Il presente contributo esamina l’impiego dell’intelligenza artificiale nella vigilanza sui mercati finanziari, concentrandosi sui benefici, sui rischi e sulle garanzie giuridiche connessi all’integrazione di sistemi automatizzati nei procedimenti delle autorità di supervisione. Sebbene l’uso dell’intelligenza artificiale da parte degli operatori finanziari abbia già ricevuto significativa attenzione sul piano regolatorio, il suo utilizzo da parte delle autorità pubbliche di vigilanza rimane ancora relativamente poco esplorato. Lo studio analizza il quadro delineato dall’AI Act europeo, soffermandosi sulla possibile qualificazione dei sistemi impiegati nella supervisione finanziaria come sistemi ad alto rischio e sui conseguenti obblighi in materia di gestione dei rischi, trasparenza, tracciabilità e controllo umano. Il contributo sostiene che la supervisione umana non possa ridursi a un adempimento meramente formale, ma debba consentire alle autorità di comprendere, contestualizzare e, ove necessario, contestare gli esiti probabilistici prodotti dai sistemi di intelligenza artificiale. Attraverso un caso di studio relativo alla manipolazione del mercato nell’ordinamento svizzero, l’analisi evidenzia inoltre come l’obbligo di motivazione possa costituire una garanzia essenziale di intelligibilità, controllo e legittimità delle decisioni adottate con il supporto dell’intelligenza artificiale.
This paper examines the use of artificial intelligence in financial-market supervision, focusing on the benefits, risks, and legal safeguards associated with the integration of automated systems into the activities of supervisory authorities. While the use of artificial intelligence by financial institutions has already attracted significant regulatory attention, its deployment by public supervisory bodies remains comparatively underexplored. The study analyses the framework established by the EU AI Act, with particular regard to the potential classification of AI systems used in financial supervision as high-risk systems and to the resulting obligations concerning risk management, transparency, traceability, and human oversight. It argues that human oversight cannot be reduced to a mere formal requirement but must enable supervisory authorities to understand, contextualise, and, where necessary, challenge the probabilistic outputs generated by artificial intelligence systems. Drawing on a case study concerning market manipulation under Swiss law, the paper further shows that the duty to state reasons can operate as a central safeguard of the intelligibility, accountability, and legitimacy of decisions adopted with the support of artificial intelligence.
1. Introduction
The deployment of artificial intelligence (“AI”) tools by financial institutions has attracted significant scholarly, regulatory, and public attention in recent years, prompting the emergence of the first dedicated regulatory frameworks[1]. By contrast, the use of similar technologies by financial supervisory authorities has remained comparatively underexplored[2]. This relative silence is striking: AI systems hold considerable promise for enhancing the oversight of financial markets, and representatives of supervisory bodies have already acknowledged – albeit informally – their growing reliance on such tools. Against this backdrop, important questions arise regarding the risks associated with the use of AI by supervisory authorities and the appropriate regulatory framing of AI‑enabled financial supervision[3].
Situated within the broader context of The Swan Song of the Anthropocentric Administration in Europe, this contribution seeks to illuminate the evolving balance between human and machine in administrative decision‑making, particularly in the field of financial supervision. It does so through a legal analysis grounded primarily in European law, complemented by a case study drawn from Swiss law. While anchored in these two legal orders, the reflections developed here resonate more broadly and offer insights relevant to jurisdictions beyond Europe and Switzerland.
The chapter proceeds in six parts. Section 2 examines the functions of AI in financial supervision and identifies the risks inherent in its integration into supervisory processes. Section 3 outlines the European regulatory framework applicable to AI and assesses the extent to which it governs AI‑based market supervision. Section 4 turns to the substantive requirements for AI‑enabled financial oversight, with particular emphasis on the necessity of maintaining meaningful human control. Section 5 complements this analysis by exploring transparency obligations and the constitutional duty to provide reasons, understood as a core component of the right to a fair trial. Section 6 illustrates these issues through a concrete case study involving market manipulation. The chapter concludes in Section 7 with a synthesis of the main findings and the broader implications for the future of technologically augmented supervision.
2. Integration of AI into Financial Supervision
2.1. Functions of AI in Supervisory Practice
The integration of AI into financial supervision reflects the growing complexity and digitalisation of financial markets. Supervisory authorities operate in an environment characterised by high-frequency trading, algorithmic decision-making, complex financial products and cross-border flows of capital. Traditional analytical tools – often manual, fragmented and resource-intensive – struggle to keep pace with such developments. AI-based systems may offer a significant enhancement in supervisory capacity by enabling the systematic processing and interpretation of vast quantities of structured and unstructured data[4].
In our view, AI tools relevant for financial supervision can essentially be divided into two main categories[5].
First, AI tools can improve data management and information processing, particularly in the context of auditing and reporting obligations. Auditors and supervisory authorities receive extensive reporting documentation from regulated institutions, often in diverse formats and with varying degrees of structure. Natural language processing and automated classification systems can support the organisation, extraction and interpretation of relevant information from these submissions. This facilitates a more coherent and timely supervisory overview and reduces administrative burdens associated with manual data processing[6].
A second and more sophisticated area in which AI may contribute to supervisory practice is support to decision-making by providing structured insights:
- Typically, this includes the detection of anomalous or fraudulent market behaviours. Machine-learning systems can analyse extensive datasets relating to transaction flows, market movements and trading patterns, thereby identifying indicators of insider trading, market manipulation or other similar illicit behaviours. Unlike traditional rule-based monitoring tools, which rely on predefined scenarios, machine-learning models can detect emerging patterns that were not explicitly coded ex ante. This adaptability is particularly valuable in a context where illicit strategies evolve rapidly and often exploit novel market conditions[7].
