Artificial intelligence has become central to the Labour Government’s plans for economic growth. The government’s Financial Services Growth and Competitiveness Strategy, published in July 2025, sets out a ten-year ambition for the UK to become the world’s most technologically advanced global financial centre. The Financial Conduct Authority (FCA) has moved apace to supercharge the adoption of AI in financial services and deliver a competitive regulatory environment.
More than 75% of UK financial services firms already use AI. AI has the potential to make financial services cheaper, faster and more accessible; improve fraud detection and credit assessment; personalise products; and give ordinary consumers access to analytical capabilities which were previously the preserve of professionals.
Pandora’s box has now been opened and there is no going back. AI is progressing from helping humans make decisions, to ultimately agentic finance, in which autonomous AI systems could act for us – selecting products, moving money, managing investments and executing transactions. The FCA’s own research suggests that one in five UK adults – around 11 million people – would be likely to use AI capable of acting autonomously within pre-set goals.
The potential benefits are enormous. So are the risks. What happens when consumers trust AI they do not understand? Who is responsible when it gets something wrong? What if the leading AI systems and the data on which they depend are controlled outside the UK, compromising our data sovereignty, and what happens if thousands of financial institutions and millions of consumers use similar models which reach the same conclusion and act at the same time?
Financial markets have always suffered from herding and feedback loops. AI potentially introduces automated herding at machine speed. At the extreme, could autonomous and interconnected AI amplify a financial shock at such speed that neither humans nor regulators can regain control? Could the technology intended to drive economic growth ultimately contribute to economic Armageddon?
Against that background, what protections do we have and, more importantly, are they enough?
Unlike the EU, the UK does not currently have a single AI statute, let alone a financial services AI statute. Instead, AI sits within a patchwork of existing financial, prudential, data protection, competition and consumer regulation.
The Bank of England, The Prudential Regulatory Authority (PRA) and the FCA have adopted a “technology-agnostic” approach. The FCA says it does not presently plan additional AI-specific regulation and has concluded that the risks arising from AI may be addressed through existing legislative and regulatory requirements. AI and the FCA: Our Approach
For consumers dealing with an FCA-regulated firm, the most important protection is the Consumer Duty. The firm remains responsible for consumer outcomes whether a decision or communication is produced by a person or an algorithm.
There are also governance protections. The Senior Managers and Certification Regime provides individual accountability, while the PRA’s SS1/23 Model Risk Management Principles require relevant banks to identify, govern, validate and mitigate model risk, including risks associated with AI and machine learning.
UK GDPR (data protection) requirements concerning fairness, transparency, accountability and data security apply where personal data is processed using AI.
The Digital Markets, Competition and Consumers Act 2024 also provides protections against unfair practices and gives the Competition & Markets Authority (CMA) significant powers over digital markets, although it does not provide an equivalent to the Consumer Duty or a private right of redress for economic loss.
Taken together, these are significant protections as regards regulated firms’ use of AI. The difficulty is that the next generation of AI may not fit comfortably within this architecture.
Recognising that the effect of the next phase of change and its pace “could be profound, having the power to reshape markets, change the way firms compete and how consumers use retail financial services”, FCA press release. the FCA commissioned Sheldon Mills to undertake a long-term review of how AI could transform retail financial services to 2030 and beyond. It is an unusually forward-looking exercise. Mills expressly considers the possibility that AI will become more autonomous, adaptive and interconnected, including systems capable of independent decision-making and continuous learning.
The Mills Review identifies four broad shifts:
Within those themes it recognises many of the problems that should concern us: hallucinations and inaccurate outputs; algorithmic bias; opaque decision-making; fraud and identity abuse; vulnerability and exclusion; consumers becoming over-reliant on AI; concentration amongst a small number of technology and infrastructure providers; cyber risks; and the possibility that increasingly autonomous and interconnected systems create new systemic vulnerabilities. Mills expressly recognises that AI could reduce consumer agency and that longer-term autonomy and interconnectedness could amplify existing risks and create new ones.
The Review nevertheless reaches a relatively reassuring conclusion. The UK’s existing principles-based and outcomes-focused framework is regarded as fundamentally sound. The answer is principally to adapt the existing framework rather than create a new financial services AI regulatory regime.
The Review makes seven priority recommendations:
There is much to welcome here. Particularly important is the recommendation that the FCA examine the scale and impact of general-purpose AI operating outside the regulatory perimeter. Mills also recognises that regulators themselves need considerably greater technological capability if they are to supervise firms whose technology may be developing faster than their own.
But there is an interesting tension at the heart of the Review. It recognises increasing autonomy, opacity, interconnectedness, cyber threats and concentration as risks, while simultaneously recommending that the UK “enable the foundations for agentic finance”.
That deserves closer examination.
