FCA approach to AI
Created: 2026-05-17 Updated: 2026-09-18 Source count: 18
Updated 2026-09-18 based on S-2026-09-18-weekly-briefing (own weekly synthesis) — cross-week read complementing the same-day daily-scan banner below: the FCA’s exploration of “agentic supervision” surfaced in the same week at least six vendors shipped agent control planes to firms (see AI Governance Platforms). Supervisor and supervised are adopting the same agentic-AI class at once, so the human-oversight, accountability and logging evidence the FCA will expect of firms is evidence the FCA is itself now having to produce. Interpretive synthesis, not stated in any source. [S-2026-09-18-weekly-briefing]
Updated 2026-09-18 based on S-2026-09-18-fca-financial-crime-protecting-hive (daily regulatory-intelligence scan) — in the speech “Financial crime: protecting the hive” (Steve Smart, executive director of enforcement and market oversight; Law Society Economic Crime Conference 2026, delivered 17 September 2026) the FCA disclosed that its own intelligence systems now process “over 56 million records every day” using AI to flag high-risk firms earlier, and that it is “exploring… the potential for agentic supervision – something we’re looking at more broadly across the FCA”, while insisting “AI doesn’t – and won’t – replace human judgment” but “can strengthen it”. This is a concrete new data point that reinforces (does not contradict) the page’s existing supervisory-AI thread from the 24 June 2026 Rathi speech (agentic AI as a supervisory “first responder” over ~a billion rows/day): the supervisor is itself moving toward agentic AI. The speech’s primary subject — the FCA taking on AML supervision of ~60,000 legal/accounting entities from “the backend of 2028” — is financial-crime supervision (synthesised on FCA — Financial Conduct Authority), not AI governance. Added as a Key Point and a Source; drafted speech (may differ from delivery), surfaced via FCA news RSS then fetched in full. Practitioner inference (not in source): a supervisor that runs its own agentic-supervision tooling will find it harder to treat firms’ human-oversight and assurance shortcuts leniently — the FCA’s own controls over agent-generated outputs become an implicit benchmark for what it expects of supervised firms [inference] [S-2026-09-18-fca-financial-crime-protecting-hive]. Updated 2026-09-09 based on S-2026-08-27-fca-young-investors-ai-trust (daily regulatory-intelligence scan) — the FCA published research “Young investors trust AI more than TV or celebrities” (27 August 2026, survey fielded 24 July, n=666, ages 18–40). It quantifies the consumer-facing side of the regulatory-perimeter thread this page already tracks (the Perimeter Report 2026/27 flagged general-purpose AI for borrowing/saving/investing guidance as an out-of-perimeter consumer risk): four in five less-experienced investors have used AI for investing help and 56% trust AI tools, yet 44% wrongly believe AI-generated financial information is regulated, 38% think it acceptable to invest solely on AI outputs, and ~32% wrongly expect FSCS/Ombudsman compensation if AI advice fails. The FCA restates the perimeter boundary — general-purpose AI chatbots are not regulated, while a tool “specifically set up to provide financial advice would be likely to fall within the FCA’s remit”. Reinforcing (not contradicting) the page’s existing-frameworks / perimeter thesis; adds hard consumer-attitude data and a Consumer Duty consumer-understanding hook. Added as a Key Point, a Detail note and an Open Question. Retrieved via the FCA news RSS feed (full press-release body); the read-across to Consumer Duty is the wiki’s assessment, not stated in the release [S-2026-08-27-fca-young-investors-ai-trust]. Updated 2026-08-14 based on S-2026-08-10-fca-high-growth-firms-good-poor-practice — the FCA’s “High-growth firms: good and poor practice” review (10 August 2026) is not the awaited AI good/poor-practice publication (still pending); it is a prudential governance review of high-growth firms. Its AI relevance is secondary but concrete: AI/new technology is named as an emerging area where firms must maintain structured governance and strengthen data governance, change control, cyber testing and third-party oversight as they introduce it, and where risk-management resources must scale with “greater use of new technologies such as AI”. Added as a Key Point (with an explicit disambiguation note) and a Source; reinforcing the page’s existing-frameworks / governance-and-controls thesis, not contradicting it. Primary synthesis of this publication lives on FCA — Financial Conduct Authority. (FCA publication fetched in full via WebFetch — see Source page.) Updated 2026-07-07 based on S-2026-07-06-mills-review-vendor-reactions — the vendor-positioning wave around the Mills Review began within a day of publication: core-banking vendor SaaScada is converting the review into a data/core-infrastructure-readiness pitch (“banks can’t expect to innovate with agentic AI” on legacy foundations), TrendAI into an AI-fraud-controls pitch (synthetic-identity fraud as an under-weighted “sleeper threat”, AI-vs-AI stress-testing, senior accountability, explainability), The Payments Association into an agentic-liability governance case (58% of UK online merchants believe AI agents already transact on their platforms; only 41% confident in liability frameworks — its own survey), and OpenPayd into an infrastructure-layer-controls case; Norton Rose Fulbright reads the review as putting operational resilience and the regulatory perimeter under near-term stress with SM&CR and Consumer Duty also stressed. Vendor statements are self-interested positioning, not verified capability. Notably, no core data-governance vendor (catalogue/lineage/DQ) reacted in this first wave. Added as a Key Point and an Open Question; reinforcing the page’s existing Mills Review content, not contradicting it. [S-2026-07-06-mills-review-vendor-reactions] Updated 2026-07-06 based on S-2026-07-06-fca-mills-review-findings — the Mills Review was published on 6 July 2026 (confirming the