The AI Rules Every EU Wealth-Management Firm Must Follow (2026)
If you run AI in an EU wealth-management firm, five bodies of rules already apply to that use: MiFID II conduct rules, MiFID II recordkeeping, ESMA's 2024 statement on AI in investment services, the GDPR, and the EU AI Act. None of them is an "AI regulation" in isolation. Four of the five predate the AI Act and already bind the AI tools you use today. The AI Act adds transparency duties from 2 August 2026 and, for a narrow set of high-risk uses, a heavier regime whose main deadline the EU pushed to 2 December 2027. This guide sets out each rule, what it means for an AI workflow in practice, and the compliant fix.
This article sits inside Serra's AI-for-wealth pillar. For the UK equivalent, see the AI mistakes UK financial advisers make; for why the underlying problem is governance rather than adoption, see the AI gap in wealth is governance, not adoption.
Does MiFID II apply to AI, or is AI a separate regime?
MiFID II applies; AI gets no carve-out. ESMA's position is that a firm using AI must still meet its existing MiFID II obligations. In its May 2024 statement, ESMA said firms using AI are expected to comply with relevant MiFID II requirements on organisational aspects, conduct of business, and acting in the client's best interest.
That is ESMA's own framing (Public Statement on AI and investment services, ref. ESMA35-335435667-5924, 30 May 2024). In practice the conduct standard you already meet for a human-drafted client communication is the standard an AI-drafted one must also meet. MiFID II requires that information addressed to clients be fair, clear and not misleading. An AI model that produces a polished, confident client note is producing a regulated communication, and confident wording is not the same as accurate wording.
The compliant fix: treat model output that touches a client as a draft, not a deliverable. Put a named human between the model and the client, and make that reviewer accountable for the fair-clear-not-misleading standard. Suitability is the same story: a model can help assemble a suitability case, but the firm, not the model, owns the assessment that the product fits the client.
What does ESMA specifically expect from a firm using AI?
ESMA expects firms to map AI use onto duties that already exist, not to wait for a new rulebook. Its 2024 statement lists the realistic use cases (customer service, investment advice, portfolio management, compliance, risk, fraud detection), flags the risks it wants managed (bias, data quality, opacity, over-reliance, privacy), and requires transparency about AI's role.
ESMA lists those use cases and risks in ESMA35-335435667-5924 (30 May 2024). It expects firms to be transparent about the role AI plays in the investment decision-making process and to present that information in a manner that is clear, fair and not misleading (same source).
The compliant fix: write down where AI sits in each client-facing workflow, who owns the output, and how bias and data quality are checked. That record is what ESMA's "organisational aspects" language is asking for, and it is the same document your auditor will want.
What does MiFID II require me to keep on record when AI is in the workflow?
Recordkeeping does not soften because a model did the drafting. MiFID II Article 16(6) requires records of all services, activities and transactions sufficient for the competent authority to verify compliance. Article 16(7) requires recording of communications relating to transactions and client orders, client notification, and a minimum five-year retention.
Those provisions are in Directive 2014/65/EU Article 16 (ESMA Interactive Single Rulebook, esma.europa.eu). The practical exposure: every model-drafted memo, AI-summarised client call, and model-screened shortlist that feeds a client decision is a record that has to be reconstructable after the fact. A firm that cannot show what the model was asked, what it produced, and who signed off has a recordkeeping gap, not a productivity gain.
The compliant fix: log the AI step inside the same evidence chain you already keep for the human one. Capture the prompt, the output, the reviewer, and the sign-off, and retain it on the MiFID II clock (five years minimum under Article 16(7)).
Is client data in an AI prompt a GDPR problem?
Yes. The moment client personal data goes into a prompt, the GDPR applies to that processing. A wealth client's name, holdings and circumstances are personal data. The sharper rule is Article 22: a data subject has the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
The GDPR (Regulation (EU) 2016/679) governs that processing, and Article 22(1) grants that right; where automated decision-making is permitted, Article 22(3) requires safeguards including human intervention, the right to express a view, and the right to contest (gdpr-info.eu / EUR-Lex). For a wealth firm this bites in two places. Pasting client data into a general-purpose tool never scoped for confidential financial data is a processing decision the firm must justify. And a decision that materially affects a client, a suitability outcome or a portfolio action, cannot rest on the model alone without the Article 22 safeguards.
The compliant fix: decide which tools are allowed to see client data and contain that work inside a covered environment; keep a human in the loop on any decision that significantly affects a client; and, as a baseline discipline, keep live client data out of general-purpose AI tools entirely. The full argument on client data in AI tools sets out the practical test.
What EU AI Act risk category does typical wealth-management AI fall into?
For most wealth uses, limited-risk transparency, not the high-risk regime. Under the AI Act, the only financial-services use listed as high-risk is narrow: AI that evaluates a person's creditworthiness or sets their credit score, with an exception for fraud detection. Drafting communications, summarising research, and internal productivity work are not on that list.
That high-risk item is AI Act Annex III point 5(b) (Regulation (EU) 2024/1689, artificialintelligenceact.eu); Annex III's high-risk areas are biometrics, critical infrastructure, education, employment, essential public and private services, law enforcement, migration, and administration of justice. So the typical wealth stack, a model drafting a memo, summarising a manager call, or screening a deal, is generally not high-risk. It is subject instead to the Article 50 transparency obligations. The exception matters: a firm that runs AI to score the creditworthiness of individual clients has a high-risk system under Annex III point 5(b) and carries the heavier regime.
