financial-crime silos must give way to integrated intelligence. Meanwhile, regulatory divergence demands genuinely multi-jurisdictional thinking. The EU’s continuing simplification agenda reinforces another lesson: compliance teams must anticipate rules changing in both directions. The winners will not simply build larger compliance functions. They will build smarter, faster ones that influence technology, products and strategy before regulatory change becomes a constraint.
And what about you…?
- Who is accountable in your organisation when an AI system influences, recommends or autonomously makes a business decision?
- How well do you understand the regulatory risks hidden beyond your immediate organisation, including cloud providers, AI vendors, outsourced services and fourth parties?



