SPP sets AI governance framework for UK pensions trustees

The Society of Pension Professionals warns that 100% of pension firms now use AI, yet governance frameworks have failed to keep pace.

A brightly lit data center hallway features two symmetrical rows of glass-front server cabinets displaying glowing green and blue indicator lights, extending towards a far wall with a pair of similar cabinets.

The Society of Pension Professionals (SPP) has published a practical AI governance framework aimed at UK pension scheme trustees, marking a significant escalation in how the £2 trillion-plus pensions sector is approaching the operational and fiduciary risks of AI deployment. The paper, released in July 2026, follows SPP survey data showing that 87% of pension firms used AI in 2025, rising to 100% in 2026, a saturation rate that has outpaced regulatory development.

The framework does not propose new legal duties. Instead, it calls for trustees to apply existing fiduciary, governance and risk management obligations to AI-enabled activities. It identifies five overarching principles: transparency, accountability, proportionality to risk, security by design, and meaningful human oversight. These map directly onto The Pensions Regulator's (TPR) May 2026 AI Plan, which makes clear that trustees remain accountable for outcomes even when AI functions are delegated to administrators or advisers.

AI risk taxonomy and the agentic investment question

Central to the SPP's approach is a three-tier risk classification. Low-risk uses, internal drafting and summarisation, require baseline controls. Medium-risk uses, including member communications, warrant closer oversight. High-risk uses, any AI output influencing benefit calculations or member decisions, require enhanced governance and, in some cases, prohibition without robust validation. The framework extends this taxonomy specifically to investment management, noting that asset managers are increasingly deploying agentic AI systems capable of initiating trading or rebalancing decisions autonomously. Trustees are told to treat a manager's AI governance quality as a due diligence factor equivalent to any other operational risk assessment.

That instruction carries weight beyond the pensions sector. Asset managers running multi-asset mandates for pension schemes are among the largest allocators in UK capital markets. If trustees begin inserting AI governance audit rights into investment management agreements, as the SPP framework recommends, the compliance burden will travel upstream to fund managers, custodians and model providers. This is a governance contagion dynamic: regulation originating in a beneficiary-protection context reshaping procurement and contracting norms across institutional finance.

Employer covenant and the macro AI disruption lens

The SPP framework contains an underappreciated section on employer covenant assessment that reframes AI as a macroeconomic risk variable. Trustees are advised to monitor whether the sponsoring employer is adapting to AI-driven competitive disruption, noting that firms slower to adopt AI risk deteriorating cash generation and "more uncertain prospects." The paper also cites a June 2026 joint advisory from Five Eyes cyber agencies warning that frontier AI models are expanding the threat surface for cyber-attacks, with the timeline measured in months rather than years. In a covenant context, a significant cyber event can trigger business interruption with direct implications for scheme funding levels.

This framing is notable because it positions AI not merely as an operational tool but as a systemic risk factor affecting the financial durability of the employers that underwrite pension liabilities. For cross-sector investors and capital allocators, it signals that AI resilience is becoming a material variable in assessing any business with a defined-benefit pension obligation, a category that still encompasses a substantial share of FTSE-listed companies.

The regulatory backdrop is also tightening outside pensions specifically. The UK's Data (Use and Access) Act 2025 relaxed some automated decision-making constraints but introduced new safeguards requiring meaningful human intervention rights for individuals subject to automated outcomes. The SPP framework requires trustees to map these obligations across every administrator and adviser using AI, including fourth-party sub-processors. Combined with the DWP's ongoing review of fiduciary duties, which the SPP says should encompass AI as a systemic risk alongside climate, the governance perimeter around institutional AI deployment is contracting steadily.

The SPP's conclusion is direct: "The question is no longer whether trustees should engage with AI, but whether they are governing its use with the same discipline, challenge and oversight that they apply to any other material source of risk and opportunity." For the broader market, the pensions sector's structured adoption of AI governance frameworks may prove an early template for how regulated fiduciaries across financial services formalise accountability in an era of agentic AI.