The FCA does not currently operate a separate AI rulebook for financial services. Its stated approach is principles based and outcomes focused, relying on existing regulatory frameworks rather than introducing additional FCA regulations simply because a firm uses artificial intelligence.
That does not mean AI is unregulated. Consumer Duty, SMCR and wider accountability, systems and controls, data protection, financial crime, operational resilience and product-specific conduct rules can all become relevant depending on what the AI system does. The compliance task is therefore to map each use case to the regulated decision or customer outcome it can affect.
The July 2026 Mills Review is important strategic context because it considers how AI, including more autonomous systems, could reshape retail financial services by 2030. It is not itself a Handbook rule. Firms should use it to understand the direction of risk and supervision while continuing to apply the rules that are in force today.
Start with the regulated outcome, not the technology label
An AI chatbot answering general service questions presents a different regulatory risk from a system influencing investment recommendations, credit decisions, fraud alerts or complaint outcomes. The governance framework should therefore classify use cases by the business decision they affect, customer population, degree of autonomy and potential harm.
Terms such as generative AI, machine learning or agentic AI are useful technically but do not determine the FCA rule. The firm should ask which regulated obligation would apply if a human performed the same function and then identify what changes because software now performs or assists it.
This approach prevents two common errors: creating a large generic AI policy detached from business controls, or assuming a familiar technology tool is low risk because it is not marketed internally as 'AI'.
An AI inventory is a practical control even though the FCA does not prescribe one universal template
A firm cannot govern AI it does not know it uses. A controlled inventory is therefore a practical way to record material use cases, although firms should not describe one particular inventory format as an FCA-prescribed requirement unless a specific rule says so.
Useful fields can include business owner, purpose, customer impact, model or provider, data used, regulated activity affected, human oversight, material third-party dependency, validation status and monitoring. The level of detail should be proportionate to the use case.
Procurement and technology change should feed the inventory. Otherwise centrally approved systems may be governed while employees use embedded AI features in ordinary software without anyone assessing whether confidential data, regulated communications or customer decisions are affected.
Senior accountability should follow existing governance and SMCR
The FCA's AI approach expressly highlights accountability and governance and points firms to SMCR. Senior accountability should therefore be aligned with existing responsibilities rather than create an artificial new 'AI owner' whose role conflicts with product, technology, risk or compliance responsibilities.
A Senior Manager responsible for a customer proposition should understand how material AI use changes the risks within that proposition. Technology leadership should understand model and security risk, while compliance should provide regulatory interpretation and independent challenge appropriate to the firm's framework.
The governing body should receive enough information to understand significant AI exposures, failures and customer outcomes. It does not need model-level detail for every internal productivity tool, but it should not discover a material automated decision system only after an incident or FCA question.
Consumer Duty applies to AI-driven customer journeys
Where the Consumer Duty applies, firms remain responsible for good retail customer outcomes when AI is used to design, distribute or support products and services. Automation does not transfer that responsibility to the model provider.
A generative assistant can create consumer-understanding risk if it gives inconsistent or overly confident explanations. A recommendation or personalisation engine can affect whether a customer reaches an appropriate product. Automated support can create barriers where a vulnerable customer cannot reach a human or where the model repeatedly misunderstands the issue.
Firms should test the actual journey. Output accuracy, customer comprehension, escalation rates, complaints, abandonment and differential outcomes can all provide evidence. The relevant question is not only whether the model performs well technically, but whether the customer experience remains consistent with the firm's regulatory obligations.
Data and model controls should match the consequence of error
AI governance should identify the data used to train, configure or operate a system and the consequences of incorrect, incomplete or biased outputs. The control depth should increase where the system influences a regulated decision, handles sensitive information or operates at large scale.
Validation can include accuracy testing, benchmark scenarios, bias or outcome analysis where relevant, prompt and configuration controls, security testing and review of failure modes. A model that drafts internal meeting notes does not need the same assurance as one that materially affects a customer's financial outcome.
The firm should also distinguish deterministic business rules from probabilistic model behaviour. Traditional control testing may assume identical inputs produce identical results, while generative systems can require scenario-based monitoring and tolerances for variation.
