FCA Overhauls UK Transaction Reporting Rules
The FCA has finalised UK transaction reporting reforms, reducing reporting fields and narrowing the scope for energy and commodity firms.
The SFC’s AI governance framework is translated into six practical priorities energy and commodity trading compliance may wish to consider, covering AI ownership, human oversight, competence, records, control testing and AI agents.
As AI becomes embedded in energy and commodity trading workflows, compliance needs to understand where its use affects existing obligations and whether appropriate controls can be demonstrated.
Energy and commodity trading compliance teams should identify material AI use, assign accountable owners, define human review points, retain relevant evidence, test controls and govern AI agents through permissions and audit trails.
On 18 September 2026, Dr Kelvin Wong, the Chairman of Hong Kong’s Securities and Futures Commission (SFC), delivered a speech (click here) on AI governance, culture and competence. His central message is that organisations can use AI to improve performance, but people must remain accountable for its use. Although the speech addresses boards and listed companies in Hong Kong, it gives Compliance teams a useful framework for examining how AI is approved, used and overseen in their own organisations.
As energy and commodity trading firms introduce AI into existing workflows, Compliance needs to establish where its use affects an obligation the firm already has. Recent regulatory and practitioner discussions offer practical ways to examine ownership, human review, records and the evidence that controls are working.
A recent article (click here) by Fintech Global, a FinTech information services provider, on the future of RegTech illustrates the wider discussion.
Global regulators are placing greater scrutiny on operational resilience, senior management accountability, and algorithmic explainability. This regulatory pressure is pushing firms away from flashy, ‘black box’ solutions and toward systems that are auditable, controllable, and deeply embedded into daily operations.
RegTrail reviews the SFC speech alongside three additional perspectives published in recent months that help translate AI governance principles into practical questions for Compliance teams:
The SFC speech leads our analysis. The other three sources are practical observations, not regulatory requirements, and each is used to help inform and translate the speech's principles into questions Compliance teams can put to its own firm. Together, they raise a question for Compliance: where does the organisation’s use of AI affect an existing regulatory obligation or control, and can the firm demonstrate how that obligation is met?
An inventory of AI use cases and their owners gives Compliance a practical starting point. It shows where AI is used in regulated work, such as preparing customer communications or investigating surveillance alerts, and who remains responsible for the outcome. Compliance can then assess the obligations affected by each material use case and determine what evidence the firm needs to show that the relevant controls worked.
An AI inventory may reveal risks or control gaps that Compliance cannot resolve alone. The board provides oversight, while business owners decide how AI is used in their activities. Risk and Technology teams assess how the systems operate and identify what could go wrong. Information Security reviews access to sensitive information. Legal and Compliance assess the records questions that arise from each use case. Compliance teams can bring the relevant findings to each team, explain their regulatory significance and help record the decisions made. That gives a firm a clearer account of its approach if a regulator later asks how a use case was governed.
Dr Wong structures his speech around governance, culture and competence.
The speech is addressed substantially to Hong Kong listed issuers. Its discussion of directors’ duties under Hong Kong’s Companies Ordinance should be read in that context. An energy or commodity trading firm elsewhere can reference the speech to help ask similar questions about its own AI governance. It must assess its answers against the laws and obligations that apply to its activities.
The three supporting perspectives bring these questions closer to Compliance’s day-to-day responsibilities. An AI tool might summarise a trader’s conversations with a broker or operational staff, then place that summary in a surveillance case. Another tool might help a surveillance analyst explain why an alert was closed. Compliance may also use AI to analyse a regulatory obligation before updating a policy or control. In each example, the firm needs to understand how the AI output was checked and used. It must then decide what records its existing obligations require it to keep.
We review the SFC speech and supporting sources through six AI governance priorities:
The six themes below begin with a basic question for Compliance. Does the firm know where AI is being used? Answering that requires more than a list of approved AI use cases. The firm needs to identify material uses and the people responsible for them.
For each material use case, Compliance can identify the affected obligation, agree who reviews the AI assisted work and establish what evidence will show that the review took place.