previously medium-confidence date), with a same-day FCA event. Its central recommendation is that the FCA should publish comprehensive, practical guidance by end-2026 on (i) how consumer-protection rules apply to firms’ use of AI and (ii) the accountability and level of assurance expected from senior managers under SM&CR for harm caused through AI — and it reaffirms that the FCA will not create a new AI rulebook, instead testing whether Consumer Duty, SM&CR and operational-resilience requirements remain appropriate as AI becomes more autonomous and agentic toward 2030. This confirms and sharpens the page’s existing “no separate rulebook / test existing levers” thesis and, for the first time, names senior-manager assurance for AI harm as an explicit forthcoming-guidance topic — the direct hook for an independent-assurance offer. Reinforcing, not contradicting; the 6 July date and end-2026 guidance recommendation are corroborated across multiple legal-firm summaries (exact wording medium-high confidence pending direct FCA-document retrieval — see Source page). Added as this banner, a Key Point, an updated Open Question and a Source. [S-2026-07-06-fca-mills-review-findings] Updated 2026-06-26 based on S-2026-06-26-fca-mills-review-date — timing confirmation only: the Mills Review will be published on 6 July 2026 (the FCA hosting a same-day event), fixing the previously tracked “summer 2026” / “in a couple of weeks” framing to a date; the AI Input Zone closed 19 June 2026; and the FCA reaffirmed (2 June 2026 blog) it will not introduce new AI-specific rules — Consumer Duty, SM&CR and existing governance/controls expectations govern. No change to substance; the Mills Review date is medium-confidence (secondary commentary, see Source page). Key Point date and an Open Question updated. Updated 2026-06-25 based on S-2026-06-24-fca-rathi-ai-speech — FCA CEO Nikhil Rathi’s speech “Rethinking regulation for the age of AI” (techUK, 24 June 2026) reinforces and previews the existing approach rather than changing it: it confirms the Mills Review is due “in a couple of weeks” and the good/poor-practice AI publication “later in the year” (both already tracked here), and hardens three expectations into CEO-level language — (i) “accountability for regulated activities and outcomes must remain clear” with “the right human oversight” designed in as agentic AI scales; (ii) boards “must understand the risks” and “dependencies - particularly on model providers and third parties - must be properly mapped and governed, and the Critical Third Parties regime becomes more important than ever”; and (iii) the FCA will lean more on stewardship, its competition objective and system-wide powers (“a regular part of our toolkit”), and agentic AI as a supervisory ‘first responder’ (a billion rows of data/day) to act before legislation catches up. Added as a Key Point, a Detail subsection and an Open Question; reinforcing, not contradicting, the no-separate-rulebook stance. (FCA CEO speech; located via WebSearch then confirmed by direct WebFetch — drafted speech, may differ from delivery.) Updated 2026-06-19 based on S-2026-06-cmorg-frontier-ai-firm-guidance — CMORG published “Firm Guidance for Frontier AI” v1.0 (June 2026, TLP CLEAR), the industry deliverable that operationalises the 15 May 2026 FCA/BoE/HMT joint statement (CMORG was already named on this page as the engagement channel). It is voluntary guidance, explicitly not regulatory rules or supervisory expectations, consolidating leading practice into a coherent capability system across governance & leadership, attack-surface reduction & resilient architecture, responding at pace (compressing remediation from weeks to days/hours), automation/AI in defence, and supply-chain/ecosystem risk — pairing “Firms Should” actions with board-level “Ask Themselves” questions, and treating AI systems as privileged applications (scoped access, logging, human oversight, kill-switches). Added as a Key Point and a Detail note under the frontier-AI section;
domain/op-resiliencetag added. (Industry artefact; identified via WebSearch fallback then the PDF retrieved directly — see Source page.) Updated 2026-06-16 based on S-2026-06-11-fca-emerging-tech-horizon-scan — the FCA published its Emerging Technology Horizon Scan 2026 (11 June 2026), naming three converging forces: personalised intelligence (AI embedding into consumers’ budgeting/saving/investing, raising autonomy, digital-exclusion and harm questions), synthetic crime (audio/video deepfakes as a new fraud/authentication surface) and programmable finance (tokenisation, smart contracts, shared ledgers moving from pilots to national strategies). Forward-looking horizon-scanning, not new rules; added as a Key Point and an Open Question. Updated 2026-06-04 based on S-2026-05-21-fca-ai-input-zone — the FCA reopened its AI Input Zone (call for views, responses by 19 June 2026) to build the evidence base for the good/poor-practice AI publication previously only “promised”; this gives the previously abstract “good / poor practice examples later in 2026” commitment a concrete evidence-gathering mechanism and an explicit “examples not principles” framing across governance, resilience, oversight, assurance, deployment controls and consumer outcomes. Updated 2026-06-02 based on S-2026-03-26-fca-perimeter-report-2026-27 — FCA Perimeter Report 2026/27 flags consumer-facing general-purpose AI for borrowing/saving/investing guidance as a new out-of-perimeter consumer risk; added as a Key Point and Open Question. Updated 2026-06-01 based on S-2026-05-fca-smcr-review-ps26-6 — FCA SM&CR review (PS26/6, phase 1 reforms) integrated; the SM&CR recalibration previously only “signalled” (22 April 2026 speech) is now in policy form. Updated 2026-05-29 based on S-2026-05-15-fca-boe-treasury-frontier-ai-cyber — FCA/BoE/HMT joint statement on frontier AI models and cyber resilience integrated; five firm-level expectation domains added. Updated 2026-05-28 based on S-2026-04-fca-work-programme-2026-27 — FCA annual work programme 2026/27 commitments to AI-enabled supervision added.
