Britain’s financial regulator has decided the biggest technology shift in a generation does not need a new rulebook. The Financial Conduct Authority published the Mills Review on July 6, 2026, its long-term assessment of how artificial intelligence will reshape retail financial services through 2030 and beyond, and its central conclusion is that the FCA’s existing, principles-based framework is built to flex around AI rather than be rewritten for it. For an industry that has spent two years guessing whether a UK AI Act was coming, that is the headline decision, not the technology survey around it.

What the review actually found

The review, led by the FCA’s Sheldon Mills, draws on an engagement period that closed on February 24, 2026, gathering input from financial firms, consumer groups, trade associations, technology providers, academics and policymakers. It documents how far adoption has already run: millions of UK consumers are using generative AI for everyday financial management, and more than 75% of UK financial firms have deployed some form of AI system. The review treats that as the baseline, not the ceiling, and organizes its analysis around four themes: how the technology itself will keep evolving toward autonomous, multimodal and agentic systems; how it will reshape market structure and competition; how consumer behavior and vulnerability will shift as people delegate financial decisions to AI; and whether the regulatory framework itself is ready.

The upside the FCA is trying to protect

The document is not a risk memo dressed up as a review. It credits AI with enabling sharper personalization and customer understanding, lower friction in switching and automated financial management, reduced operational costs that can be passed to consumers, and a potential dent in financial literacy gaps. It frames UK competitiveness in global financial services as a live stake, not an afterthought: a regulator that strangles adoption exports the innovation, and the customers, elsewhere.

Advertisement

FinTech Your brand belongs here. Reach the decision-makers who read FinTech every day. Premium placements across the site and newsletter. Advertise with us

The risks it puts in writing

The review is specific about where it thinks the damage shows up first. On consumer protection, it flags algorithmic bias and discrimination, decision-making that becomes opaque once multiple AI systems interact, a decline in consumer agency and understanding as delegation increases, and exposure to AI-generated misinformation and hallucinated outputs presented as financial guidance. On financial crime, it names sophisticated AI-enabled fraud that exploits synthetic identities, deepfake-driven identity abuse, autonomous criminal ecosystems and model manipulation as cyber-enabled threats. On market structure, it warns of concentration among a handful of dominant AI platform providers, “winner-takes-most” dynamics driven by data feedback loops and network effects, value migrating to AI system controllers that sit outside the regulatory perimeter altogether, and a paradox where personalization narrows real consumer choice even as it appears to expand it.

No new AI law, but not a hands-off approach either

The FCA’s answer to all of that is not a bespoke AI statute. It confirmed it will not introduce prescriptive AI-specific regulation, choosing instead to stretch four existing levers around the technology: Consumer Duty, adapted to AI-mediated advice and product relationships; the Senior Managers and Certification Regime, to fix accountability for AI deployment decisions inside firms; Operational Resilience rules, extended to cover interconnected AI system failures; and the Critical Third Parties regime, aimed squarely at firms’ growing dependence on hyperscalers and foundation-model providers.

That is a bet that outcomes-based supervision ages better than a technology-specific statute, but the review pairs it with two concrete delivery mechanisms. The Supercharged Sandbox, built with NVIDIA, gives firms a controlled environment to test AI systems before they touch real customers. AI Live Testing extends that into live market conditions, with the FCA recently opening a second cohort. Behind both sits a promise to turn the regulator’s own supervision more preventative: more in-house AI capability for detecting risk before it compounds, deeper data-enabled supervision, a shift from ex-post enforcement toward ex-ante intervention, and closer coordination with the Competition and Markets Authority, the Information Commissioner’s Office and the Digital Regulation Cooperation Forum, plus international counterparts.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

What the Mills Review means for the finance leader

For a bank, lender, payments firm or platform operating in the UK, the practical read is that AI governance obligations are arriving through channels compliance teams already know, not through a parallel AI compliance regime. That is easier to plan for, but it raises the bar on documentation: firms now need to show, under SM&CR, exactly who is accountable for an AI system’s outputs, and under Consumer Duty, that an AI-mediated product or recommendation still delivers good outcomes when nobody can fully explain how the model reached its answer. The Critical Third Parties signal deserves particular attention from any firm whose core AI infrastructure sits with a single cloud or model provider: that dependency is now explicitly a supervisory concern, not just a vendor-risk exercise buried in procurement. This runs in parallel to the Financial Stability Board’s own move from AI monitoring to prescribing 12 sound practices for banks, which suggests supervisors on both sides of the Atlantic and beyond are converging on the same playbook: use existing accountability structures, harden them for AI, and reserve new rulemaking for cases existing rules genuinely cannot reach.

The review is candid that adoption may not move as fast as the technology itself. It notes that “change may prove more incremental” than the pace of AI development implies, because “human behaviour and institutional inertia can slow adoption” even where the tools are ready. That is not a reason for finance leaders to relax the timeline on governance work; it is a reason to use the slower runway to get the accountability mapping, third-party dependency reviews and Consumer Duty evidence in order before agentic systems, the review’s own first theme, become the norm rather than the pilot.

What to do next

Firms should treat the Mills Review as confirmation that AI oversight sits inside the tools they already report against, and start now on three things: map SM&CR accountability for every live AI system to a named senior manager, stress-test Consumer Duty evidence for AI-mediated decisions the way audit already stress-tests pricing, and inventory single-vendor AI dependencies before the Critical Third Parties regime forces that inventory into a formal filing. The firms that treat this as a paperwork update will be the ones the FCA’s ex-ante supervision finds first.

Source: Financial Conduct Authority