FCA — Nikhil Rathi speech “Rethinking regulation for the age of AI”

Tag: S-2026-06-24-fca-rathi-ai-speech Type: article (speech — drafted text) Author(s): Nikhil Rathi, Chief Executive, Financial Conduct Authority Date of source: 2026-06-24 Date ingested: 2026-06-25 Authority weight: high — primary FCA CEO speech setting the regulator’s stated supervisory direction on AI; note it is a signal of intent/posture, not binding rules (the FCA flags it is a drafted speech that may differ from delivery). Raw file: S-2026-06-24-fca-rathi-ai-speech.md. External URL: https://www.fca.org.uk/news/speeches/rethinking-regulation-age-ai

What it claims

On 24 June 2026, FCA Chief Executive Nikhil Rathi delivered “Rethinking regulation for the age of AI” at techUK’s Agents of Change: AI in UK Financial Services 2026. The speech argues that financial services must sit at the heart of the UK’s ambition to be a leading AI economy, and that the central question is not simply how to regulate AI but “how do we preserve trust, competition, and resilience when technology is moving markets dramatically faster than the frameworks governing them?” [S-2026-06-24-fca-rathi-ai-speech].

Main points:

  • Scale, not pilots. More than 80% of financial services firms are already adopting AI; the question is now scale. Two scaling opportunities stand out: agentic systems (which “don’t just support financial decisions, but coordinate and transact” across retail and wholesale markets) and tokenisation (the FCA, with the Bank of England, approved Baillie Gifford and BNY Mellon to launch the UK’s first natively tokenised authorised fund) [S-2026-06-24-fca-rathi-ai-speech].
  • Accountability and human oversight must remain clear. “Investors will be wary to delegate important decisions to systems they don’t understand. Accountability for regulated activities and outcomes must remain clear. Designed with the right human oversight, and in a way that gives consumers confidence to engage.” [S-2026-06-24-fca-rathi-ai-speech]
  • A different regulatory model. Legislation “will never keep up”; the FCA is rebalancing risk, leaning more on stewardship as well as supervision, and expects to use its competition objective and system-wide powers more frequently “as a regular part of [its] toolkit” (Enterprise Act; Digital Markets, Competition and Consumers Act). It cites Buy Now Pay Later as a case where it intervened before the activity formally entered the perimeter [S-2026-06-24-fca-rathi-ai-speech].
  • Agentic AI as supervisory “first responder”. The FCA is exploring agentic AI to speed how it monitors wholesale markets, “harnessing technology and our large data sets – a billion rows of data per day - alongside our supervisory judgement to tackle market abuse faster” [S-2026-06-24-fca-rathi-ai-speech].
  • Resilience and third-party concentration. Financial services are “increasingly reliant on cloud providers, model providers, data providers. Many parts of the AI stack.” Boards and leadership “must understand the risks. Dependencies - particularly on model providers and third parties - must be properly mapped and governed, and the Critical Third Parties regime becomes more important than ever.” 98% of operational incidents reported last year related to technology and cyber; frontier AI could magnify cyber risk for both defenders and attackers [S-2026-06-24-fca-rathi-ai-speech].
  • Fraud and cross-sector collaboration. UK Finance’s Annual Fraud Report cites ~£1.3bn lost to payment fraud last year, two-thirds of authorised fraud originating on social media / messaging platforms; tackling it needs collaboration across financial services, tech and telecoms (work with Ofcom on the Online Safety Act) [S-2026-06-24-fca-rathi-ai-speech].
  • FCA support tooling. Supercharged Sandbox (real-world data/compute, with Nvidia and soon Google), AI Lab (with a new Agentic Academy), and the AI Consortium with the Bank of England. Forthcoming: the Mills Review (“in a couple of weeks”) on how AI could reshape retail financial services, followed by a publication on good and poor AI practice later in the year [S-2026-06-24-fca-rathi-ai-speech].

Notable quotes

“Dependencies - particularly on model providers and third parties - must be properly mapped and governed, and the Critical Third Parties regime becomes more important than ever.” — Nikhil Rathi, 24 June 2026

“Accountability for regulated activities and outcomes must remain clear. Designed with the right human oversight, and in a way that gives consumers confidence to engage.” — Nikhil Rathi, 24 June 2026

“Technology is moving much faster than many regulatory paradigms. Legislation will never keep up. … A growing part of our role will be stewardship, as well as supervision.” — Nikhil Rathi, 24 June 2026

What’s speculative vs. asserted

  • Asserted (FCA position / fact): existing-framework reuse; the Critical Third Parties regime’s growing importance; accountability and human oversight requirements; the FCA’s own use of agentic AI in supervision; the approval of the first natively tokenised authorised fund; the 98%-of-incidents and ~£1.3bn-fraud figures (attributed, the latter to UK Finance).
  • Forward-looking / intent: greater use of competition and system-wide powers “as a regular part of [the] toolkit”; the Mills Review due “in a couple of weeks”; the good/poor-practice AI publication “later in the year”; exploration of agentic AI as supervisory first responder.
  • Caveat in source: the FCA states this is “a drafted speech and may differ from the delivered version”.

Topics this feeds

  • FCA approach to AI — strongest overlap: reinforces the no-separate-rulebook / existing-frameworks stance, previews the Mills Review and the good/poor-practice publication, and hardens expectations on accountability, human oversight and third-party governance.
  • Operational Resilience and Third Party Risk — model-provider / AI-stack dependency mapping and the Critical Third Parties regime; 98%-tech/cyber-incident figure.
  • FCA — primary regulator position.

Open questions raised

  • Will the forthcoming Mills Review and good/poor-practice publication convert these speech-level expectations (accountability, human oversight, third-party mapping) into concrete supervisory benchmarks or examples?
  • How will the FCA’s stated intent to use competition and system-wide powers “more frequently” interact with firms’ AI deployment and model-provider concentration in practice?
  • What will “properly mapped and governed” model-provider dependencies require as evidence under the Critical Third Parties regime as agentic AI scales?

Ingestion note

The FCA publications landing page surfaces policy statements and consultations only; the speech was located via WebSearch and then confirmed by direct WebFetch of the FCA speech page (HTML metadata: published/updated 2026-06-24). Full speech text retrieved; figures (80% adoption, 98% of incidents tech/cyber, ~£1.3bn fraud) are as stated by the FCA, with the fraud figure attributed to UK Finance’s Annual Fraud Report 2026. No PDF version was downloaded — the web speech text is the source of record.