Author: Priscilla Gaudoin, Head of Risk & Compliance, published August 2026
Topics: Accountability, AI, Governance, Third Party Risk Management
Regions and Regulators: UK - FCA, Europe - ESMA, APAC - ASIC, MAS, Global - IOSCO
Time to read: 4 minutes
TL:DR: The Mills Review is a clear regulatory warning shot: the FCA expects AI, including autonomous agentic AI, to become foundational to UK retail financial services by 2030.
- Executive Summary
- Why the Review Matters
- Four Themes Shaping The Sector
- Impact across the Ecosystem
- Key Challenges & Indicative Urgency
- The Roadmap
- Is the UK Aligned with other Regulators?
- What the Board should do Now
- Looking ahead
- How Ruleguard can help
- Contact Ruleguard
Executive summary
On 6 July 2026 the Financial Conduct Authority published the Mills Review. This is the first regulator-led assessment, anywhere in the world, of how AI is likely to reshape retail financial services through to 2030. The review does not introduce new rules today. It does set out the FCA's expectation that AI, including autonomous ‘agentic AI’, will become an active participant in financial markets rather than a supporting tool, and it puts firms on notice that governance, accountability and resilience expectations will tighten as that happens.
What does this mean for the board? The regulatory perimeter is under active review from July to December 2026. Firms that can demonstrate mature AI governance, clear accountability under the SM&CR, and resilience against third-party AI dependency will be best placed as expectations firm up. This is now a board-level strategic priority.
Why the review matters
AI is already embedded across retail financial services: banks, insurers, investment platforms and fintechs use it for customer service, fraud detection, compliance automation and operational efficiency. The FCA's judgement is that the next phase will be qualitatively different. Rather than acting as an assistant, AI is expected to increasingly make decisions, interact directly with customers, compare and switch products, manage portfolios, and act autonomously on a consumer's behalf. The review poses a key question to the industry and to the FCA:
Is the UK's regulatory framework ready for a financial system in which AI is an active participant rather than a supporting technology?
Four themes shaping the sector
The review organises its findings into four interconnected themes. Together they form a useful lens for assessing your own firm's exposure.

Figure 1: the Mills Review's four interconnected themes
1. AI will transform firms
Financial institutions are expected to automate increasingly complex, customer-facing activities, (customer servicing, complaints handling, financial guidance, underwriting, fraud detection, investment support), and internal decision-making. Adoption in customer-facing functions is expected to accelerate sharply over the next five years.
2. Consumer behaviour will change
The most striking finding is the anticipated rise of agentic AI. Instead of consumers searching for products themselves, AI agents may compare products, negotiate prices, recommend and switch accounts, optimise savings, arrange insurance, manage investments and execute transactions automatically. Consumer appetite for this is already significant, but many consumers do not realise that regulated-advice protections do not automatically extend to general AI tools.
3. Markets could be reshaped
Large technology and cloud providers supplying the AI models underpinning the sector may become disproportionately influential, creating concentration risk. If many firms depend on the same handful of providers, the sector could see correlated decision-making, systemic operational failures, reduced competition and new barriers to entry. These are issues that move beyond firm-level risk into financial stability.
4. Regulators must evolve
The FCA acknowledges that traditional supervisory approaches may not suffice for highly autonomous AI systems and is considering how it should adopt AI itself while strengthening its capability to supervise increasingly automated markets. For now, existing principles, Consumer Duty and operational resilience requirements, remain the starting point, but the FCA has signalled that further rule-making may follow as the technology matures.
Impact across the ecosystem
Although the review focuses on retail financial services, its implications extend across the financial ecosystem because AI adoption will not remain confined to individual firms or discrete use cases.
