AI in Capital Markets: What IOSCO’s Report Means for Regulators

If the past few years were about discovering what artificial intelligence could do for financial markets, the next few years would be about governing it responsibly. 

That shift is reflected clearly in IOSCO’s March 2025 consultation report, “Artificial Intelligence in Capital Markets: Use Cases, Risks, and Challenges. Rather than asking whether AI belongs in capital markets, the report starts with the assumption that it already does. The real challenge now is ensuring firms deploy it responsibly, regulators supervise it effectively, and market integrity is not compromised in the process. 

This is IOSCO’s most comprehensive assessment of AI in capital markets since its 2021 guidance. Developed by the Board-level AI Working Group (AIWG), the report draws on surveys of 24 member regulators, six self-regulatory organisations (SROs), 184 industry respondents, and a series of stakeholder roundtables held across Europe, North America, and Asia. 

What makes the report particularly valuable is that it moves beyond theory. Instead of speculating AI’s future, it documents how financial institutions are already using the technology, where regulators see emerging risks, and which governance challenges are likely to shape the next phase of regulation. 

AI in Capital Markets Right Now

Only a few years ago, most conversations around AI in capital markets centred on experimentation. Today, that picture has changed considerably. IOSCO’s findings suggest that many firms have already moved beyond pilots and are deploying AI in production environments across trading, compliance, client servicing, and operations. The pace of adoption varies across institutions, but the direction is unmistakable: AI is becoming part of day-to-day market infrastructure rather than an emerging technology waiting on the sidelines. 

Among broker-dealers, client communications top the list – 67% of IOSCO member respondents observed it as a current use case. Algorithmic trading came in at 63%, and surveillance and fraud detection at 53%. Asset managers are investing most heavily in robo-advising and portfolio optimisation (60%), followed by AI-supported investment research (40%). For exchanges and market infrastructures, transaction processing and automation leads at 40%. 

Across all organisation types, the AMCC survey – 184 respondents from five continents – found that internal productivity support is the most widely deployed use case. Document summarisation, coding assistance, meeting transcription, internal chatbots: these are where most firms are starting. That makes sense. Internal deployments carry lower regulatory exposure, and they give firms the time to understand what these tools can and cannot do before taking them into client-facing or trading functions. 

But the movement is clearly outward. Large language models (LLMs) are being wired into AML investigations and compliance review. Retrieval-Augmented Generation (RAG) systems are pulling answers from internal knowledge bases to support staff queries. And on the near horizon, agentic AI systems – tools that plan and act with minimal human instruction – are attracting serious interest from financial institutions. The pace of capital markets AI adoption is not slowing. If anything, competitive pressure is accelerating. 

What IOSCO's Data Reveals

One of the report’s strengths is its balanced perspective. 

IOSCO avoids portraying AI as either an existential threat or a silver bullet. Instead, it presents AI as a powerful technology whose benefits depend largely on how well firms manage the risks that accompany it. 

Importantly, many of these risks are not entirely new. Financial regulators have spent decades overseeing issues such as outsourcing, operational resilience, model governance, cybersecurity, and market abuse. AI doesn’t replace those challenges – it amplifies them, often at greater scale and speed. 

The report identifies four areas that deserve particular attention.  

1. Fraud, Deepfakes, and Malicious Use

Perhaps the most striking aspect of the report is the amount of attention given to AI as a tool for criminals rather than financial institutions. 

Generative AI is changing the nature of financial fraud. Deepfake technology, AI-generated voice cloning, and synthetic identity documents are making impersonation attacks significantly more convincing than traditional phishing attempts. These technologies are no longer hypothetical – they are already being used against financial institutions. IOSCO points to a November 2024 FinCEN alert warning that synthetic media was being used to bypass identity verification and customer due diligence controls. 

Relationship investment scams are evolving just as quickly. Fraudsters are using AI to create highly personalised communications, sustain conversations over extended periods, and build trust before promoting fraudulent investment opportunities. 

The Ontario Securities Commission found that participants exposed to AI-enhanced investment scams invested roughly 22% more than those presented with conventional scams. That statistic is difficult to ignore. 

Compounding the challenge is the falling cost of sophisticated attacks. Open-source generative AI models and purpose-built malicious variants are now widely accessible, lowering the barrier to entry for cybercriminals around the world.

2. Model Limitations and Data Quality

AI governance for financial regulators runs directly into a fundamental challenge: LLMs are, by design, non-deterministic. They produce probabilistic outputs. They can generate responses that are fluent, confident, and wrong – what the report calls hallucinations or confabulations. In a compliance context, where the outputs of AI tools might feed investment advice, regulatory filings, or trading decisions, those errors carry consequences. 

Data quality is the other side of this. Models trained on biased, incomplete, or unrepresentative data reproduce those problems at scale. The sector’s growing reliance on a concentrated set of data aggregators – for training data, for market data, for alternative data – means a quality failure at one source can propagate quickly across many downstream systems. For vendor-supplied or open-source models, firms often have no visibility into what data was used for training, whether it was obtained with appropriate consent, or whether it contains the kind of biases that would create compliance exposure in a regulated context.

3. Third-Party Dependency and Concentration Risk

One issue that deserves more attention than it often receives is concentration. Many financial institutions may believe they are building independent AI capabilities, but beneath the surface they frequently rely on the same cloud providers, foundation models, and data vendors. That creates a form of shared dependency that regulators have worried about for years in other parts of financial infrastructure – and AI may reinforce it rather than reduce it. 

IOSCO notes that many of the most critical AI building blocks sit outside the traditional regulatory perimeter. Cloud providers and foundation model vendors are not securities regulators’ direct supervisees, yet they increasingly influence how regulated firms operate. 

