The AI Learning Hub Journal
◆ References

Checking This Course Against the Sources

Weighing what you read about AI in financethe higher the rung, the more weight a claim carries on its own — weight increases upwardsRUNGWHAT IT IS, AND WHY IT SITS HEREEXAMPLES BEHIND THIS COURSEWEIGHT Primary regulation and rules binding — everything below it is a readingThe text that creates the duty. Every rungbelow is somebody reading it, and readingsdrift from the text over time.The EU AI Act, GDPR, MiFID II, theMarket Abuse Regulation and DORA;ECOA with Regulation B in the US Supervisory expectations how the bodies that examine you read themNot law, but the closest available statementof how the rules will be applied to your firm.Reissued often — check the version.US banking agencies on model risk;the UK PRA’s model risk principles;FINRA Rules 3110 and 2210; the FCA Standards and evidence disinterested, and the method is shownNo product to sell, and the method is on thepage. General and slow — it describes apopulation, not your book.The NIST AI Risk ManagementFramework; FSB, IOSCO and BaselCommittee work on AI in finance Practitioner commentary fast and concrete, but nobody checked itSays what a deployment actually feels like,which no supervisor writes down. Generalisesfrom one firm, and is reviewed by no one.Conference talks, client alerts,blog posts, and single-firmexperience written up informally Vendor material written by the party selling the answerThe only source for what a product actuallydoes, and the least disinterested one youwill read. Each claim is one to test.Product pages, benchmark claims,demos, and case studies with noindependent replication Closest to you and not on this ladder: your own regulator’s guidance, your model risk policy and inventory, your compliance and records retention rules, and your approved-tool list — the group that settles the most real questions Read downwards to find what binds you; read upwards to check what you were told This course is not on the ladder — it is model-drafted orientation, and it carries no authority at all
Every rung has a use — the ladder is about how much weight a claim carries on its own.

How This Course Was Made

This course was drafted by an AI model working to an editorial brief and then edited. It has not been reviewed by a practising risk, compliance or supervisory professional in any jurisdiction, and it claims no authority. Treat it as orientation: vocabulary, the shape of the arguments, and the questions worth putting to somebody whose job it is to be right about them. It is not a basis for a model approval, a compliance position, a control design, or an investment decision — each of those needs a source that carries responsibility for the answer, and a course page does not. That is also why the lessons say where an answer is jurisdictional instead of supplying one.

  • Model-drafted to an editorial brief and edited — not reviewed by a practising risk, compliance or supervisory professional
  • It carries no authority, so treat each claim as a prompt to check a source rather than as a finding
  • Never a basis for a model approval, a compliance position, a control design, or an investment decision
  • Where a lesson says the answer is jurisdictional, that is the content — uniform confidence would be the larger error

The Source Ladder

When you read anything about AI in finance, including this, the useful first question is which rung it came from. Primary regulation and directly applicable rules sit at the top: they bind you whether or not anybody has summarised them accurately. Below that, supervisory expectations and official guidance from the authorities that examine you — not law, but the closest available statement of how the rules will be applied to your firm. Below that, standards and peer-reviewed evidence, disinterested and method-transparent but general and slow. Then practitioner commentary, which is fast, concrete and reviewed by nobody. Vendor material sits last: the only source for what a product does, and the least disinterested one you will read.

  • Primary regulation binds you; everything below it is somebody reading it, and readings drift from the text
  • Supervisory expectations are the nearest thing to knowing how the rules will be applied to your firm
  • Standards and peer-reviewed work are disinterested and show their method, but are general and slow
  • Commentary is unreviewed; vendor accuracy and performance claims are claims to test, never evidence

The Sources This Course Rests On

These are the anchors the lessons were written against, grouped by rung and named so you can read them rather than take this course's word for anything. They are deliberately unlinked, because deep links rot and the issuing body's own site is where the current version lives. Where an instrument is described by its issuing body and subject rather than by a reference number, that is deliberate. Two caveats matter more than the list. Everything jurisdictional is scoped, and the EU, UK and US items say nothing about obligations anywhere else. And the last group settles more real questions than the first five, because it is the only one that knows your firm.

  • Model risk: the US federal banking agencies' interagency supervisory guidance on model risk management, and the UK PRA's supervisory statement setting out model risk management principles for banks
  • International bodies, standards and method: the Financial Stability Board on AI in financial services and its financial stability implications; IOSCO on the use of AI and machine learning by market intermediaries and asset managers; the Basel Committee on Banking Supervision on the digitalisation of finance; cross-sector, the NIST AI Risk Management Framework with its generative AI profile; and, behind module 3, the finance literature on backtest overfitting and multiple testing in strategy research, on deflated performance measures, and on leakage and cross-validation in financial machine learning
  • In the EU: the AI Act and its risk tiering, including creditworthiness assessment of natural persons as a high-risk use; GDPR, including its provisions on automated decision-making; MiFID II on suitability, product governance and communication records; the Market Abuse Regulation on inside information; DORA on digital operational resilience and third-party risk; and supervisory communications from the EBA and ESMA on AI use in banking and investment services
  • In the UK: the FCA and the Bank of England on AI in financial services, the FCA's Consumer Duty, and the critical third parties regime for the firms the sector depends on
  • In the US: FINRA on broker-dealer supervision (Rule 3110) and communications with the public (Rule 2210); the SEC's books-and-records and compliance requirements for investment advisers, its marketing rule for advisers, and its actions on off-channel business communications; Regulation Best Interest for retail broker-dealer recommendations; and the Equal Credit Opportunity Act with Regulation B, written by the CFPB, behind the adverse-action explanation duty on credit declines
  • Closest to you, and not on this page: your own regulator's guidance on AI in financial services, your institution's model risk policy and model inventory, its compliance and records retention rules, and its approved-tool list

Keeping Current, and What to Do When This Is Wrong

Everything above moves, and this area moves faster than most. The EU AI Act's obligations phase in over time rather than arriving at once. Supervisors in several jurisdictions are still issuing their first substantive expectations on AI, and consultations were open while this was written. Guidance gets reissued, and a statement that was correct can become wrong with nothing being retracted. So check the issuing body's own site for the current text rather than trusting a summary, this one included. Several questions raised here have no general answer at all: whether a use is high-risk, what may lawfully be processed, what must be retained and for how long, and who must be told after an incident are per-jurisdiction and often per-firm.

  • Check the issuing body's own text — summaries, including this one, date faster than their sources
  • Risk classification, lawful processing, retention periods and incident notification are per-jurisdiction answers
  • Phased regimes and reissued guidance turn correct statements wrong without anything being retracted
  • Report an error you find here — naming sources is an invitation to check them, not a claim to have got them right

Prefer slides, quizzes, and saved progress? Read this lesson in the library — free, no sign-up.