The Commonplace
Home Papers Evidence Explore Trends Syntheses Digests References Docs 🎲 Workforce Futures
← Papers
Direction, evidence grade, and study type are AI-generated labels (gpt-5-mini), not human-verified. Syntheses are LLM-written. "Tensions" are machine-detected candidates, not confirmed contradictions. A research-acceleration tool, not peer review. How this is built →

The EU's MiFID II lets AI flourish in financial markets but leaves AI-specific risks unaddressed; a new risk-based taxonomy is needed to align obligations with emerging AI harms and keep regulation adaptive.

AI governance after MiFID II: beyond (mere) technological neutrality?
Alessio Azzutti · February 02, 2026 · ERA Forum
openalex theoretical n/a evidence 7/10 relevance Full text usable extracted full text DOI Source PDF

Structured author observations

Linked only from stored provider relations; the raw author line above is never matched by name.

OpenAlex

Latest observation:

  1. Alessio Azzutti provider ID

Semantic Scholar

Latest observation:

  1. Alessio Azzutti provider ID
MiFID II's technology-neutral, activity-based approach enables AI deployment in finance but is normatively silent on AI-specific risks, so the paper proposes a risk-based taxonomy of financial AI to align regulatory obligations and future-proof EU financial regulation.

Citation observations

Cumulative provider counts captured on specific dates; providers are never combined.

Abstract This article examines the evolving intersections between artificial intelligence (AI) and EU financial regulation, focusing on the Markets in Financial Instruments Directive II (MiFID II). Grounded in the principle of technological neutrality, MiFID II seeks to enhance investor protection, safeguard market integrity, and ensure that innovation develops within competitive and well-regulated markets across the Union. The article argues, however, that while this neutrality renders the framework functionally enabling , it also leaves it normatively silent in the face of the distinctive and evolving risks introduced by financial AI. As AI applications become increasingly heterogeneous—both across the financial functions in which they are deployed and in their underlying lifecycles and value chains—MiFID II’s activity-based logic increasingly struggles to accommodate their diverse and evolving risk profiles. Reflecting the EU’s broader shift toward risk-based AI governance, the article outlines an initial taxonomy of financial AI applications designed to guide the proportionate alignment of regulatory obligations with AI-related risks, thereby supporting the continued adaptability, coherence, and future-proofing of EU financial services law.

Summary

Main Finding

MiFID II’s technology-neutral, activity-based design continues to bring AI-enabled financial services within its regulatory perimeter, but that neutrality is increasingly insufficient. It leaves MiFID II functionally enabling (flexible, innovation-friendly) yet normatively silent about AI‑specific and heterogeneous risks. The article argues for evolving MiFID II toward a risk-proportionate approach—harmonising MiFID II’s functional obligations with the EU’s cross‑sectoral, risk‑based AI governance (the AI Act and ESMA/ESA supervisory guidance)—including an initial taxonomy of financial AI applications to align regulatory intensity with actual risk profiles.

Key Points

  • Scope and status quo

    • MiFID II remains activity-based: it regulates services (e.g., investment advice, portfolio management, trading) irrespective of the technology used.
    • AI deployment across EU financial firms is widespread (banks, asset managers, trading firms) but supervisory visibility is limited; ESMA and other authorities are collecting more systematic information.
  • Domains mapped under MiFID II

    • Market access & authorisation: authorisation requirements (Art. 5; programme of operations) capture AI indirectly (resources, outsourcing, continuity, risk controls) but lack AI‑specific disclosure rules—placing weight on supervisory interpretation.
    • Consumer‑facing applications: robo‑advice, digital onboarding, and GenAI chatbots must still meet MiFID II conduct, suitability and communication obligations (Arts. 24–25). Neutrality does not lessen firms’ responsibility; machines cannot be legal “advisers.”
    • Market‑facing applications: algorithmic and high‑frequency trading are the most technology‑specific area under MiFID II (Art. 17 and RTS/RTS6). ML/adaptive systems create particular challenges for pre‑deployment testing, explainability, and post‑trade reconstruction.
    • Firm‑internal (RegTech) and supervisory (SupTech) uses: MiFID II’s organisational, reporting and audit rules apply, but guidance on model validation, data governance, third‑party risk (including cloud/AI providers) is increasingly provided via soft law and other EU instruments (e.g., DORA).
  • Limits of technological neutrality