TL;DR
The Financial Conduct Authority is anchoring AI oversight in existing frameworks — Consumer Duty, SM&CR, Operational Resilience, and the Critical Third Parties regime — rather than introducing a separate AI rulebook. The flagship initiative is the Mills Review (long-term impact of AI on retail financial services), with recommendations due to the FCA Board in summer 2026. Live experimentation runs through the FCA AI Live Testing programme (cohort 2 began April 2026). Firms are expected to evidence AI governance through outcomes-based controls — particularly explainability, fairness, resilience and accountability. The FCA / BoE / HMT joint statement on frontier AI models and cyber resilience (15 May 2026) reinforces these expectations specifically for the cyber-resilience surface: board-level understanding of frontier-AI risks, vulnerability triage at speed and scale, third-party / supply-chain AI cyber risk management, and response/recovery aligned to the October 2025 effective-practices guidance [S-2026-05-15-fca-boe-treasury-frontier-ai-cyber].
Key Points
- The FCA’s published position is that existing frameworks provide sufficient oversight; no AI-specific rules are planned [S-2026-01-27-fca-mills-review].
- The Mills Review — Review into the long-term impact of AI on retail financial services — was launched 27 January 2026 by Sheldon Mills (Executive Director, Consumers and Competition); call for input closed 24 February 2026; recommendations due to the FCA Board in summer 2026 [S-2026-01-27-fca-mills-review]. The review was published on 6 July 2026 with a same-day FCA event. Its headline recommendation is that the FCA should publish comprehensive, practical guidance by end-2026 covering (i) how consumer-protection rules apply to firms’ use of AI and (ii) the accountability and level of assurance expected from senior managers under SM&CR for harm caused through AI; it reaffirms the FCA will not create a new AI rulebook but will test whether Consumer Duty, SM&CR and operational-resilience requirements remain appropriate for increasingly autonomous/agentic AI toward 2030 (medium-high confidence; corroborated across legal-firm summaries pending direct FCA-document retrieval) [S-2026-07-06-fca-mills-review-findings].
- The review explicitly tests whether existing levers (Consumer Duty, SM&CR, Operational Resilience, Critical Third Parties regime) are fit to manage AI-driven risks — particularly agentic and autonomous AI systems — to 2030 and beyond [S-2026-01-27-fca-mills-review].
- FCA AI Live Testing, cohort 2 — applications January 2026, testing began April 2026; evaluation report expected Q1 2027 [S-2026-01-27-fca-mills-review].
- AI Lab good / poor practice examples to publish later in 2026; promised in Jessica Rusu’s speech 21 April 2026 [S-2026-04-21-fca-rusu-speech]. The FCA reopened its AI Input Zone (week of 18 May 2026; responses by 19 June 2026) as the evidence-gathering mechanism for that publication, asking for concrete examples — not principles or policies — across governance, resilience, oversight, assurance, deployment controls and consumer outcomes, on (i) what enables safe/responsible AI deployment, (ii) what blocks it, and (iii) what themes the publication should cover [S-2026-05-21-fca-ai-input-zone].
- FCA is embedding generative AI into its own supervisory and authorisation workflows [S-2026-04-21-fca-rusu-speech][S-2026-04-fca-work-programme-2026-27].
- The FCA annual work programme 2026/27 commits the FCA to being a “smarter, more data-driven regulator” — using AI to speed authorisations and identify key risks earlier; minimum / flat fees rise by 1% (lowest since 2017/18) despite investment in data analytics and digital tooling [S-2026-04-fca-work-programme-2026-27].
- The FCA published its Retail Banking Regulatory Priorities Report in March 2026, replacing over 40 individual portfolio letters [S-2026-01-27-fca-mills-review].
- Four firm-level evidence criteria recur across FCA artefacts: explainability, fairness, resilience, accountability — synthesised as the FCA’s de-facto AI governance assurance lens, though not a formal FCA label [S-2026-01-27-fca-mills-review].
- Joint FCA / PRA / Bank of England Policy Statement PS26/2 on operational incident and third-party reporting comes into force 18 March 2027 [S-2026-03-fca-ps26-2].