Human oversight must be meaningful rather than ceremonial
The FCA's own description of its AI use emphasises that people remain integral for judgement while AI supports fact extraction and analysis. Firms should similarly define when human review is needed and what the reviewer is expected to challenge.
A nominal human-in-the-loop control is weak where staff approve outputs automatically because volumes are too high or the interface discourages challenge. The reviewer needs sufficient information, competence and authority to identify when the system is wrong and to override it.
The correct model varies by risk. Low-impact automation can operate with monitoring and exception handling, while higher-impact decisions may justify pre-decision human review, second-line sampling or other safeguards. The firm should document why its oversight design is proportionate.
Third-party AI providers need governance beyond procurement due diligence
Many firms consume AI through cloud services, software vendors and external model providers. The regulated firm remains responsible for the obligations affected by those services even where it cannot inspect the provider's source code or training data.
Due diligence should therefore focus on information the firm needs to control its own risk: service description, data handling, security, change process, material limitations, incident notification, subcontracting, resilience, audit or assurance rights and the ability to exit or switch where appropriate.
Model updates create a particular challenge. A vendor can change behaviour centrally without the regulated firm's own software release. Contracts and monitoring should therefore identify changes that require reassessment rather than assuming the system remains equivalent because the product name has not changed.
Monitoring should focus on drift, incidents and customer outcomes
AI controls should continue after approval. The system can drift because the provider updates the model, customer behaviour changes, input data changes or staff begin using the tool for purposes beyond the approved use case.
Monitoring can include output sampling, incident rates, complaints, override patterns, customer outcome measures, security events and changes in usage. Thresholds should trigger investigation and, where necessary, restriction or suspension of the system.
The firm should also define what counts as an AI incident within its internal process. A hallucinated answer that is caught before use is different from repeated inaccurate advice sent to customers, but both can provide useful control information. Serious operational or customer-impact events may also engage ordinary FCA notification rules.
The Mills Review is direction of travel, not current legal text
The Mills Review published in July 2026 considers a future in which AI may recommend actions, initiate transactions and execute decisions within agreed parameters. It identifies benefits alongside risks including fraud, cyber threats, consumer harm and changing market power.
The review makes recommendations to the FCA Board. Firms should not convert those recommendations into invented present-day rules. Instead, they can use the review as a strategic stress test: would today's governance remain effective if the firm's AI moved from assistance to delegated action?
This is especially useful for product roadmaps. A use case that is low-autonomy today may become more capable through vendor updates, so governance should be able to reassess it before expanded autonomy reaches customers.
What a proportionate FCA AI governance framework should demonstrate
A well-designed framework should allow management to answer which material AI systems are in use, who owns them, which regulatory obligations they affect, what data and third parties they rely on, how they were tested, where human judgement sits, what monitoring is performed and what happens when the system fails.
Those controls can be integrated into existing product governance, change management, third-party risk, Consumer Duty and operational-resilience frameworks rather than built as a parallel compliance universe.
The objective is evidence that the firm remains accountable for the outcome. The FCA's principles-based approach gives firms flexibility in how to achieve that, but flexibility increases the importance of being able to explain why the chosen control model is appropriate.
How Regulatory Counsel can support
Regulatory Counsel supports FCA-regulated firms with the regulatory, governance and remediation issues covered in this article. We can review the existing framework, identify gaps and support practical implementation or independent assurance.
Speak to Regulatory Counsel to discuss this area.
Frequently Asked Questions
No. The FCA states that it does not plan to introduce extra regulations for AI and will rely on existing frameworks, while keeping its approach under review.
Yes where the underlying retail activity is within scope. Using AI does not remove the firm's obligations to deliver good customer outcomes.
The FCA does not prescribe one universal AI-register template. An inventory is a practical governance control that can help firms identify and manage material AI use cases.
No. The July 2026 Mills Review is a strategic review and makes recommendations to the FCA Board. It should not be presented as current Handbook rules.
Yes. We can map AI use cases to FCA obligations, assess accountability, Consumer Duty, third-party controls, monitoring, documentation and governance.