From assistant to decision-maker: the FCA’s Mills Review charts AI’s path through retail financial services
On 6 July 2026, the UK Financial Conduct Authority (FCA) published the much anticipated final report of the Mills Review (see our earlier coverage on the Review’s engagement paper here). The Review explores how artificial intelligence (AI) could reshape retail financial services by 2030 and beyond and sets out seven priority recommendations for how the FCA should respond to that transformation.
The Review is the latest in a growing body of regulatory thinking on the use of AI in financial services (see our recent coverage on emerging regulatory expectations for governance and operational resilience here). Taken together, these publications provide an increasingly clear indication of financial services regulators’ evolving expectations for firms deploying AI.
Importantly, the Review does not recommend AI-specific regulation, nor does it propose wholesale reform of the existing UK regulatory framework. Instead, it concludes that the current framework provides a strong foundation for AI-enabled finance. At the same time, it recognises that a number of existing regimes, including operational resilience, the regulatory perimeter, the advice guidance boundary, the Senior Managers Regime and the Consumer Duty, will come under increasing pressure as AI evolves from an assistive tool to autonomous systems capable of acting on behalf of firms and consumers. The Review therefore recommends a ‘disciplined and progressive’ adaptation of the existing framework to ensure it can continue to deliver good outcomes for consumers while supporting innovation, competition and growth.
In this briefing, we highlight our key takeaways from the Review and consider what they may reveal about the FCA’s emerging approach to regulating the use of AI in retail financial services.
1. The real AI revolution is the shift from assistance to delegation
The Review’s central insight is that retail financial services are undergoing a fundamental shift from human-led, episodic financial activity towards services that are AI-enabled, continuous and delegated. As the Review observes, “AI becomes more significant for financial services when it moves from supporting action to taking action.” This shift from assistance to delegation, driven by agentic AI, underpins almost every aspect of the Review.
To illustrate this transition, the Review introduces an ‘AI autonomy spectrum’ capturing the evolving role of the human: from using AI as an on-demand supporting tool (the ‘Operator’ stage), through increasing levels of collaboration and consultation with the AI, to humans acting primarily as ‘Approvers’ and, ultimately, ‘Observers’ who monitor outcomes rather than making decisions, as the AI system acts continuously within boundaries set in advance.
The Review anticipates that by 2030, leading firms in their respective retail markets are likely to have embedded AI into almost every aspect of their business. Indeed, it may become the principal method by which they serve customers, process information and evidence outcomes. The Review also observes that initial deployments of AI by retail financial services firms have mostly had limited autonomy, with humans still being ‘Operators’ or ‘Collaborators’. With current deployments setting the foundations for later expansions, future AI use cases are expected to become more autonomous. As operations, front office, risk and compliance evolve along the ‘AI autonomy spectrum’, the degree of autonomy will depend on factors including the risk of the activity, the reversibility of decisions and the strength of governance. A risk-tiered model may, for example, provide for greater automation for routine tasks that are easy to reverse and stronger human controls for actions that are high value or material to customer outcomes.
AI adoption will also be shaped by consumer demand and acceptance. Research commissioned for the Review found that consumers are currently most comfortable with AI acting as an aid rather than a decision-maker. However, consumer appetite for delegation is already emerging: one in five UK adults are open to AI making decisions for them, suggesting the shift to agent-led customer journeys is credible. Consumer demand for AI appears strongest in areas where decisions are complex, high-stakes or hard to navigate, including debt advice, pensions and investments.
As autonomy grows, the nature of regulatory risk also changes. Concepts such as accountability, auditability, human oversight, consumer protection and redress become considerably more complex. Much of the Review can therefore be understood as an attempt to prepare firms and the FCA regulatory framework for a future in which delegation, rather than assistance, becomes the defining characteristic of AI in retail financial services.
2. Governance will need to evolve as AI becomes a core operational capability
The Review suggests that governance will become an increasingly important differentiator, and potentially a competitive advantage, as firms deploy AI more widely and with greater autonomy. While existing governance and model risk management frameworks provide a strong foundation, the Review acknowledges that AI will place new pressures on these arrangements. We expect a key focus for the FCA will be whether firms’ governance evolves in step with their use of AI.
