FCA unleashes agentic AI, mandates tougher finance oversight

The gist
The FCA is unleashing agentic AI to police UK finance, mandating tougher oversight and radical transparency to rein in runaway risks by 2030.
What to know
- The FCA’s Mills Review introduces an 'AI autonomy spectrum' and sets a 2030 deadline for robust, transparent AI governance across all financial firms.
- Agentic AI is now the FCA’s ‘first responder,’ sifting billions of data points daily to supervise 95,000 firms and automate risk detection.
- Regulators warn that rapid AI adoption is outpacing internal controls, exposing consumers to financial crime and cyber threats unless governance catches up fast.
AI Governance Revolution Begins
The FCA’s new autonomy spectrum and 2030 roadmap signal a shift to agentic, consumer-facing AI, demanding transparent oversight and industry-wide coordination to manage emerging risks and build public trust.
The FCA’s Mills Review sets a forward-looking roadmap for AI adoption in retail financial services, emphasizing that by 2030, robust AI governance and model risk management will be critical capabilities for firms. This framework introduces an 'AI autonomy spectrum' spanning five levels from human-operated to fully autonomous AI with human oversight, reflecting the sector’s shift towards agent-led consumer journeys where one in five consumers are already willing to delegate financial decisions to AI. Such developments underscore the imperative for regulatory frameworks that ensure transparency, consumer control, and trust while managing emerging risks in AI-driven financial advice and services.
Recognizing that traditional supervisory methods cannot keep pace with AI’s adaptive and continuous learning capabilities, the FCA is pioneering AI-powered supervisory tools, including agentic AI models and its AI Lab initiatives, to enhance risk prioritization and accelerate investigations, particularly in anti-money laundering and market abuse detection. FCA CEO Nikhil Rathi described agentic AI as a 'first responder' processing billions of data points daily, enabling the regulator to manage an expanded supervision workload of over 95,000 firms. This strategic deployment of AI reflects a broader regulatory trend towards continuous, automated oversight to address compliance gaps and rising complaint volumes.
HM Treasury’s Financial Services AI Adoption Plan, which embraces the independent AI Champions’ recommendations, reinforces a principles-based, outcomes-focused regulatory approach that prioritizes clarity and practical application over prescriptive rules. Central to this plan is enhanced coordination among regulators like the FCA, PRA, ICO, and CMA, alongside the creation of a Financial Services AI Adoption Support Hub designed to consolidate guidance and expert access for firms, thereby reducing duplication. The plan also accelerates the Critical Third-Party regime, extending oversight to major cloud providers such as AWS and Microsoft, and proposes voluntary industry-led initiatives including AI consumer disclosures and third-party assurance schemes to standardize AI governance and incident reporting.
The FCA stresses that AI integration is no longer a peripheral tool but a fundamental component of firms’ operating models, requiring governance frameworks that align with existing regulatory standards like the Consumer Duty and SM&CR. This necessitates accountability and traceability in AI decision-making, with senior management held responsible for ensuring AI-driven outcomes are safe, secure, and consumer-focused. Moreover, the FCA cautions that rapid growth fueled by AI must be matched by robust governance and independent challenge to mitigate risks, as weaknesses often arise when firms’ control frameworks fail to evolve alongside shifting business models and customer bases, potentially increasing consumer harm.
Accountability Gap Exposed
UK finance firms face a critical shortage of AI expertise and unclear ownership, as pressure to deploy rapidly outpaces the development of tailored, cross-functional governance frameworks.
Effective AI governance in UK financial services demands a risk-based, proportionate approach that aligns controls with the AI use case's integration level, data sensitivity, and regulatory context. As highlighted in the Passle analysis, governance frameworks must distinguish between AI deployed as separate assistants versus those embedded in live workflows, implementing tailored permissions, monitoring, and escalation mechanisms to balance innovation with risk management. This nuanced approach prevents overly rigid controls that stifle adoption or lax oversight that obscures AI usage, ensuring practical, operational governance rather than static policy documents.
A critical governance challenge is establishing clear ownership and accountability across legal, compliance, procurement, and business teams to avoid diffuse responsibility that undermines oversight. Research shows that 77% of UK finance firms lack in-house expertise to understand AI agent operations, with 21% uncertain who would be accountable for significant AI errors. This gap is exacerbated by intense pressure to prioritize rapid AI deployment over governance, leading to outdated internal controls and limited confidence in explaining AI decisions to regulators, underscoring the urgent need for integrated, cross-functional governance ownership.
The rise of agentic AI systems, which autonomously execute decisions, is forcing financial institutions to fundamentally rethink governance architectures by embedding human override capabilities, audit trails, and access controls directly into system design. As detailed in analyses from August 2026, separating action initiation from approval—mirroring Indian banking controls—and co-authoring clear Statements of Business Purpose before development enable outcome-based accountability. This shift challenges traditional vendor-client dynamics and demands governance frameworks that treat AI as a living system requiring continuous monitoring and lifecycle compliance rather than one-off checks.