Where AI agents are deployed, a further question follows. What information and systems can an agent access, and what can it change without approval? An AI agent may do more than produce an answer. It might retrieve trading information or update a surveillance case. Compliance needs to understand what the agent is permitted to access and which actions require human approval. Business owners and Technology teams should define those limits. Compliance can assess where the agent’s actions affect regulatory obligations and escalate material gaps to Risk, Information Security or the board as appropriate.
The SFC speech identifies a gap between use of AI and structured oversight within firms. Citing research by the Hong Kong Chartered Governance Institute, Dr Wong says that almost nine in 10 issuers refer to AI in their disclosures, while fewer than 20% report structured governance frameworks with clear oversight roles, policies and controls across the AI lifecycle. He urges boards to understand material AI deployments and receive information on their owners, risk classifications, performance, incidents and overdue remediation (SFC speech, pages 2–3).
For Compliance, visibility starts with the AI use case. A list of purchased AI products will not explain how people use them. One enterprise tool may help an employee prepare meeting notes while another could help in drafting a customer response. A third tool might aid in reviewing surveillance alerts. Each activity can affect different compliance obligations and call for a different level of review.
A useful AI inventory should describe the activity as well as the system. It should identify a business owner and explain what information the AI can access. It should also show where the output goes and what happens before someone relies on it. These details help Compliance decide which use cases need closer assessment.
An AI inventory based only on procurement approvals can miss tools already in use. Theta Lake’s enterprise guide to AI compliance solutions (click here) points out that AI features may be added to software that a firm has already approved. For example, a communications platform used by traders might introduce automatic meeting summaries without a separate AI purchase. Employees may also use an unapproved tool to draft or analyse work material. Theta Lake recommends identifying these uses so the firm can decide which need further review.
The Theta Lake webinar discussion with Zoom’s CIO (click here) provides another practical example. Zoom’s CIO describes the need to understand, before a new feature is deployed in a regulated setting, whether relevant content and context can be captured and made available for review. One example concerns changes to a participant’s displayed name during a Zoom meeting. A final transcript alone may not explain who appeared under a particular name at a particular point in the conversation. The example shows why firms should check whether their platforms preserve enough context to reconstruct an interaction accurately, including how each participant was identified at the time.
Reed Smith’s speakers describe a related challenge. Employees can create new AI functions within platforms the firm has already approved, without purchasing another tool. A platform approval therefore does not tell Compliance every purpose for which AI is being used. Business owners need a way to report when a new function begins supporting a regulated activity.
Compliance should help to decide which AI use cases require closer review because they affect a regulated activity. Technology and business teams should identify the systems and their owners. They also need a clear way to report new AI uses created within an already approved platform.
Compliance AI governance suggestions:
The SFC places human accountability at the centre of AI governance. Dr Wong says boards may delegate functions, but they retain responsibility for oversight. He asks them to establish guidelines that define where human judgement must remain. Boards should also check whether the organisation’s controls support the claims it makes about AI use. In his proposed division of responsibilities, the board sets strategy and risk appetite. Management implements the arrangements, while committees provide focused challenge and assurance (SFC speech, pages 2-4).
For Compliance, “human in the loop” is useful only when the AI workflow identifies what the person must decide. A reviewer might approve a customer communication before it is sent. A surveillance analyst might assess an alert and decide whether to escalate it. Someone preparing a regulatory response might need to check an AI generated explanation against its source material.
These reviews have different purposes. Each needs an accountable owner who knows what to verify. Asking a person to glance at a large volume of AI output offers little assurance that a significant mistake will be found.
In the Theta Lake webinar, a speaker discusses how AI generated content can move from an employee’s working tool into an external communication. For an energy or commodity trading firm, it raises a question about communications with brokers and counterparties. When AI helps to draft a message, who checks its accuracy before it is sent? A trader might need to verify a description of a transaction or a statement about market conditions against the underlying facts with a third-party broker. Surveillance can review the resulting communication, but it may also face a higher volume of AI generated material. Metrigy’s representative notes that people cannot inspect every item individually as volumes grow. Firms therefore need to identify the communications that require review before sending and test whether their surveillance process can handle the rest.