- Similarly, AI may contribute to systemic risk analysis and stress-testing. Machine-learning algorithms can simulate complex market dynamics by incorporating heterogeneous datasets, including macroeconomic indicators, liquidity profiles, and behavioural responses of financial institutions. These models can support the development of predictive tools that help identify vulnerabilities within the financial system before they materialise. In doing so, AI-based systems enhance supervision by allowing authorities to assess a broader range of potential risk scenarios than would be feasible through traditional methods[8].
2.2. Risks and Challenges of AI-Based Supervision
The deployment of AI in financial market supervision not only offers significant advantages but also introduces a series of risks that may challenge the integrity, reliability and legitimacy of supervisory action. These risks must be carefully analysed to understand the limits of AI-assisted oversight and to identify the legal safeguards necessary to maintain compliance with administrative law standards and fundamental rights.
A first category of concerns relates to operational risks[9], which arise from the technical and functional characteristics of machine-learning systems. Unlike deterministic rule-based tools, machine-learning models may evolve over time in response to changing data inputs, which can lead to model drift or unexpected variations in output quality. Similarly, the performance of such systems depends heavily on the quality, representativeness and completeness of training data. Biased, incomplete or outdated datasets may produce erroneous risk assessments or distort supervisory priorities. Operational risks also encompass explainability limitations: AI systems may generate outputs that are difficult to interpret, particularly when based on deep learning architectures. This opacity complicates the integration of AI outputs into supervisory processes that require traceability and reasoned decision-making[10].
Second, the use of AI raises significant bias and fairness concerns. Machine-learning systems identify patterns based on historical data, which may encode systemic biases or reflect pre-existing market structures. If such biases are inadvertently reproduced or amplified, supervisory decisions based on AI outputs may disproportionately affect certain categories of institutions or transactions. This risk is particularly problematic for public authorities, which are bound by principles of equality and non-discrimination. Unchecked algorithmic bias may thus translate into differentiated supervisory burdens, inconsistent risk classifications or unequal treatment of market participants[11].
A third category, which is related to the preceding ones, concerns ethical and reputational risks. Financial supervisory authorities play a central role in maintaining market confidence and ensuring the proper functioning of the financial system. If AI-assisted assessments produce inconsistent or discriminatory results, or if they appear arbitrary to supervised institutions, the credibility of supervisory action may be undermined. The mere perception that authorities rely excessively on opaque algorithms can also erode trust, particularly if market participants fear that automated tools may misinterpret legitimate behaviour as suspicious. Such reputational vulnerabilities have direct implications for the legitimacy of supervisory interventions and may expose authorities to criticism or public scrutiny[12].
A fourth – and somewhat distinct – risk category concerns cybersecurity and data protection[13]. Supervisory authorities handle highly sensitive financial information, often subject to strict confidentiality requirements. The integration of AI systems introduces new vulnerabilities linked to data access, model security and the integrity of digital infrastructures. Adversarial attacks, data poisoning or model inversion techniques may compromise the reliability of AI outputs or expose confidential supervisory information. Moreover, the use of large datasets and automated analysis tools raises concerns under data protection law, particularly regarding profiling, automated processing and the storage of granular financial data.
3. Financial Supervision Based on AI: Regulatory Framework and Qualifications
3.1. Supervisory Authorities Subject to the EU AI Act
The EU AI Act establishes a regulatory framework applicable to both private and public entities[14], including supervisory authorities. The EU AI Act applies to public authorities because it is designed as a horizontal regulatory framework that governs all actors who develop, place on the market, or use AI systems within the EU – regardless of whether they are private companies or public bodies. Public authorities frequently deploy AI in areas that directly affect individuals’ rights, such as social services, law enforcement, migration, and public administration[15].
In this connection, one of the critical aspects is the distinction between providers and deployers, which determines the set of obligations applicable to supervisory authorities[16]. As a rule, financial supervisory authorities qualify as deployers, since they use AI systems without placing them on the market. However, they may exceptionally be considered providers when they develop bespoke tools or substantially modify an existing system[17].
3.2. Supervisory AI Tools as Potential High-Risk Systems
The EU AI Act is a comprehensive regulation which applies to all AI systems, defined in essence as adaptable machine-learning systems[18]. Furthermore, it is a risk-based regulation, making a critical distinction between high-risk AI systems and lower risk AI systems. High-risk AI systems are essentially defined as such when they may have a significant harmful impact on the health, safety and fundamental rights of persons. More specifically, Article 6 EU AI Act, which provides classification rules for high-risk AI systems, refers to annexes to this Act[19].
In relation to financial supervision, Annex III, based on Article 6(2) EU AI Act, is of particular relevance:
- High-risk AI systems comprise AI systems in the area of administration of justice, namely AI systems intended to be used by a judicial authority[20] or on their behalf to assist a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts, or to be used in a similar way in alternative dispute resolution[21].
- The reason for inclusion is due to the potentially significant impact on democracy, rule of law, individual freedoms as well as the right to an effective remedy and to a fair trial. With respect to the nature of the potential harm, the risks are potential bias, errors and opacity[22].
- Regarding the exceptions, «[t]he classification of AI systems as high-risk should not, however, extend to AI systems intended for purely ancillary administrative activities that do not affect the actual administration of justice in individual cases, such as anonymisation or pseudonymisation of judicial decisions, documents or data, communication between personnel, administrative tasks»[23].
In light of the above, the qualification of AI systems deployed by financial supervisory authorities under the EU AI Act depends on the specific purpose and context of their use, rather than on the mere fact that an authority deploys them. The Act does not automatically classify AI tools used by supervisory bodies as high-risk. Instead, the categorisation results from an assessment of the system’s intended function, operational role, and potential impact on the legal position of supervised entities.
