/

/

Resource Hub

/

/

Resource Hub

The CUBE Read: 3 shifts in financial services regulation, August 2026

The CUBE Read: 3 shifts in financial services regulation, August 2026

CUBE

In brief: Regulatory enforcement is intensifying across APAC, the UK, and the EU simultaneously. AI governance has crossed from internal policy into active regulatory guidance. And the perimeter of what risk and compliance teams need to cover - from stablecoins to climate disclosure to frontier AI risks - is expanding faster than most coverage models were built to absorb. This edition covers late July to early August 2026.

The CUBE Read is CUBE’s fortnightly take on regulatory change in financial services and what it means for risk and compliance teams.

1. AI governance has crossed from internal policy into active regulatory pressure

For most of 2025, AI governance in financial services was largely an internal question - firms setting their own standards ahead of formal mandates. That has shifted.

The ESAs have published guidance urging financial firms to upgrade their cyber defences specifically against frontier AI-driven attacks, treating AI-enabled threats as a distinct risk category requiring a distinct response. The ECB separately found that banks can model geopolitical stress scenarios but have identifiable weaknesses in translating those models into liquidity terms - a finding with direct implications for how AI-assisted risk modelling is validated and evidenced.

What we’re seeing is consistent with the regulatory direction: AI governance concerns are rising sharply across the industry, diversifying well beyond hallucination risk into AI note-taker bans on compliance and record-keeping grounds, hesitation over long-term vendor commitments driven by uncertainty about agentic AI, and active benchmarking of AI-generated regulatory summaries against multiple models before trusting the output - a pattern emerging across banking, insurance, and asset management alike.

What it means for risk and compliance teams: AI governance is now a live regulatory workstream, not just an internal policy question. Firms need to be able to evidence their approach to AI-related risks - including the risks of the AI tools they use to manage regulatory obligations - against a standard that regulators are actively shaping.

2. Enforcement thresholds are rising across jurisdictions

A cluster of enforcement actions and registration decisions this fortnight points in the same direction: regulators across the UK, Australia, Hong Kong, and the EU are raising the threshold for what constitutes an acceptable compliance standard.

ASIC issued a $594,000 fine for late financial reports, explicitly flagged FY26 as a warning year for reporting discipline, and delivered its highest number of banning orders and licence cancellations in five years. The FCA is tightening scrutiny of Annex 1 firm registrations specifically over financial crime risk - a gateway tightening, not just a post-registration enforcement action.

The Upper Tribunal cut fines for pension transfer advisers but upheld the FCA ban - signalling that financial penalties are negotiable on appeal, but the prohibition on activity itself is not. The SEC has created a specialised unit to pursue accounting and financial reporting fraud, adding institutional capacity behind what is already a stated enforcement priority.

What it means for risk and compliance teams: The tolerance for process failures - late reporting, unaddressed red flags, incomplete registration - is falling. And in several jurisdictions, the threshold is moving at the registration and licensing stage, before a firm is fully in-scope. Coverage needs to include the gateway, not just the operational obligations that follow.

3. The regulatory perimeter is extending into new instruments and emerging risks

Several developments this fortnight add new instruments, new risk categories, and new jurisdictional combinations to the compliance perimeter - none of them incremental adjustments to existing frameworks.

The US and UK updated on stablecoin and AI cooperation at the Financial Regulatory Working Group - a joint coordination mechanism covering two of the fastest-moving areas of regulatory development simultaneously. The SFC and CSRC unveiled a fast-track ETF registration mechanism and a climate disclosure pilot, extending the Hong Kong and mainland China regulatory perimeter into climate reporting in a single move. ASIC is proposing to loosen pre-prospectus IPO advertising rules, changing what is permissible in a space that has been tightly constrained. The EBA is consulting on a reporting framework to validate ISDA’s margin model - a technical but significant addition to derivatives oversight.

EBA data shows banks’ climate risk exposures held broadly steady in the second half of 2025, but the ESMA stakeholder group has warned of cost risks in the supervisory overhaul and is urging a competitiveness check - suggesting the rulemaking direction continues even as the cost-benefit debate intensifies. The EBA has also recommended no supervisory action on trading book boundary ahead of FRTB relief, signalling deliberate restraint in one area while the broader framework settles.

