TL;DR
Every respondent to a Society of Pension Professionals survey reported using AI, up from 87% a year earlier. The Pensions Regulator has published an initial AI plan covering governance, transparency, cyber security and member protection. The harder problem is that much of the adoption sits inside suppliers’ systems rather than schemes’ own.
Universal adoption, partial visibility
Going from 87% to complete coverage in a year is less interesting than where the technology actually entered. Comparatively little of it arrived as a scheme deciding to build something. It came bundled — inside administration platforms, consultancy workflows and the systems that generate member communications.
That is the governance problem in one line. A trustee board can hold a policy on AI it commissions directly and still have no view of what its administrator has switched on. Chris Eastwood, chief executive of the provider Penfold, put the obligation where it lands: “Outsourcing the use of AI does not remove an organisation’s responsibility for appropriate governance and oversight.”
What the regulator expects
The Pensions Regulator’s plan sets initial expectations rather than binding rules — appropriate governance, transparency over use, cyber security, and safeguards for members. Penfold’s suggested starting point is more concrete, and reads as a due diligence sequence: find every place AI touches the scheme, including at suppliers; name who is accountable for approving and challenging it; establish what member data those systems can reach, process or keep; ask administrators and technology vendors to evidence their own testing and controls; work out which AI-produced outputs could materially affect a member and require human review there; then monitor use consistently rather than once.
The risks cut both ways. Eastwood notes AI strengthens fraud detection while also enabling impersonation, alongside the possibility of member data being used in ways nobody sanctioned.
Looking forward
UK financial services keeps arriving at the same conclusion from different directions. Advisers told researchers this month they welcome AI for administration but draw the line at client money. Banking coverage has shown how a single mistranscribed word can propagate through downstream systems for years. Insurers have been warned they may already be covering AI risk without having priced it.
Pensions add a distinctive wrinkle: the time lag. A flawed communication or a mis-processed instruction may not surface as harm for a decade or more, by which point the supplier, the platform and the trustees have all changed. That makes the supplier audit the load-bearing item on the list, not the accountability framework — and it is the one requiring cooperation from firms with no obligation to give it. Schemes still shopping for administrators have leverage now that they will not have later.