The Review highlights several areas where governance may need to adapt to address challenges with general purpose and frontier AI models. It points to the need for a shift from validation at the point of deployment towards live monitoring for issues such as model drift, model degradation and outliers. This reflects the fact that, unlike traditional models, AI models may update continuously, draw on third-party inputs and produce probabilistic rather than deterministic outputs, which can produce outputs that are plausible but incorrect.
Firms’ governance arrangements must also evolve to address increased financial crime and cyber risks. Firms will need clear permissions, effective monitoring and auditability, as well as robust escalation mechanisms. The Review emphasises that “these are not additional safeguards, but the conditions that enable AI to be deployed in regulated environments.”
The Review identifies firm-level controls of AI as a cornerstone of effective governance, emphasising that “capable models still require controls for reliability, consistency, explainability and accountability, alongside human oversight as more is delegated to them.” In other words, better models do not reduce the need for controls; they increase it.
The Review envisages controls operating across the entire AI lifecycle rather than focusing solely on the model itself. Firms will need to consider the quality of data inputs, pre-deployment testing and on-going monitoring. The implication is that regulatory scrutiny will increasingly focus on whether firms can demonstrate that their AI systems remain reliable and appropriately controlled in practice, rather than simply showing that a model performed well during development or at deployment.
A recurring theme throughout the Review is explainability. It notes that AI models may produce different answers to similar questions, creating challenges for firms that are expected to provide consistent treatment, maintain clear audit trails and deliver explainable outcomes: as the Review states, “[a] useful answer is not enough if the basis for it cannot be reconstructed.” The Review therefore points towards an expectation that firms maintain robust records and governance processes capable of tracing how AI-assisted decisions were reached.
The Review also signals a more nuanced approach to human oversight. Rather than treating ‘human in the loop’ as a safeguard in itself, it questions whether that oversight is genuinely capable of providing meaningful challenge. Human review will only be effective where the reviewers have access to the right information and are able to interrogate AI outputs. The Review suggests that firms will need to decide where human approval is required, what reviewers should see and how challenge should be recorded. Those decisions should be calibrated according to the risk of the activity and whether an action can be reversed.
3. Fraud and financial crime: strengthening resilience against AI-enabled threats
The Review recognises that AI is likely to amplify fraud and cyber risks in the near future. By 2030, it anticipates that AI will make fraud faster, cheaper, more scalable and harder to spot. Cloned voices, synthetic identities and AI-generated content lower the barrier to entry for criminals, while consumer delegation to AI agents creates a further vulnerability, as consumers who stop challenging automated decisions become easier to exploit. The Review notes that the same capability can cut both ways: well-governed AI could strengthen detection and disruption, but poorly governed AI may create false assurance or generate volumes of non-actionable alerts that overwhelm rather than support human oversight.
For firms, the practical implication is an ongoing evidential obligation. Firms should be able to demonstrate that their AI-enabled fraud controls improve detection, triage or disruption relative to existing controls, remain effective as threats evolve, and retain meaningful human control where decisions affect fairness, accountability or customer harm.
The Review also identifies a structural gap at system level. AI-enabled fraud will increasingly operate across firms, platforms, payment rails and jurisdictions, while the UK’s existing intelligence-sharing architecture remains, as described in the government’s call for evidence, a ‘complex patchwork’. The Review identifies a need for the FCA to develop clearer escalation routes and shared standards across public and private actors, with the Review identifying cross-firm and cross-sector coordination as critical to an effective response.
Beyond fraud, the Review warns that autonomous AI agents may execute attacks end-to-end with little human direction, at machine speed, requiring defence to be equally automated. It also flags the ‘harvest now, decrypt later’ quantum risk, where encrypted data captured today could be decrypted by future quantum computers, and recommends firms begin building “crypto-agility” (the ability to switch cryptographic methods) into their systems now.
4. Redress: preserving accountability in increasingly autonomous retail financial services
Consumer research commissioned for the Review found that 67% of consumers expressed high concern about a lack of protection if something goes wrong with AI in financial services, underlining the extent to which accountability and redress are central to consumer confidence in AI-enabled services.