Some supervisory use cases – for example, systems designed to assess compliance, identify potentially unlawful behaviours, or produce risk scores that may inform enforcement measures – may fall within the category of as high-risk systems. In such situations, AI-generated outputs may contribute to supervisory interventions or form part of the factual basis upon which regulatory actions are taken. This functional connection to decision-making processes increases, in our view, the likelihood that the system will be regarded as high-risk.
Conversely, certain AI tools used by supervisory authorities may fall within the category of limited-risk systems. In our opinion, these include systems employed primarily for exploratory analysis, pattern detection without immediate regulatory consequences, internal workflow optimisation or preliminary data structuring. When AI outputs do not directly influence supervisory decisions, and when the system’s role remains confined to assisting internal processes without shaping legal outcomes, the justification for categorising the system as high-risk becomes less evident.
Accordingly, the qualification of an AI system used by supervisory authorities requires a case-by-case assessment. Authorities must examine the system’s operational purpose, its degree of influence on supervisory decisions and the potential impact of its outputs on supervised entities. This nuanced analysis reflects the risk-based logic of the EU AI Act and ensures that regulatory obligations are proportionate to the system’s actual role within supervisory practice.
4. Regulatory Requirements Applicable to Financial Supervision Based on AI
4.1. No prohibition; Overview of Applicable Requirements
As a first and important note, the use of AI systems by financial supervisory authorities is not prohibited, as it does fall in the category of prohibited systems under the EU AI Act[24].
High-risk AI systems are subject to detailed requirements under Chapter II of the EU AI Act, it being specified that these obligations generally fall on providers; however, deployers must ensure that the systems they use comply with these requirements, which include the following: risk management systems ensuring continuous identification, mitigation and monitoring of risks[25]; standards on data and data governance, including training data quality, representativeness and relevance[26]; technical documentation requirements ensuring traceability and auditability[27]; record-keeping obligations, including automated logging of system interactions[28]; transparency obligations, ensuring that deployers understand the system’s capabilities and limitations[29]; human oversight mechanisms, enabling effective supervision, override and intervention[30]; requirements on accuracy, robustness and cybersecurity[31].
Supervisory authorities, acting as deployers, are subject to additional obligations, which aim to ensure that the deployment of AI tools does not compromise procedural fairness, fundamental rights or public accountability in supervisory processes: Implementation of appropriate technical and organisational measures[32]; Designation of competent individuals to exercise human oversight[33]; Maintenance of log records to ensure traceability[34]; Registration duties for high-risk systems used by public authorities[35]; Mandatory fundamental rights impact assessments[36], expressly required for public-sector deployers.
4.2. Human Oversight: Justification and Implications
Among the above-mentioned requirements, human oversight deserves particular attention in relation to financial supervision based on AI:
- The fact that human oversight is required when high-risk AI systems are used is a manifestation of the human centric approach that the EU takes to regulating AI and demonstrates that there is a lack of trust towards machines. Hence, «human oversight is an attempt to counterbalance autonomy, which refers to the increasing capacity of the technology to act without human control or supervision»[37].
- The lack of trust towards the machine does not reach the level of prohibiting the use of AI systems in the context of financial supervision but, as it stems from the concept of human oversight, forces to implement the proper measures to ensure that humans remain in control.
As per the EU AI Act, human oversight means notably that the high-risk AI system shall be provided to the deployer in such a way that natural persons to whom human oversight is assigned are enabled, as appropriate and proportionate:
(a) to properly understand the relevant capacities and limitations of the high-risk AI system and be able to duly monitor its operation, including in view of detecting and addressing anomalies, dysfunctions and unexpected performance;
(b) to remain aware of the possible tendency of automatically relying or over-relying on the output produced by a high-risk AI system (automation bias), in particular for high-risk AI systems used to provide information or recommendations for decisions to be taken by natural persons;
(c) to correctly interpret the high-risk AI system’s output, taking into account, for example, the interpretation tools and methods available; and
(d) to decide, in any particular situation, not to use the high-risk AI system or to otherwise disregard, override or reverse the output of the high-risk AI system[38].
In this regard, it is worth noting that, prior to deploying high‑risk AI systems – and subject to certain exceptions – public‑sector deployers are required to conduct an impact assessment that includes a detailed account of the human oversight mechanisms put in place[39]. This requirement underscores the centrality of meaningful human oversight in the use of high‑risk AI systems by public authorities.
4.3. Interpreting the Output: Need to Consider the Probabilistic Results
As indicated above, human oversight means notably that the natural person using the high-risk AI system should be in a position to correctly interpret the high-risk AI system’s output, taking into account, for example, the interpretation tools and methods available.
In this context, it is essential to recall that AI‑based systems operate on probabilistic inferences rather than deterministic conclusions[40]. As a result, an AI‑generated indication that enforcement action should be prioritized, or that potentially fraudulent market behavior has occurred, may rest on a probability of 51% or, alternatively, 90%, two scenarios that are qualitatively distinct. This raises the question of the extent to which supervisory authorities should assess such probabilistic information.
Several observations can be made in this regard:
- First, it is somewhat surprising that the EU AI Act remains silent on the concept of probabilistic results, despite its emphasis on human oversight[41].
- Second, with respect for instance to decisions concerning the prioritization of supervisory or enforcement activities, supervisory authorities traditionally enjoy a broad margin of discretion. Given this margin of discretion, there appears to be limited justification for requiring detailed assessment of the probabilistic outputs generated by AI systems in relation to such decisions.