    • Heterogeneous AI architectures, lifecycles and emergent behaviours produce context‑specific risks (opacity, bias, emergent systemic feedbacks) that a purely technology‑neutral regime struggles to distinguish and address proportionately.
    • Disclosure and reconstruction obligations are strained by ML opacity and adaptive updating; “same activity, same rule” can under‑ or over‑regulate depending on a system’s riskiness.
  • Evolving regulatory landscape

    • The AI Act introduces a horizontal, risk‑based classification (including some financial AI in the high‑risk category) and lifecycle obligations that MiFID II lacks.
    • ESMA/ESAs have issued non‑binding supervisory expectations for AI in retail investment services (board accountability, testing, human oversight, data quality, client transparency).
    • The author argues for a calibrated approach: keep the functional, activity‑based core of MiFID II but add proportionate, risk‑sensitive obligations for different classes of financial AI.

Data & Methods

  • Methodological approach

    • Doctrinal and normative legal analysis: close reading and interpretation of primary EU legal instruments (MiFID II, delegated/regulatory technical standards, Market Abuse Regulation, AI Act) and secondary soft‑law (ESMA guidance, ESA statements).
    • Regulatory mapping: categorisation of AI applications across four domains (consumer‑facing, market‑facing, firm‑internal, supervisory) and identification of gaps between existing MiFID II provisions and AI‑specific governance needs.
    • Literature and policy synthesis: integration of supervisory reports and international standard‑setter warnings (EBA, ECB, ESMA, IOSCO, FSB) and recent academic/industry commentary.
  • Data used

    • Legal texts, EU regulation and delegated acts, ESAs/ESMA surveys and public statements, supervisory reports. No original empirical dataset (quantitative) is used; analysis is conceptual and policy‑oriented.
  • Output

    • An initial taxonomy of financial AI applications mapped to risk profiles and regulatory intensity to guide proportionate alignment of MiFID II obligations with AI risks.

Implications for AI Economics

  • Market structure, competition & innovation

    • Risk‑based augmentation of MiFID II could change incentives for AI adoption: stricter rules on higher‑risk AI uses (e.g., autonomous trading, personalised nudging) may raise compliance costs and favor larger incumbents with compliance capacity, potentially accelerating concentration around a few third‑party model/cloud providers.
    • Conversely, clearer rules and supervisory expectations could reduce regulatory uncertainty, lowering barriers for responsible innovators and encouraging socially beneficial adoption.
  • Systemic risk & market dynamics

    • ML‑driven strategies with similar training data and objectives may create correlated trading behaviour and new procyclical amplification channels. Economists should model endogenous risk amplification from model homogeneity and shared third‑party dependencies.
    • Agent‑based and network models can help simulate emergent systemic effects (feedback loops, liquidity evaporations) from widespread AI adoption in trading and risk management.
  • Consumer welfare, distributional effects & information asymmetries

    • Hyper‑personalisation and algorithmic price discrimination can alter consumer surplus and distributional outcomes; welfare analysis should incorporate behavioural responses and potential informational harms.
    • Suitability and disclosure obligations affect the information set available to retail investors; empirical work could estimate how AI‑mediated advice changes portfolio outcomes and mis‑selling risks.
  • Compliance costs & regulatory design tradeoffs

    • A risk‑proportionate overlay will create heterogeneous compliance burdens. Microeconomic analyses should quantify fixed vs marginal compliance costs across firm sizes and relate these to adoption trajectories and market entry/exit decisions.
    • Cost‑benefit and regulatory impact assessments should weigh innovation externalities against consumer protection and stability benefits.
  • Empirical and modelling research agenda (concrete suggestions)

