How Europe Is Wiring AI Into Regulated Finance

Brussels is teaching machine learning to read the rulebook before it learns to trade.

European finance has always treated technology the way Gothic architects treated stone, slowly, with structural reverence, and on a timeline that outlives most product cycles. Three statutes now anchor the regulated AI stack. The Markets in Crypto-Assets Regulation, fully applicable since the end of 2024, sketched a unified perimeter for token issuance, stablecoin issuance, and crypto-asset services. The Digital Operational Resilience Act, in force since January 2025, demands that banks, insurers, and their critical ICT third parties prove they can absorb shocks rather than merely document them, and it pulls AI vendors inside the regulatory tent. The AI Act, with its high-risk obligations phasing in through 2026 and 2027, treats credit scoring under Annex III, pricing of life and health insurance, and biometric identification as territory that needs documentation, human oversight, and a quality management system, not a clever model card.

Layered above the statutes are the supervisory voices. The European Banking Authority, EIOPA, and ESMA have each issued guidance on machine learning in internal models, on automated underwriting, and on the explainability burden that follows any algorithm sitting between a customer and a regulated decision. The European Central Bank’s targeted review of internal models has begun to ask, in plain terms, whether the inputs to a given model can be reproduced in three years by a successor analyst, a question that quietly punishes opaque architectures. KPMG’s Pulse of Fintech reports roughly thirteen billion dollars of European fintech investment across the second half of 2024 and the first half of 2025, with AI-native business models capturing a steadily growing share.

Spain offers a useful microcosm. Law 7/2020 created the country’s financial sandbox, jointly supervised by the Banco de España, the CNMV, and the Dirección General de Seguros, and according to data published by the Treasury and the Banco de España, more than ten supervisory cohorts have entered the program since 2021, with a recurring share of cases involving AI in credit scoring, fraud detection, and automated investment advice. Madrid and Barcelona have emerged as two of the largest fintech hubs in continental Europe, and AEFI, the Spanish fintech association, estimates that several hundred firms now operate in the sector. BBVA, Santander, and CaixaBank have all published responsible AI frameworks, and Bizum, the instant payments rail co-owned by the major Spanish banks, processes transactions for more than thirty million users, a base that is fertile ground for AI-driven anti-fraud.

Across the continent the picture rhymes. According to the OECD, more than fifteen national sandboxes have operated in Europe since 2018, and tracking by the European Banking Federation suggests that more than sixty percent of large eurozone banks have at least one machine learning model embedded in their credit risk infrastructure, most often for early warning signals and stage migration under IFRS 9. EIOPA’s 2024 thematic review on AI underwriting found that nearly seventy percent of European insurers piloting AI in pricing or claims handling reported model drift as their main operational pain. The discipline that emerges is less a triumphant deployment story and more a new craft of model stewardship, a constant gardening of features, monitoring thresholds, and challenger benchmarks. McKinsey estimates European banks now spend roughly seven billion euros a year on AI capabilities, below the United States but rising in the high teens of percent annually.

The next horizon is the autonomous agent, software that does not merely advise a human but takes its own decisions, opens accounts, moves liquidity, files claims, and underwrites credit. In Europe, that horizon arrives through a forest of regulation, and every clearing has a different keeper. The AI Act lists credit scoring in Annex III as high-risk, which means a credit-deciding agent must come with a logging trail, a human override channel, and conformity documentation that survives inspection. DORA pulls model providers into the operational resilience perimeter, so a bank whose agent depends on an external foundation model has to treat that supplier the way it treats a core banking vendor. MiCA conditions any agent that touches crypto-assets, stablecoins, or e-money tokens on the underlying authorization of the venue, the issuer, and the custodian. The revised PSR and PSD3, working their way through the legislative pipeline, ask how strong customer authentication can be reconciled with software that signs on a person’s behalf.

