Hugo Rousseau: The FCA published the Review led by Sheldon Mills on 6 July 2026, looking at the long-term impact of AI on retail financial services.
The Review recognises the significant opportunity AI-transformation creates for both firms and consumers - from more efficient operations and better fraud detection to more personalised support, more responsive services and improved customer outcomes.
At the same time, the Review highlights amplified financial crime and cyber risk, noting that AI could make threats faster, cheaper, more scalable and more persuasive.
The recommendations focus on four areas: the regulatory perimeter, supervision and coordination, the foundations for agentic finance, and consumer access and outcomes.
The most immediate recommendation is for the FCA to review the scale and impact of general-purpose AI tools outside the perimeter, including advice-like outputs. Other important recommendations include developing a trusted framework for AI agents and building an AI-enabled supervisory model.
These recommendations will now be considered by the FCA Board. In parallel, the FCA has said it will publish AI good and poor practice later this year, drawing on its engagement with firms.
The Treasury published the Financial Services AI Adoption Plan on 14 July 2026. This is a separate independent report, developed by the AI Champions for financial services: Harriet Rees, Group Chief Information Officer at Starling Bank, and Dr Rohit Dhawan, Head of AI and Advanced Analytics at Lloyds Banking Group.
The Plan is focused on how the UK can move from AI pilots to scaled, safe and responsible adoption across the industry. It identifies five key themes: regulatory clarity, the regulatory perimeter, AI sovereignty and resilience, skills and talent, and readiness for agentic payments.
The ten recommendations are practical. They include clearer and more accessible regulatory support on how existing frameworks apply to AI; an FCA review of financial guidance and advice-like outputs generated by general-purpose large language models; faster implementation of the Critical Third Party regime for key AI and cloud providers; voluntary AI incident and near-miss sharing; an industry-led AI third-party assurance scheme; and a sector-wide AI skills plan; as well as a trust framework for agentic payments.
The Plan overall is about making the existing UK framework more usable, more coordinated and better able to support AI adoption at scale. The Government has welcomed the AI Champions’ plan and the next stage will be working with the regulators and industry, including considering the Mills Review.
For firms, the immediate takeaway is that both reports are consistent with the UK’s current approach: not rushing to legislate or create a standalone AI rulebook, but relying on existing outcomes-based regimes, with targeted clarification where needed. The reports do not change firms’ obligations today, and the FCA has not yet confirmed which, if any, of the Mills Review recommendations it will decide to take forward.
But policy and regulatory activity is increasing, and both reports signal that existing regimes may come under pressure as firms adopt more complex, autonomous and agentic AI. Firms should therefore act now to ensure compliance with existing expectations: for example considering mapping current and planned AI use, testing deployments against the Senior Managers Regime, the Consumer Duty, model risk, operational resilience and third-party risk expectations, and strengthening assurance and governance across the AI lifecycle.