Desiree Sainthrope stands at the intersection of traditional global compliance and the frontier of financial technology. As a seasoned legal expert with a career built on the meticulous drafting of trade agreements and the oversight of intellectual property, she has become a leading voice on how emerging technologies reshape our legal landscapes. In an era where algorithms drive market integrity, her insights provide a necessary bridge between the rapid pace of innovation and the fundamental principles of human rights and corporate accountability. This conversation explores the shifting regulatory tides across the UK, EU, and US, the lessons learned from systemic technological failures, and the delicate balance between fostering innovation and protecting the public interest.
The UK has notably opted for a “hands-off” approach, relying on the Consumer Duty and the Senior Managers and Certification Regime rather than enacting specific AI laws. Do you believe these existing frameworks are robust enough to handle the unique challenges of algorithmic decision-making?
The decision to lean on the Consumer Duty is theoretically defensible because many of the harms we see today, such as discrimination, exclusion, and mis-selling, are not inherently new to the financial sector. However, we are currently witnessing an odd spectacle where the industry is actually pleading for more regulatory specificity while the regulator remains silent. By pushing the interpretive work onto the firms themselves, the Financial Conduct Authority has created an environment where businesses feel they cannot operate with absolute confidence. Without clearer guidance on how these older rules apply to modern neural networks, the burden of risk falls entirely on the private sector, which could lead to a fragmented and inconsistent application of consumer protections.
Reflecting on the Post Office Horizon scandal, what specific safeguards must be integrated into fintech regulation to ensure that AI outputs can be effectively contested?
The Horizon scandal serves as a haunting lesson for all of us in the legal field about what happens when a system’s outputs are treated as infallible and cannot be effectively challenged. To prevent such a catastrophe in fintech, we must move toward a system that mandates tamper-proof records and comprehensive logs of how every automated decision was reached. It is not enough to simply have an output; there must be a traceable path that allows for meaningful human analysis after the fact. If even the developers of a “black-box” system cannot explain why a specific output was produced, then that opacity represents a fundamental limit on how far that system can be trusted in a public-facing financial context.
As we navigate 2026, the EU’s AI Omnibus has delayed the implementation of certain high-risk rules until December 2027. How does this timeline affect the way multinational institutions harmonize their compliance strategies across different jurisdictions?
The delay until December 2027 for rules governing high-risk systems, such as creditworthiness evaluations, reflects the EU’s desire to support innovation by giving companies an extended timeline to test their systems. For a multinational institution, this creates a complex puzzle where they must distill core principles and standards that satisfy the EU’s 2024 AI Act while also adhering to the UK’s more flexible, principles-based regime. The challenge lies in building a singular internal infrastructure that is robust enough for the EU’s strict risk-based system but adaptable enough for local requirements in the US or UK. It is a period of intense fine-tuning, as firms try to hit a moving target across three or four different regulatory philosophies simultaneously.
The Central Bank of Ireland has championed four core principles—strategic alignment, accountability, explainability, and proportionate governance. How do these pillars change the day-to-day operations for a firm implementing AI?
These four principles shift the focus from mere implementation to active, ongoing stress testing of the technology. In practice, this means a firm can no longer get away with a “rubber-stamping” culture where a human simply signs off on whatever the algorithm suggests. To meet the standard of explainability, staff must maintain the actual human ability to perform the tasks the AI is doing, ensuring they can identify when a machine’s logic has veered off course. It requires a significant investment in human capital and training, as the regulator will likely demand a granular explanation of exactly how the AI was used and why it was deemed sufficient for a specific task during supervisory interactions.
There is a growing concern that AI will lead to a surge in litigation regarding misleading financial advice and financial crime. What must be done to ensure that the “marketing rhetoric” of AI benefits is backed by real-world evidence?
We have to recognize that the promise of AI making our lives better remains just rhetoric until we have robust evidence of how these systems serve people in specific, real-world contexts. Regulation in the public interest must insist on seeing the data—not just regarding the benefits, but regarding the nature, extent, and distribution of adverse impacts on the population. Governments should ground their oversight in international human rights frameworks to ensure that anyone whose legal rights are affected by an automated decision has a clear path to redress. This isn’t just about efficiency; it’s about ensuring that as we move toward 2027 and beyond, the cost of innovation is not paid by the most vulnerable members of the financial system.
What is your forecast for the evolution of fintech oversight?
I anticipate that the next two years will see a dramatic shift from high-level aspirations to a much more granular, evidentiary-based form of supervision. As we approach the December 2027 deadlines in Europe, I expect the “odd spectacle” of the UK’s regulatory silence to end, as the sheer volume of litigation from misleading advice will force the FCA to provide the specificity that firms are currently begging for. We will see a move toward “explainable AI” as a mandatory standard rather than a luxury, where the ability to contest a machine’s decision becomes a fundamental consumer right. Ultimately, the industry will realize that transparency isn’t just a regulatory hurdle—it is the only way to maintain the public trust required to keep these technologies viable in the long run.