- An SM&CR recalibration was signalled at the “Getting firms fit to run” speech on 22 April 2026 [S-2026-01-27-fca-mills-review]; it is now in policy form via PS26/6 — SM&CR review (phase 1), which streamlines the regime (≈15% fewer certification roles, more time/flexibility on approvals and Directory updates, clearer SMF definitions), with phase 2 (HM Treasury) to reconsider the certification regime and the number of approved senior managers [S-2026-05-fca-smcr-review-ps26-6].
- FCA / BoE / HMT joint statement on frontier AI models and cyber resilience (15 May 2026) — five firm-level expectation domains (governance and strategy; vulnerability triage at speed and scale; third-party / supply-chain AI cyber risk; protection and access management; response and recovery aligned to the October 2025 effective-practices guidance) — framed as reinforcement of existing operational-resilience rules, not new requirements [S-2026-05-15-fca-boe-treasury-frontier-ai-cyber].
- The joint statement asserts that current frontier-AI cyber capabilities already exceed what a skilled practitioner could achieve, at higher speed, greater scale and lower cost [S-2026-05-15-fca-boe-treasury-frontier-ai-cyber].
- Cross Market Operational Resilience Group (CMORG) is the engagement channel; CMORG Frontier AI Risk Mitigation Webinar held 14 May 2026 [S-2026-05-15-fca-boe-treasury-frontier-ai-cyber]. CMORG subsequently published “Firm Guidance for Frontier AI” v1.0 (June 2026, TLP CLEAR) — voluntary, industry-developed guidance (explicitly not regulatory rules or supervisory expectations) that operationalises the joint statement into a coherent capability system, with the central thesis that frontier AI compresses vulnerability discovery-to-exploitation timelines so firms must shrink remediation “from weeks to days, and in some cases hours” and that “the primary challenge is no longer understanding what good looks like, but executing it consistently at pace and at scale” [S-2026-06-cmorg-frontier-ai-firm-guidance].
- The FCA Perimeter Report 2026/27 (26 March 2026) names “the growing use of general-purpose AI for guidance on borrowing, saving and investing” as a key new issue falling outside the FCA’s perimeter that may pose consumer risk — alongside “Annex 1” AML-only firms and speculative prediction-market products [S-2026-03-26-fca-perimeter-report-2026-27].
- The FCA is integrating generative AI into its own authorisations and supervision (document review rolling out after successful testing), expanding the Supercharged Sandbox with synthetic data, and proposing only a 1% minimum/flat-fee rise (0.7% AFR increase, the lowest in a decade) [S-2026-03-26-fca-perimeter-report-2026-27].
- FCA CEO speech “Rethinking regulation for the age of AI” (Nikhil Rathi, techUK, 24 June 2026): with >80% of FS firms already adopting AI, the issue is scale — chiefly agentic systems that “coordinate and transact” and tokenisation (the FCA/BoE approved the UK’s first natively tokenised authorised fund). Three governance-relevant assertions: accountability for regulated activities/outcomes “must remain clear” with human oversight designed in; boards must understand AI risks and dependencies on model providers and third parties “must be properly mapped and governed, and the Critical Third Parties regime becomes more important than ever”; and the FCA will rely more on stewardship, its competition/system-wide powers “as a regular part of our toolkit”, and agentic AI as a supervisory “first responder” — confirming it may “act before legislation catches up” [S-2026-06-24-fca-rathi-ai-speech].
- Vendor reaction to the Mills Review (6–7 July 2026): within a day of publication, technology vendors began positioning against the review’s pressure points — SaaScada (core banking) arguing agentic AI requires modernised data/core foundations first; TrendAI naming synthetic-identity fraud an under-weighted threat and calling for AI-vs-AI stress-testing, senior accountability for AI decisions and explainability; The Payments Association citing its survey that 58% of UK online merchants believe AI agents already transact on their platforms while only 41% are confident in liability frameworks, urging firms to treat agentic AI “as an accountability and governance issue now”; OpenPayd locating identity/authorisation/fraud controls at the infrastructure layer. All are self-interested vendor positioning; no catalogue/lineage/DQ data-governance vendor reacted in this first wave [S-2026-07-06-mills-review-vendor-reactions].
- The FCA’s “High-growth firms: good and poor practice” review (10 August 2026) — drawn from the Early and High Growth Oversight pilot of 15 firms — is a prudential governance review, not the still-pending AI good/poor-practice publication, but it reinforces the FCA’s existing-frameworks/governance-and-controls posture and names AI directly: firms must maintain structured governance over emerging technologies such as AI, ensure risk-management resources scale where they make “greater use of new technologies such as AI”, and strengthen change control, data governance, cyber testing, third-party oversight and operational-resilience planning “particularly where firms were introducing new technology, automation, platform changes or AI”. Illustrative supervisory expectation-setting, not new rules; primary synthesis on FCA — Financial Conduct Authority [S-2026-08-10-fca-high-growth-firms-good-poor-practice].