- Third, by contrast, once supervisory authorities move beyond the mere organization or prioritization of their activities and enter the realm of adopting formal enforcement measures in individual cases, the nature of their responsibilities changes fundamentally. At this stage, the epistemic quality of AI‑generated findings becomes critical. Assume the use of an AI‑based tool to conduct stress tests on a financial institution with significant exposure to interest‑rate fluctuations. If the stress tests indicate that the institution is undercapitalized in light of the simulated scenarios, the supervisory authority may require the institution to increase its capital buffers. In such a context, it becomes essential to understand the degree of confidence with which the AI system reaches its conclusions. A supervisory decision based on an output associated with a confidence level of 51% is of a fundamentally different nature from one supported by a confidence level of 90%. The legitimacy and legal defensibility of the resulting enforcement measure depend, at least in part, on the authority’s ability to assess and interpret this confidence level appropriately.
- Although AI systems do not, as a rule, provide explicit confidence levels or explanations for their outputs, supervisory authorities should nevertheless interrogate these systems to understand why certain facts, indicators, or assumptions were weighted or disregarded. Hence, human oversight must not be reduced to a formalistic requirement but should instead entail a substantive capacity to question, challenge, and contextualize AI‑generated outputs.
4.4. Decision-Making through AI?
A final question arising in connection with human oversight concerns whether a decision may, in principle, be produced entirely by a machine. Although it is important to recall that the degree of autonomy attributed to AI systems is frequently overstated[42] – and that such a scenario remains largely theoretical in the current context of financial supervision – the issue warrants careful consideration:
- The wording of Article 6 EU AI Act does not appear to prohibit this possibility. The provision requires only that the resulting decision be subject to human oversight; it does not mandate that humans must themselves generate each component of the decision‑making process.
- Recital 61 EU AI Act adopts a seemingly more restrictive tone, stating that «[t]he use of AI tools can support the decision-making power of judges or judicial independence, but should not replace it: the final decision making must remain a human driven activity»[43]. At first sight, this might suggest that the involvement of AI must be limited to an auxiliary role.
- Yet, in our view, the two sources can be reconciled. There is no compelling reason – assuming it is technically feasible – why an authority could not delegate the entire preparatory phase of a decision to an AI system, provided that the authority subsequently exercises diligent and substantive control over the outcome. Such control necessarily presupposes that the system is capable of providing a complete account of its reasoning, not in algorithmic terms, but in a form that can be translated into a legally cognizable methodology.
- Ultimately, the decision is, in any event, formally adopted by the competent authority. What matters, therefore, is not whether the machine drafts the decision, but whether the human decision‑maker is able to understand, verify, and endorse the reasoning on which it rests. This ensures compliance with both the letter and the spirit of the EU AI Act’s human‑oversight requirements.
5. Transparency Requirements Applicable to Financial Supervision Based on AI?
5.1. No Transparency Based on the EU AI Act
Ultimately, the central issue is ensuring that interventions by supervisory authorities are both substantively justified and intelligible to the financial institutions and other actors subject to their oversight. In other words, supervisory decision‑making must remain reasoned, transparent, and amenable to external scrutiny.
These considerations raise the question of whether the use of AI systems – and the manner in which human oversight has been exercised – should be disclosed by supervisory authorities.
No such requirement arises from the provisions governing human oversight, nor from any other provisions of the EU AI Act. More specifically, the transparency obligations set out in Article 13 EU AI Act aim solely to ensure that deployers understand the system’s capabilities and limitations[44]. Likewise, the transparency obligations under Article 50(1) require only that natural persons interacting directly with an AI system be made aware of that fact[45].
B. Duty to State Reasons as Sufficient Safeguard
More fundamentally, the issue turns on the constitutional guarantee embodied in the duty to state reasons:
- This guarantee requires that the addressee of an administrative decision be able to understand both the decision itself and the reasoning that underpins it[46]. In and of itself, the guarantee does not require the authority to indicate whether it relied on a computational system to establish certain facts or to assess them from a legal perspective.
- One may nonetheless ask whether an evolution of the duty to state reasons is desirable when supervisory authorities in the financial sector use AI systems, on the grounds that such use may affect the transparency or legitimacy of administrative action. Under this view, the authority would be required to incorporate explanations regarding how AI systems were used, how their outputs were evaluated, and how potential shortcomings or uncertainties were addressed[47].
- In our view, however, these elements – aside from the mere information that an AI system was used, which is of limited relevance in itself – add nothing beyond what the duty to state reasons already requires. Whether the assessment of a case is performed by a human or by a machine, the decision must contain a pertinent and convincing legal rationale. In reality, the duty to state reasons operates as an additional safeguard that, in practice, reinforces the concept of human oversight: if the authority is unable to understand and evaluate the reasoning produced by the system, it will be unable to reproduce that reasoning in its decision. This would either violate the duty to state reasons or result in a substantively weak decision that is highly susceptible to challenge by the addressee.
6. Case Study: Trade-Based Manipulation and Swiss Financial Market Supervision
6.1. Swiss Regulatory Framework
Art. 143(1)(b) FinMIA prohibits any form of trade-based manipulation involving securities admitted on trading on a trading venue or a DLT trading facility with its registered office in Switzerland[48]. This provision seeks to safeguard the integrity of the Swiss financial market by sanctioning transactions capable of impairing its proper functioning. It covers transactions that generate, or are likely to generate, false or misleading signals as to market conditions. Practices such as painting the tape, wash trades, matched orders, or spoofing are typically behaviours that may mislead investors[49].
