1 September 2026
Share Print

Pensions Regulator AI plan

To The Point
(2 min read)

The Pensions Regulator (TPR) has published an AI plan which clarifies its expectations of trustees and administrators in relation to AI.  Pension scheme trustees are legally accountable for scheme decisions and outcomes even when they delegate tasks to administrators, so they need to understand where and how AI is being used on behalf of the scheme.  We look at the Regulator's expectations of trustees in relation to AI use.

The Pensions Regulator (TPR) has published an AI plan which clarifies its expectations of trustees and administrators in relation to AI and outlines TPR’s role and approach to supporting the use of AI in pensions.

TPR refers to the Society of Pensions Professionals’ 2026 AI Survey which indicates universal use of AI within the pensions industry and plans for increased integration into core services.  Schemes are using AI to provide personalised support for members, for example answering questions about retirement options or modelling outcomes.  Schemes are using machine learning and data analytics to automate routine tasks and improve fraud detection.

TPR highlights risks from current AI use.  These include members using unregulated AI tools for pensions advice and fraudsters using AI to make their frauds more convincing, for example when conducting impersonation fraud.

TPR’s approach to AI

TPR describes its approach to AI as being outcome-focused and “technology agnostic”.  Its position is that AI adoption must be safe and in the interests of members.

TPR’s expectations of trustees and scheme administrators

TPR flags that trustees remain legally accountable for scheme decisions and outcomes even when they delegate tasks to scheme administrators or advisers.  Trustees therefore need to understand where and how AI is being used by or on behalf of the scheme.

TPR expects trustees to:

  • establish clear governance and accountability for the use of AI systems and technologies;
  • assure themselves that their administrators, service providers and advisers have similarly robust governance arrangements in place;
  • carry out rigorous testing, assurance and ongoing monitoring, both at the point of implementation and on a regular basis afterwards;
  • identify and evaluate risks, make sure appropriate controls are in place, review these regularly and adapt as necessary;
  • work to prevent their members being scammed by being aware of AI-driven fraud methods and responding effectively to the evolving fraud threat.

TPR also recommends that trustees and administrators:

  • invest appropriate time and resources to understand AI technologies including their limitations and risks;
  • are transparent with scheme members and stakeholders about AI use;
  • stay informed on UK government guidance, emerging standards and cross-industry best practice; and
  • share experiences, successes and concerns with others in industry and TPR.

In relation to data, TPR expects trustees to:

  • have a clear data strategy, allocate resources for improvements, and challenge service providers where standards are not met;
  • ensure scheme and member data is of high quality, as a critical input into AI-supported processes;
  • comply with data protection legislation and guidance, including as it relates to automated decision-making and use of information in AI systems;
  • understand how AI models use and process data and ensure there are robust controls in place in line with TPR’s cyber security guidance.

TPR says it expects trustees and administrators to seek “appropriate and proportional” professional advice when considering or implementing innovations.

TPR’s workplan includes publishing guidance for pension schemes this year on the responsible adoption of AI.  TPR also says that it will continue engaging with schemes on their data quality controls as they prepare for pensions dashboards.

Our thoughts

As TPR’s AI plan highlights, trustees have ultimate legal responsibility for how the scheme is operated, and that principle applies to any delegated functions regardless of whether they are performed by AI.  To ensure appropriate controls are in place, trustees need to understand how their administrators and other service providers are currently using AI.  As the adoption of AI has advanced so rapidly, trustees may be unaware of all the circumstances in which AI is being used in relation to their scheme.  Current contracts with service providers may make little or no reference to AI use.  Any review of such contracts should consider the need for more detailed clauses (eg a requirement to keep trustees informed about AI use in relation to the scheme).  

Trustees should take care to identify any automated decision-making, as specific requirements under UK GDPR apply to such decision-making, eg a scheme member may have the right to require an automated decision to be reviewed by human.  The SPP’s paper on “Governance in the Age of AI” is a useful guide for trustees, identifying key questions that trustees should be asking in relation to AI use.

To the Point


Subscribe to receive legal insights and industry updates directly into your inbox

Sign up now