On 6 July 2026, the Financial Conduct Authority (FCA) published the Mills Review into artificial intelligence (AI) and the future of retail financial services.

Background

On 27 January 2026, the FCA announced that it was launching a review into the implications of advanced AI on consumers, retail financial markets and regulators. The review was be led by Sheldon Mills and the FCA was seeking views on 4 interrelated themes:

  • How AI could evolve in the future, including the development of more autonomous and agentic systems.
  • How these developments could affect markets and firms, including changes to competition and market structure and UK competitiveness.
  • The impact on consumers, including how consumers will be influenced by AI but also influence financial markets through new expectations.
  • How financial regulators may need to evolve to continue ensuring that retail financial markets work well.

Summary

The review highlights that advances in AI will be a systemic driver of changes in financial services and that, related to this, there will be four system shifts that will reshape financial services until 2030. As a result, the review highlights that the regulatory framework will need to evolve to in light of these changes and the role the FCA can play in this, in particular recommending seven priority recommendations. In summary:

The systemic driver: Advances in AI capability

Key findings in relation to AI capability include:

  • AI capability is advancing rapidly and is likely to keep doing so to 2030 and beyond, transforming what firms and consumers can do with AI.
  • Agentic AI is enabling a shift from assistance to delegation, with systems taking on longer tasks and more actions within firm and consumer workflows.
  • Capable models still require controls for reliability, consistency, explainability and accountability, alongside human oversight as more is delegated to them.
  • Future architectures are likely to change what is possible, making AI more efficient, explainable, adaptable and aware, and potentially more general.
  • Artificial General Intelligence (AGI) and quantum are disruptive uncertainties with unknown timing but far-reaching potential consequences, so firms and regulators should prepare now.

Four system shifts

In light of this, the review highlights that four shifts will define the market between now and 2030, and sets out the following observations:

  • The transformation of firms: Retail financial services firms are moving from using AI as a tool to deploying increasingly autonomous systems across functions such as customer service, underwriting, compliance, claims handling and product design. By 2030, AI could become the primary means by which leading firms process information, serve customers and demonstrate outcomes. As this happens, employees’ roles are likely to shift from direct decision-makers to supervisors who monitor performance and intervene when necessary. Firms will need new skills, stronger governance and enhanced model risk management, particularly where they rely on third-party providers. While AI could significantly boost productivity and economic growth, consumers will benefit only if firms remain accountable and competition remains effective.
  • New consumer journeys: AI is likely to transform how consumers engage with financial services, with increasing use of AI agents that act on their behalf. Over time, these systems could move beyond providing information and recommendations to delivering ongoing financial management within agreed parameters. This has the potential to improve outcomes, address persistent issues such as low switching rates, advice and protection gaps, and better support those with lower financial capability. However, risks remain, including bias, opaque pricing and personalised manipulation. Consumer trust, control and the ability to understand and challenge AI-driven decisions will be critical. While unequal access could widen financial inclusion gaps, well-designed AI services could significantly improve outcomes for many consumers.
  • A reshaped competition landscape: AI could significantly reshape competition in financial services. On one hand, it may lower barriers to entry, support innovation and enable digital-native firms to scale quickly, potentially delivering better products and lower costs for consumers. On the other, firms may become increasingly dependent on powerful AI providers that control critical technology, data and computing resources. Control of AI-driven customer interfaces could become a key source of market power, influencing which products consumers see and choose. This may shift customer relationships away from financial services firms towards AI platform providers. For regulators, these developments raise important questions about competition, consumer protection, market concentration and how regulatory boundaries should apply to AI-enabled services.
  • Amplified financial crime and cyber risk: By 2030, AI is likely to increase both financial crime threats and the tools available to combat them. Those committing fraud will be able to use AI to create deepfakes, synthetic identities and highly personalised scams that are cheaper, faster and more difficult to detect. As consumers increasingly rely on AI agents to manage financial activities, vulnerabilities could spread more quickly across interconnected systems. At the same time, AI can strengthen defences by improving fraud detection, cybersecurity monitoring and regulatory oversight. To remain effective, firms, regulators and law enforcement will need access to comparable AI capabilities and stronger information-sharing arrangements to identify, prevent and respond to emerging threats before significant harm occurs.

