Last updated:
ESMA's AI and machine learning expectations set out how EU investment firms must apply MiFID II obligations when using AI. The European Securities and Markets Authority issued guidance on AI in retail investment services in May 2024, followed by a supervisory briefing on algorithmic trading on 26 February 2026 that addresses AI and its interaction with the EU AI Act.
What did ESMA's 2024 guidance require?
ESMA's May 2024 statement confirmed that using AI changes nothing about a firm's existing MiFID II obligations. Firms must still meet organisational and conduct-of-business requirements and act in the best interests of the client, whether a decision came from a person or a model. The statement covers AI used for customer support, fraud detection, risk management, compliance, investment advice and portfolio management. ESMA identified the recurring risks as algorithmic bias and data quality problems, opaque decision-making that staff cannot explain, overreliance on AI by both firms and clients, and privacy and security exposure from large-scale data processing.
What does the February 2026 supervisory briefing add?
On 26 February 2026 ESMA published a supervisory briefing on algorithmic trading under MiFID II, aimed at both firms and National Competent Authorities to drive consistent supervision across member states. It responds to the growth of AI in trading algorithms and addresses the interaction with the EU AI Act. The practical consequence for firms is that they are expected to consider the influence of AI on their trading algorithms as part of their annual self-assessment, instead of treating AI as a separate governance track.
How does this interact with the EU AI Act?
The two operate in parallel, not in sequence. The EU AI Act imposes obligations based on a system's risk classification, while MiFID II imposes obligations based on the regulated activity being performed. An investment firm can owe duties under both for the same system, and ESMA's briefing is explicit that AI Act compliance does not discharge MiFID II obligations. Firms that maintain one control set per regulation end up duplicating evidence, so mapping a single system to multiple frameworks at once is the more sustainable pattern.
What controls do firms need in place?
For algorithmic trading, the existing MiFID II regime already requires pre-trade controls, kill functionality, testing before deployment, change management and detailed records. ESMA's position is that AI-driven algorithms are not exempt from any of it. An algorithm that adapts its own behaviour still needs documented testing, defined limits, and a demonstrable ability to be stopped. Human oversight and clear documentation of model calibration are the areas supervisors probe first.
Real world example:
An EU investment firm uses a machine-learning model to optimise trade execution. Under the February 2026 briefing, its annual self-assessment must now document how AI influences the algorithm's behaviour, not simply that an algorithm exists. The firm records its pre-trade limits, its kill-switch procedure and who can invoke it, the testing performed before each retraining, and its bias-testing results. Because the same model also falls in scope of the EU AI Act, the firm maps one set of evidence to both regimes instead of maintaining separate files for its national competent authority and its AI Act obligations.