Compliance should explore working with each business owner to identify the point at which an AI output could affect a regulated obligation. An internal note used only to help an employee organise their work may need a basic accuracy check by the employee without Compliance involvement. A regulatory submission needs closer review because the firm is formally reporting information to an external authority. The person signing it off should verify the figures and statements against the underlying records, rather than rely on the AI draft.
The review point changes again when AI is used in trading activity. If a trader uses AI to draft an explanation of a transaction for a broker or counterparty, the trader should check that the message is accurate and does not disclose restricted information before sending it. If a surveillance analyst uses AI to summarise a surveillance alert, the analyst must assess the supporting trading data and communications before deciding whether to close or escalate the case. Compliance’s role is to define these review requirements with the business, explain the regulatory reason for them and check that the firm retains evidence of who made the final decision.
Compliance AI governance suggestions:
Dr Wong notes that boards need enough AI knowledge to ask probing questions and recognise material risks. Directors need enough understanding to ask management where AI is used, what it is allowed to do and who remains responsible for its results. They should be able to examine the information they receive about material deployments, including incidents and unresolved control gaps. Dr Wong suggests that this capability should extend across the board rather than sit with one specialist director. He recommends reflecting AI relevant skills in the board skills matrix and developing them through regular briefings, workshops and scenario exercises (SFC speech, pages 3-4).
The same principle applies to Compliance teams. Knowing that a firm uses an approved AI tool tells the team little about the risk of a particular use. If an employee uses it to draft an internal meeting note, Compliance may need to ask whether the note is checked before anyone relies on it. If the tool drafts a response to a counterparty, the questions change: who verifies its claims before the response is sent, and is the final communication retained? An AI agent that can read confidential trading information and update a surveillance case raises further questions about access and authority. Compliance needs to understand each workflow well enough to identify the regulatory obligation it affects, the point where human review is needed and the evidence the firm can produce afterwards.
In the Compliance and AI podcast, TrueFoundry’s Nikunj Bajaj describes what happens when an agent moves beyond answering questions. It may retrieve a document from Google Drive, update a record in Salesforce or ServiceNow, and send information through Slack or Teams. Each system has its own access controls. Bajaj recommends that a firm must be able to trace which tools the agent used and what actions it took. He also raises a risk that appears when AI agents work together. For example, a customer facing agent that is allowed to use information about one counterparty may ask a second agent to search the firm’s records to answer a question. If that second agent has broader access and does not receive the first agent’s restrictions, it could retrieve confidential information about another counterparty. The firm therefore needs to check that access limits still apply when an agent passes a task (and information) to another agent.
Looking ahead at how agentic AI can impact energy or commodity trading firms, consider how an energy or commodity trading firm might use an agent to prepare a response to a counterparty’s question. It retrieves a contract from a shared drive and checks the counterparty record before drafting a reply. Compliance would need to know whether the agent was authorised to access that contract and whether a person reviewed the reply before it was sent. If the agent changed a record, the firm would also need to establish what changed and why. It gives Compliance two practical questions to ask Technology: is the agent’s access limited to what it needs, and can the firm reconstruct what it did? The answers will depend on the agent’s role and the systems it can use.
Board competence also affects how directors judge whether an AI investment is delivering its intended business benefits while keeping risks within acceptable limits. The SFC asks boards to understand what problem an AI investment is intended to solve. They should consider the value it produces and the risks it creates. They also need to know what findings would justify expanding, changing or stopping it. Dr Wong suggests measuring outcomes and control quality, rather than judging progress by the number of pilots or the speed of rollout (SFC speech, pages 4-5).
Compliance can make these measures concrete by linking them to the work AI is doing. If an AI tool drafts responses to counterparties, track how often reviewers correct a material fact before sending them. A high correction rate may mean the tool is being used for tasks it cannot handle reliably, or that it lacks the information it needs. If AI helps triage surveillance alerts, examine cases that surveillance analysts reopen after the tool suggested no further review. Those cases may reveal risks that an overall count of processed alerts would hide. AI incident reporting should show whether a failure was escalated, who owns the fix and whether the same problem occurred again. Management can then judge whether the tool is improving the workflow and whether the controls around its use remain effective.
AI training should prepare people for the decisions they actually make. A board member reviewing an AI surveillance project should be able to ask what problem it solves, how the firm checks for missed cases and what results would cause management to stop or change the deployment.
