Ok
logo_outline-1
shutterstock_2731456311
CheckCircle

Author: Priscilla Gaudoin, Head of Risk & Compliance, published August 2026

CheckCircle

Topics: Accountability, AI, Governance, Third Party Risk Management

CheckCircle

Regions and Regulators: UK - FCA, Europe - ESMA, APAC - ASIC, MAS, Global - IOSCO

ICA_R_BAD_CPD_19769

Time to read: 4 minutes


TL:DR:
The Mills Review is a clear regulatory warning shot: the FCA expects AI, including autonomous agentic AI, to become foundational to UK retail financial services by 2030.

Boards should treat this as a strategic risk priority now, strengthening AI governance, SM&CR accountability, Consumer Duty oversight, model risk controls and third-party resilience before the FCA decides whether to extend the regulatory perimeter later in 2026.

Executive summary


On 6 July 2026 the Financial Conduct Authority published the Mills Review.
This is the first regulator-led assessment, anywhere in the world, of how AI is likely to reshape retail financial services through to 2030. The review does not introduce new rules today. It does set out the FCA's expectation that AI, including autonomous ‘agentic AI’, will become an active participant in financial markets rather than a supporting tool, and it puts firms on notice that governance, accountability and resilience expectations will tighten as that happens.

What does this mean for the board? The regulatory perimeter is under active review from July to December 2026. Firms that can demonstrate mature AI governance, clear accountability under the SM&CR, and resilience against third-party AI dependency will be best placed as expectations firm up. This is now a board-level strategic priority.

Why the review matters

AI is already embedded across retail financial services: banks, insurers, investment platforms and fintechs use it for customer service, fraud detection, compliance automation and operational efficiency. The FCA's judgement is that the next phase will be qualitatively different. Rather than acting as an assistant, AI is expected to increasingly make decisions, interact directly with customers, compare and switch products, manage portfolios, and act autonomously on a consumer's behalf.  The review poses a key question to the industry and to the FCA:

Is the UK's regulatory framework ready for a financial system in which AI is an active participant rather than a supporting technology?

 

Four themes shaping the sector 

The review organises its findings into four interconnected themes. Together they form a useful lens for assessing your own firm's exposure.

Figure 1: the Mills Review's four interconnected themes

Figure 1: the Mills Review's four interconnected themes

1. AI will transform firms

Financial institutions are expected to automate increasingly complex, customer-facing activities, (customer servicing, complaints handling, financial guidance, underwriting, fraud detection, investment support), and internal decision-making. Adoption in customer-facing functions is expected to accelerate sharply over the next five years.

2. Consumer behaviour will change

The most striking finding is the anticipated rise of agentic AI. Instead of consumers searching for products themselves, AI agents may compare products, negotiate prices, recommend and switch accounts, optimise savings, arrange insurance, manage investments and execute transactions automatically. Consumer appetite for this is already significant, but many consumers do not realise that regulated-advice protections do not automatically extend to general AI tools.

3. Markets could be reshaped

Large technology and cloud providers supplying the AI models underpinning the sector may become disproportionately influential, creating concentration risk. If many firms depend on the same handful of providers, the sector could see correlated decision-making, systemic operational failures, reduced competition and new barriers to entry. These are issues that move beyond firm-level risk into financial stability.

4. Regulators must evolve

The FCA acknowledges that traditional supervisory approaches may not suffice for highly autonomous AI systems and is considering how it should adopt AI itself while strengthening its capability to supervise increasingly automated markets. For now, existing principles, Consumer Duty and operational resilience requirements, remain the starting point, but the FCA has signalled that further rule-making may follow as the technology matures.

Impact across the ecosystem

Although the review focuses on retail financial services, its implications extend across the financial ecosystem because AI adoption will not remain confined to individual firms or discrete use cases.

As AI becomes embedded in customer journeys, product design, pricing, servicing, fraud controls, investment support and third-party infrastructure, the effects will compound across banks, insurers, wealth managers, fintechs, technology providers and consumers. This creates opportunities for faster innovation, more personalised services, improved access and lower operating costs, but it also introduces a more interconnected risk landscape: decisions made by one model, provider or platform may affect multiple firms and customer groups at the same time. The practical impact is that AI governance can no longer be treated as a narrow technology control.  It needs to be understood as an ecosystem-wide resilience, conduct, competition and accountability issue.

