Skip to content

FinTech and the office of the CFO

Subscribe

The State of FinTech 2026

The year supervision was rewritten. Four instruments changed what financial institutions must document, three of them by removing requirements rather than adding them, and the sector has not yet adjusted to what that means.

The State of FinTech 2026

Annual report. Written for financial services leadership.

THE 2026 REGULATORY RESETFour instruments, and one direction of travel12 May 2025All 17 CFPB circulars withdrawn,including 2022-03 on adverseaction17 Apr 2026SR 11-7 and OCC 2011-12rescinded, replaced by SR 26-2and OCC 2026-1327 Jul 2026EU AI Act Annex III obligationsdeferred to 2 December 202710 Jul 2027EU AML single rulebook applies.The only hard forward date in thesetConfirm each against the operative article of the instrument rather than a summary, particularly where numbering may have changed.

Every date is drawn from the operative instrument rather than a summary page. Three of the four narrow or defer an existing obligation. Only one adds a deadline.

This report reviews the published regulatory record for financial technology as it stood at the start of August 2026. It is not a survey and it contains no original data. Where a widely repeated figure could not be traced to a source with a method and a date, it has been left out rather than repeated, and section five explains what that leaves missing.

1. Supervision was rewritten, mostly by subtraction

The defining feature of 2026 is that three of the four instruments that changed the compliance position did so by removing or deferring an obligation, not by adding one. That is unusual, and it has produced a widespread misreading.

On 17 April 2026 the Federal Reserve's SR 11-7 and the OCC's Bulletin 2011-12, the two documents that had governed model risk management in United States banking for fifteen years, were rescinded and replaced by SR 26-2 and OCC Bulletin 2026-13. The replacement narrows the definition of a model, drops the expectation of annual validation, and places generative and agentic AI expressly outside its scope in a footnote.

On 12 May 2025 the Consumer Financial Protection Bureau withdrew all seventeen of its circulars at 90 FR 20084, including Circular 2022-03, which had addressed adverse action notices produced by models a lender could not explain.

On 27 July 2026 Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force and deferred the Annex III high-risk obligations, which include creditworthiness assessment and life and health insurance pricing, from 2 August 2026 to 2 December 2027.

The misreading is to treat withdrawal as permission. In each case the underlying statutory duty survived the guidance that explained it. The obligation under 12 CFR 1002.9 to give a specific reason for an adverse action did not change when the circular describing it was withdrawn. What changed is that the firm now has to construct its own defensible interpretation rather than point at a supervisory document.

That is a harder position, not an easier one. Guidance is a shield. Its removal transfers the interpretive burden to the institution, and the examiner who arrives in 2028 will ask what framework the firm applied in the interval.

2. The one hard date

Against three deferrals and withdrawals sits a single firm deadline. The European Union's anti-money-laundering single rulebook applies from 10 July 2027. No deferral has been proposed and none should be assumed.

For any institution operating in or into the European Union, that is the date most worth planning against, precisely because it is the one in the set that has not moved.

The practical consequence is a sequencing decision. Work deferred because the AI Act moved should not be reallocated to nothing. The AML deadline is closer in real terms than the December 2027 AI Act date, because the underlying data and screening work is heavier.

3. What the sixteen months are actually for

The AI Act deferral gives firms sixteen additional months. The obligations attached to high-risk classification are overwhelmingly evidentiary: risk management, data governance, technical documentation, logging for traceability, human oversight, accuracy and robustness testing, post-market monitoring and serious-incident reporting.

Every one of those is a record. Records cannot be produced retrospectively. A firm that arrives at 2 December 2027 without logs covering the intervening period is in exactly the position it would have been in on 2 August 2026, having had sixteen months of notice.

The two items most often deferred are the two that gate everything else. The first is a complete inventory of every system that influences a decision about a person, including systems bought as something other than a model. The second is instrumentation: logging inputs and outputs from now, because that is the obligation that cannot be met after the fact.

  • Inventory every system that influences a decision about a customer, including ones procured as workflow tools.

  • Classify each as assistive or decisional using the override rate, not the product description.

  • Begin logging inputs and outputs immediately, regardless of which regime you expect to apply.

  • Test on your own population at a stated interval, with a named reviewer.

  • Document purpose, data, oversight and monitoring. The deliverable is a file, not a feature.

The single most useful governance metric in this area is the override rate: how often a human rejects the system's recommendation. Almost nobody measures it, and without it every claim that a tool is merely assistive is an assumption rather than a finding.

