Finance Firms Keep 87% of AI Use Cases Internal as EU Rules Take Effect

Monday, 24/08/2026 | 10:41 GMT by Damian Chmiel
  • Only 13% of the 847 reported projects served customers or investment functions.
  • Still, 76% of respondents expected the AI Act to have a moderate or strong business impact.
A sign of the euro
A sign of the euro

FM Intelligence found that 87% of 847 AI use cases reported by EU securities firms were internal. The findings were published today (Monday).

For brokers and platform providers, customer-facing AI agents remain a small part of documented adoption.

The full FM Intelligence report places the immediate workload in governance, staff access, vendor control and transparency.

At firm level, 23% of respondents expected the European Union's Artificial Intelligence Act (AI Act) to affect them strongly and 53% expected a moderate impact. Together, that is 76%.

Internal Tools Dominate the Reported Base

The European Securities and Markets Authority (ESMA) survey received responses from 728 firms in 19 countries. Among them, 395 firms reported 847 use cases, with no more than three principal cases requested from each respondent.

Internal work accounted for 87% of those cases. Customer relationship tools made up 10%, while systems used to provide investment services represented 3%.

Drafting and internal assistance led the reported applications. ESMA said firms were pursuing operational efficiency, not direct revenue.

The public picture is more client-facing. Your Bourse opened its trade server to permissioned AI queries and actions this month, including hedges and position closures that require human confirmation.

Capital.com connected AI agents to trading for MENA clients in June, with two confirmations required before execution.

Large Firms Pull Away on AI Investment

ESMA's investment figures show a wide gap by company size. In 2024, 93% of large respondents invested in AI, compared with 40% of small firms and 21% of micro firms.

The 72-percentage-point difference between large and micro firms does not measure spending amounts. One hundred respondents did not answer the investment question or said they did not know.

Hosting also leaned toward external infrastructure. Of 397 respondents that answered the question, 62% used only commercial cloud services and 41% relied on a single commercial provider.

Microsoft was the top-ranked third-party AI provider by fees for 47% of 344 firms that named at least one supplier. OpenAI followed with 20% and Amazon Web Services with 8%.

Those percentages measure provider mentions, not market share, workloads or spending. Firms can also reach one model through another vendor's cloud, leaving common dependencies behind apparently separate contracts.

Public GenAI Access Runs Ahead of Formal Policies

ESMA reported that 74% of respondents allowed employees to access public generative AI tools. Unrestricted access was permitted by 39%, while 32% reported having a formal policy.

The regulator did not publish a separate response count for each question. The percentages are reported survey shares and should not be treated as population estimates for all EU financial firms.

Training data carry another limitation. Sixty-five percent of respondents said they had trained or planned to train employees, combining completed programs with future intentions.

Only 17% reported complete AI understanding at board or senior-management level, falling to 8% among operational staff. Human approval may limit a system's autonomy, but it does not show whether the reviewer can identify a faulty output.

The AI Act Does Not Treat Every Finance Tool Alike

The European Commission began enforcing applicable AI Act rules on Aug. 2. The new transparency requirements include disclosure when users interact with certain AI systems.

Customer credit scoring is one of the finance-related uses listed as high-risk. Standard internal drafting, market surveillance and algorithmic trading do not become high-risk merely because they use AI.

That distinction does not remove existing financial rules. Firms still need to account for model access, audit trails, outsourcing, resilience and responsibility for third-party systems.

A recent FinanceMagnates.com article argued that the immediate compliance test for AI trading is supervision, including whether a broker can reconstruct a client's instruction and the resulting order.

The Denominator Changes the 76% Reading

The 87% and 76% figures measure different things. The first is a share of reported use cases. The second combines firm-level answers to the impact question, for which ESMA did not publish a separate response count.

They therefore cannot be read as a direct comparison or proof that internal tools caused the expected regulatory impact. The survey was voluntary and ESMA said its results were not necessarily representative of all EU securities firms.

Regulators are also assessing risks that extend beyond classification. The UK's Financial Conduct Authority (FCA) warned in July that shared reliance on a small group of models and providers could create common points of failure.

AI Act transparency requirements started applying on Aug. 2, 2026. The main duties for stand-alone high-risk systems under Annex III are scheduled for Dec. 2, 2027, while product-linked systems under Annex I move to Aug. 2, 2028.

The complete FM Intelligence report examines the firm-size investment gap, provider concentration, public GenAI controls and the deadlines that apply after August 2026.

FM Intelligence found that 87% of 847 AI use cases reported by EU securities firms were internal. The findings were published today (Monday).

For brokers and platform providers, customer-facing AI agents remain a small part of documented adoption.

The full FM Intelligence report places the immediate workload in governance, staff access, vendor control and transparency.