As AI becomes embedded in customer journeys, product design, pricing, servicing, fraud controls, investment support and third-party infrastructure, the effects will compound across banks, insurers, wealth managers, fintechs, technology providers and consumers. This creates opportunities for faster innovation, more personalised services, improved access and lower operating costs, but it also introduces a more interconnected risk landscape: decisions made by one model, provider or platform may affect multiple firms and customer groups at the same time. The practical impact is that AI governance can no longer be treated as a narrow technology control. It needs to be understood as an ecosystem-wide resilience, conduct, competition and accountability issue.
|
Segment |
Expected impact |
|
Banks & Building Societies |
AI-enabled customer journeys, personalised products and automated servicing. |
|
Insurers |
Underwriting, pricing, claims and fraud detection transformed with new scrutiny on transparency and fairness. |
|
Wealth & Asset Managers |
Increasingly AI-assisted investment recommendations and portfolio management, with greater governance and accountability scrutiny. |
|
Fintechs |
Innovation opportunity, paired with heightened expectations on governance, consumer protection and resilience. |
|
Technology providers |
Unprecedented regulatory focus on model developers and cloud providers, given their systemic influence even though they sit outside financial regulation. |
|
Consumers |
Gains: personalisation, lower costs, better access and inclusion. Risks: misinformation, manipulation, fraud, overreliance and unclear regulatory protection. |
At the same time, firms will face new risks, including misinformation, manipulation, fraud, overreliance on AI and uncertainty regarding regulatory protections. The key message for boards is that the benefits of AI will only be sustainable if firms can demonstrate that innovation is matched by clear accountability, robust oversight and effective safeguards across the wider ecosystem.
Key challenges and urgency
The review flags six strategic challenges that should be treated as connected board-level risks rather than isolated technical issues. Each challenge reflects a different way in which AI could alter the relationship between firms, consumers, infrastructure providers and regulators:
- consumers may receive AI-enabled guidance without understanding the limits of protection
- autonomous systems may make or influence decisions without clear human accountability
- dependence on a small number of AI and cloud providers may create concentration and resilience risk
- the same technology that improves fraud detection may also enable more sophisticated cyber and financial crime threats.
The table below is our assessment of near-term (12–24 month) urgency, and is not an FCA classification. It should assist firms in assessing their governance, investment and assurance activity.
|
Challenge |
Summary |
Urgency |
|
Consumer protection |
Consumers may rely on AI guidance without knowing whether regulated protections apply. |
High |
|
Governance & accountability |
As AI becomes more autonomous, accountability for machine-made decisions must be clearly assigned. |
High |
|
Operational resilience |
Heavy dependence on a small number of AI providers introduces systemic vulnerability. |
Medium |
|
Cybersecurity & fraud |
AI enables both better fraud defence and more sophisticated attacks (deepfakes, synthetic identity, automated scams). |
High |
|
Competition |
Dominant AI platforms may reduce competition and raise concentration. |
Medium |
|
Regulatory capability |
Regulators themselves need the expertise and tooling to supervise AI-driven markets. |
Medium |
The overall implication is that firms should move from monitoring AI risk in principle to evidencing active ownership, controls, testing and escalation across each of these challenge areas.
The Roadmap
The review is deliberately forward-looking and there are no immediate rule changes. We do have a defined timeline for the next regulatory decision point:

Figure 2: key dates in the Mills Review process
The FCA launched the Mills Review in January 2026, issuing a Call for Input to industry, consumer groups and other stakeholders. The final review was then published in July 2026, setting out the FCA's strategic assessment. Between July and December 2026, the FCA will consider whether the regulatory perimeter should extend to AI services that influence consumer financial decisions but currently sit outside financial regulation.
By 2030, the FCA expects AI to be a defining and foundational feature of retail financial services, with autonomous systems playing a far greater role across consumer interactions, firm operations and market infrastructure.
Is the UK aligned with other regulators?
Every major regulator is currently in the same position as the UK. Regulators are applying existing rules now, actively monitoring agentic AI, and treating third-party AI and cloud concentration as an emerging systemic risk.
The UK stands out in terms of ambition. The Mills Review is the most forward-looking document amongst its peers. Most supervisors are still issuing exam priorities and briefings rather than long-range strategic assessments.

Figure 3: comparable regulatory positions internationally, as of July 2026
European Union
ESMA expects firms using AI in investment services to meet existing MiFID II obligations (organisational controls, conduct of business, and the duty to act in clients' best interests) rather than imposing AI-specific rules while ESMA and national regulators continue monitoring for gaps. The EU AI Act currently classifies only a narrow set of financial use cases (credit scoring, life and health insurance pricing) as high-risk, leaving most AI-driven trading and advice under comparatively light-touch treatment. Separately, the European Systemic Risk Board has published analysis on AI and systemic risk that closely mirrors the Mills Review's concentration-risk theme.