Regulatory implications of AI-enabled finance

Based on the observations about the systemic driver and related systemic shifts the review makes clear that the regulatory framework will need to evolve, in summary it finds:

  • The overall regulatory framework remains sound but is under strain: The review sets out that the overall regulatory framework remains sound due to the principles and outcomes-based approach, including the Consumer Duty, Senior Managers Regime (SMR), operational resilience and other key features, that were designed to flex across changing business models. However, the review also suggests that the question is therefore how the framework can be applied as the human role changes and the AI systems operate with greater autonomy.
  • Senior Managers Regime: The SMR allocates responsibility for regulated activities to named individuals and requires them to take reasonable steps to prevent regulatory breaches and, therefore, it can act as an important safeguard against firms pursuing AI-driven growth without adequate oversight, ensuring personal accountability remains central. The regime is generally considered robust where AI supports human decision-making, but greater autonomy and opacity may create challenges in identifying responsibility and maintaining meaningful human control. Clearer regulatory guidance on the reasonable steps expected of senior managers, supported by AI assurance tools and monitoring, could increase firms’ confidence in adopting advanced AI while maintaining accountability, consumer protection and market integrity.
  • Operational resilience: The UK’s operational resilience framework requires firms to identify important business services, set tolerance levels for disruption and ensure they can continue operating during incidents. The Critical Third-Party regime complements this by bringing systemically important service providers under regulatory oversight. Firms can manage AI-related risks through dependency mapping, contingency planning and resilience testing. However, AI may create new systemic risks that extend beyond individual firms, including shared reliance on the same models, correlated decision-making and concentration among technology providers. These ecosystem-wide vulnerabilities could increase the risk of widespread disruption, requiring closer coordination between firms, regulators and critical technology providers.
  • Regulatory perimeter: The UK regulatory perimeter determines which financial activities require FCA authorisation and is based on the activity being carried out, rather than the technology used. This approach generally remains effective for AI-enabled financial services. However, AI may create new challenges where influential AI platforms shape consumer decisions without clearly performing regulated activities. This could create gaps between where financial influence sits and where regulatory protections apply. Competitive tensions may also arise if AI platforms exert similar influence to regulated firms without equivalent obligations. As consumer reliance on AI grows, regulators may need to clarify regulatory boundaries to maintain consumer protection, competition and innovation.
  • Advice guidance boundary review: The advice/guidance boundary distinguishes regulated financial advice, which involves personalised recommendations and requires FCA authorisation, from guidance, which provides information without recommending specific actions. The introduction of targeted support allows firms to offer recommendations to groups of consumers with similar characteristics, helping to address the advice gap. AI could extend this further by delivering highly personalised support at scale, improving financial inclusion and decision-making. However, increasingly sophisticated AI may blur the distinction between advice and guidance, create consumer protection risks and enable regulatory arbitrage where unregulated AI platforms provide advice-like services. Regulators may need to review the framework as AI capabilities evolve.
  • The Consumer Duty: The Consumer Duty requires firms to deliver good outcomes for retail customers by providing suitable products, fair value, effective communications and appropriate support. While the framework applies readily where AI supports human decision-making, greater AI autonomy creates new challenges. AI-driven pricing may make it harder to distinguish beneficial personalisation from unfair value extraction, while dynamic and personalised customer journeys can complicate efforts to demonstrate consumer understanding and informed consent. AI can improve customer support but may still require human involvement for complex issues. As firms increasingly deploy autonomous systems, clearer regulatory guidance may be needed on evidencing outcomes, maintaining meaningful consent and ensuring fair treatment across customer groups.
  • Enabling infrastructure for agentic finance: Agentic finance refers to AI agents acting on behalf of consumers and businesses to manage a wide range of financial tasks, from making payments to monitoring savings, switching providers, managing investments and handling claims. Its success will depend on trusted infrastructure that enables AI to act safely, transparently and accountably. Key challenges include consumer trust, control, consent and liability when things go wrong. Robust frameworks covering data access, identity, authority to act, transaction execution and accountability will be essential. If implemented effectively, agentic finance could reduce friction, improve financial inclusion, address advice gaps, boost productivity and support UK growth, innovation and competitiveness while maintaining consumer protection.
  • Implications for the regulator and supervisory model: The review suggests that the rise of AI will require significant changes not only within regulated firms but also within the FCA’s supervisory model. As AI becomes a core operational capability across financial services, the regulator will need to adopt an increasingly AI-enabled approach to supervision. An agentic supervisory model could improve efficiency through faster authorisations, real-time monitoring and more effective enforcement, while helping the FCA support both consumer protection and economic growth. AI could also strengthen the FCA’s ability to detect risks earlier, intervene more quickly and address harm at greater scale. At the same time, the regulator must keep pace with firms, consumers and bad actors who are increasingly using advanced AI systems. Supervision is therefore likely to evolve from periodic, retrospective reviews towards more continuous, proactive oversight. While firms will remain responsible for customer outcomes, the FCA will need greater capability to identify and monitor system-wide risks arising from shared AI providers, common models, automation and interconnectedness across the sector. Concentration, correlated behaviour and increasing complexity may create risks that are not visible through firm-by-firm supervision alone. Effective oversight will depend on high-quality, timely and structured data, enabling the FCA to monitor emerging risks across the financial system while maintaining appropriate human oversight, transparency and accountability.
  • International co-operation: AI creates cross-border dependencies on shared models, cloud infrastructure and technology providers, meaning disruptions or failures can have simultaneous global impacts. As a result, regulators will need stronger international cooperation, information-sharing and coordinated responses to AI-related risks. Stakeholders across jurisdictions broadly recognise both the opportunities and risks of AI, including financial crime, data flows and reliance on global providers. Although international principles and guidance are emerging, regulatory approaches remain fragmented, reflecting differing national priorities and levels of AI capability. Over time, more structured supervisory cooperation, engagement with AI providers and greater alignment on standards and agentic finance protocols may be needed to manage systemic risks effectively.

