ESMA Named AI a 2027 Supervisory Priority. It Didn't Say What Oversight Means.

ESMA's September 23, 2026 announcement makes AI and tokenisation a Union Strategic Supervisory Priority from 2027, with no defined methodology published yet. Argues the EU's established pattern, naming a priority before building the measurement instrument (seen again in AMLA's October 2026 finalised technical standards), means firms should build an AI governance evidence trail now rather than wait for the eventual framework. Covers implications for CSSF-regulated and FSC Mauritius-regulated entities.

6 min readThought Leadership

A steel measuring caliper resting open on a blank sheet of paper on a dark desk, nothing measured yet

ESMA's 2027 supervisory priority on AI and tokenisation, announced on 23 September 2026, tells national supervisors where to look but not yet what good oversight looks like. Management companies, TCSPs and fund administrators that use AI in KYC or AML work should start building the evidence trail now, because the methodology will arrive after the questions do.

No technical standard accompanied the announcement. No list of required controls. No definition of what "oversight" will actually test for.

That gap is not an oversight on ESMA's part. It is how EU financial supervision works now, and compliance teams at management companies, TCSPs, and fund administrators who wait for the methodology before they build the evidence will spend 2027 explaining a system they built after the fact.

The ESMA AI Supervisory Priority: What Was Announced and What Wasn't

ESMA's press release is short. The headline finding is straightforward: digital innovation becomes a named Union Strategic Supervisory Priority (USSP), and "in collaboration with National Competent Authorities, our initial focus will be on how supervised entities use artificial intelligence and tokenisation." The priority runs alongside the cyber and operational resilience USSP, active since 2025, as the ESG disclosures USSP launched in 2023 winds down this year.

The deeper finding is in what the release does not say. There is no scope definition for which AI uses count. There is no measurement framework for "oversight." ESMA states only that it will "remain flexible to address future technological developments as they emerge." For an authority that regulates capital markets infrastructure, not AML/KYC directly, this is a signal aimed at National Competent Authorities as much as at firms. The CSSF in Luxembourg is part of that coordination. FSC Mauritius is not, but supervisory posture travels faster than formal rulemaking.

Naming the Risk Before Building the Instrument Is the Pattern, Not the Exception

This is not an isolated case of a regulator moving ahead of its own toolkit. On 1 October 2026, AMLA finalised three regulatory technical standards under the AMLR, covering the distinction between business relationships and occasional transactions, customer due diligence, and group-wide AML/CFT arrangements, and submitted the final drafts to the European Commission for adoption. The AMLR itself was adopted back in 2024 (Regulation (EU) 2024/1624). The technical standards that tell firms exactly what the law requires are arriving in pieces, years later, and these three still have to be adopted by the Commission.

The sequence is consistent: legislation or priority is named first, obligations follow in headline form, and the technical detail that would let a compliance team build a checklist arrives last, incrementally, sometimes years after the deadline pressure has already started. ESMA's digital innovation USSP follows the same order. The priority exists now. The rulebook does not.

Firms that have internalised this pattern from AMLR do not wait for RTS to start building CDD evidence. The same logic applies here: waiting for ESMA's AI methodology before building an AI governance evidence trail repeats a mistake the AMLR rollout already taught the market not to make.

What "Oversight" Will Probably Ask For, Based on How Supervisors Already Behave

ESMA has not published a checklist, but supervisors do not invent new evidentiary standards from nothing. They ask for what they have always asked for: a record that shows a human understood and could explain the system's output. Applied to AI in KYC and AML workflows, that means four things firms can build now without waiting for a technical standard. An inventory of where AI or ML models touch a compliance decision, whether that is identity verification, sanctions screening, risk scoring, or alert prioritisation. A record of what data trained or calibrated each model, and when it was last reviewed. A log of every case where a human reviewer overrode, confirmed, or escalated a model's output, with the reasoning attached, not just the outcome. And a documented answer to who owns the model's performance when it degrades, which echoes the "who signs the file" question that already applies to AI agents acting inside KYC workflows today.

ESMA has not said what it will ask for, so the table below is our reading, not ESMA's text. Each row is a record a supervisor can ask to see, and each one should exist before anyone asks.