4. Where liability moved, and where it did not

The United Kingdom's reimbursement regime for authorised push payment fraud has now run long enough to produce evidence rather than prediction. The maximum reimbursement is set at 85,000 pounds, the cost is split equally between sending and receiving firms, and the Payment Systems Regulator's evaluation published on 1 July 2026 reported losses down by roughly 73 million pounds a year with no observed market exits.

That combination matters because the principal argument against the regime was that it would drive smaller payment firms out of the market. On the published evidence to date, it has not.

A common error in cross-market comparison is to treat Singapore's Shared Responsibility Framework as the equivalent instrument. It is not. Its scope is phishing, not authorised push payment fraud generally, and comparisons that ignore the distinction overstate the similarity between the two regimes.

5. What this industry still does not publish

This section exists because a report that only states what is known gives a false impression of how much is known.

No credible published figure exists for straight-through processing rates in insurance claims. Every number in circulation traces to vendor marketing without a sample, a denominator or a definition of what counts as straight-through.

No published benchmark exists for the proportion of intent-flagged accounts that convert, in any adjacent market, from any vendor, analyst or academic source.

Close-cycle benchmarks are published, but the widely cited figures come from surveys with self-selected respondents and no stated definition of when a close begins. They describe who answered the survey rather than the market.

A buyer evaluating any technology in these categories should ask for the denominator and the period before the percentage. In our experience of reading this material, the question ends most vendor claims immediately, which is itself a useful filter.

6. A buyer's framework for the next eighteen months

Four questions, in order, for any decision that touches a model, a customer outcome or a cross-border flow.

  • Which obligation actually binds us, and is it statutory or guidance? Guidance can be withdrawn. Statute usually is not.

  • If the guidance we relied on were withdrawn tomorrow, what would we point at instead? If the answer is nothing, that is the gap.

  • Which of our records could we not reconstruct if asked in two years? Start logging those now.

  • What is our single hardest date? For most firms operating in Europe it is 10 July 2027, not December 2027.

The firms that will be comfortable in 2028 are not the ones that moved fastest in 2026. They are the ones that kept building records through a period when three of the four instruments told them they did not have to.

This is reporting on financial technology and operations. It is not investment, legal, accounting or tax advice.

References

Every figure and legal citation in this article is drawn from the sources below. Where an instrument is proposed rather than in force we say so in the text.

  1. Board of Governors of the Federal Reserve System, SR 26-2, model risk management, superseding SR 11-7, 17 April 2026. https://www.federalreserve.gov/supervisionreg/srletters/srletters.htm

  2. Office of the Comptroller of the Currency, OCC Bulletin 2026-13, model risk management, rescinding OCC 2011-12, 17 April 2026. https://www.occ.gov/news-issuances/bulletins/index.html

  3. Consumer Financial Protection Bureau, Withdrawal of guidance documents, 90 FR 20084, 12 May 2025. https://www.federalregister.gov/documents/2025/05/12/2025-08286/withdrawal-of-guidance

  4. European Union, Regulation (EU) 2026/1744, the Digital Omnibus on AI, deferring the Annex III high-risk obligations, adopted 8 July 2026, in force 27 July 2026. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng

  5. European Union, Regulation (EU) 2024/1689, the AI Act, Annex III, in force 2024. https://artificialintelligenceact.eu/annex/3/

  6. European Union, Regulation (EU) 2024/1624, the anti-money-laundering single rulebook, applying from 10 July 2027, 31 May 2024. https://eur-lex.europa.eu/eli/reg/2024/1624/oj

  7. Payment Systems Regulator, Evaluation of the authorised push payment reimbursement requirement, 1 July 2026. https://www.psr.org.uk/publications/

  8. Monetary Authority of Singapore, Shared Responsibility Framework, phishing scam scope, 2024. https://www.mas.gov.sg/regulation/consumer-protection

  9. United States Code of Federal Regulations, 12 CFR 1002.9, notifications under Regulation B, unchanged. https://www.ecfr.gov/current/title-12/chapter-X/part-1002/section-1002.9

How we work. This article was researched and written by the Financy editorial team. We do not republish press releases. Every number and legal citation is checked against a primary source, which is named and linked above. Where an instrument is proposed rather than in force, we say so. Corrections are made openly on the article itself, never by silent edit. If you believe something here is wrong, write to info@financyhub.com and tell us what and why.

Filed under RegTech & Compliance · Get The Weekly Brief

Relevant research

  • The State of FinTech 2026The year supervision was rewritten. Four instruments changed what financial institutions must document, three of them by removing requirements rather than adding them, and the sector has not yet adjusted to what that means.

The briefing

Keep reading the stack.

One email a week on financial technology and the finance stack.