- FCA research “Young investors trust AI more than TV or celebrities” (27 August 2026) quantifies consumer reliance on AI for investing and a protection-perception gap: among 18–40-year-old investors, four in five have used AI for investing help and 56% trust AI tools (more than TV/radio, press or influencers), yet 44% wrongly believe AI-generated financial information is regulated, 38% think it fine to invest solely on AI outputs, and ~32% wrongly expect FSCS/Financial Ombudsman compensation if AI advice fails (73% do know AI can be inaccurate; 86% understand the need to check sources). The FCA reiterates the perimeter position — general-purpose AI chatbots are not regulated, while a tool specifically set up to provide financial advice would likely fall within its remit — directly reinforcing the Perimeter Report 2026/27 out-of-perimeter-AI concern with hard consumer data; self-reported research (Attest U&A study, fielded 24 July 2026, n=666) [S-2026-08-27-fca-young-investors-ai-trust].
- FCA’s own use of AI / “agentic supervision” (speech, 17 September 2026): in “Financial crime: protecting the hive”, Steve Smart (executive director of enforcement and market oversight) said the FCA’s intelligence systems process “over 56 million records every day” using AI to flag high-risk firms earlier, and that the FCA is “exploring… the potential for agentic supervision… more broadly across the FCA”, while affirming “AI doesn’t – and won’t – replace human judgment. But it can strengthen it.” This reinforces the Rathi (24 Jun 2026) “agentic AI as a supervisory first responder (~a billion rows/day)” thread with a concrete figure and the explicit phrase “agentic supervision” — evidence the supervisor is itself adopting agentic AI. Delivered in a financial-crime/AML-supervision speech (the FCA also confirmed it will take on AML supervision of ~60,000 legal/accounting entities from “the backend of 2028”); drafted speech, direction not new firm rules [S-2026-09-18-fca-financial-crime-protecting-hive].
- The FCA Emerging Technology Horizon Scan 2026 (11 June 2026) names three converging forces reshaping conduct, fraud risk and market infrastructure: personalised intelligence (AI embedding into consumers’ budgeting/saving/investing decisions, raising autonomy, digital-exclusion and harm questions), synthetic crime (audio/video deepfakes becoming indistinguishable from real content — a new fraud and authentication surface), and programmable finance (tokenisation, smart contracts and shared ledgers moving from pilots to national strategies). It is forward-looking horizon-scanning, not new rules, but signals the supervisory horizon firms should anticipate [S-2026-06-11-fca-emerging-tech-horizon-scan].
Detail
”No separate AI rulebook” stance
The FCA has consistently signalled that AI risks are addressable within existing principles-based frameworks. Consumer Duty covers consumer-outcome monitoring; SM&CR covers individual accountability for AI-driven decisions through statements of responsibility; Operational Resilience covers AI-system continuity within important business services; and the Critical Third Parties regime covers AI / GPAI providers as third parties. Firms are expected to map AI accountability to Senior Manager Functions (notably SMF24 and SMF4) and to prepare evidence of how AI risks flow into Consumer Duty outcomes monitoring [S-2026-01-27-fca-mills-review].
Mills Review and the four test criteria
The Mills Review, named after Sheldon Mills, examines how AI — and particularly agentic and autonomous AI — may reshape consumer interactions to 2030 and beyond. Across review artefacts and speeches, four firm-level evidence criteria recur: explainability, fairness, resilience, accountability. Paul’s synthesis is that these are becoming the FCA’s de-facto AI governance assurance lens [S-2026-01-27-fca-mills-review]. Note: this is practitioner synthesis, not FCA’s own formal labelling.
Live Testing as a supervisory tool
The FCA is moving from principles-based AI statements to supervised experimentation. Cohort 2 of AI Live Testing began in April 2026; firms participating need demonstrable AI governance, model risk, and consumer outcome controls evidenced in real time [S-2026-01-27-fca-mills-review]. The expectation that the FCA will subsequently publish examples of good vs poor practice [S-2026-04-21-fca-rusu-speech] means the sandbox is effectively shaping the next phase of supervisory expectations.
Evidence-gathering for the good/poor-practice publication — the AI Input Zone
The reopening of the AI Input Zone (responses by 19 June 2026) is the concrete intake mechanism behind the promised good/poor-practice publication. The FCA’s emphasis on specific examples rather than principles or policies, scanned across governance, resilience, oversight, assurance, deployment controls and consumer outcomes, signals that the eventual guidance will be evidence-led and illustrative, drawn from what firms are actually doing [S-2026-05-21-fca-ai-input-zone]. Practitioner inference (not in source): this favours firms (and assurance providers) who can supply demonstrable, working AI controls now — early, well-evidenced submissions are likely to disproportionately shape the de-facto benchmark, and the exercise itself is a low-cost channel to surface a practice’s framework artefacts to the regulator’s attention.
Operational resilience: PS26/2
PS26/2 represents a regulatory shift from one-time compliance exercises to demonstrating continuous adherence to impact tolerances [S-2026-03-fca-ps26-2]. AI-system incidents are not yet explicitly in scope but plausibly will be in practice — see Open Questions.
Frontier AI and cyber resilience — the 15 May 2026 joint statement
The FCA, Bank of England and HM Treasury issued a joint statement on 15 May 2026 setting out how UK firms should plan for and mitigate cyber-resilience risks from frontier AI models. The framing is explicit: the statement does not introduce new expectations but reinforces existing operational-resilience rules in light of frontier-AI capabilities that the authorities judge “already exceeding what a skilled practitioner could achieve” at higher speed, scale and lower cost [S-2026-05-15-fca-boe-treasury-frontier-ai-cyber]. Five expectation domains are named:
- Governance and strategy — boards and senior management must have sufficient understanding of frontier-AI risks; investment, resourcing and insurance posture must reflect the emerging threat, including exposure from end-of-life systems.