Seven priority recommendations

The review concludes that the analysis points to clear opportunities to support greater productivity and growth in UK financial services and that the FCA should proactively adapt the regulatory framework to enable safe, trusted and innovative AI adoption by firms and consumers, while mitigating emerging risks. As a result, the review sets out seven priority recommendations for the FCA Board to consider with the Executive, namely:

  • Secure and adapt the regulatory perimeter: In the short terms the review recommends, that the FCA consider the impact of general-purpose AI and large language models on retail financial services to ensure the regulatory perimeter remains fit for purpose. The review should assess how consumers use AI across savings, investments, pensions, mortgages and debt management, and evaluate implications for consumer protection, competition, innovation and market integrity. It should also examine potential regulatory gaps, including the application of advice and guidance rules, financial promotions and “by way of business” tests in AI-enabled journeys. The FCA could then decide whether guidance, perimeter changes or legislative reform are required. In the longer term, the review recommends that the FCA should continue monitoring AI developments and consider enhanced regulatory powers if growing AI adoption creates regulatory gaps or systemic risks.
  • Strengthen system-wide coordination and oversight: The review recommends that the FCA strengthen coordination across UK regulators and international partners to manage the opportunities and risks created by AI. In the absence of a dedicated AI regulator, effective cooperation will be essential across areas including resilience, competition, consumer protection, data governance, security and supervisory standards. Greater international collaboration may also be needed to address shared dependencies on AI models, cloud infrastructure and technology platforms, and to coordinate responses to cross-border incidents. The FCA should assess whether existing coordination arrangements remain effective and, where necessary, support enhanced cross-regulatory frameworks or new mechanisms to address emerging AI-related systemic risks.
  • Monitor the transition to autonomous models and adapt regulatory frameworks: The review recommends that the FCA monitor the transition towards more autonomous AI and adapt regulatory frameworks accordingly. As AI becomes a core operational capability and agentic finance develops, decision-making will increasingly be shared between humans and AI systems, accelerating innovation but also creating new risks. The FCA will need to clarify how existing accountability, governance and consumer protection frameworks apply in this environment. Firms’ model risk management frameworks will also need to evolve to address challenges such as model drift, bias, opacity and unexpected behaviours. The FCA and PRA should support the development of more dynamic AI governance, monitoring, assurance and explainability practices to maintain effective oversight.
  • Scale up the FCA’s AI Lab to support AI models and system innovation in financial services: The review recommends that the FCA establish a dedicated capability within its AI Lab to assess AI models and systems used in financial services, with particular focus on emerging and increasingly powerful technologies. Working with firms, model developers, researchers and technical experts, this function would support early engagement, knowledge sharing, technical assessment and practical testing where appropriate. The aim is to help the FCA understand how new AI capabilities could affect regulated activities before they become widely adopted. This would strengthen the FCA’s ability to address issues such as explainability, governance and assurance, while supporting responsible innovation, growth and the UK’s position as a leader in AI-enabled financial services.
  • Enable the foundations for agentic finance: The review recommends that the FCA should consider leading the development of a trusted framework for AI agent participation in financial services, clarifying how agents can be authorised, identified and held accountable, creating the conditions for safe adoption of more autonomous AI-enabled services.
  • Build and adopt an AI-enabled agentic supervisory model: The review recommends that the FCA develop an AI-enabled agentic supervisory model to improve both firm-level supervision and system-wide oversight. The approach would enhance efficiency across the regulatory lifecycle, including authorisation, supervision and enforcement, while helping the FCA identify emerging AI-related risks this would be intended to complement, not replace, human judgement and existing supervisory frameworks. By enabling more continuous monitoring and faster intervention, the model could improve consumer protection and regulatory effectiveness. It would also support the FCA’s growth objective by streamlining authorisations, supporting innovation and strengthening oversight of risks arising from shared AI models, data, infrastructure and technology dependencies across the financial system.
  • Develop a trusted public-interest AI-enabled financial capability service: The review also recommends that the FCA take a more proactive role in promoting financial capability and ensuring access to trusted AI-enabled financial services. As consumers increasingly rely on AI to obtain information, compare products and make financial decisions, access to high-quality support should not depend on the ability to pay for premium AI tools. The FCA should work with government, industry, consumer groups and the Money and Pensions Service to explore a free, publicly accessible AI-enabled financial support service, such a service could provide reliable information, guidance and support, helping improve financial inclusion, consumer outcomes and confidence in AI-enabled financial services.