Segment

Expected impact

Banks & Building Societies

AI-enabled customer journeys, personalised products and automated servicing.

Insurers

Underwriting, pricing, claims and fraud detection transformed with new scrutiny on transparency and fairness.

Wealth & Asset Managers

Increasingly AI-assisted investment recommendations and portfolio management, with greater governance and accountability scrutiny.

Fintechs

Innovation opportunity, paired with heightened expectations on governance, consumer protection and resilience.

Technology providers

Unprecedented regulatory focus on model developers and cloud providers, given their systemic influence even though they sit outside financial regulation.

Consumers

Gains: personalisation, lower costs, better access and inclusion.

Risks: misinformation, manipulation, fraud, overreliance and unclear regulatory protection.

At the same time, firms will face new risks, including misinformation, manipulation, fraud, overreliance on AI and uncertainty regarding regulatory protections. The key message for boards is that the benefits of AI will only be sustainable if firms can demonstrate that innovation is matched by clear accountability, robust oversight and effective safeguards across the wider ecosystem.

Key challenges and urgency

The review flags six strategic challenges that should be treated as connected board-level risks rather than isolated technical issues. Each challenge reflects a different way in which AI could alter the relationship between firms, consumers, infrastructure providers and regulators:

  • consumers may receive AI-enabled guidance without understanding the limits of protection
  • autonomous systems may make or influence decisions without clear human accountability
  • dependence on a small number of AI and cloud providers may create concentration and resilience risk 
  • the same technology that improves fraud detection may also enable more sophisticated cyber and financial crime threats.

The table below is our assessment of near-term (12–24 month) urgency, and is not an FCA classification.  It should assist firms in assessing their governance, investment and assurance activity.

Challenge

Summary

Urgency

Consumer protection

Consumers may rely on AI guidance without knowing whether regulated protections apply.

High

Governance & accountability

As AI becomes more autonomous, accountability for machine-made decisions must be clearly assigned.

High

Operational resilience

Heavy dependence on a small number of AI providers introduces systemic vulnerability.

Medium

Cybersecurity & fraud

AI enables both better fraud defence and more sophisticated attacks (deepfakes, synthetic identity, automated scams).

High

Competition

Dominant AI platforms may reduce competition and raise concentration.

Medium

Regulatory capability

Regulators themselves need the expertise and tooling to supervise AI-driven markets.

Medium

The overall implication is that firms should move from monitoring AI risk in principle to evidencing active ownership, controls, testing and escalation across each of these challenge areas.

The Roadmap

The review is deliberately forward-looking and there are no immediate rule changes.  We do have a defined timeline for the next regulatory decision point: 

Figure 2: key dates in the Mills Review process

The FCA launched the Mills Review in January 2026, issuing a Call for Input to industry, consumer groups and other stakeholders. The final review was then published in July 2026, setting out the FCA's strategic assessment. Between July and December 2026, the FCA will consider whether the regulatory perimeter should extend to AI services that influence consumer financial decisions but currently sit outside financial regulation.

By 2030, the FCA expects AI to be a defining and foundational feature of retail financial services, with autonomous systems playing a far greater role across consumer interactions, firm operations and market infrastructure.

Is the UK aligned with other regulators?

Every major regulator is currently in the same position as the UK.  Regulators are applying existing rules now, actively monitoring agentic AI, and treating third-party AI and cloud concentration as an emerging systemic risk.

The UK stands out in terms of ambition. The Mills Review is the most forward-looking document amongst its peers. Most supervisors are still issuing exam priorities and briefings rather than long-range strategic assessments.

Figure 3: comparable regulatory positions internationally, as of July 2026

European Union

ESMA expects firms using AI in investment services to meet existing MiFID II obligations (organisational controls, conduct of business, and the duty to act in clients' best interests) rather than imposing AI-specific rules while ESMA and national regulators continue monitoring for gaps. The EU AI Act currently classifies only a narrow set of financial use cases (credit scoring, life and health insurance pricing) as high-risk, leaving most AI-driven trading and advice under comparatively light-touch treatment. Separately, the European Systemic Risk Board has published analysis on AI and systemic risk that closely mirrors the Mills Review's concentration-risk theme.