Even obtaining adequate technical information from these providers – about training data, model behaviour, and known failure modes – can be challenging. 

4. Human Oversight and Automation Bias

Technology often dominates discussions about AI, but IOSCO reminds readers that many of the biggest risks remain fundamentally human. As AI systems become more capable, users naturally become more willing to trust their outputs. That tendency – known as automation bias—is well documented, but it takes greater significance in regulated environments where accountability ultimately rests with people, not algorithms. 

A practical concern here is that confidence is not the same as correctness. An AI system that presents answers fluently and quickly can create a strong impression of reliability even when the underlying reasoning is weak. 

IOSCO also highlights a talent challenge. Firms need professionals who understand AI systems, financial markets, and regulatory obligations simultaneously. That combination remains relatively rare. 

How Regulators Are Responding Globally

One encouraging finding is that regulators are not starting from scratch. Most jurisdictions are starting from a technology-neutral baseline: existing rules on conduct, risk management, disclosure, and outsourcing apply to AI-powered activities just as they apply to any other. That gives regulators something to work with immediately, without waiting for new frameworks. 

On top of that, many regulators are issuing targeted guidance to clarify how existing obligations apply in AI contexts. ESMA published guidance in May 2024 on AI in retail investment services, mapping AI use cases to MiFID II obligations. Canada’s securities administrators published a staff notice in December 2024 doing the same for Canadian markets. The Commodity Futures Trading Commission (CFTC) issued a staff advisory the same month reminding registered entities of their obligations under the Commodity Exchange Act as they integrate AI. 

Some jurisdictions are going further with AI-specific frameworks. The EU AI Act is the most prominent example, introducing risk-based obligations for certain AI applications. Japan, Brazil, Australia, and Canada are also developing more explicit AI governance frameworks. 

Singapore’s Project MindForge stands out as a model worth watching. MAS co-created a GenAI risk framework with major banks and technology firms, mapping risks across the full AI lifecycle – accountability, governance, transparency, fairness, cybersecurity, and more. The framework is now being extended to insurance and asset management. Collaborative co-creation between regulators and industry is a meaningful alternative to top-down rulemaking, particularly in a space where the technology is moving faster than the legislative cycle. 

Across the board, regulators are also investing in their own AI capability for financial supervision: specialist teams, updated examination priorities, academic partnerships, and – notably – the use of AI itself to support supervisory functions like document analysis, anomaly detection, and surveillance. 

What Comes After Phase One

IOSCO is explicit that this is Phase One of a broader effort. Phase Two will assess whether additional tools, guidance, or recommendations are needed to address the risks identified in the report. 

Several themes are already emerging: 

  • Investor education on AI-enabled fraud 
  • Cross-border supervisory cooperation 
  • Accountability frameworks for third-party AI providers 
  • Capacity-building support for regulators in emerging markets 

The report also flags longer-term questions that remain unresolved, including whether widespread use of similar AI models could lead to herding behaviour in markets and whether autonomous trading agents could develop problematic interactions that were never explicitly programmed. 

Those risks remain more theoretical than immediate, but IOSCO is right to put them on the radar early. 

Where RegTech Fits In

Reading across all four risk areas, a common thread emerges: trusted regulatory data. Whether the issue is model governance, fraud detection, third-party oversight, or supervisory analytics, everything ultimately depends on accurate, validated, and traceable data. Without that foundation, even sophisticated AI systems struggle to produce reliable outcomes. 

That is precisely where purpose-built platforms like IRIS iFile come in. IRIS iFile supports regulators and financial supervisory authorities with automated data collection, validation, and real-time analytical oversight – the kind of infrastructure that helps supervisors manage growing data volumes without sacrificing transparency or accountability. 

The principles IOSCO identifies for sound AI governance in capital markets – transparency, accountability, reliability, and robust human oversight – apply as much to the tools regulators use as to the tools they oversee. Supervisory platforms built on those principles are better positioned for the next phase of regulatory engagement with AI. 

AI in Capital Markets Is a Governance Story

The biggest takeaway from IOSCO’s report is that the conversation around AI has matured. Technology is already embedded across capital markets. The more pressing questions now concern governance, accountability, transparency, and supervisory readiness. 

Phase One establishes a shared understanding of where the industry stands today. Phase Two is likely to shape how regulators expect firms to manage AI going forward. 

For financial institutions, technology providers, and supervisory authorities alike, this is an opportunity to prepare before expectations harden into formal requirements. Those who invest early in robust governance, high-quality data, and effective oversight will be far better positioned as the regulatory landscape continues to evolve. 

Leave a Reply

Your email address will not be published. Required fields are marked *

Are you human? Please solve:Captcha


IRIS RegTech Solutions Limited (formerly known as IRIS Business Services Limited)
Subsidiaries

IRIS Regtech Sdn. Bhd. (Malaysia)

IRIS Business Services (Asia) Pte. Ltd., Singapore

IRIS Business Services, LLC, USA

Atanou S.r.l. (Italy)

IRIS Data Solutions Private Limited

Follow Us On Social
Stay connected and follow us on social media for the latest updates and news.
Avantage
Headquarters
Visualize quality intellectual capital without superior collaboration and idea sharing installed base portals.
Our locations
Where to find us?
https://i0.wp.com/irisregtech.com/wp-content/uploads/2020/04/img-footer-map-1.png?fit=280%2C142&ssl=1
Get in touch
Avantage Social links
Taking seamless key performance indicators offline to maximise the long tail.

©2025 IRIS RegTech Solutions Limited. All rights reserved.
Read our Privacy Policy, Cookies Policy, and Terms & Conditions for more.