- Identification and risk management of vulnerabilities — firms must triage, prioritise, risk-assess and remediate vulnerabilities more quickly, more frequently and at scale, including through automation while mitigating operational risks from automation itself.
- Managing risks from third parties — firms must identify, monitor and manage external applications, libraries and services integrated into their networks (including open-source software), and be prepared to remediate vulnerabilities flagged by third parties at scale.
- Protection — effective access management, network security and data protection should reduce the attack surface; firms should consider AI-enabled defences to operate at comparable speed to AI-driven attacks.
- Response and recovery — firms should align to the effective practices on cyber resilience published by the Bank, PRA and FCA in October 2025.
The Government and UK financial authorities will continue to engage industry through CMORG; firms are pointed to the CMORG Frontier AI Risk Mitigation Webinar (14 May 2026) and NCSC guidance for support [S-2026-05-15-fca-boe-treasury-frontier-ai-cyber]. Practitioner inference (not in source): although the statement disclaims new expectations, it materially raises the supervisory bar for what “sufficient” board understanding and vulnerability management look like in practice — particularly for firms with material end-of-life or out-of-support technology estate.
The CMORG “Firm Guidance for Frontier AI” v1.0 (June 2026) is the operational follow-through to the joint statement. It consolidates industry and public-authority thinking into a single voluntary reference and is organised as five mutually-reinforcing capability areas, each with concrete “Firms Should” actions and board-level “Ask Themselves” questions: (1) Take Control — executive ownership, evidence-led governance that separates observed threats from speculative scenarios, risk-appetite updates that explicitly authorise rapid-remediation/service-availability trade-offs, and an operating-model shift to “machine speed” with DevSecOps / shift-left and continuous (not periodic) assurance; (2) Protect Your Organisation — continuous attack-surface reduction and assume-breach architecture (Zero Trust, segmentation, least privilege), and governing AI systems as privileged applications (scoped permissions, robust logging, human oversight for high-impact actions, kill-switches); (3) Prepare to Respond at Pace — intelligence-led detection, risk-based remediation targets measured in hours/days prioritised by exploitability and business impact, pre-agreed emergency remediation pathways, and reporting on exposure duration and remediation validation; (4) automation/AI used to cut latency but designed to “fail safely” with human accountability for high-impact decisions; and (5) Work Collectively — treating suppliers, open-source components, cloud and AI providers as part of the sector’s attack surface, with firms remaining accountable for third-party resilience failures [S-2026-06-cmorg-frontier-ai-firm-guidance]. Practitioner inference (not in source): the guidance doubles as a ready-made assurance checklist — the “Ask Themselves” questions map cleanly onto a board-readiness review and the “Firms Should” actions onto an independent control-design assessment of a firm’s frontier-AI cyber-resilience posture [inference].
CEO-level direction — the 24 June 2026 Rathi speech
Rathi’s techUK speech is the most senior restatement to date of the FCA’s AI posture, and it sharpens three threads already on this page. First, scaling and accountability: the FCA’s attention is moving from generative-AI assistance to agentic systems that coordinate and transact, and Rathi is explicit that “accountability for regulated activities and outcomes must remain clear” with “the right human oversight” — i.e. autonomy does not dilute the SM&CR accountability chain [S-2026-06-24-fca-rathi-ai-speech]. Second, resilience and third-party concentration: framing FS as “increasingly reliant on cloud providers, model providers, data providers … many parts of the AI stack”, he states dependencies “must be properly mapped and governed, and the Critical Third Parties regime becomes more important than ever”, anchored by the figure that 98% of operational incidents reported last year were technology/cyber-related — see Operational Resilience and Third Party Risk [S-2026-06-24-fca-rathi-ai-speech]. Third, a changing regulatory model: with legislation that “will never keep up”, the FCA will lean on stewardship alongside supervision, expects to use its competition and system-wide powers “as a regular part of [its] toolkit”, and is itself deploying agentic AI as a supervisory “first responder” over ~a billion rows of data per day to tackle market abuse faster [S-2026-06-24-fca-rathi-ai-speech]. The speech also fixes near-term timing: the Mills Review is due “in a couple of weeks” and the good/poor-practice AI publication “later in the year”. Practitioner inference (not in source): the “properly mapped and governed” model-provider language effectively pre-positions AI-stack dependency mapping and CTP-aligned third-party governance as the evidence supervisors will expect when the good/poor-practice publication lands [inference].