What it means for risk and compliance teams: The scope of what needs to be monitored is not stabilising. Stablecoins, climate disclosure, AI risk, derivatives margin models, and fast-track ETF registration are all live coverage questions now. Firms with fixed, jurisdiction-based coverage models face the same structural challenge that has defined the past two years: the regulation doesn’t arrive where the model was built to look.

The through-line

Risk and compliance in financial services is shifting from awareness to execution - from spotting a regulatory change to interpreting it, acting on it, and evidencing it, everywhere a firm operates. Enforcement is rising, AI governance is now a regulatory expectation, and the perimeter of what requires coverage keeps moving. It’s the challenge CUBE is built for: applying AI to regulatory workflows, built on 15 years of regulatory data, inside the platforms risk and compliance teams already use.

For more detail on the latest regulatory developments, download CUBE’s RegTrend app for free.

Frequently asked questions

What is The CUBE Read?

The CUBE Read is CUBE’s fortnightly briefing on regulatory change in financial services - the shifts most relevant to risk and compliance teams, and what they mean in practice.

What’s driving the rise in enforcement activity in 2025-26?

ASIC delivered its highest number of banning orders and licence cancellations in five years in 2025-26, alongside a $594,000 fine for late financial reporting. In the UK, the FCA has tightened scrutiny at the registration stage for Annex 1 firms, specifically citing financial crime risk - suggesting the enforcement posture extends upstream of traditional post-authorisation supervision.

Why are regulators focusing on AI governance now?

Regulatory guidance on AI governance has moved from general principles to specific risk categories. The ESAs have identified frontier AI-driven cyber attacks as a distinct threat requiring an explicit firm response. The ECB’s stress-testing findings highlight weaknesses in how AI-assisted models translate into liquidity outputs. Both point to AI governance becoming a supervisory topic, not just an internal one.

What is the FRTB trading book boundary issue?

The Fundamental Review of the Trading Book (FRTB) establishes rules for how banks classify instruments between the trading book and the banking book. The EBA has recommended no supervisory action on the boundary ahead of FRTB relief provisions, signalling deliberate regulatory restraint in that area while the broader framework is still being implemented.

How often is The CUBE Read published?

Fortnightly. Each edition covers the regulatory shifts most relevant to risk and compliance teams in financial services.

Sources: CUBE, Cost of Compliance Report 2025; ASIC enforcement action and enforcement data 2025-26; FCA Annex 1 guidance; ECB geopolitical stress-testing findings; ESA cyber guidance on frontier AI; EBA climate risk data H2 2025; SEC specialised fraud unit announcement; US-UK Financial Regulatory Working Group update; SFC-CSRC ETF and climate disclosure announcement; ESMA stakeholder group competitiveness statement; EBA FRTB trading book boundary recommendation; Upper Tribunal pension transfer adviser ruling; ESAs margin exemption consultation; ASIC IPO advertising consultation; EBA ISDA margin model consultation; ECB whistleblowing SSM report. The CUBE Read is published by CUBE.

Keep up to date with our latest news and insights

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

RegTech 100 2026 award
AI 100 award
Bank Tech Awards 2025 award
RegTech of the Year APAC award
RegTech Company of the Year award

2026 ©CUBE Content Governance Global Limited and all its affiliated companies. All rights reserved.

CUBE Content Governance Global Limited is registered in England and Wales. Company No. 07886383. VAT number: GB125503739.

Registered address: CUBE, Tower 42, 25 Old Broad Street, London EC2N 1HN, United Kingdom.

2026 ©CUBE Content Governance Global Limited and all its affiliated companies. All rights reserved.


CUBE Content Governance Global Limited is registered in England and Wales.

Company No. 07886383. VAT number: GB125503739.


Registered address: CUBE, Tower 42, 25 Old Broad Street, London EC2N 1HN, United Kingdom.

TOP

TOP