United States

US banking regulators, such as the Federal Reserve, OCC and FDIC, issued revised model risk management guidance in April 2026 (SR 26-2) that explicitly places generative and agentic AI outside its formal scope, while stating that existing risk principles still apply. The SEC has taken the same position for investment firms: no dedicated AI rulebook, but active examination focus on AI representations, marketing claims and governance. Congressional pressure on the SEC over agentic trading tools in retail brokerage apps shows the same ‘AI acting autonomously for consumers’ concern the Mills Review raises, now playing out in a live product context.

Asia-Pacific

Singapore's Monetary Authority published an AI Risk Management Operationalisation Handbook under Project MindForge in March 2026, and India's Reserve Bank released a framework for responsible and ethical AI enablement in the financial sector.  Both are more operationally prescriptive than the FCA's current stance. Whereas Australia's ASIC has gone furthest in naming the specific risk: its 2026 key issues outlook explicitly lists consumer harm from agentic AI, citing its capacity to plan and act independently, as one of ten systemic risks facing the market.

Global standard-setters

IOSCO, the international body coordinating securities regulators, has made AI a named focus of its 2026 workplan.  It aims to build a shared supervisory toolkit and disclosure or governance guidance that individual regulators, including the FCA, can draw on. This suggests today's patchwork of national positions may converge over the next 18–24 months.

What this means for firms operating across borders

  • Expect convergence, not divergence, in the medium term.  IOSCO's coordinating role and shared concerns (concentration risk, agentic AI, governance) point toward common ground rather than a fragmented compliance burden.
  • The UK's forward posture is a competitive signal. Firms that get ahead on governance now are positioning for a market the FCA expects to arrive by 2030, not just meeting a UK-specific requirement.
  • US and EU firms should not read ‘no new rules yet’ as ‘no supervisory attention’ as examination and enforcement activity (SEC, FINRA) is already active even without new statutes.

What the board should do now

The review does not create any new obligations today, but the organisations should invest time in governance now to be better placed as expectations evolve. Our suggested priorities, roughly in order of urgency:

Workstream

Likely owner

Horizon

AI governance framework & policy

Board / Chief Risk Officer

Now

Accountability mapping under SM&CR

Senior Managers / HR

Now

Consumer Duty implications of AI use

Compliance

Now

Third-party AI dependency mapping

CTO / Procurement

2026

Model risk management

Risk

2026

Operational & cyber resilience

CISO / COO

2026

AI explainability standards

Data & Analytics

2026–27

Data governance

CDPO

2026–27

Future workforce capability

HR / L&D

2027+

Looking ahead

The Mills Review can viewed as a strategic roadmap. It signals that AI will become foundational to retail financial services within the decade, and that while the FCA has stopped short of new AI-specific rules today, the regulatory landscape will keep evolving as capability matures, in step with peer regulators internationally.

For boards, AI governance is a strategic priority spanning consumer protection, resilience, competition, risk management and regulatory compliance.  Organisations should embed governance, transparency and accountability early to capture the opportunity while continuing to manage their risk profile.

How Ruleguard can help


Ruleguard helps firms turn these board-level AI risks into an operational control framework by connecting regulatory obligations, policies, controls, monitoring activity and assurance evidence in one continuous compliance environment.

The platform supports ongoing oversight,  enabling firms to evidence how AI-related risks are owned, assessed, tested, escalated and reported. For firms responding to the Mills Review, this means clearer accountability, stronger audit trails, better visibility of third-party and operational dependencies, and more timely management information for boards and senior managers as regulatory expectations evolve.

Learn more about Ruleguard's Consumer Duty Solutions. 

Book a tailored discovery call 

Ready to turn GRC into a board-level advantage?
Book a tailored discovery call with Ruleguard to see how leading firms unify risk and compliance, surface the insights executives care about, and stay audit-ready, without the spreadsheet sprawl. 

Lets chat!-2

 

About the Author

In a career spanning 30 years, Priscilla has worked as a consultant, CCO and MLRO providing regulatory oversight and advice to firms across the financial services industry. She is responsible for our thought leadership programme, writing regular articles and white papers, and hosting webinars on a variety of regulatory matters.
 
She is a Fellow of the International Compliance Association, a certified GRC practitioner, and a member of the Institute of Risk Management.
 
Contact Priscilla
Priscilla Gaudoin