Sectoral AI regulation: one control, several regulators
An organisation operating across financial services, healthcare products and consumer markets faces three regulators with three vocabularies asking, underneath, a version of the same question.
How do you build once for several regulators?
By finding the control they all describe in different vocabulary. A sectoral regime produces overlapping expectations rather than one statute, and underneath the differing language each regulator asks the same thing: which identified person was accountable for this decision, and what can you show.
- Sectoral regulation avoids one broad statute and produces several overlapping sets of expectations instead.
- The overlap is substantial: accountability for outcomes, appropriate human involvement, and records that demonstrate both.
- Building one control that satisfies the common core is cheaper than building three, and it is what an organisation can do before guidance settles.
Part of AI oversight and regulation
The regulatory shape
A principles-based sectoral approach asks existing regulators to apply cross-cutting principles within their remits. The principles typically include safety, transparency, fairness, accountability and contestability.
For a firm this means no single compliance deadline and no single rulebook — and correspondingly, no single place to look for the answer.
What different regulators ask, in their own vocabulary
| Regulatory context | Characteristic question |
|---|---|
| Financial conduct | Which senior individual is accountable for this system's outcomes, and can they evidence oversight? |
| Medical products | Was the device used within its intended purpose, and was clinical judgement exercised? |
| Competition and markets | Did an automated system produce an outcome the firm is responsible for? |
| Data protection | Was there meaningful human involvement in decisions with significant effects? |
| Safety regulation | Who set the operating envelope and on what basis? |
Different words, overlapping substance. Each is asking who was responsible and what they actually did.
The common core
Three requirements appear in every column above, which is what makes a single control worth building.
- A named accountable individual for each system and for consequential decisions under it.
- Evidence that human involvement occurred where it was required, with what the person saw.
- Records that survive — retrievable, intact and meaningful years after the decision.
An organisation that has these can answer any of the sectoral questions. One that has policies describing them can answer none of them with specifics.
Where senior accountability regimes bite hardest
In financial services, individual accountability regimes attach responsibilities to named senior individuals who must take reasonable steps in their area. That framing is unusually sharp for AI systems.
A senior manager responsible for a function that uses an automated decisioning system needs to be able to show reasonable steps. "There is a governance committee" is weaker than "here are the decisions escalated to me, what I was shown, and what I decided".
Building once, evidencing several times
# One record, read by different regulators for different reasons
{
"system": "underwriting-v4",
"accountable_individual": "[named senior manager, role]",
"decision": "D-2025-88213",
"model_version": "4.2.1",
"inputs_digest": "sha256:...",
"outcome": "adverse",
"human_involvement": {
"reviewer": "[named individual]",
"authority": "may override",
"rendered_digest": "sha256:...",
"decision": "upheld",
"rationale": "[free text]"
},
"signature": "..."
}
# Conduct regulator reads: accountability + reasonable steps
# Data protection reads: meaningful human involvement
# Sector regulator reads: appropriate use and judgement
The record does not need to be tailored per regulator. It needs to contain the union of what they ask about, which is smaller than it appears.
The cost of the sectoral approach
Worth stating plainly, because organisations often expect it to be lighter than a single statute and find otherwise.
- Expectations arrive as guidance, speeches and supervisory correspondence rather than as a rulebook
- They differ in emphasis between regulators, and a firm in several sectors must track all of them
- There is no single certification that demonstrates compliance
- Timing is uncertain, which makes investment decisions harder
The flip side is flexibility: a firm that builds to the common core is well positioned under any of the emerging expectations, and is not locked to one statute's definitions.
A reasonable posture
- Map which regulators have a view on each AI system you operate. This is often surprising — systems touch more remits than expected.
- Identify the named accountable individual for each. If the answer is a committee, that is a finding.
- Instrument the common core: accountable individual, human involvement with rendered content, durable records.
- Track guidance per regulator, and expect to add specifics rather than rebuild.
This describes regulatory structure at a general level and is not legal advice. Sectoral expectations differ and continue to develop; take specifics to counsel.
A worked example: one decision, four filings
| Regulator's framing | What they want from it |
|---|---|
| Senior accountability regime | The named individual whose responsibility this fell under |
| Data protection | Evidence the human involvement was meaningful, not rubber-stamping |
| Sector safety body | That the person was competent and had authority to stop it |
| Internal audit | That the record was not produced after the fact |
| What the receipt contains | Identity, what was rendered, when, countersigned |
The fourth row is the one that carries the others: a record generated at the moment of decision and signed by hardware is very different from a report assembled during an investigation.
Objections and honest limits
“Sectoral regulation means we can wait for our regulator.” Your regulator's expectations will arrive shaped by the others, and the lead time on instrumenting decisions is longer than the lead time on guidance.
“Four regulators means four programmes.” Four reporting formats, yes. One evidence base, if you build the artefact rather than the reports.
This is a general description of regulatory shape, not legal advice. Obligations depend on sector, jurisdiction and facts.
Building once for several regulators
- List the regulators with a claim on your AI use. Usually more than expected.
- Translate each expectation into a question. Strip the vocabulary.
- Find the questions that are the same. Accountability and evidence almost always are.
- Instrument that once, at the decision point. A signed record, not a report.
- Generate each regulator's format from it. Reporting is a projection, not a programme.
Terms used here
- Sectoral regulation
- Empowering existing regulators to apply their own regimes to AI rather than passing one statute.
- Senior accountability regime
- A framework assigning named individuals personal responsibility for defined functions.
- Meaningful human involvement
- Involvement with real authority and real information, as opposed to formal sign-off.
Frequently asked questions
Is sectoral regulation lighter than a single AI statute? Not necessarily. Expectations arrive as guidance rather than a rulebook, differ between regulators, and offer no single certification.
What do different regulators have in common? A named accountable individual, evidence that human involvement occurred where required, and records that survive and remain meaningful.
Why do individual accountability regimes matter here? They attach responsibility to named senior individuals who must show reasonable steps. Pointing to a governance committee is weaker than showing what was escalated and decided.
Should records be tailored per regulator? No. Build the union of what they ask about — it is smaller than it appears — and let each read it for their own purpose.
Does sectoral regulation mean lighter obligations? No. It means overlapping ones, expressed in different vocabulary, with no single compliance target.
What is the common core? Which identified person was accountable, what were they shown, and what can you produce to a third party.
Is this legal advice? No. It describes regulatory shape generally; obligations are sector- and jurisdiction-specific.
Where this fits in Manav
Manav produces one artefact that answers the question every regulator asks in its own words: which named human authorised this, and what were they shown.
Sources and further reading
- UK policy papers on a pro-innovation approach to AI regulation.
- Financial regulator publications on AI and senior management accountability.
- Medical device regulator guidance on software and AI-enabled products.
- Data protection guidance on automated decision-making and human involvement.
- Regulation (EU) 2024/1689 (AI Act)