The Review highlights that AI could reshape the redress landscape, with redress accountability featuring prominently in the context of priority recommendations 5 (agentic finance), 6 (agentic supervisory model) and 7 (public-interest financial capability service), and reflecting the need for systems-wide solutions. Where financial services are provided via partnerships between regulated firms and model providers, consumers may find it more difficult to understand whether responsibility sits with the firm, the model provider, the platform or an agent acting on their behalf.
The Review emphasises that trust in AI-enabled financial services will depend on consumers being able to understand decisions, challenge outcomes and access redress. For firms, this is likely to increase the importance of auditable records, clear complaints routes and an understanding of AI outputs to enable them to explain the basis for decisions to consumers. In particular, firms will need to ensure that decision logic is sufficiently documented to allow outcomes to be explained to consumers, and that complaints routes are clear even where a consumer’s journey involved parties outside the traditional financial services relationship, such as a third-party model provider or platform.
The Review notes that AI may transform the complaints process itself. While AI could improve access to redress by helping consumers understand their rights and prepare complaints, it could equally lead to a significant increase in low-quality, automated complaints that put extra strain on firms and the Financial Ombudsman Service (FOS).
Looking further ahead, the Review also considers a scenario in which consumer AI agents raise complaints and firm AI agents triage or resolve them. While the Review identifies this scenario as a potential efficiency gain, it notes that this would depend on systems being reliable, interoperable, auditable and capable of escalating complex or sensitive cases to human reviewers.
The Review recommends that the FCA should consider the impacts of changes on the redress system, incorporating them into its work with HM Treasury, the FOS, the Financial Services Compensation Scheme and firms.
It makes clear that resolving liability attribution is a commercial as well as a regulatory imperative. Where a regulated firm cannot clearly allocate responsibility for loss caused by a third-party agent, it is likely to require human-authenticated confirmation at each step of a transaction. The Review identifies this as a source of friction that prevents progress along the ‘AI autonomy spectrum’, giving firms a direct incentive to address accountability questions before deploying autonomous models rather than treating them as a secondary concern.
5. Control of the AI ‘interface’ – not the product – could become the next battleground for market power
One of the Review's more thought-provoking observations concerns competition: “as consumers use AI services to inform, compare options and act, the interface that interprets their intent may become the point at which competition is shaped.” The Review notes that those interfaces could determine which providers are visible, which products are compared, how trade-offs are explained and when action is taken. Accordingly, the Review notes that this creates a more complicated form of competition.
However, the Review also notes that the consumer interface will not be AI-mediated for everyone by 2030 and that AI-mediated competition will coexist with more traditional forms of competition. Some consumers may actively prefer non-AI human-led routes, particularly for complex, high-value or emotionally significant decisions.
The Review also highlights industry concerns about a level playing field. With retail financial services often being delivered as bundles of regulated and adjacent services, AI providers may be able to unbundle some parts, such as information, support or comparison, from outside the regulatory perimeter, and then monetise these through referrals, commissions or partnerships. The Review identifies that competition between activities inside and outside the regulatory perimeter may therefore become more complex.
6. The biggest systemic risks may sit outside individual firms
The Review acknowledges that the most significant change for the FCA to monitor is at system level. The FCA usually understands systemic risk through a prudential lens, focused on financial stability and confidence. As firms increasingly rely on common models, cloud providers, datasets and AI infrastructure, risks may emerge not because individual firms fail but because too many firms become dependent on the same underlying technologies.
The Review identifies the possibility of correlated behaviour, common points of failure, concentration risk and unexpected interactions between AI agents operating across firms and markets. Future supervision may therefore need to focus not only on how individual firms govern AI but also on how AI behaves across the wider financial ecosystem.
To combat these risks, the Review suggests that regulators will need AI-enabled supervisory capabilities to identify patterns across different firms, emerging harms and system-wide risks (referred to as the ‘Agentic Supervisory Model’). The Review also notes that deeper international cooperation on cross-border AI dependencies, collective monitoring of concentration and ecosystem vulnerabilities, and a coordinated response to incidents affecting multiple firms or jurisdictions simultaneously may be required.
