EU AI Act: What Capital Markets Firms Must Do Now

The News

The EU AI Act’s high-risk provisions became enforceable this week, establishing the first binding regulatory framework requiring risk management systems, human oversight mechanisms, and full audit trails for AI deployed in consumer-facing financial services including credit scoring and insurance underwriting. While capital markets infrastructure falls outside the current scope, industry observers argue the regulatory logic will migrate. Edwin Mata, CEO and Co-Founder of Brickken, contends that trading, settlement, and asset-servicing systems are moving faster on AI adoption than their compliance architectures can support, and that tokenization offers a structural path to embedding the accountability layer regulators will eventually require.

Analyst Take

The Compliance Perimeter Is a Starting Line, Not a Finish Line

Regulators rarely draw a boundary and hold it. The EU AI Act’s initial scoping decisions reflect political feasibility, not a principled judgment that algorithmic trading poses less systemic risk than algorithmic credit scoring. The accountability logic is identical in both cases. When an automated system makes a consequential decision affecting third parties, someone needs to be able to explain what happened, who authorized it, and why. Consumer finance got that rulebook first because the harms are visible and the constituents are voters. Capital markets will follow because the harms, when they materialize, are larger and faster.

That creates a genuine strategic window. Firms that treat the current enforcement gap as an invitation to delay are making a bet that regulators won’t move, and that bet has a poor track record. The smarter read is to use the runway to build the audit trail and delegated-authority infrastructure now, before it becomes a remediation fire drill with a regulatory deadline attached.

The Engineering Problem Hidden Inside the Compliance Problem

Mata’s argument is fundamentally an architectural one, and it deserves to be read that way by technical audiences. The claim isn’t just that financial institutions lack documentation; it’s that their current infrastructure is incapable of producing the evidence an audit trail requires. Fragmented document repositories and manual approval chains aren’t slow versions of a working compliance system. They’re a different kind of system entirely, one that generates ambiguity rather than provenance.

The problem is that retrofitting is genuinely hard. Compliance controls bolted onto existing settlement and asset-servicing infrastructure face the same challenge that security teams face when they try to add controls to systems that weren’t designed with them in mind. ECI Research’s 2026 Application Development survey found that 21.0% of respondents cited security review bottlenecks as the biggest barrier to end-to-end CI/CD maturity, a signal that organizations consistently underestimate how deeply compliance concerns need to be woven into the build process rather than appended at the end. Capital markets firms are about to learn the same lesson at infrastructure scale.

Where Tokenization Fits

Brickken’s specific argument is that tokenization solves the provenance problem structurally. When ownership rights, transfer restrictions, and compliance rules are encoded directly into a digital asset rather than maintained in separate systems of record, the audit trail becomes a property of the asset itself. An AI agent acting on a tokenized instrument doesn’t need to consult a separate compliance layer because the compliance layer is the instrument.

That’s a meaningful architectural claim, and it maps cleanly onto a broader trend. ECI Research’s 2026 Application Development survey found that 47.4% of respondents selected software supply chain security as a top investment priority for the next 12 months, reflecting growing recognition that security and provenance need to be built into assets and pipelines rather than inspected at the boundary. The logic transfers directly. Just as software supply chain security requires provenance at the artifact level, financial infrastructure AI requires provenance at the transaction level.

The accountability question Mata raises, specifically who is liable when an autonomous system executes a bad transaction, is one regulators have already answered for consumer finance and will answer for capital markets. The answer they gave for consumer finance is that the institution deploying the AI is accountable, regardless of whether a human reviewed the specific decision. Capital markets firms should expect the same answer, which means the delegated-authority and audit trail infrastructure isn’t optional.

Looking Ahead

The EU AI Act’s enforcement calendar will compress the decision window faster than most capital markets participants currently expect. The high-risk provisions that became enforceable this week cover a defined perimeter, but the European Commission has already signaled intent to extend guidance to additional financial services use cases. Firms operating cross-border should assume that any AI system touching regulated financial decisions in the EU will face audit trail requirements within a two-to-three year horizon, and that U.S. regulators watching the EU framework will use it as a reference point for domestic rulemaking.

The competitive dynamic here favors firms that make the infrastructure investment early. Building audit trail and delegated-authority capabilities into asset infrastructure while the regulatory deadline is still abstract is cheaper and faster than doing it under enforcement pressure. Brickken’s tokenization thesis is one architectural approach; it won’t be the only one. What’s clear is that the firms still relying on document repositories and manual approval chains to reconstruct accountability after the fact are operating on borrowed time, and the EU AI Act just started the clock.

Author

  • Paul Nashawaty

    Paul Nashawaty, Practice Leader and Lead Principal Analyst, specializes in application modernization across build, release and operations. With a wealth of expertise in digital transformation initiatives spanning front-end and back-end systems, he also possesses comprehensive knowledge of the underlying infrastructure ecosystem crucial for supporting modernization endeavors. With over 25 years of experience, Paul has a proven track record in implementing effective go-to-market strategies, including the identification of new market channels, the growth and cultivation of partner ecosystems, and the successful execution of strategic plans resulting in positive business outcomes for his clients.

    View all posts