The UK’s Financial Conduct Authority has spent much of 2026 arguing that existing rules can stretch to cover agentic AI in financial services, most recently in its Mills Review. This week it went a step further: instead of only writing guidance for firms to build AI on their own, the regulator brought a frontier AI lab inside its own sandbox to help build it with them. Anthropic is now supplying Claude, including Claude Code and Claude Cowork, to the second cohort of the FCA’s Supercharged Sandbox, a signal that UK regulators are moving from overseeing AI adoption to actively provisioning it.

A regulator that now ships compute, not just guidance

The Supercharged Sandbox is a cohort-based program that gives financial firms a secure cloud environment with GPU infrastructure, enterprise tooling, synthetic datasets, and expert mentorship to test AI applications. Cohort 2 launched on July 13, 2026 and runs through December 31, with a showcase demo day set for November 26. The FCA selected 21 organizations from 199 applications, a 51 percent jump in applications compared with the first cohort. Accepted firms span insurers, compliance vendors, and infrastructure providers, including Scottish Widows, TrueLayer, Money Advice Trust, Sardine AI, Condukt, Deepflow, and calQrisk.

Participation costs firms nothing, and the program is open to both FCA-regulated entities and unregulated technology vendors. Crucially, the FCA is explicit that taking part does not amount to regulatory approval or endorsement of any product built inside it. The sandbox builds on infrastructure support the FCA already had in place from NayaOne and NVIDIA; Anthropic’s involvement adds a foundation-model layer on top of that compute and tooling stack.

Advertisement

FinTech Your brand belongs here. Reach the decision-makers who read FinTech every day. Premium placements across the site and newsletter. Advertise with us

Why a model provider, not just a cloud vendor

Cohort 2 firms are testing use cases across five areas: safer agent-led payments and commerce, fraud and economic crime detection, AI governance and accountability, expanding access to financial services for vulnerable and underserved consumers, and streamlining compliance and business automation. That list overlaps directly with the open questions the FCA raised in its own Mills Review, which concluded existing rules could likely govern agentic AI in retail financial services but left open how firms would actually build and supervise agents safely in practice.

Handing participants direct access to Claude Code and Claude Cowork addresses that gap operationally rather than theoretically. Firms in the sandbox are not just discussing AI governance frameworks; they are building agents that make or recommend financial decisions, then testing them against the FCA’s own synthetic datasets and mentorship before those agents ever touch a live customer.

Part of a broader pattern in UK financial AI oversight

The FCA’s move follows a string of announcements in which frontier AI labs have attached themselves directly to financial infrastructure and its guardrails, rather than staying at arm’s length as general-purpose tool vendors. Anthropic has separately extended a partnership with FIS on financial security applications, and 1Password has built an agent-specific credential model with Anthropic aimed at preventing AI agents from holding standing access to sensitive systems. Card networks have moved in a parallel direction: Mastercard opened its own UK sandbox for testing agentic commerce earlier this month.

Taken together, these moves suggest UK financial regulation is settling into a model where oversight of agentic AI happens inside controlled, regulator-run environments before firms deploy publicly, rather than through after-the-fact enforcement once agents are already live. The trend is not confined to the UK. Asia’s Electronic Payments Association Alliance and HSBC have started a working group with a similar aim: writing the liability rules for AI agents that spend money before those agents are common in the market rather than after an incident forces the issue.

The five focus areas the FCA chose also reveal where regulators expect the first real friction. Agent-led payments and fraud detection sit at the top of the list because both involve an AI system making or influencing a financial transaction autonomously, the exact scenario existing consumer-protection rules were not written with in mind. By running that testing inside a sandbox with synthetic data rather than live customer accounts, the FCA gets visibility into failure modes before they reach the market, and participating firms get a defensible testing record if a supervisor later asks how a deployed agent was validated.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

What this means for the finance leader

For compliance and technology leaders at UK financial firms, the practical takeaway is that sandbox participation is becoming a credible way to de-risk an agentic AI pilot, not just a PR exercise. A product tested inside the Supercharged Sandbox carries evidentiary value with the regulator even though it confers no formal approval: firms can point to synthetic-data testing, FCA mentorship, and documented governance practices when they eventually seek permissions or respond to supervisory questions.

That said, the FCA’s own disclaimer matters. Sandbox participation is not a shortcut around authorization, and firms building agent-led payments or fraud tools still need to map their pilot against existing permissions regimes such as the Payment Services Regulations and Consumer Duty. The sandbox reduces technical and governance risk; it does not reduce regulatory risk.

How to evaluate whether a sandbox pilot is worth pursuing

Firms weighing whether to apply to a future cohort, or to partner with a firm that has, should look for three things: whether the use case sits in one of the FCA’s five priority areas, whether the vendor stack (model provider plus infrastructure partner) is disclosed rather than opaque, and whether the firm has a plan to translate sandbox learnings into a live authorization request rather than treating the sandbox as the finish line. The firms in Cohort 2 that convert testing into filed permissions by early 2027 will be the clearest evidence of whether this model actually shortens the path from AI pilot to regulated product.

Source: Financial Conduct Authority