In the application of Art. 143(1)(b), the decisive criterion is the capacity of the transaction to convey a false or misleading signal to the market. The concept of signal implicitly refers to the reasonable investor test[50]. This latter, developed by the United States Supreme Court[51] and subsequently endorsed by Swiss case law[52], requires an assessment of whether the transaction is likely to influence the investment decision of a reasonable investor[53]. This figure serves as an objective standard for determining whether the transaction produces a market signal. According to doctrinal approaches, the reasonable investor either refers to a rational and idealized investor or to the market as a whole[54]. However, it appears that recent Swiss doctrine, as well as decisions of the Federal Criminal Court, seem to adopt the interpretation of the reasonable investor as representing the market as a whole[55].
The reasonable investor test constitutes an objective and qualitative assessment conducted from an ex ante perspective. It therefore requires consideration of all relevant circumstances of the case in order to determine whether the transaction was likely to influence the investment decision of a reasonable investor. In this respect, actual market reactions may nonetheless be taken into account to assess the materiality threshold, that is, the point at which a transaction conveys a signal to the market.
FINMA supervises the conduct of market participants in the Swiss financial market in order to ensure the integrity of price formation. It is responsible for enforcing Art. 143(1) FinMIA. The supervisory instruments provided for under FINMASA apply to any person engaging in market manipulation[56]. The monitoring of securities transactions is delegated to trading venues, which are required to report suspicious transactions to FINMA. In Switzerland, two stock exchanges – namely SIX Swiss Exchange and BX Swiss Exchange – are authorized by FINMA.
6.2. Case 2C_315/2020: Spoofing and Layering Acts
In a judgment of 7 October 2020, the Federal Supreme Court upheld FINMA’s decision against a company and its sole shareholder, acting as its governing body, which had, inter alia, breached Art. 143(1)(b) FinMIA[57]. The Federal Supreme Court relies on the conduct of the perpetrators to establish the existence of market manipulation. In this respect, it applies FINMA Circular 13/8 to determine whether the conduct in question was manipulative.
The supervisory authority of SIX Swiss Exchange examined the company’s trading conduct for the period from 3 December 2012 to 5 August 2013. On 26 March 2014, it forwarded its investigation report to FINMA, which subsequently initiated an enforcement proceeding on the basis of substantiated indications of systematic market manipulation. In its final decision of 20 June 2017, FINMA found that the company had seriously breached regulatory requirements. According to FINMA, the company and its shareholder engaged in market manipulation by employing spoofing, layering and ramping strategies.
In the present case, on all analyzed trading days on which the complainants traded derivative instruments with the corresponding shares as underlying assets (approximately 100 samples), his trading behavior was characterized by the systematic creation of a misleading surplus of orders in the underlying securities (spoofing), predominantly placed at multiple price levels (layering), followed by the immediate cancellation of those orders[58]. The complainant thereby derived economic benefits in the value of the related derivative instruments. He further switched sides of the order book with high frequency, repeatedly reproducing the same trading pattern. In nearly all instances, a persistent inconsistency was observed between executed trades and submitted orders[59]. Within the sample examined, only a marginal proportion of the total recorded order volume was ultimately executed.
According to the Swiss Federal Supreme Court, the short interval between the placement and cancellation of orders, together with their high volume, indicates the absence of any genuine economic rationale for the transactions. Virtually all analyzed samples reflect a systematic and disproved trading pattern. Thus, the complainants’ conduct was aimed at generating impermissible income through manipulative trading strategies, of which he must have been aware[60].
As evidenced by the random samples, the complainant repeatedly created the appearance of selling a certain volume of securities. Other market participants followed the price movement thereby induced, generating selling pressure on the securities concerned[61]. The complainant subsequently cancelled his sell orders, waited a few second, and replenished his holding at lower prices. Following the acquisition of the securities, market prices rose again, enabling the complainant to resell the securities at a profit[62].
In its defense, the complainant contends that it was engaged in market-making and activities[63]. However, market makers ensure continuous bids and ask quotations for securities with broadly symmetrical volumes on both sides of the order book, with aim of profiting from the spread between bid and ask prices. Hedging, by contrast, seeks to mitigate price risk, typically by offsetting exposure in the underlying asset through derivative positions. According to the Swiss Federal, nothing in the present case suggests that the complainant acted in either capacity. Liquidity was provided only on a large scale for very short periods and in a unilateral manner, creating one-side order book surpluses that were regularly withdrawn almost immediately. Such conduct is inconsistent with that of a market maker. Moreover, the extent to which the complainant engaged in hedging in neither apparent nor substantiated. This conclusion is further supported by the fact that the positions taken in the underlying assets were generally of limited economic significance, while the leverage of the derivative positions was comparatively high, militating against any genuine neutralization of market risk[64].
6.3. AI-Based Supervision against Manipulative Behaviours
SIX Swiss Exchange relies on an AI-based surveillance tool, known as Prometheus, to monitor trading activity:
- This system identifies patterns suggesting insider trading and market manipulation. The technology underlying this system incorporates, inter alia, machine learning techniques capable of identifying both known and previously undiscovered forms of market manipulation. Its effectiveness stems in particular from its ability to process large volumes of trading data and to establish correlations between data points that may not have been identified through traditional surveillance methods[65].
- In this process, the system identifies suspicious transactions and generates an alert, which is then transmitted to the team responsible for conducting a more in-depth investigation of the conduct in question[66]. Where SIX considers the conduct to be manipulative, it subsequently transmits all relevant documentation to FINMA.
It follows from the above that the process implemented by SIX reflects the following division of tasks: the quantitative component – namely the identification of correlations within large datasets – is performed by the machine, whereas the reasonable‑investor test, which constitutes a qualitative assessment, is carried out by humans. In other words, the signal generated by the system serves merely as an indication that must subsequently be corroborated through a qualitative human analysis. This balance is broadly consistent with the requirements governing human oversight under the EU AI Act.