The compliant fix: classify each AI system by what it does, not by how advanced it is. Map any creditworthiness-scoring use to the high-risk track. Treat client-facing generative and interactive uses as limited-risk transparency obligations, covered next.
What transparency does the EU AI Act require, and when does it apply?
Article 50 is the provision that reaches everyday wealth AI. It requires providers of AI that interacts directly with people to ensure those people are told they are dealing with an AI system, unless that is obvious. It also requires deployers who generate published public-interest text to disclose that it was artificially generated.
Those duties are AI Act Article 50(1) and 50(4) (Regulation (EU) 2024/1689, artificialintelligenceact.eu). On timing: the AI Act entered into force on 1 August 2024 and applies in phases (European Commission, digital-strategy.ec.europa.eu). Prohibited practices applied from 2 February 2025, and general-purpose AI and governance rules from 2 August 2025. The Article 50 transparency obligations apply from 2 August 2026. One element moved: machine-readable marking of AI-generated content under Article 50(2) applies from 2 December 2026 for systems already on the market, following the EU's Digital Omnibus package adopted by the Council on 29 June 2026 (White & Case; CMS, 2026). The high-risk regime for standalone Annex III systems was deferred by that same package from 2 August 2026 to 2 December 2027 (European Commission; CMS, 2026).
The compliant fix: for any client-facing chatbot or assistant, disclose that clients are dealing with AI. For AI-generated content you publish, disclose it where Article 50(4) applies. Diarise 2 August 2026 for the transparency baseline, and 2 December 2026 for the content-marking element on existing systems.
How does the EU approach compare with the US?
The EU is ahead of the US on codified AI rules for this sector. In the US the SEC's predictive-analytics proposal (S7-12-23) is withdrawn, not pending, so US firms face AI-washing enforcement under existing antifraud rules rather than a bespoke AI conduct code. In the EU the code already exists across MiFID II, the GDPR, and the AI Act.
The US enforcement reference points are the SEC's Delphia and Global Predictions settlements (400,000 USD total, 18 March 2024). That is the operating environment a EU wealth firm plans against: a settled body of rules already in force, not a proposal that may or may not arrive.
The binding constraint is governance, not the model
Read the five rule-sets together and one thing is constant: not one of them regulates which model you pick. They regulate whether a human owns the output, whether client data stays contained, whether client-facing AI is disclosed, and whether you can reconstruct what the model did. That is governance, and it sits in the workflow around the model.
A firm can swap GPT for Claude for Gemini and change nothing about its compliance position, because the binding constraint is the workflow. This is the work Serra Education does with wealth firms: adopting AI with the guardrails built in from the start. Validated output with a named human check, contained client data, disclosed client-facing use, and an audit trail that exists before anyone asks for it. The differentiator in the engagement is the Regulator Test: we build each AI workflow so it can answer the question an ESMA or national-competent-authority reviewer would actually ask, before the reviewer asks it.
The entry point is a Consulting 1 session, 250 EUR, and that fee credits toward the Tier 1 audit if you go on to the full engagement. The firms that close the governance gap first turn AI into a durable advantage. The firms that leave it open are deferring a compliance cost to the first audit.
See the full picture at the AI-for-wealth pillar. To book the Consulting 1 session or request the Tier 1 audit outline, use the report and booking page.
FAQ
Does MiFID II apply to AI used in a wealth-management firm?
Yes. ESMA's position is that a firm using AI must still meet its existing MiFID II obligations on organisational arrangements, conduct of business, and acting in the client's best interest (ESMA35-335435667-5924, 30 May 2024). The technology creates no carve-out; an AI-drafted client communication must meet the same fair, clear and not misleading standard as a human-drafted one.
Can an EU wealth firm put client data into a general-purpose AI tool?
Not safely. The moment client personal data enters a prompt, the GDPR applies to that processing, and pasting it into a tool never scoped for confidential financial data is a decision the firm must justify (Regulation (EU) 2016/679, Article 22). The baseline discipline is to keep live client data out of general-purpose AI tools and contain any real-data work in a covered environment.
Is typical wealth-management AI high-risk under the EU AI Act?
Usually not. The only financial-services use the AI Act lists as high-risk is evaluating a person's creditworthiness or credit score (Annex III point 5(b), Regulation (EU) 2024/1689). Drafting memos, summarising calls, and screening deals fall under the lighter Article 50 transparency obligations instead. Only a firm scoring individual clients' creditworthiness enters the high-risk regime.
When do the EU AI Act transparency rules start applying?
The Article 50 transparency obligations apply from 2 August 2026 (European Commission, digital-strategy.ec.europa.eu). Machine-readable marking of AI-generated content under Article 50(2) applies from 2 December 2026 for systems already on the market, and the high-risk regime for standalone Annex III systems was deferred to 2 December 2027 following the Digital Omnibus package adopted 29 June 2026.
What is the single most important AI compliance step for an EU wealth firm?
Governance around the model, not the choice of model. Put a named human between AI output and the client, contain client data in a covered environment, disclose client-facing AI use, and keep a reconstructable record of what the model was asked and who signed off. None of the five applicable rule-sets regulates which model you pick; they all regulate the workflow around it.
Serra Education provides process and tooling consulting only, never Serra Wealth investment advice.
This article is general information on AI-adoption process and governance. It is not investment, legal, or compliance advice. Each firm remains responsible for its own regulatory compliance and for validating AI output. No live client data should be placed in any AI workflow. Regulatory positions and timelines can change; confirm current obligations with qualified counsel and against the primary sources before you rely on them.