Manav.id
Compliance · 4 min read

Sectoral AI regulation: one control, several regulators

Sectoral AI regulation: one control, several regulators

An organisation operating across financial services, healthcare products and consumer markets faces three regulators with three vocabularies asking, underneath, a version of the same question.

How do you build once for several regulators?

By finding the control they all describe in different vocabulary. A sectoral regime produces overlapping expectations rather than one statute, and underneath the differing language each regulator asks the same thing: which identified person was accountable for this decision, and what can you show.

Key takeaways
  • Sectoral regulation avoids one broad statute and produces several overlapping sets of expectations instead.
  • The overlap is substantial: accountability for outcomes, appropriate human involvement, and records that demonstrate both.
  • Building one control that satisfies the common core is cheaper than building three, and it is what an organisation can do before guidance settles.

The regulatory shape

Financial conductsenior accountabilitywho was responsibleData protectionmeaningful human involvementwas a person involvedSafety regulatorcompetent oversightwho signed offOne signed recordnamed human, rendered effectanswers all four
Four questions, one artefact that answers all of them.

A principles-based sectoral approach asks existing regulators to apply cross-cutting principles within their remits. The principles typically include safety, transparency, fairness, accountability and contestability.

For a firm this means no single compliance deadline and no single rulebook — and correspondingly, no single place to look for the answer.

What different regulators ask, in their own vocabulary

Regulatory contextCharacteristic question
Financial conductWhich senior individual is accountable for this system's outcomes, and can they evidence oversight?
Medical productsWas the device used within its intended purpose, and was clinical judgement exercised?
Competition and marketsDid an automated system produce an outcome the firm is responsible for?
Data protectionWas there meaningful human involvement in decisions with significant effects?
Safety regulationWho set the operating envelope and on what basis?

Different words, overlapping substance. Each is asking who was responsible and what they actually did.

The common core

Three requirements appear in every column above, which is what makes a single control worth building.

  1. A named accountable individual for each system and for consequential decisions under it.
  2. Evidence that human involvement occurred where it was required, with what the person saw.
  3. Records that survive — retrievable, intact and meaningful years after the decision.

An organisation that has these can answer any of the sectoral questions. One that has policies describing them can answer none of them with specifics.

Where senior accountability regimes bite hardest

In financial services, individual accountability regimes attach responsibilities to named senior individuals who must take reasonable steps in their area. That framing is unusually sharp for AI systems.

A senior manager responsible for a function that uses an automated decisioning system needs to be able to show reasonable steps. "There is a governance committee" is weaker than "here are the decisions escalated to me, what I was shown, and what I decided".

Building once, evidencing several times

# One record, read by different regulators for different reasons
{
  "system": "underwriting-v4",
  "accountable_individual": "[named senior manager, role]",
  "decision": "D-2025-88213",
  "model_version": "4.2.1",
  "inputs_digest": "sha256:...",
  "outcome": "adverse",
  "human_involvement": {
    "reviewer": "[named individual]",
    "authority": "may override",
    "rendered_digest": "sha256:...",
    "decision": "upheld",
    "rationale": "[free text]"
  },
  "signature": "..."
}

# Conduct regulator reads: accountability + reasonable steps
# Data protection reads: meaningful human involvement
# Sector regulator reads: appropriate use and judgement

The record does not need to be tailored per regulator. It needs to contain the union of what they ask about, which is smaller than it appears.

The cost of the sectoral approach

Worth stating plainly, because organisations often expect it to be lighter than a single statute and find otherwise.

The flip side is flexibility: a firm that builds to the common core is well positioned under any of the emerging expectations, and is not locked to one statute's definitions.

A reasonable posture

  1. Map which regulators have a view on each AI system you operate. This is often surprising — systems touch more remits than expected.
  2. Identify the named accountable individual for each. If the answer is a committee, that is a finding.
  3. Instrument the common core: accountable individual, human involvement with rendered content, durable records.
  4. Track guidance per regulator, and expect to add specifics rather than rebuild.

This describes regulatory structure at a general level and is not legal advice. Sectoral expectations differ and continue to develop; take specifics to counsel.

A worked example: one decision, four filings

The same artefact, read four ways
Regulator's framingWhat they want from it
Senior accountability regimeThe named individual whose responsibility this fell under
Data protectionEvidence the human involvement was meaningful, not rubber-stamping
Sector safety bodyThat the person was competent and had authority to stop it
Internal auditThat the record was not produced after the fact
What the receipt containsIdentity, what was rendered, when, countersigned

The fourth row is the one that carries the others: a record generated at the moment of decision and signed by hardware is very different from a report assembled during an investigation.

Objections and honest limits

“Sectoral regulation means we can wait for our regulator.” Your regulator's expectations will arrive shaped by the others, and the lead time on instrumenting decisions is longer than the lead time on guidance.

“Four regulators means four programmes.” Four reporting formats, yes. One evidence base, if you build the artefact rather than the reports.

This is a general description of regulatory shape, not legal advice. Obligations depend on sector, jurisdiction and facts.

Building once for several regulators

  1. List the regulators with a claim on your AI use. Usually more than expected.
  2. Translate each expectation into a question. Strip the vocabulary.
  3. Find the questions that are the same. Accountability and evidence almost always are.
  4. Instrument that once, at the decision point. A signed record, not a report.
  5. Generate each regulator's format from it. Reporting is a projection, not a programme.

Terms used here

Sectoral regulation
Empowering existing regulators to apply their own regimes to AI rather than passing one statute.
Senior accountability regime
A framework assigning named individuals personal responsibility for defined functions.
Meaningful human involvement
Involvement with real authority and real information, as opposed to formal sign-off.

Frequently asked questions

Is sectoral regulation lighter than a single AI statute? Not necessarily. Expectations arrive as guidance rather than a rulebook, differ between regulators, and offer no single certification.

What do different regulators have in common? A named accountable individual, evidence that human involvement occurred where required, and records that survive and remain meaningful.

Why do individual accountability regimes matter here? They attach responsibility to named senior individuals who must show reasonable steps. Pointing to a governance committee is weaker than showing what was escalated and decided.

Should records be tailored per regulator? No. Build the union of what they ask about — it is smaller than it appears — and let each read it for their own purpose.

Does sectoral regulation mean lighter obligations? No. It means overlapping ones, expressed in different vocabulary, with no single compliance target.

What is the common core? Which identified person was accountable, what were they shown, and what can you produce to a third party.

Is this legal advice? No. It describes regulatory shape generally; obligations are sector- and jurisdiction-specific.

Where this fits in Manav

Manav produces one artefact that answers the question every regulator asks in its own words: which named human authorised this, and what were they shown.

See the artefact →

Sources and further reading