Our comments

Jonathan Herbst:

“The report shines a light on a fundamental regulatory question – if consumers increasingly rely on AI systems provided by a small number of technology companies to make financial decisions, does it still make sense for those services to sit largely outside the traditional regulatory perimeter? Mills is not proposing an immediate crackdown on Big Tech, but he is asking whether the rules need to evolve to reflect how financial services are actually being delivered. That’s a big question for policymakers and one that will only become more pressing as AI adoption accelerates.”

Matt Gregory:

The seven recommendations in the Mills Review will shape the evolution of the regulatory framework for retail financial services at pace.

“Mapped against an AI autonomy spectrum, the report identifies a series of pressure points in the current regulatory framework, with operational resilience and the regulatory perimeter suffering pressure points in the near term. As a result, the report calls for the FCA to consider undertaking an urgent review to secure and adapt the regulatory perimeter, to consider greater coordination between authorities and to lay the foundations for agentic finance – effectively building the structures to ensure that the regulatory framework remains fit for purpose as agentic models advance.

“What all of this means is that we can expect a substantial new phase of work to be undertaken by the FCA, with potentially significant implications for the landscape of all retail financial services in the months and years ahead. The report identifies significant shifts in market dynamics towards new forms of AI-mediated retail financial services.

“As the FCA identified in its recent technology horizon scan, personalised intelligence and programmable finance could radically change the ways firms design, distribute and deliver products and services – and consumers’ own use of advanced models will change how markets function as a whole. Acknowledging the transformative potential of the AI autonomy spectrum for consumers, the report is clear-sighted on the significant risks they pose and there are calls for some significant developments to the financial services framework to address them.

“The report identifies five areas in which the current regulatory framework is likely to suffer stress as firms move across the AI autonomy spectrum. Operational resilience and the regulatory perimeter stand out as more likely to suffer stress in the nearer term. The SMCR and Consumer Duty are also highlighted as being under stress, in circumstances where the relationship between humans and AI systems moves towards humans as observers – where AI acts within boundaries which are monitored by humans.

“Stepping back, it is clear that firms are no longer masters of their own destiny in connection with their response to the rise of AI systems. Changing consumer use, the evolving role of the consumer in conjunction with their AI agents, and the increasing deployment of AI systems by other firms and within system infrastructure means that firms must adapt their governance models now.

“As well as setting out a call to action for the FCA, the report challenges firms to reconsider the necessary make-up of internal skills, experience and expertise to respond effectively to this changing world. There are numerous insights for firms grappling now with questions of accountability, oversight and liability when ‘things go wrong’.”