United States
US banking regulators, such as the Federal Reserve, OCC and FDIC, issued revised model risk management guidance in April 2026 (SR 26-2) that explicitly places generative and agentic AI outside its formal scope, while stating that existing risk principles still apply. The SEC has taken the same position for investment firms: no dedicated AI rulebook, but active examination focus on AI representations, marketing claims and governance. Congressional pressure on the SEC over agentic trading tools in retail brokerage apps shows the same ‘AI acting autonomously for consumers’ concern the Mills Review raises, now playing out in a live product context.
Asia-Pacific
Singapore's Monetary Authority published an AI Risk Management Operationalisation Handbook under Project MindForge in March 2026, and India's Reserve Bank released a framework for responsible and ethical AI enablement in the financial sector. Both are more operationally prescriptive than the FCA's current stance. Whereas Australia's ASIC has gone furthest in naming the specific risk: its 2026 key issues outlook explicitly lists consumer harm from agentic AI, citing its capacity to plan and act independently, as one of ten systemic risks facing the market.
Global standard-setters
IOSCO, the international body coordinating securities regulators, has made AI a named focus of its 2026 workplan. It aims to build a shared supervisory toolkit and disclosure or governance guidance that individual regulators, including the FCA, can draw on. This suggests today's patchwork of national positions may converge over the next 18–24 months.
What this means for firms operating across borders
- Expect convergence, not divergence, in the medium term. IOSCO's coordinating role and shared concerns (concentration risk, agentic AI, governance) point toward common ground rather than a fragmented compliance burden.
- The UK's forward posture is a competitive signal. Firms that get ahead on governance now are positioning for a market the FCA expects to arrive by 2030, not just meeting a UK-specific requirement.
- US and EU firms should not read ‘no new rules yet’ as ‘no supervisory attention’ as examination and enforcement activity (SEC, FINRA) is already active even without new statutes.
What the board should do now
The review does not create any new obligations today, but the organisations should invest time in governance now to be better placed as expectations evolve. Our suggested priorities, roughly in order of urgency:
|
Workstream |
Likely owner |
Horizon |
|
AI governance framework & policy |
Board / Chief Risk Officer |
Now |
|
Accountability mapping under SM&CR |
Senior Managers / HR |
Now |
|
Consumer Duty implications of AI use |
Compliance |
Now |
|
Third-party AI dependency mapping |
CTO / Procurement |
2026 |
|
Model risk management |
Risk |
2026 |
|
Operational & cyber resilience |
CISO / COO |
2026 |
|
AI explainability standards |
Data & Analytics |
2026–27 |
|
Data governance |
CDPO |
2026–27 |
|
Future workforce capability |
HR / L&D |
2027+ |
Looking ahead
The Mills Review can viewed as a strategic roadmap. It signals that AI will become foundational to retail financial services within the decade, and that while the FCA has stopped short of new AI-specific rules today, the regulatory landscape will keep evolving as capability matures, in step with peer regulators internationally.
For boards, AI governance is a strategic priority spanning consumer protection, resilience, competition, risk management and regulatory compliance. Organisations should embed governance, transparency and accountability early to capture the opportunity while continuing to manage their risk profile.
How Ruleguard can help
Ruleguard helps firms turn these board-level AI risks into an operational control framework by connecting regulatory obligations, policies, controls, monitoring activity and assurance evidence in one continuous compliance environment.
The platform supports ongoing oversight, enabling firms to evidence how AI-related risks are owned, assessed, tested, escalated and reported. For firms responding to the Mills Review, this means clearer accountability, stronger audit trails, better visibility of third-party and operational dependencies, and more timely management information for boards and senior managers as regulatory expectations evolve.
Learn more about Ruleguard's Consumer Duty Solutions.
Book a tailored discovery call
Ready to turn GRC into a board-level advantage?
Book a tailored discovery call with Ruleguard to see how leading firms unify risk and compliance, surface the insights executives care about, and stay audit-ready, without the spreadsheet sprawl.

About the Author