    • Measurement: compile firm‑level AI adoption indicators via surveys, regulatory filings, ESMA/ESA returns, job postings, and API/usage data from third‑party providers.
    • Natural experiments & event studies: exploit policy announcements (AI Act milestones, ESMA public statements, NCA enforcement actions) to measure changes in adoption, trading behaviour, liquidity, spreads, and retail outcomes.
    • Transaction‑level analysis: use microstructure data to test whether ML/GenAI trading exhibits distinct patterns (clustering, tail events) relative to traditional algorithmic strategies.
    • Structural/agent‑based models: simulate market stability under varying degrees of model similarity, update frequency, and third‑party concentration; calibrate to historical flash events.
    • Difference‑in‑differences: assess effects of supervisory intensity across member states (e.g., sandboxes, guidance) on FinTech entry, investment, and product offerings.
    • Distributional studies: evaluate retail investor outcomes from AI‑mediated advice versus human advice (returns, suitability breaches, complaint rates).
  • Policy and modelling recommendations for economists advising regulators

    • Incorporate regulatory uncertainty and compliance heterogeneity into diffusion/adoption models.
    • Model third‑party dependencies explicitly (cloud providers, foundational models) as nodes creating correlated risk; include counterfactuals for concentration mitigation policies.
    • Use forward‑looking stress tests incorporating adaptive/learning strategies and their potential to generate novel tail risks.
    • Support supervisory data needs: design metrics that are informative for both prudential and conduct supervision (e.g., model‑update frequency, training data provenance, black‑box explainability scores, provenance of third‑party components).

Concluding note The article highlights a turning point: MiFID II’s technology neutrality remains valuable for flexibility, but effective governance of financial AI requires layering in risk‑sensitive obligations, better supervisory data, and coordination with the AI Act. For economists, this creates a rich agenda—measuring adoption, modelling systemic channels, estimating compliance impacts, and informing policy tradeoffs between innovation and stability.

Assessment

Paper Typetheoretical Evidence Strengthn/a — The paper is a legal and normative analysis proposing a taxonomy and regulatory argument rather than testing causal claims or presenting empirical evidence. Methods Rigormedium — Rigorous conceptual and doctrinal analysis of MiFID II and EU policy is likely applied, but the paper does not present empirical validation, formal modeling, or quantitative tests of the proposed taxonomy or its effects. SampleQualitative analysis of EU legal texts and regulatory frameworks (primarily MiFID II), related EU policy documents on AI and financial services, regulatory literature, and illustrative examples of AI applications in finance; no primary empirical dataset. Themesgovernance innovation GeneralizabilityEU-specific legal and institutional context (MiFID II) — limited applicability outside the EU without adaptation, Normative taxonomy not empirically validated across jurisdictions or market structures, Rapidly evolving AI technologies and business models may outpace the proposed taxonomy, Focus on financial regulation limits direct transferability to non-financial sectors

Claims (4)

ClaimDirectionOutcomeConfidence & EvidenceDetails
MiFID II is grounded in the principle of technological neutrality and seeks to enhance investor protection, safeguard market integrity, and ensure that innovation develops within competitive and well-regulated markets across the Union. Governance And Regulation positive investor protection, market integrity, and supportive regulatory environment for innovation
Reading fidelity high
Study strength high
not reported
0.2
While technological neutrality renders the MiFID II framework functionally enabling, it leaves the framework normatively silent in the face of the distinctive and evolving risks introduced by financial AI. Governance And Regulation mixed alignment of regulatory norms with AI-specific risks
Reading fidelity high
Study strength medium
not reported
0.12
As AI applications become increasingly heterogeneous across financial functions and in their lifecycles and value chains, MiFID II’s activity-based logic increasingly struggles to accommodate their diverse and evolving risk profiles. Governance And Regulation negative regulatory fit/adaptability of activity-based logic to AI risk profiles
Reading fidelity high
Study strength medium
not reported
0.12
A taxonomy of financial AI applications can guide the proportionate alignment of regulatory obligations with AI-related risks and thereby support the continued adaptability, coherence, and future-proofing of EU financial services law. Governance And Regulation positive alignment of regulatory obligations with AI risks; adaptability/coherence/future-proofing of regulation
Reading fidelity high
Study strength speculative
not reported
0.02

Notes