Maturing AI governance transcends compliance checklists to become a foundational security and operational capability that integrates data integrity, continuous monitoring, and cross-functional accountability. Industry leaders like Mouli S., Global CTO at HGS, emphasize embedding governance from AI design stages with governance-by-design principles, robust data governance, and risk-based controls. CFOs and auditors are increasingly professionalizing AI oversight by demanding measurable ROI and audit trails, creating a feedback loop that elevates AI quality and accountability. However, widespread challenges remain, including shadow AI usage, insufficient visibility into AI deployments, and the need to harmonize governance with existing enterprise risk and security frameworks to preserve trust and resilience.
Agentic AI Redefines Operations
Autonomous AI is transforming financial workflows, enabling real-time decision-making and compliance while raising the stakes for data control, auditability, and human oversight.
Agentic AI is revolutionizing operational models in financial services by autonomously executing complex tasks across interconnected systems, significantly boosting efficiency but also amplifying risks related to data access and control. As highlighted in the 2026 analysis on financial crime controls, these AI systems can instantly retrieve and synthesize sensitive information, such as summarizing restricted deal documents or generating client communications, thereby challenging traditional information barriers and necessitating robust governance frameworks to monitor permissions, maintain audit trails, and ensure regulatory compliance.
Leading institutions like Hatch Bank are embedding AI as the foundational infrastructure to enable real-time data ingestion, normalization, and decision-making, moving beyond viewing AI as a mere efficiency tool. This structural transformation supports continuous partner data processing rather than periodic batch reporting, allowing compliance teams to deliver institutional-grade outputs with fewer resources. Their approach emphasizes narrow AI use cases with human-in-the-loop checkpoints and rigorous sandbox vetting, ensuring outputs are examiner-aware and reviewed by specialists before influencing decisions, thereby balancing automation with essential human oversight.
Agentic AI enhances compliance effectiveness and customer experience by providing teams with superior visibility and audit tools, enabling faster, more accurate interventions without supplanting human judgment. This dual benefit is evident in credit unions and banks where AI automates routine tasks like fraud alert triage and dispute intake, freeing employees to focus on complex problem-solving and relationship management. However, maintaining high standards of accuracy, explainability, and subject matter expert involvement remains critical, especially in regulated workflows where every AI-driven interaction must be auditable and transparent.
The primary challenge in AI integration lies in harmonizing advanced AI capabilities with legacy infrastructure, data quality, regulatory demands, and organizational culture. Top banks are adopting comprehensive AI-at-scale blueprints that reimagine business functions, roles, governance, and data engineering to support multi-stream, multi-project programs rather than isolated use cases. This holistic approach ensures AI outputs are reliable and decision-ready, enabling faster, more consistent outcomes while embedding responsible governance frameworks with clear guardrails, ongoing monitoring, and defined review points to sustain trust and compliance.
Consumer Risk at a Tipping Point
Regulatory delays and weak controls leave consumers vulnerable to AI-driven financial crime and cyber threats, forcing firms to prioritize robust governance over speed of adoption.
The FCA Mills Review starkly warns that regulatory delays in addressing AI adoption expose consumers to 'huge risk,' as insufficient oversight heightens vulnerabilities to financial crime and cybersecurity threats. Industry leaders echo this urgency, emphasizing that without timely regulatory action, AI's capacity to accelerate access and sharing of inside information—especially through autonomous agentic AI systems—could amplify market abuse risks and undermine consumer protection. This dynamic challenges compliance teams to adapt existing governance and accountability frameworks to the AI era rather than await AI-specific rules, underscoring the critical need for robust controls around data access, audit trails, and permissions to safeguard market integrity.
The rise of frontier AI intensifies cybersecurity threats, prompting coordinated responses such as Singapore’s AI-Driven Cyber and Technology Risk Taskforce and calls from Bank of England Governor Andrew Bailey for rigorous stress and penetration testing. Bailey stresses that banks must 'strengthen their detection efforts and responses, patch vulnerabilities faster, and be able to recover when things do go wrong,' highlighting that policies alone are insufficient. This regulatory push for verifiable assurance and international cooperation aims to mitigate cross-border risks and protect consumers from AI-driven cyber incidents that could disrupt operations and erode trust in financial markets.
Within insurance and investment sectors, the FCA underscores that governance quality trumps adoption speed for consumer protection. While smaller brokers and MGAs may adopt AI rapidly due to lighter oversight, this can increase exposure to cyber incidents, as exemplified by Anthropic’s revelation of state-sponsored manipulation of its Claude Code AI. The FCA now demands firms demonstrate that AI delivers good customer outcomes through transparency and auditability, especially given AI’s limited explainability in sensitive applications like personal lines pricing. Concurrently, rapid growth in investment firms without commensurate governance and updated controls risks operational and value harms, reinforcing that strong risk management is essential to prevent foreseeable consumer harm amid evolving business models.




