Financial Services AI Adoption Plan: HM Treasury accepts independent AI Champions’ recommendations
On 14 July 2026, HM Treasury (HMT) published the Financial Services AI Adoption Plan, prepared by its independent AI Champions. HMT has welcomed the Adoption Plan, accepted its recommendations and confirmed that it will work with regulators and industry on next steps. This includes considering the AI Champions’ work alongside other relevant developments in this area, such as the Financial Conduct Authority’s (FCA) recent Mills Review (see our coverage of the final report of the Mills Review here).
The Adoption Plan sets out practical steps for the UK government, regulators and industry, including:
- ten recommendations focused on immediate actions and initiatives to support near-term scaling and consistent adoption of AI, spanning five areas: regulatory framework, regulatory perimeter, resilience, skills and agentic payments readiness; and
- three broader considerations for the UK government as it develops its wider AI strategy, including longer-term actions to manage systemic risks and support the UK’s competitiveness.
Regulatory clarity on the use of AI in financial services has been an ongoing focus for the UK regulators and industry. The Adoption Plan takes a step towards translating those considerations into more concrete priorities and initiatives.
In this blog post, we discuss the key themes from the Adoption Plan.
Regulatory clarity
The Adoption Plan highlights the importance of greater regulatory coordination. It identifies as a high priority the need for regulators, including the FCA, the PRA, the Information Commissioner’s Office (ICO) and the Competition and Markets Authority, to work together to provide firms with clearer and more accessible support as they adopt AI. This includes greater clarity on how existing regulatory frameworks apply to common AI and agentic use cases, as well as making regulatory initiatives easier for firms to navigate.
One practical proposal is the creation of a Financial Services AI Adoption Support Hub, which provides a central information portal for current initiatives (including FCA AI Lab updates and ICO agentic reports), alongside access to supervisory and subject matter experts for novel use cases. If implemented effectively, the Hub could indeed reduce duplication across regulators and provide firms with a more coherent route for regulatory engagement.
Regulatory perimeter
The Adoption Plan recommends that the FCA undertake a comprehensive review of the consumer, competition and wider market impacts of financial guidance and advice-like outputs generated by general-purpose large language models (LLMs). This aligns with the recommendation in the FCA’s recent Mills Review, which proposed that such a review should be launched within the next three to six months. The Adoption Plan emphasises that any review should support innovation, rather than unduly constrain and in doing so risk limiting the consumer benefits it could unlock. The Adoption Plan recognises that, if deployed within an appropriate regulatory framework, AI-driven advice could fundamentally reshape advice provision by making it lower cost, more personalised and available at scale. The Adoption Plan notes the potential to address the UK’s longstanding ‘advice gap’ by changing the underlying economics of advice in a way that previous initiatives have been unable to achieve.
Critical Third-Party Regime
The Adoption Plan calls for an acceleration of the implementation of the Critical Third-Party (CTP) regime, including assessment of key AI/cloud providers. This follows the designation, from 13 July 2026, of four major global cloud services and technology providers as CTPs. The UK government has emphasised that it is “taking a targeted and proportionate approach” to the CTP regime, with further providers expected to be designated over time where necessary to protect the resilience of the UK financial system.
Industry-led initiatives as a bridge to regulatory clarity
A notable feature of the Adoption Plan is the extent to which it looks to industry to develop solutions ahead of formal regulatory intervention. Consistent consumer disclosures for AI-driven services, an AI incident and ‘near-miss’ repository and a third-party AI assurance scheme for financial services are all envisaged as voluntary, industry-led initiatives rather than regulatory mandates.
AI technology is arguably evolving far more rapidly than legislative or regulatory reform can realistically keep pace with. By encouraging industry to develop these frameworks first, the Adoption Plan gives firms an opportunity to help shape emerging market standards, which regulators may later incorporate into supervisory expectations or build upon. Rather than waiting for regulatory requirements to take shape, firms have a chance to influence the standards that could ultimately define good practice across the sector.
Skills and talent
The skills and talent recommendations deserve attention too. Beyond the headline proposals for a sector-wide AI skills plan and visa reform, the more significant message is that AI capability is becoming a governance consideration for firms.
As more responsibilities are delegated to AI, senior managers will need sufficient AI literacy to understand the risks in an AI-enabled environment and to take "reasonable steps" to prevent regulatory breaches. This has clear implications for accountability under the Senior Managers and Certification Regime. Firms should expect AI capability to become an increasingly important factor in how regulators assess effective oversight and whether senior managers have discharged their responsibilities.
The FCA is expected to publish practical guidance later this year on accountability and the level of assurance expected from senior managers for harm caused through the use of AI, following stakeholder feedback on the Mills Review and recommendations from the Treasury Select Committee earlier this year.
Agentic payments readiness
The Adoption Plan was published on the same day as HMT’s consultation on modernising payment services regulation, which the Adoption Plan itself identifies as an opportunity to establish a ‘trust framework’ to support agentic payments. The framework would need to address a range of foundational issues, including legal and liability frameworks, know your agent protocols, and authentication and governance.
This work starts from a genuine gap in the current framework: the UK does not currently define AI agent identity or require agent verification, nor is there a registry of AI agent operators. As a result, where an AI agent initiates a payment, it would reach a firm with no verified identity, no registered accountability and no reliable way to distinguish a legitimate agent from an impersonator.
The Adoption Plan suggests that focusing on agentic payments provides a ‘highly practical proxy’ for a wider set of emerging financial services use cases. This closely mirrors the conclusions of the FCA’s Mills Review, which recommends that the FCA take a leading role in developing a trusted framework for AI agent participation in financial services. In particular, the Review identifies two approaches as the most viable: the building of a ‘trusted agent protocol’ that firms would follow when designing and deploying AI agents, and the development of ‘trusted agent standards’ into Open Finance.
Legal and liability frameworks for AI agents are likely to be among the most challenging issues to resolve if financial services firms and consumers are to adopt increasingly autonomous AI use cases with confidence. The Adoption Plan reflects a wider policy debate on this issue. In his speech at the Financial and Professional Services Dinner on 14 July 2026, Andrew Bailey highlighted the difficult question of how liability should be allocated where an AI agent with no legal persona acts on behalf of a principal. As he observed:
[T]ypically, in law a principal becomes responsible for an agent while the agent operates within the remit given to it by the principal. If the agent goes beyond that remit, or acts improperly, it becomes responsible. Traditionally that had depended on the agent having a legal persona, i.e. being a human or a company etc. But when the agent has no legal persona does that leave the principal responsible at all times? If so, principals may need to constrain agents in ways that cut against the direction of innovation in AI models.
This debate is also beginning to crystallise elsewhere. On 7 July 2026, the UK Jurisdiction Taskforce published its legal statement on liability for AI harms, concluding that existing common law is sufficiently flexible to address many legal issues arising from AI. At the same time, it identified specific gaps that the UK government needs to address, including whether product liability law applies to both AI-embedded products and standalone AI software as well as situations where harm occurs but negligence cannot be evidenced.
Looking ahead
These developments suggest that 2026 will be a formative year for the UK’s regulatory approach to AI in financial services. The Adoption Plan, the Mills Review and HMT’s consultation on modernising payment services regulation point towards a shared set of priorities: improving regulatory coordination and clarity, developing a workable trust framework for agentic payments, reassessing the regulatory perimeter, implementing the CTP regime and addressing questions of legal accountability and liability.
We will continue to track these developments and their implications for firms.