Assuming that AI tools were, in the future, capable of performing the qualitative assessment as well, such an evolution would, in our view, remain acceptable – taking into account the considerations developed earlier in this Chapter – provided that human oversight does not become a mere formality. Human reviewers would need to engage meaningfully with the probabilistic nature of AI outputs, questioning the system to understand why certain parameters were weighted more heavily than others, or why some were disregarded altogether. Ultimately, the reasoning must be clearly intelligible and reflected in the authority’s final decision.
In our view, the use of AI systems should not alter the applicable legal test. Their deployment cannot exempt SIX or FINMA from the obligation to assess conduct through a qualitative examination grounded in the reasonable‑investor standard. Both institutions must remain capable of substantiating – where appropriate with the assistance of AI tools – that the transactions at issue were capable of influencing the investment decision of a reasonable investor. While model‑based methods may be employed, the assessment of the signalling effect must remain qualitative and must take into account all relevant circumstances.
7. Conclusion
As a preliminary note, while the use of AI tools by regulated entities has already attracted considerable regulatory attention, the deployment of such tools by financial supervisory authorities remains comparatively underexplored. Against this backdrop, the main findings and arguments advanced in this contribution may be summarized as follows:
- The initial issue that arises concerns the applicable legal framework. Within the European Union, it is acknowledged that the use of AI by public authorities entails risks comparable to those associated with private actors. Consequently, the EU legislature has opted to subject both categories of users to the EU AI Act. Moreover, it is recognized that AI‑enabled public authority activities may pose heightened risks to individual rights and freedoms – a category that, in our view, may encompass supervisory functions in the financial sector.
- A further question concerns the limits and requirements governing such use, particularly with respect to the human–machine relationship. In line with its human‑centric approach, the EU AI Act unequivocally requires the presence of human oversight, while remaining silent on the precise modalities through which such oversight must be exercised. Given the inherently probabilistic nature of AI systems, supervisory authorities must be able to interrogate these systems in order to understand why certain facts, indicators, or assumptions were weighted or disregarded. Human oversight therefore cannot be reduced to a merely formal requirement. Moreover, the EU AI Act is ambiguous as to whether a decision may be fully prepared through AI‑based processes. In our view, this should indeed be permissible for supervisory authorities – although it is doubtful that current AI tools are capable of achieving such a result – provided that the final output is subjected to meaningful human review.
- The final issue concerns the degree of transparency required of supervisory authorities that rely on AI. The EU AI Act itself does not impose explicit transparency obligations in this regard. However, this absence is of limited practical consequence, as supervisory authorities are already bound by constitutional requirements to provide reasons for their decisions. This obligation ensures that the authority’s reasoning must be articulated clearly. At the same time, it exerts a disciplining effect on authorities, reinforcing the necessity of critically assessing and validating the output generated by AI systems.
In light of the foregoing, the balance struck between machine and human involvement in financial‑market supervision appears acceptable under the EU’s AI‑specific regulatory framework, particularly when read together with the constitutional guarantee of the duty to state reasons. This balance may also serve as a reference for other jurisdictions, including Switzerland.
- See, for instance, Swiss Financial Market Supervisory Authority FINMA Guidance 08/2024, of 18 December 2024, Governance and risk management when using artificial intelligence, available at https://www.finma.ch/en/news/2024/12/20241218-mm-finma-am-08-24/; Turksen, Benson, Adamyk, Legal implications of automated suspicious transaction monitoring: enhancing integrity of AI, in Journal of Banking Regulation, 2024, Vol. 25, pp. 359 et seq. ↑
- On 14 October 2025, the Swiss Federal Audit Office has issued a report titled “Use of artificial intelligence in supervision” which focuses on the said use by the Swiss Financial Market Supervisory Authority (FINMA); this report is available at https://www.efk.admin.ch/en/audit/use-of-artificial-intelligence-in-supervision/. In September 2025, the U.S. Securities and Exchange Commission (SEC) has issued the “SEC’s 2025 AI Compliance Plan” which is available at https://www.sec.gov/ai. On this topic, see also, for instance, Bains et al., AI Projects in Financial Supervisory Authorities – A Toolkit for Successful Implementation, IMF Working Paper WP/25/199, October 2025, available at https://www.imf.org/-/media/files/publications/wp/2025/english/wpiea2025199-source-pdf.pdf; Toronto Centre, The Supervisor of the Future, June 26, 2025, available at chrome-extension://efaidnbmnnnibpcajpcglclefindmkaj/https://www.imf.org/-/media/files/publications/wp/2025/english/wpiea2025199-source-pdf.pdf https://torontocentre.org/index.php?option=com_content&view=article&id=600&Itemid=99#:~:text=AI%20can%20assess%20systemic%20risks,Behavioural%20analytics; Kasireddy, The Ethical Implications of AI in Financial Market Surveillance: Are We Over-Monitoring traders?, in European Journal of Accounting, Auditing and Finance Research, 2025, Vol.13, No. 4, pp.17 et seq. ↑
