It's not the AI rules but the pile-up of digital regulation that is holding back AI adoption at banks
The banks consider the individual rules fine; it is the combination that causes the problem
:quality(80))
It is the accumulation of legislation and regulation, not the AI rules themselves, that is slowing AI adoption at Dutch banks. That is the finding of conversations with Dutch banks conducted by Mila Verhaag, AI governance expert at Ace, former VU Amsterdam student Quirinne Lammers and Arthur Willigenburg, CEO and founder of Ace. The banks consider the individual rules fine; it is the combination that causes the problem. And geopolitically, this is no luxury problem: while the US deregulates and China presses ahead with AI, Europe cannot afford to let its banks lose speed to their own regulatory stack.
Multiple frameworks, multiple supervisors, one application
Take a consumer credit model. It already meets the current rules under prudential supervision, but from December 2027 it will also be a high-risk application under the AI Act, it falls under the GDPR for personal data, and under DORA for the IT systems behind it. Four frameworks, multiple supervisors, one application, and nobody spelling out exactly how they overlap. So banks test everything separately, everything gets stuck, and by the time it is done, the model already needs updating. "Technically, we could have done it faster," as one interviewee put it.
The most painful obstacle is the burden of proof under each framework: how do you prove that no prohibited AI application is running anywhere in your organisation? Evidencing an absence takes a great deal of work without making any risk smaller. Add to that the fragmentation of regulation and supervision.
The stack can be untangled
Notably, the banks are not really asking for fewer rules. The principles of the AI Act (transparency, human oversight, risk management) align with what banks want to do themselves and in part already do. What they are asking of supervisors, then, is not deregulation but coherence. Look at legislation and regulation as a single whole rather than as separate layers. If implementation takes an integrated approach, there is no need to tick off every framework separately, and one evidence file can serve multiple purposes.
The solution? Use AI precisely to untangle the AI rules: AI can place frameworks side by side, make overlaps visible and keep evidence files searchable. The debate should therefore not be about whether AI regulation stifles innovation, but about how to ensure that frameworks which are each defensible on their own also form a workable whole.
How we see it at Ace
The banks in this research describe a challenge we recognise from our own work with financial institutions: the difficulty is not any single framework, but keeping oversight of how they all fit together. That is why we built RegAI Helia, our GenAI-powered compliance workbench.
RegAI Helia traces each requirement back to its regulatory source and links requirements across frameworks, so one application can be assessed against the AI Act, the GDPR, DORA and prudential rules in a single view. Overlapping obligations become visible, internal policies can be rationalised rather than duplicated, and every assessment stays traceable to the evidence behind it.
In other words, it puts into practice what the banks in this research are asking for: an integrated approach to regulation, with AI helping to untangle the AI rules.
Read the full article by BNR (NL) here.