At firm level, 23% of respondents expected the European Union's Artificial Intelligence Act (AI Act) to affect them strongly and 53% expected a moderate impact. Together, that is 76%.

Internal Tools Dominate the Reported Base

The European Securities and Markets Authority (ESMA) survey received responses from 728 firms in 19 countries. Among them, 395 firms reported 847 use cases, with no more than three principal cases requested from each respondent.

Internal work accounted for 87% of those cases. Customer relationship tools made up 10%, while systems used to provide investment services represented 3%.

Drafting and internal assistance led the reported applications. ESMA said firms were pursuing operational efficiency, not direct revenue.

The public picture is more client-facing. Your Bourse opened its trade server to permissioned AI queries and actions this month, including hedges and position closures that require human confirmation.

Capital.com connected AI agents to trading for MENA clients in June, with two confirmations required before execution.

Large Firms Pull Away on AI Investment

ESMA's investment figures show a wide gap by company size. In 2024, 93% of large respondents invested in AI, compared with 40% of small firms and 21% of micro firms.

The 72-percentage-point difference between large and micro firms does not measure spending amounts. One hundred respondents did not answer the investment question or said they did not know.

Hosting also leaned toward external infrastructure. Of 397 respondents that answered the question, 62% used only commercial cloud services and 41% relied on a single commercial provider.

Microsoft was the top-ranked third-party AI provider by fees for 47% of 344 firms that named at least one supplier. OpenAI followed with 20% and Amazon Web Services with 8%.

Those percentages measure provider mentions, not market share, workloads or spending. Firms can also reach one model through another vendor's cloud, leaving common dependencies behind apparently separate contracts.

Public GenAI Access Runs Ahead of Formal Policies

ESMA reported that 74% of respondents allowed employees to access public generative AI tools. Unrestricted access was permitted by 39%, while 32% reported having a formal policy.

The regulator did not publish a separate response count for each question. The percentages are reported survey shares and should not be treated as population estimates for all EU financial firms.

Training data carry another limitation. Sixty-five percent of respondents said they had trained or planned to train employees, combining completed programs with future intentions.

Only 17% reported complete AI understanding at board or senior-management level, falling to 8% among operational staff. Human approval may limit a system's autonomy, but it does not show whether the reviewer can identify a faulty output.

The AI Act Does Not Treat Every Finance Tool Alike

The European Commission began enforcing applicable AI Act rules on Aug. 2. The new transparency requirements include disclosure when users interact with certain AI systems.

Customer credit scoring is one of the finance-related uses listed as high-risk. Standard internal drafting, market surveillance and algorithmic trading do not become high-risk merely because they use AI.

That distinction does not remove existing financial rules. Firms still need to account for model access, audit trails, outsourcing, resilience and responsibility for third-party systems.

A recent FinanceMagnates.com article argued that the immediate compliance test for AI trading is supervision, including whether a broker can reconstruct a client's instruction and the resulting order.

The Denominator Changes the 76% Reading

The 87% and 76% figures measure different things. The first is a share of reported use cases. The second combines firm-level answers to the impact question, for which ESMA did not publish a separate response count.

They therefore cannot be read as a direct comparison or proof that internal tools caused the expected regulatory impact. The survey was voluntary and ESMA said its results were not necessarily representative of all EU securities firms.

Regulators are also assessing risks that extend beyond classification. The UK's Financial Conduct Authority (FCA) warned in July that shared reliance on a small group of models and providers could create common points of failure.

AI Act transparency requirements started applying on Aug. 2, 2026. The main duties for stand-alone high-risk systems under Annex III are scheduled for Dec. 2, 2027, while product-linked systems under Annex I move to Aug. 2, 2028.

The complete FM Intelligence report examines the firm-size investment gap, provider concentration, public GenAI controls and the deadlines that apply after August 2026.

About the Author: Damian Chmiel
Damian Chmiel
  • 3879 Articles
  • 116 Followers
About the Author: Damian Chmiel
Damian Chmiel is a Senior Analyst & Editor at Finance Magnates with more than 15 years of experience in the CFD and online trading industry. Active as both a trader and journalist since 2010, he focuses on broker coverage, fintech innovation, and regulatory developments across Europe, the Middle East, and Asia. His work includes interviews with C-level leaders at major brokerages and fintech platforms, as well as co-authoring Finance Magnates’ quarterly industry benchmarking reports. Damian’s reporting is data-driven, market-aware, and grounded in direct industry engagement. His analysis and commentary have also been cited by external media outlets, including Investing.com, Binance, The Asset, Stockhead, and Dispatch. Education: MA in Finance and Accounting, Cracow University of Economics
  • 3879 Articles
  • 116 Followers

More from the Author

Retail FX

!"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|} !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}