Consumer-facing AI and the perimeter — the 27 August 2026 research
The FCA’s consumer-attitudes research puts numbers on a risk this page has tracked abstractly since the Perimeter Report 2026/27: consumers are already leaning on unregulated, general-purpose AI for investment decisions, and many misunderstand the protection that carries. The headline gap is that 44% believe AI-generated financial information is regulated and ~32% expect FSCS/Ombudsman cover that general-purpose chatbots do not provide [S-2026-08-27-fca-young-investors-ai-trust]. The FCA’s response in the release is consumer education plus a restatement of the perimeter line (general-purpose chatbot = outside remit; advice-specific tool = likely inside), not new firm rules. Practitioner inference (not in source): for authorised firms the read-across is Consumer Duty — where a firm’s own customers rely on general-purpose AI around its products, the consumer-understanding outcome and the duty to avoid foreseeable harm make it hard to treat that reliance as purely outside the firm’s concern, even though the tool itself is unregulated; this is the kind of “does an existing lever already bite?” question the Mills Review said the FCA will test [inference].
Practical Applications
- Map AI controls to SMF holders. Build statements of responsibility that explicitly cover AI-system decisions (SMF24 for CDO; SMF4 for CRO-equivalent risk oversight) [S-2026-01-27-fca-mills-review].
- Build evidence packs by Consumer Duty outcome. Show how AI risks flow into the four outcomes monitoring streams.
- Participate in AI Live Testing where relevant. Cohort 2 evidence will benchmark good practice [S-2026-01-27-fca-mills-review].
- Prepare for SM&CR recalibration. Signalled in the “Getting firms fit to run” 22 April 2026 speech [S-2026-01-27-fca-mills-review].
- Evidence frontier-AI cyber-resilience posture. Build board-level briefings on frontier-AI cyber risk; map vulnerability triage / remediation processes against speed-and-scale expectations; refresh third-party / supply-chain inventories to cover AI-enabled and open-source components; align response/recovery playbooks to the October 2025 effective-practices guidance [S-2026-05-15-fca-boe-treasury-frontier-ai-cyber].
Related Concepts
- relates-to → FCA — this topic synthesises the published AI approach advanced by the FCA (the entity). [S-2026-01-27-fca-mills-review]
- depends-on → Consumer Duty — primary existing lever for AI consumer-outcome oversight. [S-2026-01-27-fca-mills-review]
- depends-on → Senior Managers and Certification Regime — individual accountability for AI-driven decisions (SMF24 / SMF4). [S-2026-01-27-fca-mills-review]
- depends-on → Operational Resilience — AI-system continuity within important business services. [S-2026-01-27-fca-mills-review]
- depends-on → Critical Third Parties regime — covers AI / GPAI providers as third parties. [S-2026-01-27-fca-mills-review]
- relates-to → EU AI Act — EU parallel; FCA / UK approach is materially lighter on prescriptive rules.
- relates-to → BCBS AI Governance Framework — Basel ten-step playbook as a defensible benchmark against FCA’s principles-based stance.
- relates-to → EBA Supervisory Direction on AI and Governance — EBA takes a comparable “existing-framework-reuse” stance for EU banking.
- relates-to → Three Lines of Defence for AI — how SM&CR responsibilities flow into 1LoD / 2LoD / 3LoD coverage.
- relates-to → Operational Resilience and Third Party Risk — PS26/2 sits here.
Open Questions
- What specific examples will the FCA publish as “good vs poor practice” from the AI Lab later in 2026, and which themes from the AI Input Zone submissions (closed 19 June 2026) will it prioritise? [S-2026-05-21-fca-ai-input-zone][S-2026-06-26-fca-mills-review-date]
- (Largely addressed 2026-07-06: the Mills Review published 6 July 2026 recommends the FCA issue by-end-2026 practical guidance on AI-and-Consumer-Duty and SM&CR senior-manager assurance for AI harm, and affirms — rather than replaces — the existing levers, pending the FCA’s formal response. Open residual: whether the FCA adopts the recommendation and whether the guidance introduces concrete good/poor-practice benchmarks.) [S-2026-07-06-fca-mills-review-findings]
- How will “the level of assurance expected from senior managers” under SM&CR for AI-caused harm — newly named by the Mills Review as a forthcoming-guidance topic — be evidenced in practice, and what independent-assurance artefacts would satisfy it? [S-2026-07-06-fca-mills-review-findings]
- Will the SM&CR recalibration introduce or modify prescribed responsibilities specific to AI? (Partly addressed: PS26/6 phase 1 streamlines the regime but does not introduce AI-specific responsibilities; phase 2 with HM Treasury is still open [S-2026-05-fca-smcr-review-ps26-6].)
- Will existing frameworks be judged sufficient for agentic / multimodal AI by the Mills Review?
- How the four de-facto criteria (explainability, fairness, resilience, accountability) will be evidenced in practice.
- What specific evidence of “sufficient” board understanding of frontier-AI risk will satisfy supervisors in practice? [S-2026-05-15-fca-boe-treasury-frontier-ai-cyber]
- Will supervisors treat alignment to the voluntary CMORG “Firm Guidance for Frontier AI” as evidence of adequate frontier-AI cyber-resilience posture despite its explicit non-endorsement caveat, and how do its “remediation in hours/days” expectations reconcile with change-management, testing and service-availability obligations under the operational-resilience regime and PS26/2? [S-2026-06-cmorg-frontier-ai-firm-guidance]
- How does the FCA expect firms to manage consumer reliance on out-of-perimeter general-purpose AI for financial guidance under Consumer Duty, and will this gap be closed by perimeter legislation, FCA guidance, or firm-level controls? The 27 Aug 2026 research quantifies the protection-perception gap (44% think AI info is regulated; 32% expect FSCS/Ombudsman cover) but stops at consumer education — leaving open whether the FCA moves to perimeter legislation, guidance, or firm-level Consumer Duty expectations [S-2026-03-26-fca-perimeter-report-2026-27][S-2026-08-27-fca-young-investors-ai-trust].