7. Existing regulatory frameworks will need to evolve, not be replaced
The Review concludes that the UK’s existing regulatory framework remains sound. In particular, its principles and outcomes-based approach, including the Consumer Duty, the Senior Managers Regime, operational resilience requirements and the wider conduct framework were designed to apply across evolving business models and continue to provide flexible tools for governing AI deployment within FCA-regulated firms.
The key question is therefore how these frameworks should be applied as AI capabilities continue to develop. As firms move further along the ‘AI autonomy spectrum’, applying these existing frameworks becomes increasingly complex. The Review identifies a number of pressure points across the current regulatory regime that are likely to require further regulatory clarification and supervisory focus.
- Senior Managers Regime: the Review acknowledges that without guidance, the combination of greater opacity in AI-mediated decisions and factors such as model drift could make it harder for the regulator to identify a de facto responsible individual, or for senior managers to exercise and evidence ‘meaningful human control’ where appropriate. Stakeholder feedback has called for clearer guidance on what constitutes the ‘reasonable steps’ expected of senior managers to prevent regulatory breaches in an AI-enabled environment. In its January 2026 report on AI in financial services, the Treasury Select Committee (TSC) also recommended that by the end of 2026, the FCA should publish comprehensive, practical guidance for firms on accountability and the level of assurance expected from senior managers for harm caused through the use of AI.
- Operational resilience (including the operational resilience framework and the Critical Third Party (CTP) regime): the Review highlights that AI could introduce a new dimension of systemic risk that extends beyond the scope of firm-level resilience frameworks. These risks may arise from shared dependencies on common models, providers or infrastructure, as well as from the potential for correlated behaviours across firms using similar AI systems. The resulting concentration and interconnectedness could create new channels through which disruption propagates across the financial system, pointing to the need for closer coordination between firms and regulators. The Review’s observations sit within a broader regulatory focus on the role of critical technology providers in the financial ecosystem: the TSC has recommended that HM Treasury designate major AI providers as CTPs.
- Regulatory perimeter: the Review concludes that the FCA’s existing activity-based foundation remains broadly sound, capturing specified activities regardless of the technology used. However, general-purpose AI applications and platforms may increasingly influence consumer outcomes without clearly undertaking regulated activities, creating potential gaps between where influence over consumer outcomes sits and where regulatory protections apply. The Review noted that potential competitive asymmetry may emerge where regulated firms face obligations under conduct rules and financial promotion requirements, while platforms and model providers may exert similar influence without equivalent obligations. Evolving commercial models, such as referral arrangements and preferential routing, may further blur the boundary between regulated and unregulated activities. The Review therefore suggests that regulatory boundaries may require further clarification to maintain effectiveness.
- Advice guidance boundary and targeted support: the Review identifies greater complexity as AI enables increasingly personalised financial support. General-purpose large language models (LLMs) and frontier models may generate advice-like recommendations based on individual consumer information, potentially going beyond what targeted support currently allows while operating outside the regulatory perimeter. This raises concerns around regulatory arbitrage, as regulated firms report that they are constrained from offering similar personalised support while unregulated AI platforms may exert comparable influence without equivalent obligations. The Review recommends continued monitoring of the boundary as part of the FCA’s perimeter review, including whether future advances in AI capability could justify adapting targeted support or other measures to better enable firms to use AI on a more individualised basis.
- Consumer Duty: the Review’s observation is that as consumer journeys become more dynamic, personalised and delegated, demonstrating compliance will become more complex. For example, dynamic and tailored interactions could create challenges for firms in evidencing that consumers genuinely understand products, decisions and risks. AI-enabled pricing may make it more difficult to determine circumstances where consumers are paying more without receiving added value. Ensuring consumer understanding may become challenging where AI makes thousands of micro-decisions over time, raising questions about whether one-off consent remains sufficient. As AI increasingly influences product design and delivery, firms will also need to ensure that outcomes remain appropriate and fair across different consumer groups, including where models may reproduce historic biases. Stakeholders also highlighted that firms need a clearer understanding of how to evidence outcomes in dynamic journeys, particularly at high levels of autonomy.
