In brief: Risk and compliance in financial services is shifting from tracking regulation to interpreting it. Moving a regulatory change from identification to implementation takes over a year at 74% of institutions - an industry-wide gap, according to CUBE's Cost of Compliance Report 2025. Firms are setting internal AI governance policies ahead of the EU AI Act's December 2027 high-risk deadline, and the growing volume of regulatory change is straining coverage models built for a handful of major jurisdictions.
The CUBE Read is CUBE's fortnightly take on regulatory change in financial services and what it means for compliance and risk teams. This edition covers mid July 2026.
1. Risk and compliance teams are expected to interpret regulation, not just track it
The expectation on the risk and compliance function has moved beyond monitoring. Teams are now asked to extract obligations, map them to source law, distinguish proposed regulation from enacted regulation, and assess applicability.
The operating reality lags the expectation. CUBE's Cost of Compliance Report 2025, based on a survey of over 2,000 senior compliance and risk officers, found that at 74% of institutions, moving from identifying a regulatory change to full implementation takes more than a year - not for lack of effort, but because the analytical workload has grown faster than the capacity to absorb it.
The stakes of getting that judgment right are live right now. In the US, SEC Commissioner Hester Peirce warned this month that crypto vaults and onchain lending arrangements may fall under federal securities law depending on how they're structured and managed - an applicability call firms have to make well ahead of any final rule. In Hong Kong, the SFC's HK$6.8 million fine against an asset manager for failing to identify and address red flags in a dubious fund arrangement makes the same point from the enforcement side: missing the interpretation isn't a defense.
What it means for risk and compliance teams: the gap is no longer about spotting regulatory change - it's about interpreting and acting on it fast enough, with resource that hasn't grown to match the load.
2. Firms are setting internal AI policies ahead of the rulebook
Across regulated and professional-services firms, a consistent pattern is emerging: internal AI governance standards stricter than current regulation requires - sign-off before AI is applied to sensitive data, and caution over AI-assisted output where accuracy is critical.
The formal timeline is still moving. The EU AI Act's high-risk obligations for financial services are set to be deferred to December 2027 following provisional agreement on the Digital Omnibus, pending formal adoption.".
What it means for risk and compliance teams: AI governance is a live risk and compliance workstream now, well before the formal mandate - and tooling decisions are being judged against these internal policies first.
3. The volume of change is straining fixed coverage models
Firms with global or specialist mandates face regulatory change that doesn't fit a fixed, jurisdiction-count coverage model: informal local guidance in emerging markets, non-English source material, data-residency requirements in smaller jurisdictions, and concentrated bursts of change that ignore the annual planning calendar.
The past two weeks underline the point. The US Treasury's second sanctions-list modernization action removed 84 names from the SDN list in a single pass; the Wolfsberg Group extended its financial-crime framework to cover non-bank payment providers, flagging that financial-crime rules and licensing requirements still aren't aligned across jurisdictions; and ESMA's follow-up review credited BaFin and CySEC with real progress on cross-border investment-firm supervision while still asking both to keep enforcement calibrated to the scale of firms' cross-border activity. None of it arrives on a fixed calendar.
What it means for risk and compliance teams: coverage measured by jurisdiction count increasingly fails to match how globally operating firms actually encounter regulation.
The through-line
Risk and compliance in financial services is shifting from awareness to execution - from spotting a regulatory change to interpreting it, acting on it, and evidencing it, everywhere a firm operates. It's the challenge CUBE is built for: applying AI to regulatory workflows, built on 15 years of regulatory data, inside the platforms compliance and risk teams already use.
For more detail on the latest regulatory developments, download CUBE's RegTrend app for free.
Frequently asked questions
What is The CUBE Read?
The CUBE Read is CUBE's fortnightly briefing on regulatory change in financial services - the shifts most relevant to compliance and risk teams, and what they mean in practice.
How long does it take firms to implement a regulatory change?
According to CUBE's Cost of Compliance Report 2025, 74% of financial institutions take more than a year to move from identifying a regulatory change to full implementation, with nearly a third reporting 18-24 month cycles.
When does the EU AI Act apply to financial services?
The high-risk obligations relevant to financial services have been deferred to December 2027 following the Digital Omnibus, though many firms are adopting internal AI governance policies ahead of that date.
Why are jurisdiction-based coverage models under strain?
Regulatory change increasingly arrives as informal local guidance, non-English source material, and data-residency requirements in smaller jurisdictions - often in concentrated bursts that ignore the annual planning calendar. Coverage measured by jurisdiction count fails to match how globally operating firms actually encounter regulation.
How often is The CUBE Read published?
Fortnightly. Each edition covers the regulatory shifts most relevant to compliance and risk teams in financial services.
Sources: CUBE, Cost of Compliance Report 2025; EU AI Act / Digital Omnibus timeline. CUBE's RegTrend app. The CUBE Read is published by CUBE.