- Will the Emerging Technology Horizon Scan 2026 themes (personalised intelligence, synthetic crime, programmable finance) translate into supervisory expectations or feed the promised good/poor-practice AI publication, and what controls will the FCA expect against deepfake-enabled fraud under existing operational-resilience and Consumer Duty frameworks? [S-2026-06-11-fca-emerging-tech-horizon-scan]
- As agentic systems “coordinate and transact”, what evidence of “clear accountability” and “the right human oversight” will the FCA expect, and what will “properly mapped and governed” model-provider/third-party dependencies require under the Critical Third Parties regime? Will the imminent Mills Review and the good/poor-practice publication convert these CEO-level expectations into concrete benchmarks? [S-2026-06-24-fca-rathi-ai-speech]
- The first vendor-reaction wave to the Mills Review came from core-banking, payments and security vendors — the core data-governance vendors (Collibra, Informatica, Solidatus, Microsoft, BigID) were absent despite the review’s data-readiness implications. Will catalogue/lineage/DQ vendors build explicit Mills Review positioning, and will the FCA’s promised end-2026 guidance reference data-infrastructure readiness in a way that vendors can anchor to? [S-2026-07-06-mills-review-vendor-reactions]
- The FCA’s “no separate rulebook” stance is one leg of a transatlantic pattern this week — US SR 26-2 scoping GenAI/agentic out and the EU high-risk runway receding to Dec 2027/Aug 2028 (see Model Risk Management and Agentic AI, EU AI Act). If all three jurisdictions decline GenAI-specific rules, how do firms best evidence agentic-AI oversight against existing UK frameworks before the Mills Review and good/poor-practice publication set a benchmark? [S-2026-06-26-weekly-briefing]
Sources
- [S-2026-09-18-fca-financial-crime-protecting-hive] → S-2026-09-18-fca-financial-crime-protecting-hive — Steve Smart speech (17 Sep 2026); the FCA’s own use of AI (56m records/day) and exploration of “agentic supervision”; reinforces the supervisory-AI first-responder thread.
- [S-2026-08-27-fca-young-investors-ai-trust] → S-2026-08-27-fca-young-investors-ai-trust — FCA consumer research (27 Aug 2026) on younger investors’ use of and trust in AI; quantifies the protection-perception gap and restates the general-purpose-AI perimeter boundary.
- [S-2026-08-10-fca-high-growth-firms-good-poor-practice] → S-2026-08-10-fca-high-growth-firms-good-poor-practice — FCA good/poor-practice review of high-growth firms (10 Aug 2026); AI-relevant governance/controls hook, explicitly distinct from the pending AI good/poor-practice publication.
- [S-2026-06-26-weekly-briefing] → Weekly Briefing — 26 June 2026 — weekly synthesis situating the FCA “no separate rulebook” stance within a transatlantic pattern (US SR 26-2 + EU high-risk runway); interpretive cross-week read-across.
- [S-2026-07-06-fca-mills-review-findings] → S-2026-07-06-fca-mills-review-findings — published Mills Review findings and recommendations (6 July 2026); supersedes the timing-only date confirmation.
- [S-2026-07-06-mills-review-vendor-reactions] → S-2026-07-06-mills-review-vendor-reactions — trade-press round-up of the first vendor/industry reaction wave (SaaScada, TrendAI, The Payments Association, OpenPayd, Norton Rose Fulbright).
- [S-2026-01-27-fca-mills-review] → S-2026-01-27-fca-mills-review
- [S-2026-04-21-fca-rusu-speech] → S-2026-04-21-fca-rusu-speech
- [S-2026-04-fca-work-programme-2026-27] → S-2026-04-fca-work-programme-2026-27
- [S-2026-03-fca-ps26-2] → S-2026-03-fca-ps26-2
- [S-2026-05-15-fca-boe-treasury-frontier-ai-cyber] → S-2026-05-15-fca-boe-treasury-frontier-ai-cyber
- [S-2026-05-fca-smcr-review-ps26-6] → S-2026-05-fca-smcr-review-ps26-6
- [S-2026-03-26-fca-perimeter-report-2026-27] → S-2026-03-26-fca-perimeter-report-2026-27
- [S-2026-05-21-fca-ai-input-zone] → S-2026-05-21-fca-ai-input-zone
- [S-2026-06-11-fca-emerging-tech-horizon-scan] → S-2026-06-11-fca-emerging-tech-horizon-scan
- [S-2026-06-cmorg-frontier-ai-firm-guidance] → S-2026-06-cmorg-frontier-ai-firm-guidance
- [S-2026-06-24-fca-rathi-ai-speech] → S-2026-06-24-fca-rathi-ai-speech
- [S-2026-06-26-fca-mills-review-date] → S-2026-06-26-fca-mills-review-date