AI in Finance

CBI 2026 Supervisory Outlook: the AI section, read honestly

Published 21 April 2026

The Central Bank of Ireland published its Regulatory and Supervisory Outlook 2026 on 26 February 2026. The AI Spotlight in the report has been the most widely cited section in the Irish financial services press, and it has been substantially over-interpreted. (Source: CBI Outlook 2026 PDF.)

Based on a careful reading of the document, the Outlook does not introduce new AI rules. It reaffirms that existing frameworks already cover AI deployment. That distinction matters because it changes what an Irish regulated firm should actually do in response, and it changes how a fractional CFO should advise clients with CBI-regulated subsidiaries.

This post is the honest read. What the Outlook actually says, what is genuinely new in the Irish AI regulatory environment, and what the supervisory expectation now is.


What the Outlook actually says

The AI Spotlight is one of three spotlights in the Outlook. The other two are Operational Resilience and Consumer and Investor Protection. The Outlook sits under five 2026 supervisory priorities: resilience to geopolitical and macro-financial uncertainties, securing consumer and investor interests, responding to technology-driven transformations (where AI sits), environmental and societal transitions, and enhancing regulatory and supervisory approaches.

The verbatim wording from the AI Spotlight, cross-verified across legal commentary from Pinsent Masons, McCann FitzGerald, Arthur Cox, Grant Thornton and Mondaq:

“Advanced models and expanding data collection have long been used by leading firms, but widespread adoption of third-party AI tools changes the risk landscape and calls for stronger model governance, data quality, transparency and accountability.”

“AI can amplify existing weaknesses, with model risk a growing concern in a world where the future differs from the past and is more unstable, and as models drive more business decisions in more firms.”

“Firms remain fully accountable for outcomes generated by AI systems, including where solutions are developed, procured or operated by third party providers.”

The four supervisory expectations the CBI sets for AI deployment, in the document’s own language:

  1. “appropriate for the specific business challenge”
  2. “clear accountability and responsibility, human oversight of decisions and their explainability”
  3. “risk management practices commensurate with the scale, scope and sensitivity”
  4. “processes to ensure all EU AI Act obligations are met, including transparency requirements”

(Source: CBI Outlook 2026; Pinsent Masons summary; Grant Thornton commentary.)

Read carefully. The CBI is not introducing a new AI rulebook. It is naming AI as a risk amplifier under existing frameworks (Senior Executive Accountability Regime, Individual Accountability Framework, the revised Consumer Protection Code, Operational Resilience Cross-Industry Guidance, the Outsourcing Cross-Industry Guidance, and DORA) and telling regulated firms that accountability does not transfer to AI tools or third-party providers.

That is a meaningful supervisory signal. It is not a new code.


What is genuinely new in the Irish AI regulatory environment

Three things, none of them in the Outlook.

S.I. No. 366 of 2025. Signed by Minister Peter Burke on 25 July 2025. The European Union (Artificial Intelligence) (Designation) Regulations 2025 designate the Central Bank of Ireland as the market surveillance authority for the financial services sector under Article 74(6) of the EU AI Act, as part of an Irish distributed enforcement model with eight market surveillance authorities. (Source: Irish Statute Book.) This is the structural change. The CBI now has explicit AI Act enforcement powers in finance. The Outlook is the operational signal of how it intends to use them.

The General Scheme of the Regulation of Artificial Intelligence Bill 2026. Published by the Department of Enterprise on 4 February 2026. Pre-legislative scrutiny began at the Oireachtas Enterprise Committee on 6 May 2026. The Bill targets establishment of an AI Office of Ireland by 1 August 2026 (subject to the EU Digital Omnibus deferral discussion covered in the EU AI Act post). (Source: DETE General Scheme; William Fry analysis.)

The revised Consumer Protection Code commences March 2026. Deputy Governor Colm Kincaid, speaking to the Joint Oireachtas Committee on 3 December 2025, said the CBI is “introducing new requirements in our Consumer Protection Code from March 2026 to ensure the firms we regulate use technology with a customer focus and not in a way that seeks to unfairly exploit or take advantage of consumers to their detriment.” (Source: CBI speech, 3 December 2025.) That is genuinely new conduct rule, and AI-delivered advice, AI-assisted pricing, and AI-driven product recommendations are explicitly in scope.


How to read the CBI’s enforcement posture

The Outlook itself does not threaten enforcement. The CBI’s enforcement record signals what enforcement-via-existing-rule could look like for AI deployment failures.