- This contribution focuses on the use of AI and does not extend to other related topics, such as real time automated surveillance, which raises additional critical issues. ↑
- In April 2025, a new Integrated Risk Expertise division has been created within the Swiss Financial Market Supervisory Authority (FINMA). This cross-divisional unit provides the supervisory divisions with expertise in data-driven analysis, analysis of financial and non-financial risks and operational resilience through several competence centers. It is also responsible for the planning, coordination, implementation and quality assurance of on-site supervisory reviews. A central function of this new unit includes, among other things, the design, further development, and operation of AI systems for risk and market monitoring. See Swiss Federal Audit Office, Use of artificial intelligence in supervision, pp. 12 et seq.; this report is available at https://www.efk.admin.ch/en/audit/use-of-artificial-intelligence-in-supervision/. ↑
- Tools that merely aim to improve the authority’s internal organization and administrative functioning are set aside in this paper. In this respect, it is rather surprising that the SEC seems to rely only on such limited tools; see the excel sheet titled “2025 SEC Consolidated AI Use Cases” available at https://www.sec.gov/ai. ↑
- See notably Rohara, The Impact of Artificial Intelligence on Financial Auditing Practices, April 21, 2025, available at https://ssrn.com/abstract=5246748. It may be expected that AI systems may also play a significant role in prioritisation of supervisory tasks. Authorities typically face resource constraints preventing uniform monitoring of all market participants. AI-driven classification and clustering techniques can assist in identifying entities or behaviours that warrant closer inspection. By generating prioritisation models, AI supports a more efficient allocation of supervisory resources and contributes to a risk-based approach to oversight, which is widely recognised as a cornerstone of modern financial regulation. ↑
- See the case study in Section 6 of this paper. ↑
- Toronto Centre, The Supervisor of the Future, June 26, 2025, available at https://torontocentre.org/index.php?option=com_content&view=article&id=600&Itemid=99#:~:text=AI%20can%20assess%20systemic%20risks,Behavioural%20analytics. See also Clarke, Moreau, AI-Powered Stress Testing and Scenario Analysis for Financial Stability Assessment, available online at https://www.researchgate.net/publication/399284947_AI-Powered_Stress_Testing_and_Scenario_Analysis_for_Financial_Stability_Assessment. ↑
- Specifically, the risks associated with the use of AI in transaction surveillance lie primarily in false negatives and false positives. While a certain degree of false negatives – namely, undetected manipulative conduct – may be tolerable, false positives are more problematic, as they may trigger investigations into conduct that is in fact lawful. ↑
- With respect to the risk of error, see Recital 61 EU AI Act. ↑
- With respect to the risk of bias, see Recital 61 EU AI Act. ↑
- The concept of trust is at the heart of the report issued by Swiss Federal Audit Office titled “Use of artificial intelligence in supervision” which focuses on the said use by the Swiss Financial Market Supervisory Authority (FINMA); this report is available at https://www.efk.admin.ch/en/audit/use-of-artificial-intelligence-in-supervision/. ↑
- On this topic more generally in connection with the use of AI in the public administration, see for instance Swiss Confederation, Strategy – Use of AI systems in the Federal Administration, 11 December 2025, p. 3; this document is available at https://www.bk.admin.ch/bk/en/home/digitale-transformation-ikt-lenkung/vorgaben/sb021-strategie-einsatz-von-ki-systemen-in-der-bundesverwaltung.html. ↑
- See notable Recital 13 EU AI Act. ↑
- Recitals 3, 58 and 60 EU AI Act. ↑
- Articles 3(3) and (4) EU AI Act. ↑
- Articles 3(3) and 25 EU AI Act. ↑
- Article 3(1) EU AI Act. ↑
- Recital 7 EU AI Act. For more details regarding the various categories under the EU AI Act, see Caballero Cuevas, Systèmes d’intelligence artificielle – Les catégories de la réglementation européenne, 2024. Available at https://cdbf.ch/1390/. ↑
- In our view, the notion of “judicial authority” should be interpreted broadly to encompass administrative bodies – or at least those administrative bodies empowered to impose measures and sanctions – since the use of AI tools by such authorities raises issues comparable to those arising from their use by courts. ↑
- Annex III(8)(a) EU AI Act. Potentially, Annex III(6) EU AI Act, which relates to law enforcement, may also be relevant in the context of financial supervision, it being however specified that «AI systems specifically intended to be used for administrative proceedings by […] financial intelligence units carrying out administrative tasks analysing information pursuant to Union anti-money laundering law should not be classified as high-risk AI systems used by law enforcement authorities for the purpose of prevention, detection, investigation and prosecution of criminal offences» (Recital 59 EU AI Act). ↑
- Couneson, Classification Rules for High-Risk AI Systems, in Pehlivan, Forgo, Valcke (eds), The EU Artificial Intelligence (AI) Act – A Commentary, Wolters Kluwer, 2025, p. 213, referring to Recital 61 EU AI Act. ↑
- Recital 61 EU AI Act. ↑
