Breaking
Loading headlines…
AI Business Dispatch.

Seven Recommendations, Zero New Rules: The FCA's AI Gamble on Principles Over Prescription

Britain's financial regulator handed down its most consequential AI review of the decade in July, then politely declined to regulate anything. The question is whether that bet pays off before an agentic AI blows up a retail portfolio.

V
Victoria Ashworth · Today · 5 min read
Share:·X·LinkedIn
Seven Recommendations, Zero New Rules: The FCA's AI Gamble on Principles Over Prescription
Victoria Ashworth

75%

That's the AI adoption rate among large UK financial services firms surveyed by the FCA and Bank of England. Not 75% piloting. Not 75% experimenting in a sandbox. Deployed. And yet the regulatory response, assembled across two landmark documents published within eight days of each other, amounts to: keep doing what you're doing, but think harder about it.

The pair in question: the FCA's Mills Review, published 6 July 2026, and HM Treasury's Financial Services AI Adoption Plan, published 14 July. Both are substantial. Both are consequential. Neither creates a single binding rule.

The Mills Review: Mapping the Terrain to 2030

The Mills Review was commissioned by the FCA Board and led by outgoing Executive Director Sheldon Mills. Its mandate was sweeping: assess how AI could reshape retail financial services for consumers, firms, markets and regulators by 2030 and beyond. The review covered four systemic themes: firms' core operations, consumer journeys, market competition, and fraud and cyber risk.

What it found, via a Yonder Consulting survey of more than 5,000 UK retail financial services consumers conducted in April, is that consumers are already using AI for financial guidance but are deeply uneasy about it. Trust and control are the friction points. That is not a regulatory gap. That is a market signal.

The review concludes with seven priority recommendations. Critically, it does not recommend AI-specific regulation, nor does it propose wholesale reform of the existing UK regulatory framework. The FCA's existing toolkit: Consumer Duty, the Senior Managers and Certification Regime, operational resilience rules. All repurposed for the AI age. No new architecture. Think of it as rewiring a Victorian townhouse rather than building a smart home.

Let's Do the Maths on Accountability

Here is the accountability problem, stated plainly. An AI agent operating autonomously inside a retail financial services firm makes a bad decision. A consumer is harmed. Under SM&CR, a named senior manager is responsible. But for what, exactly? Deploying the system? Not reading its outputs? Trusting a vendor whose model drifted?

Stakeholders have been raising this question for months. The Treasury Select Committee's January 2026 report urged the FCA to publish practical guidance on accountability and the level of assurance expected from senior managers for AI-caused harm, by the end of 2026. That deadline is four months away.

Andrew Bailey, in his speech at the Financial and Professional Services Dinner on 14 July, identified the core tension: how do you allocate liability when an AI agent with no legal persona acts on behalf of a principal? It is less a question of law than of philosophy. Markets cannot wait for philosophers.

RSM UK senior analyst Erin Sims put it directly: the real test lies in how existing frameworks apply as firms move towards more autonomous, AI-enabled decision-making. Consumer Duty, operational resilience and the regulatory perimeter are the areas most likely to come under strain.

The AI Adoption Plan: Government Bets on Industry Self-Organisation

HM Treasury's Adoption Plan, prepared by independent AI Champions Harriet Rees (Group CIO, Starling Bank) and Dr Rohit Dhawan (Head of AI and Advanced Analytics, Lloyds Banking Group), makes ten recommendations across five areas: regulatory framework, the regulatory perimeter, resilience, skills, and agentic payments readiness. The government accepted all of them.

A notable feature is how far the plan leans on industry to develop solutions ahead of formal regulatory intervention. Translation: the government is watching the private sector run the experiment, then plans to legislate around the results. That is either pragmatic or reckless, depending on which direction the experiment fails.

One concrete move: from 13 July 2026, four major cloud and technology providers were designated as Critical Third Parties under the CTP regime. The Adoption Plan calls for accelerating assessment of key AI and cloud providers under the same framework. Given that the entire UK retail financial services sector increasingly runs on a handful of shared model providers, this is overdue. Systemic concentration is not a hypothetical.

Mastercard's choice of the UK as the first European launch site for its agentic payment tools, announced during the Mansion House speech, is either a validation of the regulatory environment or a test of its resilience. Probably both.

Brand Confidence Is Already Showing the Strain

The trademark data tells its own story. AIBD analysis of Intellectual Property Office data shows UK Class 36 trademark filings, which cover financial, insurance and real estate services, fell to 1,647 in Q3 2026, a 31% drop against the prior period. Class 36 is the class where fintech brands stake their commercial territory. When that filing volume drops by nearly a third, fewer new financial services brands are putting their flag in the ground.

It could reflect consolidation. It could reflect capital discipline. Given that Q1 2026 saw UK software and AI company formations surge 86% according to Beauhurst's New Startup Index, the divergence is striking: AI-adjacent companies are forming at record rates, but fewer are rushing to protect a financial services brand identity. Possibly because the regulatory environment makes the commercial opportunity feel fuzzy. Possibly because agentic AI is about to make brand in financial services irrelevant. Either reading is bearish for the incumbent fintech brand economy.

The September 1 Wrinkle

While everyone was focused on AI policy in July, a quieter regulatory switch flipped on 1 September 2026. New FCA rules and guidance on non-financial misconduct came into force, making it materially clearer when workplace behaviour can amount to a regulatory breach under COCON and SM&CR. This is not an AI rule. But it directly intersects with AI governance: the culture of a firm is now more explicitly a supervisory concern. Firms deploying AI without solid governance cultures face a compounding risk surface.

The Bubble Comparison No One Wants to Make

In 1999, telecoms companies were valued on the number of fibre miles laid, not on traffic or revenue. In 2006, structured credit vehicles were valued on the model, not the underlying collateral. In 2026, UK financial services AI deployments are being assessed primarily on adoption rates, not on governance quality or liability clarity.

The FCA has deliberately chosen a principles-based, technology-neutral approach. That approach worked adequately for algorithmic trading. It did not scale well when algo-trading contributed to the 2010 Flash Crash. Agentic AI, operating across interconnected consumer portfolios, runs at a different speed and a different scale.

The Mills Review itself flags that AI could introduce systemic risk extending beyond the scope of firm-level resilience frameworks. Read that sentence twice. The regulator is naming a systemic risk it cannot yet measure and then declining to add new rules to address it.

Buffett's line about only finding out who's swimming naked when the tide goes out applies here with unusual precision. The tide is the next AI-driven market disruption. The swimwear is the accountability framework the FCA still owes firms by December.

The Call

By Q1 2027, the FCA will publish its practical guidance on SM&CR accountability for AI-caused harm, under pressure from both the Treasury Select Committee deadline and the political cost of being caught flat-footed. That guidance, not the Mills Review itself, will be the actual regulatory event that moves compliance budgets. Firms waiting on it before deploying autonomous AI agents in consumer-facing roles are making the correct risk-adjusted call. Firms already deployed are running a regulatory clock.

ai-regulationfcamills-reviewfinancial-servicesai-adoptionhm-treasurysm-crconsumer-dutytrademarknice-class-36agentic-aiuk-fintech