The November 2025 Coinbase Europe settlement, €21.46 million for anti-money laundering failures, is the operative precedent. Failures included outsourced transaction monitoring to a US affiliate, with 30.4 million transactions worth €176 billion unmonitored between April 2021 and March 2025. (Source: Irish Times coverage, 6 November 2025.) Largest AML fine in Irish history. First crypto firm fine. The outsourcing failure is what makes it the operative AI precedent: the same accountability principle applies whether the outsourced function is transaction monitoring done by a US affiliate or model decision-making done by a third-party AI provider.

The tracker mortgage redress process, with collective fines of more than €270 million across Bank of Ireland, AIB / EBS, and PTSB between 2018 and 2022, is the consumer-detriment precedent. The pattern was governance failure that produced systematic customer harm at scale. An AI deployment that produces systematic mispricing, mis-selling, or unfair denial of service would fit that pattern exactly.

The Outlook does not say this. The enforcement record does. A regulated firm reading the Outlook in isolation will see general framing. Reading the Outlook against the enforcement record produces the operative warning.


What an Irish regulated firm should actually do

Four things, in priority order.

Document AI deployment under the existing frameworks. SEAR pre-approval-controlled-function-holders are accountable for the AI deployment decisions in their domain. The Operational Resilience Cross-Industry Guidance (in force from 1 December 2023) covers AI as a critical service. The Outsourcing Cross-Industry Guidance covers third-party AI vendor risk. The Individual Accountability Framework, with senior executives required to take “all reasonable steps,” applies to the decision to deploy. The function that documents the AI deployment against these frameworks is documented for the supervisory expectation the Outlook articulates. The function that does not is exposed under rules that already apply, not under a new code that is yet to land.

Treat the Consumer Protection Code revision (commencing March 2026) as the binding conduct rule for customer-facing AI. Pricing AI, advice AI, recommendation AI, chatbot AI in customer service. The CBI has signalled it explicitly. The new requirements take effect this year.

Engage with the AI Act timeline through the CBI as market surveillance authority. For credit-scoring deployments on natural persons and life-and-health insurance pricing AI under Annex III §5(b) and §5(c), the CBI is the regulator. The timeline is in flux pending the EU Digital Omnibus formal adoption (covered separately in the EU AI Act post). The CBI is your first regulatory interlocutor on these systems, not the DPC, not the European AI Office.

Treat the GPAI literacy obligation (Article 4 of the AI Act, in force since 2 February 2025) as a current rather than future requirement. Any team using Claude, GPT-5, Gemini, or Llama in regulated finance work needs structured AI literacy training. The CBI Outlook’s reference to “all EU AI Act obligations” includes Article 4. The function that has not delivered training to its staff is not compliant today.


What about the Irish adoption picture

Two stats worth knowing.

CSO Information Society Statistics 2025: 20.2% of Irish enterprises were using AI in 2025, up from 8.1% in 2023. Large enterprises 57.7%, medium 28.6%, small 17.2%. (Source: CSO Ireland.)

EY’s March 2026 Irish CFO Survey reported that 47% of Irish CFOs are using AI within the finance function in 2026, up from 12% in 2025. (Source: EY Ireland, March 2026.) The finance function is adopting AI faster than the rest of the business.

Bank of Ireland’s published 2025 results disclose that AI assessed approximately one billion card transactions and prevented €9.7 million in fraud, the AI-enabled contact centre reduced call transfers by 40%, and the bank produced 127 million personalised customer prompts during the year. (Source: Bank of Ireland press release, 2026.) Material deployments are now real in Irish banking. The CBI is not supervising hypothetically.


Where this lands

The CBI is not introducing new AI rules in the 2026 Outlook. It is signalling that the existing rules already apply, that AI deployment is now a supervisory priority, and that accountability does not transfer to the AI tool or to the third-party provider. The genuinely new parts of the Irish regulatory environment, S.I. 366/2025, the Regulation of AI Bill 2026, and the March 2026 Consumer Protection Code revision, sit alongside the Outlook rather than inside it.

An Irish regulated firm reading the Outlook honestly will spend less time waiting for a new AI rulebook and more time documenting compliance with the existing rulebook the CBI is signalling will be applied. The fractional CFO advising the firm has a useful, defensible position: the supervisory expectation is articulated. The frameworks are in place. The work is to evidence the deployment is governed against them.

That work is the deliverable the CBI wants to see. It is also the work that will protect the firm’s senior executives under SEAR when the supervisory enquiry lands.


Maebh Collins is a Fellow Chartered Accountant (FCA, ICAEW) with Big 4 training and twenty years of operational experience as a founder and senior finance leader, based in Ireland.

Back to Blog | AI in Finance →