RegTech and SupTech are becoming one ecosystem
Regulatory technology has always been sold in two directions. RegTech is what a bank buys to keep up with its obligations; SupTech is what the regulator deploys to watch the bank. The contributed piece below argues that the distinction only ever described who held the licence to the software, not what the software did, and that both sides now want the same thing: a live, machine-readable view of the rules, mapped to what firms actually do, with an audit trail.
The author cites a count of 197 financial authorities in 140 countries that have deployed at least one SupTech solution, up from 54 in 2022, and the UK Financial Conduct Authority's own stated interest in an agentic supervisory model. His conclusion is that supervisor and supervised will end up running on shared infrastructure, and that the question worth asking is whether that produces confusion or collaboration.
Ben Richmond is founder and chief executive of CUBE, a regulatory intelligence company whose software tracks, classifies and monitors regulatory change for financial institutions. The article that follows is a contributed piece and presents his opinion.
The global financial services industry is approaching a structural shift in how regulation is managed, monitored and enforced. Historically, the industry has maintained a clear separation between RegTech tools purchased by regulated firms to help them comply and SupTech technologies deployed by authorities to oversee the sector.
This old distinction was fundamentally about who held the technology solution, rather than what the technology actually did. Today, that boundary is becoming increasingly blurred. We are witnessing the creation of a singular, connected regulatory ecosystem, where both the supervisor and the supervised rely on the exact same underlying technology platform.
Why the distinction is blurring
Customer and industry expectations have undergone a fundamental shift from "help me comply" to "give me trusted, real-time regulatory intelligence I can act on". Regulated firms no longer want passive tools that simply aggregate text. They require trusted, real-time regulatory intelligence they can immediately action. This means a live, machine-readable view of global obligations, strategically mapped to business operations, supported by a robust audit trail.
And regulators now want the exact same thing too. Across jurisdictions, authorities are integrating SupTech into core supervisory functions, with AI, data access and cloud infrastructure seen as the critical enablers. This is the same tech stack regulated firms require. The scale of this adoption is striking: a total of 197 financial authorities across 140 countries have now deployed at least one SupTech solution. This is a significant and deliberate increase from just 54 authorities in 2022.
As both sides converge on trusted intelligence, faster access, transparency and better decisions, the buyer label is becoming redundant, as what matters is the shared functionality and capability underneath. The lines will always blur; the real question is whether that creates confusion or collaboration.
The agentic AI effect
We all recognise that artificial intelligence is the primary catalyst accelerating this trend. For regulated firms, AI has transformed compliance from being a periodic, manual exercise into a continuous real-time interpretation, a regulatory necessity. Likewise for the regulators, AI has shifted supervision functions from reactive and sample-based to proactive and evidence-led.
The UK's Financial Conduct Authority (FCA) recently published its landmark Mills Review, which is a global first-of-its-kind study exploring how AI will reshape retail financial services by 2030. The Mills Review did not just address how firms should use AI but called on the FCA to build and adopt an "AI-enabled agentic supervisory model" on the very same agentic paradigm as the firms it oversees, on a shared trusted-intelligence layer. This is further reinforced by the FCA's AI Live Testing programme, which defines AI as a system, not a standalone algorithm, which is a supervisory and a compliance data problem expressed in identical terms.
Converging on the same capabilities
We are seeing something fascinating evolving in today's regulatory landscape, as both regulators and firms are demanding the exact same functions and capabilities, including structured regulatory data, traceability, model governance and continuous monitoring. This is not a coincidence; it is clear we are witnessing a convergence in thinking.
Regulators are prioritising observable behaviour, repeatable evidence and live-environment validation, which is the same standard firms must now meet internally. What is most striking is that regulators want the same horizon-scanning and intelligence layer firms use, so both sides reason from a shared source of truth.
The Mills Review sharpens why this matters now: FCA-commissioned research found around 11 million UK adults are likely to use AI that can act autonomously within pre-set goals, but their central concern is trust and control. That trust gap is the product argument, as agentic finance is only as good as the trusted, traceable regulatory data that powers the AI behind it. That foundation is identical whether the agent sits inside a firm or indeed the supervisor.
Shared infrastructure and the real differentiator
Looking ahead, the trajectory points to a connected regulatory ecosystem built on shared requirements: machine-readable regulation, shared data standards and AI that interprets obligations consistently on both sides. All with a knowledgeable human in the loop, which has to be a non-negotiable. This is not just three lines of defence sitting alongside better technology; it is an agent and human architecture, where agents do the heavy lifting of data mapping, control tagging and monitoring, while humans provide the judgement, interpretation and escalation. AI does not replace a line of defence; it strengthens every one of them.
The regulator is now thinking in exactly these terms, with the Mills Review enabling "the foundations for agentic finance" by strengthening system-wide coordination and oversight and securing the regulatory perimeter. Both firm-side and supervisor-side infrastructure will be treated as one system, not two separate categories.
IOSCO established a SupTech Forum in 2026 to coordinate how technology is reshaping supervision, and the FCA is aligning its AI testing approach internationally with the Monetary Authority of Singapore. The providers best placed will be those, like CUBE, who can credibly serve both sides from one unified intelligence foundation that works inside the systems they already run.
It is, however, worth noting that the Mills Review's recommendations are purely advisory guidelines to the FCA board and not yet set policy, with the regulator still leaning on existing frameworks such as the Consumer Duty and the Senior Managers Regime. Adoption also remains genuinely uneven, with many authorities reporting partial implementation, and cyber risk, data quality, skills and funding cited as persistent constraints.
That said, with it looking like only a matter of time before advice becomes policy, who is going to come out on top in this new regulatory landscape? We believe trust and provenance will be the real advantage. In a converged sector the differentiator is defensible, traceable regulatory intelligence. Firms often lack the ability to trace an obligation back to its source and evidence how they have met it. Regulators face the opposite problem, as they want to be able to evidence that obligations are being met across the market. Trust has to run both ways, and that is why the Mills Review's emphasis on "trusted" AI is so important.
If we were starting the regulatory system again from scratch, it would look less like a wall and more like a web.