As another example, a surveillance analyst needs to know where AI enters the surveillance process. If an analyst relies on an AI summary to close an alert, the reviewer should understand what source material the analyst can check and what evidence of that decision is kept. The business owner of the surveillance AI use case needs to recognise when a technology change requires fresh approval. A tool initially approved to summarise alerts, for example, presents a different risk if it is later allowed to close them automatically. Training should make those boundaries clear and tell staff how to report a proposed change before it goes live.
Compliance AI governance suggestions:
The SFC speech says boards need reliable information about material AI use so they can challenge decisions and follow up when problems arise. Consider a firm that uses AI to summarise due diligence documents for a new commodity trading counterparty. If staff rely on that summary when approving the relationship, the firm needs to know which documents were reviewed and what checks the approver performed. A firm should retain the onboarding decision and supporting evidence required under its applicable rules and policies. The SFC speech does not set out recordkeeping rules for AI-generated material. Compliance should therefore work with Legal to decide whether the summary, the prompt used to produce it, earlier drafts or any agent logs must also be retained. The answer depends on how the material was used and the requirements that apply to the firm’s activities (SFC speech, pages 3-5).
Reed Smith’s discussion also addresses this topic. Its speakers explain that existing recordkeeping and communications rules continue to matter when firms use AI. The status of a particular output depends on its content and use. An internal working draft may raise a different question from a chatbot exchange with a customer.
The speakers also highlight gaps that can arise during AI tool approval. An AI review committee may examine privacy risks and supplier contracts but leave whether the firm can retain and retrieve AI generated material when needed for supervision or an investigation unanswered. Compliance should raise that question before any AI tool is approved, then assess the answer against the firm’s specific recordkeeping obligations.
In the Theta Lake webinar, Zoom’s CIO notes that AI can create new content from a conversation rather than simply transcribe what was said. A transcript of a trader’s conversation with a broker and an AI-generated account of that conversation may therefore need separate consideration. Compliance should assess how each is used before deciding what the firm must retain.
Theta Lake’s enterprise guide describes ways to capture the prompts employees submit to AI tools and the responses they receive. It also discusses bringing interactions from different tools into a format that investigators can search, with enough surrounding context to understand what happened. Consider a Compliance officer using AI to draft a response to a regulator. A firm should identify what the applicable rules require it to retain, including the final response and any supporting evidence that forms part of the required record. Compliance and Legal should decide whether any AI prompts, draft responses or review history also need to be kept. Technology can then test whether the chosen tools capture that material and allow the firm to retrieve it.
An AI records assessment should follow information from its source to its final use. A firm should know when a person changed AI generated material and which version was ultimately relied on. Compliance and Legal should then decide which versions and supporting material the firm must retain. Technology can confirm how staff will be able to retrieve them. Where the status of a prompt or intermediate draft is uncertain, the firm should document why it chose to keep or discard it.
Compliance AI governance suggestions:
The SFC asks boards for more than just policy statements. They need information that shows whether AI is working as intended and allows them to challenge management when it is not. Dr Wong suggests reporting validation results, which show how a system performed when tested against real tasks. Boards should also see how often it produces errors and how often staff override or correct its output. These measures can reveal problems that adoption figures alone would miss. Dr Wong warns that incentives focused only on speed or cost may discourage people from reporting those problems early (SFC speech, pages 3-5).
In the Theta Lake webinar, a speaker observed that surveillance alerts at one large customer almost doubled after AI use expanded across the firm. He links the increase partly to the greater volume of AI generated content and to staff sending some outputs externally without checking them. Compliance should check whether its surveillance team can handle more alerts as employees use AI to create more communications, without delaying or drowning out the review of serious concerns.
A firm introducing AI into communications or surveillance should test the effect on its existing controls. Employees may rely on AI generated content when speaking to customers or recording an interaction. Compliance needs to know whether significant errors are being identified. If the firm also uses AI to monitor that content, it needs to understand what the monitoring system misses. It should examine whether false alerts overwhelm analysts and whether they have enough context to assess a genuine concern.