- Article 5 EU AI Act. ↑
- Article 9 EU AI Act. ↑
- Article 10 EU AI Act. ↑
- Article 11 EU AI Act. ↑
- Article 12 EU AI Act. ↑
- Article 13 EU AI Act. ↑
- Article 14 EU AI Act. ↑
- Article 15 EU AI Act. ↑
- Article 26(1) EU AI Act. ↑
- Article 26(2) EU AI Act. ↑
- Article 26(6) EU AI Act. ↑
- Article 26(8) EU AI Act. ↑
- Article 27 EU AI Act. ↑
- Panezi, Human Oversight, in Pehlivan, Forgo, Valcke (eds), The EU Artificial Intelligence (AI) Act – A Commentary, Wolters Kluwer, 2025, p. 365. ↑
- Article 14(3) EU AI Act. To be further noted that human oversight must be connected with transparency requirements, which aim at addressing black box issues. See Corrêa, Transparency and Provision of Information to Deployers, in Pehlivan, Forgo, Valcke (eds), The EU Artificial Intelligence (AI) Act – A Commentary, Wolters Kluwer, 2025, p. 343. ↑
- Article 27(1) EU AI Act. More comprehensively, this assessment shall consist of the following: (a) a description of the deployer’s processes in which the high-risk AI system will be used in line with its intended purpose; (b) a description of the period of time within which, and the frequency with which, each high-risk AI system is intended to be used; (c) the categories of natural persons and groups likely to be affected by its use in the specific context; (d) the specific risks of harm likely to have an impact on the categories of natural persons or groups of persons identified pursuant to point (c) of this paragraph, taking into account the information given by the provider pursuant to Article 13; (e) a description of the implementation of human oversight measures, according to the instructions for use; (f) the measures to be taken in the case of the materialisation of those risks, including the arrangements for internal governance and complaint mechanisms. ↑
- Krause, Hübotter, Probabilistic Artificial Intelligence, ETH Zürich, 7 February 2025, available at https://arxiv.org/abs/2502.05244?. ↑
- Under the EU AI Act, the critical concept is the fact that a system has the ability to “infer” results from the input it receives, as the ability of an AI system to “infer” transcends basic data processing, enables learning, reasoning and modelling. See Feiler, König, Definitions, in Pehlivan, Forgo, Valcke (eds), The EU Artificial Intelligence (AI) Act – A Commentary, Wolters Kluwer, p. 58, 2025, referring to Recital 12 EU AI Act. ↑
- Panezi, Human Oversight, in Pehlivan, Forgo, Valcke (eds), The EU Artificial Intelligence (AI) Act – A Commentary, Wolters Kluwer, 2025, p. 365. ↑
- Recital 61 EU AI Act. ↑
- Corrêa, Transparency and Provision of Information to Deployers, in Pehlivan, Forgo, Valcke (eds), The EU Artificial Intelligence (AI) Act – A Commentary, Wolters Kluwer, 2025, p. 343. ↑
- Gils, Transparency Obligations for Providers and Deployers of Certain AI Systems, in Pehlivan, Forgo, Valcke (eds), The EU Artificial Intelligence (AI) Act – A Commentary, Wolters Kluwer, 2025, p. 780 et seq. ↑
- Bovet, Popadic, Art. 35 PA – Motifs et indication des voies de recours, N 5, in Bellanger, Candrian, Hirsig-Vouilloz (eds), Commentaire romand de la loi fédérale sur la procédure administrative, Helbing Lichtenhahn, 2024. ↑
- On this issue in general (not limited to financial supervision), see Hendrickx, The Judicial Duty to State Reasons in the Age of Automation? The Impact of Generative AI Systems on the Legitimacy of Judicial Decision-Making, September 20, 2024. Available at https://ssrn.com/abstract=5043685. ↑
- SR 958.1 (Swiss federal law register). ↑
- Circ.-FINMA 2013/8, Cm 19-30. ↑
- Federal Tribunal, 2C_315/2020, § 7.2.3 ; Federal Administrative Tribunal, B-2370/2022, § 4.1.1 ; Federal Council, 2011, Message sur les abus de marché, p. 6358. ↑
- See Basic, Inc. v. Levinson, 485 U.S. 224 (1988), p. 231 s., in particular «a substantial likelihood that the disclosure of the omitted fact would have been viewed by the reasonable investor as having significantly altered the ‘total mix’ of information made available» (emphasis omitted). ↑
- See e.g. Federal Tribunal, ATF 145 IV 407, § 3.4.1, JdT 2020 IV 163 ; Federal Criminal Tribunal, CA.2023.27, § 1.4.5.6 ; Federal Criminal Tribunal, SK.2022.30, § 2.2.4.6. ↑
- Darbellay, Caballero Cuevas, The Materiality of Sustainability Information under Capital Markets Law, in : RSDA 2023, vol. 95, No 1, p. 46. ↑
- Remund, L’exploitation d’informations d’initiés selon les articles 154 et 142 LIMF : une étude de droit suisse et comparé, thèse Lausanne, Zurich, Bâle, Genève 2021, pp. 377 et seq. ; Kumpan, Misterek, Der verständige Anleger in der Marktmissbrauchsverordnung : Zu den Eigenschaften der Massstabsfigur gür Insiderinformanionen, in ZHR, 2020, vol. 184, pp. 193 et seq.; Klöhn, Artikel 7, N 268 et seq., in Klöhn Lars, Brellochs Michael, Schmolke Klaus Ulrich, Semrau Stephan, Marktmissbrauchsverordnung : Verordnung (EU) Nr. 596/2014 über Marktmissbrauch, 2nd ed., Munich, 2023. ↑
- Federal Criminal Tribunal, CA.2023.27, § 1.4.5.6. ↑
- Art. 145 FinMIA. ↑
- Federal Tribunal, 2C_315/2020. ↑
- Federal Tribunal, 2C_315/2020, § 7.3.1. ↑
- Federal Tribunal, 2C_315/2020, § 7.3.1. ↑
- Federal Tribunal, 2C_315/2020, § 7.3.1 et seq. ↑
- Federal Tribunal, 2C_315/2020, § 7.3.1 et seq. ↑
- Federal Tribunal, 2C_315/2020, § 7.3.1 et seq. ↑
- Federal Tribunal, 2C_315/2020, § 7.3.4 ↑
- Federal Tribunal, 2C_315/2020, § 7.3.4. ↑
- Leybold, Müller, SER bekämpft Marktmissbrauch mit KI-basierter Technologie, 2022. Available at https://www.pwc.ch/de/insights/digital/six-prometheus.html. ↑
- Leybold, Müller, SER bekämpft Marktmissbrauch mit KI-basierter Technologie, 2022. Available at https://www.pwc.ch/de/insights/digital/six-prometheus.html. ↑