Two articles outside the financial code may end up shaping this most. GDPR Article 22 grants individuals the right not to be subject to a decision based solely on automated processing where it produces legal or similarly significant effects, and the European Data Protection Board has been clear that an autonomous credit refusal sits squarely inside that scope. The Market Abuse Regulation, written for human traders, has barely begun to grapple with the question of whether an agent that places orders on behalf of clients, learning from each fill, can manipulate a market without the intent that prosecutors are used to proving. Around all of this floats the AML question that no statute yet answers cleanly, the question of who signs the customer due diligence file when the actor opening an account is software that evolves between audits.

European banks are responding with caution rather than retreat. The largest institutions have begun to deploy what they describe as agentic copilots, tools that draft proposals, prepare loan files, and pre-fill compliance documentation, but that hand the binding decision to a named human being who carries personal liability. The European wager is that agency in finance will arrive in supervised increments, like a tide rising under a careful harbor master, rather than in a single wave of deployment.

The contrast with the United States is by now a familiar score. American regulators favor enforcement over codification, with the SEC, the CFPB, the OCC, the CFTC, and state attorneys general policing AI in finance through individual cases. The Stanford AI Index 2025 logged more than seventy AI-related enforcement actions across federal and state agencies in 2024 alone, ranging from fair lending to robo-advisor disclosure to algorithmic price coordination. Federal legislation remains thin, and a patchwork of state attempts has not been knit into a national rulebook. The GENIUS Act of 2025 brought payment stablecoins under federal banking supervision, although its overlap with AI-driven compliance remains negotiated case by case. Agentic finance in the American mode is therefore being shaped by private pilots, JPMorgan’s trading copilots, BlackRock’s Aladdin evolving into an analytic agent, and a wave of California fintechs experimenting with AI underwriters and robo-treasurers, with regulators arriving after the fact.

China’s path is the mirror image. The People’s Bank of China and the Cyberspace Administration of China have built a tightly choreographed system in which generative models, recommendation algorithms, and credit scoring systems require licenses, security reviews, and public registration. The CAC’s generative AI measures, in force since 2023, have produced a registry of more than one hundred and ninety domestically approved foundation models by mid-2025, according to the China Academy of Information and Communications Technology. Ant Group’s MYbank and WeBank, the digital bank backed by Tencent, have been ahead of European peers in deploying machine learning to underwrite small and medium enterprises, often returning loan decisions in minutes, and they are now extending those models into agentic functions inside walled platforms. The e-CNY, the digital yuan, is deepening that integration, with central bank digital currency rails programmable in ways that European wholesale and retail digital euro programs are still debating. The pattern is one of an explicit regulatory ceiling and a broad operational floor inside a walled garden. Speed of deployment is impressive, independence from the state is not.

Where America trusts litigation and China trusts the party, Europe is trying to trust a process. The combination of MiCA, DORA, the AI Act, the GDPR, and the coming PSR is less a competitive strategy than a constitutional one, an attempt to make regulated finance legible to itself as the mathematics grows stranger.

The European wager on AI in regulated finance is that conformity, far from being a brake, becomes a moat. A bank that has documented its model lifecycle, that can explain why a generative copilot did not enter a binding decision, that can swap a foundation model without rebuilding its risk framework, and that can attribute every agent action to a human signer ends up holding a quietly valuable asset, the right to operate. That is a thinner story than the American one and a less spectacular one than the Chinese one, and both shareholders and regulators may need patience for it to compound. CB Insights logged that AI-native fintech companies attracted close to a fifth of European fintech equity funding in 2024, and names like Quantexa in financial crime intelligence or Featurespace, absorbed by Visa, are scaling on the back of supervisory survivability rather than spectacle.

The risks are honest. European institutions can mistake documentation for understanding, and the cost of compliance weighs more heavily on smaller players than on incumbents. Talent will keep migrating across the Atlantic for compensation that the European salary scale cannot match. Yet the direction of travel is set, and the early evidence suggests that the European method, slow tides rather than sudden waves, is producing financial AI that does what regulated finance is supposed to do, namely keep promises across decades. That is not a story of speed. It is a story of trust, paid for line by line.