8. Priority recommendations for AI-enabled finance
The Review sets out seven priority recommendations for the FCA Board to consider with the Executive. These are intended to support the FCA’s statutory objectives by maintaining effective consumer protection, preserving market integrity and promoting competition, international competitiveness and growth, as AI transforms retail financial services.
- Secure and adapt the regulatory perimeter: while the Review does not recommend an immediate expansion of the perimeter, it recommends that the FCA should launch a review within three to six months to assess the scale, nature and impact of general purpose LLMs outside the perimeter. Specifically, the review should examine how consumers use AI for personal financial management across areas such as savings, investments, pensions, mortgages and debt management. The FCA should consider the resulting implications for competition, innovation and growth, as well as the risks of consumer harm, market integrity concerns and regulatory arbitrage. The application of current legal and Handbook frameworks, including the Perimeter Guidance, would need to be considered where gaps emerge.
In the long-term, the Review recommends that the FCA should keep under review the impact of capabilities and increasing AI adoption on the effectiveness of the regulatory perimeter. To mitigate system-wide and cross-sectoral risks, the Review also recommends that the FCA consider requesting the government boost to the FCA’s powers under the CTP regime (currently restricted to systemic issues) and the Designated Activities Regime, and giving direct powers under the Digital Markets, Competition and Consumers Act 2024 to the FCA and other sectoral regulators.
- Strengthen system-wide coordination and oversight: the Review recommends that the FCA considers strengthening domestic and international coordination to address the risks and opportunities that AI could deliver, including fraud, financial crime and cyber-risks and cross-border AI systemic risks.
- Monitor the transition to autonomous models and adapt regulatory frameworks: as firms and consumers move along the ‘AI autonomy spectrum’, the FCA will need to continue clarifying how key accountability, governance and consumer protection frameworks apply. Firms remain accountable for outcomes, even where aspects of model behaviour or performance sit outside their direct control, but challenges may arise in evidencing how outcomes are delivered, demonstrating reasonable steps or identifying the source of errors, bias or harm. This may require further clarification and closer supervisory attention. Although Law Commission statements provide that AI systems do not have legal personality and therefore cannot be sued or prosecuted, engagement with stakeholders points to ongoing debates. The Review therefore suggests that by monitoring developments in this area, the FCA will be able to identify where clearer interpretations and more substantive adaptations may become necessary.
- Scale up the FCA’s AI Lab to support AI models and system innovation in financial services: the Review recommends that the FCA considers establishing a structured capability, anchored in the AI Lab, to assess AI models and systems used in financial services. This would provide a practical forum for the FCA to engage with firms, model developers, researchers and technical experts earlier in the development cycle to understand how new capabilities are being developed, adapted and governed for financial services, and to identify opportunities where emerging model capabilities could address current regulatory, governance and assurance challenges.
- Enable the foundations for agentic finance: the Review recommends that the FCA considers taking a leading role in developing a trusted framework for AI agent participation in financial services, providing greater clarity on how AI agents should be authorised, identified and held accountable. Rather than creating a new regulatory regime, it envisages a targeted, principles-based framework that builds on existing regulatory foundations. The Review identifies two approaches as the most viable: the building a ‘trusted agent protocol’ that firms would follow when designing and deploying AI agents, and the development of ‘trusted agent standards’ into Open Finance. Together, working either sequentially or in parallel, these measures are intended to establish the technical and governance foundations needed to enable adoption while ensuring that accountability remains clear and enforceable.
- Build and adopt an AI-enabled agentic supervisory model: the Review recommends that the FCA considers developing AI-enabled tools across authorisation, supervision, enforcement and administrative processes, initially at the ‘Consultant’ and ‘Approver’ levels. More fundamentally, it sees agentic AI as an opportunity to move from an episodic, document-based supervisory model towards one that is more continuous, risk-based and intelligence-led. Supervisory agents could support activities such as triaging firm submissions, testing evidence against regulatory expectations, generating information requests, maintaining issue logs and supporting earlier intervention.