The participant name change example mentioned in Theme 1 also provides a practical control test. Where participants identity matters to a supervisory review, Technology can check whether the meeting record preserves relevant displayed name changes. Compliance can explain what identity information the review needs. It can then assess whether that history is needed to understand who communicated what during a supervisory review or investigation.
In the same discussion, Smarsh's Robert Cruz raises a practical question about AI providers. If they hold information the firm needs, how will the firm retrieve it for a regulatory request or litigation? Compliance can test this using a completed AI assisted communication with a broker or counterparty. Ask the relevant team to find the final message and any AI material the firm has decided to retain, then export it in a form that shows when it was created and who sent or approved it. If some material sits with the AI provider, test that retrieval route too. The exercise may reveal a gap between a policy that says records are available and what staff can actually produce.
Compliance should check controls where AI affects a regulated activity. For example, it could sample messages to brokers that traders drafted with AI and confirm that the required review happened before they were sent. It could then check whether the final messages were retained and monitored under the firm’s surveillance arrangements. If the firm cannot show who reviewed a message or retrieve it later, the control gap needs an owner and a deadline for correction. Reporting material gaps gives senior management evidence to consider before expanding the use of AI for that use case.
Compliance AI governance suggestions:
The SFC speech does not discuss AI agents specifically. Dr Wong does, however, urge firms to assign ownership to material AI uses and identify where human judgement must remain. Those principles raise further questions when an AI agent can act through a connected system. An agent might update a counterparty record, while a chatbot that only drafts text leaves the action to an employee. A firm needs to decide who authorises the agent’s actions, when a person must approve them and how it will establish what the agent did.
Reed Smith’s speakers discuss the difficulty of applying existing oversight and records arrangements when agents act with less immediate human involvement. One speaker describes reviewing an application where roughly half the users were AI agents, yet no one could explain why the agents had access or what they were doing. An agent is software that can take steps in other systems, often without a person approving each step. In a trading firm, that might mean updating a counterparty record or changing the status of a compliance case. If the action is later questioned, the firm needs to identify which agent took it, what it changed and who was responsible for its use. Reed Smith’s speakers suggest keeping audit trails for higher risk agents to help establish those facts. Whether a particular log must be retained as a regulatory record still depends on the applicable rules and how the agent is used.
In the Compliance and AI podcast, TrueFoundry’s Nikunj Bajaj explains that an agent may ask another tool or agent to complete part of a task. That creates a risk if the second system can access information that the first agent was not permitted to see. Technology is responsible for setting those access limits and keeping a record of the actions taken. Compliance’s role is to identify where an agent could affect a regulated activity, such as changing a counterparty record or a surveillance case. It can then ask Technology to show how access is restricted, which actions require human approval and how the firm would investigate an unexpected change.
The Theta Lake webinar considers what could happen when a customer’s AI agent interacts with a firm’s agent. Metrigy’s representative asks what compliance concerns might arise if the customer's agent makes a mistake. The discussion does not settle who would be responsible however it does show why a firm should examine such interactions before treating them as ordinary customer conversations. Before enabling that exchange, the business owner and Technology should establish what the firm’s agent may communicate or change. Compliance and Legal can then assess whether the resulting communication is subject to supervision or recordkeeping requirements.
For an energy or commodity trading firm, the controls should reflect what the agent can actually do. A meeting-scheduling agent may only need access to calendars and permission to send invitations. Its owner should check that it cannot expose confidential meeting details or invite the wrong external recipient. Compliance would not ordinarily need to approve each invitation, although meetings with brokers may still need to take place through approved communication channels. An agent that changes a counterparty record has a greater effect because other staff may rely on that information. Its changes may need review before they take effect and a record of who authorised them. If an agent helps investigate surveillance alerts, Compliance should define what it may prepare and which decisions must remain with an investigator. Business and Technology teams should implement those limits and be able to show how they work.
Firms exploring AI agents should identify each material use case and assign a human business owner with clear responsibility for what the agent may do. Compliance should identify where an agent could affect a regulated activity and ensure that use goes through the appropriate approval process. If the agent changes a record or influences a regulated decision, Technology should be able to show what it accessed and actioned. Compliance and Legal can then determine what review and evidence the firm needs under its applicable obligations.
Compliance AI governance suggestions: