Your guide to this week in regulation
TechnicalStay up to date with our latest round up of financial regulation.
By: Supriya Manchanda, Tim Reid
21 Jul 2026 7 min read

With greater adoption across the financial services sector, the conversation has swiftly moved from whether to adopt AI, to how to govern it effectively. The FCA recognises this and has published the Mills Review to assess how AI, particularly agentic AI, will reshape retail financial services by 2030. Boards need to review the findings and ensure their AI governance and oversight practices continue to align with the FCA’s evolving expectations.
The FCA doesn’t plan to introduce new regulations to manage the risks associated with AI. Instead, it expects boards to manage AI under existing frameworks such as the Senior Managers and Certification Regime (SM&CR), Consumer Duty, and SYSC, which will be adapted over time. As such, Boards need to consider how these frameworks apply to AI use across core operations such as customer service, credit decisioning, fraud detection, compliance monitoring and product design.
Crucially, responsibility can’t be delegated to algorithms, vendors or specialists. Boards remain accountable for explainability, risk management and effective challenge, even for complex or outsourced systems.
The Mills Review identified four ways that AI will reshape the market by 2030. Firms will transform their operations as AI takes on a broader range of tasks, with increasing degrees of autonomy. Consumer journeys will shift from human-led to agent-led, changing how people access and act on financial products. Market power and competition will evolve too, as AI capabilities becomes a differentiating factor between firms. Meanwhile, financial crime and cyber security threats and defence capabilities will accelerate. Boards need to keep pace with this transformation to ensure smooth adoption across the market, while ensuring good outcomes for consumers.
The Mills Review views AI adoption through an autonomy spectrum of five human roles, from operator to collaborator, to consultant, approver and observer. At the lower end, AI supports human judgement. At the higher end, AI systems act continuously within set parameters, with humans monitoring outcomes rather than making individual decisions.
From a governance perspective, this creates a significant challenge. Traditionally, Boards ask management to demonstrate risk management, evidence effective controls and show accountability. But as AI systems become more complex, autonomous and dependent on third-party model providers, management won’t find it as easy to show their workings and Boards may struggle to provide effective challenge.
Moving forward, Boards need a good understanding of where the firm’s AI use sits on the autonomy spectrum to ensure their AI governance and risk frameworks keep pace. This may require a degree of upskilling to understand the emerging risks from AI and to support effective challenge.
Boards will have different exposures, according to their individual business models and operating environment, but some key considerations are listed below.
As AI systems move from supporting human decisions towards preparing and executing them, firms must demonstrate how good outcomes are delivered, how controls operate and whether consumer understanding, fair value and suitability can still be shown. Boards need to ask management not just what AI is doing, but how the firm knows it is working as intended, and how it will know when it is not.
Deploying third-party AI models and infrastructure introduces risks that sit partly outside firms’ direct control, including model drift, data bias, hallucinations and emergent behaviours. The Mills Review notes that firms will increasingly require more dynamic approaches to model governance, monitoring and assurance, supported by end-to-end controls across the AI lifecycle. Boards need assurance that management has mapped these dependencies and that adequate controls exist across the full delivery chain.
Shared reliance on similar models and infrastructure could generate correlated behaviour and common points of failure across the financial system. AI is also amplifying fraud and cyber risks, making attacks faster, cheaper and more persuasive. Boards need to satisfy themselves that their firms’ defences are keeping pace, and that management is engaging with sector-wide intelligence-sharing and coordination mechanisms.
It could also be tricky to evidence reasonable steps under SM&CR. Boards must ensure that individual responsibilities for managing and overseeing these new risks are clear in their firms’ SM&CR documentation. Most, if not all, Senior Manager Function holders will inevitably have some AI oversight responsibilities going forward, which must be clearly set out in their statement of responsibilities.
Looking beyond risk management, Boards also need to maximise the value of AI to help the firm identify, and address, gaps in the market. For example, the Mills Review highlights the link between AI and Consumer Duty, noting that better use of data and personalisation could help address the information gaps that often lead to poor financial decisions. Better consumer outcomes aren't just a regulatory requirement; building customer satisfaction and loyalty are also good for business.
Similarly, Boards and senior managers who treat AI governance as a genuine priority will continue to align with the FCA’s thinking. This will build trust with the regulator and allow firms to use compliance as a competitive advantage. With no prescriptive rules in place, firms that view this work as a compliance exercise could risk management by crisis instead.
In time, these activities will present a stronger blueprint for what good AI implementation looks like. But in the meantime, AI adoption and capabilities are moving fast, leaving many firms’ oversight processes on the backfoot. Board members need to assess how these changes have affected their responsibilities, and how to pivot to an operating environment that’s more complex, more automated and more interconnected than current regulations were designed for. Drawing on the Mills Review's thinking, boards can take five key steps, as outlined below.
Boards should request regular reporting on AI performance, control effectiveness, model drift and outcomes testing. A report that confirms the use of AI is different from one that confirms it’s working safely and delivering good consumer outcomes. Every board pack should cover what could go wrong, how the board would know, and key activities to remedy it.
Board members don’t need a technical understanding of how AI models work, but they do need to know what AI the firm uses, what risks it carries, and the firm's appetite for those risks. Training should reflect each director's role and the firm's specific AI footprint. Without that grounding, boards can’t provide effective challenge.
Boards should understand where the firm sits across different AI use cases, and where each is heading. Higher autonomy use-cases warrant greater scrutiny, with AI governance frameworks adapted to match. Continuous update cycles call for more frequent review than traditional control testing allows.
Boards should understand their third-party AI dependencies and how they’re governed. This includes contingency planning for business and operational resilience if a provider changes, degrades or fails. Controls need to extend across the full AI supply chain and not stop at the firm's own systems.
AI can support all three lines, but it’ll requires stronger evidence of control in each. Boards need to challenge whether second-line risk and compliance functions have the capability to monitor AI-driven activity effectively, and whether internal audit has adapted its methodology to cover AI governance.
For further information on the Mills Review or AI governance, contact Supriya Manchanda or Tim Reid.
Stay up to date with our latest round up of financial regulation.
The FCA has reformed CASS 6 and 7 to ease the regulatory burden and align with Consumer Duty. Here's what's changed and what CASS firms should do next.
The FCA's PSM&A regime offers greater consumer protection for SIPP operators using unauthorised trustees. We look at the key features and similarities to CASS.