- Develop a trusted public-interest AI-enabled financial capability service: the Review recommends exploring the development of a free, inclusively designed, trusted AI-enabled financial capability and support system that provides consumers with access to reliable financial information, guidance and support from trusted sources. The recommendation reflects the Review’s recognition that the growing use of AI in financial decision-making could create new forms of exclusion, with consumers who lack access to reliable AI tools or sufficient AI literacy potentially left behind. It also acknowledges that market-led solutions may not, on their own, address longstanding gaps in financial capability, consumer protection and access to support. While the practical delivery model remains to be developed, the inclusion of this recommendation highlights the Review’s proposition that financial capability, vulnerability and digital access will increasingly need to be considered together.
Taken together, the recommendations suggest that, rather than introducing a standalone AI regulatory regime, the Review favours adapting existing legal and regulatory frameworks while investing in the supervisory capabilities and technical infrastructure needed to oversee increasingly autonomous financial services. They also signal a shift in regulatory focus towards enabling agentic finance and modernising supervision through greater use of technology.
For firms, this points to an increasing need for robust AI governance, effective assurance frameworks and high-quality data, not only to support compliant deployment and ensure good customer outcomes, but also to engage effectively with a more continuous, AI-enabled supervisory model.
9. Looking ahead
The Mills Review does not, in itself, change the rules that apply to firms today. It is a report to the FCA Board rather than a policy statement, and several of its more significant recommendations – from the perimeter review to any adaptation of the Senior Managers Regime, the Consumer Duty or the redress framework – would only take shape following further consultation. Its immediate value therefore lies less in new obligations than in the direction of travel it sets out, and in the focus the FCA is likely to apply to testing firms’ readiness for AI-enabled finance as that direction is followed.
In practice, the Review points to a number of concrete steps firms should be considering now, well ahead of any formal rule change:
- Map deployments against the ‘AI autonomy spectrum’: classifying existing and planned AI use cases as ‘Operator’, ‘Collaborator’, ‘Approver’, ‘Consultant’ or ‘Observer’ may become a reference point in UK supervisory conversations, and will help firms target governance investment where the pace of delegation is fastest.
- Review accountability records: with the TSC having called for the FCA’s guidance for firms on the level of assurance expected from senior managers for harm caused through the use of AI by the end of 2026, senior managers should take steps to ensure they are able to evidence how they maintain meaningful oversight of AI-mediated decisions, particularly where the basis for those decisions is not easily reconstructed.
- Revisit Consumer Duty evidencing: where consumer journeys are dynamic and personalised, firms should consider whether existing consent and outcome-testing methodologies remain adequate, or whether they need to be adapted for AI systems capable of generating many micro-decisions over the course of a customer journey.
- Track the perimeter review: the FCA’s potential review of general-purpose AI tools outside the perimeter, recommended by the Review to launch within three to six months, is worth monitoring closely – particularly for firms whose commercial models depend on referral, comparison or unbundling arrangements with unregulated AI platforms.
- Review third-party and infrastructure dependencies: firms relying on common models or shared AI infrastructure should factor in the possibility that major providers are designated critical third parties under the CTP regime by the end of 2026. Under the CTP regime, if the Bank of England, the Prudential Regulation Authority or the FCA considers a CTP has breached their rules, they may take a number of disciplinary measures against the CTP, including prohibiting the CTP from providing services to UK firms, prohibiting UK firms from using the CTP’s services and imposing conditions on the provision or receipt of the CTP’s services.
- Review AI-enabled fraud controls: firms using AI in fraud detection and financial crime prevention should consider now whether they can demonstrate that those controls improve on existing arrangements, remain effective as fraud typologies evolve and preserve meaningful human oversight where decisions affect fairness or customer harm. The Review signals that this will be an area of active supervisory focus.
Taken together, these steps point to a common theme. The FCA’s expectations will increasingly turn not on whether firms use AI, but on whether they can demonstrate – to the regulator and to their consumers – that they understand, control and can be held accountable for what their AI systems do. Firms that treat the Review as an early signal of that shift, rather than waiting for formal rule changes, will be better placed to respond as the FCA’s approach develops over the course of this year and beyond.