RecordWhat it shows a supervisorWhere it usually comes from
AI use inventoryEvery point where a model touches a compliance decision: identity verification, screening, risk scoring, alert prioritisationCompliance and IT, kept current as tools change
Data and review recordWhat data trained or calibrated each model, and when it was last reviewedThe vendor or internal model owner, signed off by compliance
Human decision logEach case where a reviewer confirmed, overrode or escalated a model output, with the reasoning attachedThe case management or KYC platform, captured as the work happens
Named ownerWho answers for the model's performance when it degradesGovernance documents and the management body's allocation of responsibilities

None of this requires anticipating ESMA's eventual definitions correctly. It requires having the infrastructure that produces this evidence on demand, for whatever question a supervisor eventually asks.

The Overlap With AMLR Obligations Firms Already Carry

Fund administrators and ManCos using AI inside AML/KYC processes are not waiting for ESMA to create a new obligation from scratch. The AMLR's Article 26 ongoing monitoring requirement and the Article 16 group compliance manager role already imply governance over any automated system feeding a monitoring or escalation decision. ESMA's digital innovation priority does not replace that obligation, it adds a second supervisory lens pointed at the same AI systems, run by an authority that coordinates with national supervisors including the CSSF, and whose posture influences how NCAs across the EU interpret "adequate governance" in practice.

A firm with one AI model feeding both a KYC alert ranking system and a transaction monitoring workflow now has two regulatory audiences asking, in effect, the same question from different angles: can you show us this worked the way you say it worked. The firms that can answer that question with a retrievable record, rather than a narrative reconstructed after a supervisor asks, will clear both audiences with the same evidence.

What This Means for Management Companies, TCSPs, and Fund Administrators

For Luxembourg-regulated entities, we expect CSSF inspections from 2027 onward to include more questions about AI governance in KYC and risk-scoring tools, even in the absence of a published CSSF circular specifically on the topic, because ESMA's posture shapes what NCAs consider a reasonable supervisory question. That is our view, not a stated CSSF position. For Mauritius-regulated TCSPs and fund administrators there is no formal ESMA linkage, but the same evidence will serve any supervisor who asks. Either way, the firms that will be ready are the ones that can already produce a model inventory, a training data provenance record, and a human override log without a scramble, because those records already exist as a byproduct of how their systems run day to day, not as a special exercise assembled when a supervisor asks.

The Principle

Regulators that name a priority before they define the method are not being vague by accident. They are reserving the right to ask a specific question once they have seen enough of the market's answers to know which question is worth asking. A compliance function built to pass a specific, anticipated checklist will always be one step behind that question. A compliance function built to produce an honest, retrievable record of what its systems did and why will answer whatever question comes, this cycle or the next one. The AMLR rollout already proved this. ESMA's digital innovation priority is the same lesson arriving through a different door.

If your AI-assisted KYC or AML workflows don't yet produce that kind of record on demand, talk to our team about what closing that gap requires.

Frequently asked questions

What is ESMA's 2027 AI supervisory priority?

On 23 September 2026, ESMA named digital innovation a new Union Strategic Supervisory Priority starting in 2027. Its initial focus, in collaboration with national competent authorities, is how supervised entities use artificial intelligence and tokenisation.

Has ESMA published a methodology for supervising AI?

Not with the announcement. ESMA said it will remain flexible to address future technological developments as they emerge. Firms should not expect a checklist before supervisors start asking questions.

How does this relate to the AMLR?

It is a separate supervisory lens on the same systems. A model used in KYC or AML work already sits under AMLR obligations on monitoring and group-wide controls, and AMLA submitted its final draft standards on customer due diligence and group-wide requirements to the European Commission on 1 October 2026.

What should a firm build before the methodology arrives?

An inventory of where AI touches a compliance decision, a record of the data behind each model and its last review, a log of human confirmations and overrides with reasons, and a named owner for each model's performance.

Sources and further reading

European Securities and Markets Authority, ESMA sets new supervisory priority on digital innovation for 2027, 23 September 2026.

Anti-Money Laundering Authority, AMLA finalises key standards for the private sector, 1 October 2026.

Commission de Surveillance du Secteur Financier, AMLA adopts key regulatory technical standards, 7 October 2026.

See it run on your own files.

Bring a sample entity and your AML rules. We will show you how Fidify handles them.