Imagine a consumer approaching retirement with £100,000 to invest. Advice from an FCA-regulated adviser attracts the protection of the Consumer Duty and potentially access to the Financial Ombudsman Service and FSCS. But the same consumer may ask a general-purpose AI system the same question and receive what appears to be personalised financial advice without those protections. This is particularly concerning because ordinary consumers may not know what questions to ask, what information the AI needs, what it has overlooked or when its answer is wrong. General consumer and data protection laws provide some safeguards, but they do not replicate the Consumer Duty or necessarily provide an effective route to compensation for investment loss.
The consumer may therefore be left to explore conventional private law claims such as contract or negligence. Neither provides an easy answer. Who is the appropriate defendant—the model developer, consumer-facing platform, firm which fine-tuned it or supplier of erroneous data? What did the provider actually promise? Does it owe the user a duty of care? And how can fault and causation be established if it is difficult to determine why the AI generated the answer in the first place?
If existing regulation provides a sufficiently strong foundation, the absence of an effective redress mechanism for this growing category of consumer is a significant weakness.
The Law Commission is reviewing whether the Consumer Protection Act 1987 remains fit for purpose for AI and other digital products. But this is a product-liability review, not a review of financial services, and it should not be assumed that reform will provide a remedy for pure investment loss.
There is, therefore, a potentially significant gap between FCA regulation, general consumer protection and traditional private-law remedies.
There is also a longer-term risk which receives less attention: de-skilling.
Experienced financial professionals using AI may become substantially more productive because their expertise allows them to recognise when the machine is wrong. But if junior analysts, advisers, underwriters and fund managers increasingly rely on AI to perform the underlying analysis, where will the next generation of experienced professionals come from?
Human oversight is only meaningful if the humans retain the expertise necessary to challenge the system.
The same issue arises for investors. AI could dramatically improve shareholders’ ability to analyse companies. But if investors increasingly delegate analysis, investment decisions and, ultimately, voting decisions to AI, there is a danger that shareholders themselves become less engaged in holding boards and companies to account.
This is not simply a jobs issue. It is a question of institutional knowledge, succession and resilience.
Mills recognises that AI is global while regulation is increasingly fragmented, with countries pursuing different regulatory and technological sovereignty strategies.
China provides a striking contrast. Its AI Plus strategy targets penetration of next-generation intelligent terminals and AI agents above 70% by 2027 and 90% by 2030, while combining rapid adoption with strong central oversight of algorithms, generative AI and infrastructure. Chinese Government – AI Plus initiative
The EU has adopted the more prescriptive AI Act, including obligations for high-risk systems and general-purpose AI. The US retains a more sectoral approach but introduced a Financial Services AI Risk Management Framework in 2026. Australia also relies largely on existing financial-services law, although its regulator, ASIC, has questioned whether this will remain sufficient. ASIC – Current regulation around AI may not be sufficient.
The concern is not simply that countries regulate AI differently. UK consumers and financial institutions may increasingly depend on models, infrastructure and data controlled in jurisdictions pursuing very different economic and strategic objectives. That raises questions of data sovereignty, foreign-state interference, cyberattack and ultimately how much control the UK retains over technology on which its financial system may depend.
The Mills Review should not be characterised as complacent. It recognises many of the identified risks and makes sensible proposals for monitoring the perimeter, strengthening coordination, improving the FCA’s technological capabilities and tracking the move towards autonomous AI. Its proposal for a trusted public-interest AI financial capability service is particularly interesting as a possible alternative to consumers simply turning to unregulated general-purpose models.
But there remains an uncomfortable tension.
The Government wants rapid AI adoption because it sees AI as an engine of economic growth. The FCA wants to facilitate innovation and competitiveness and does not currently propose AI-specific regulation. Mills concludes that the existing framework remains fundamentally sound. Yet the same Review contemplates systems that are autonomous, continuously learning and interconnected, acknowledges new forms of concentration and systemic vulnerability and recommends that Britain enable agentic finance.
The question is whether a regulatory architecture built around identifiable firms, activities and human accountability can control an entire financial ecosystem increasingly mediated by autonomous AI agents, dependent upon a handful of global technology providers and capable of making interconnected decisions at machine speed.
Pandora’s box is open. Closing it is neither realistic nor desirable. But before we hand the genie authority to manage our savings, pensions, investments and ultimately substantial parts of the financial system, we need convincing answers to some very old-fashioned questions:
ShareSoc embraces AI as a force for productivity and innovation, but remains concerned that the regulator is underestimating the associated risk and control issues. In a financial world awash with intrinsic conflict, how do we ensure that such a powerful force, which has no natural moral compass, enjoys largely unfettered access to data and has already proved itself to be utterly task-focused, can ever be unbiased?
Bozena Michalowska, director and member of ShareSoc’s Policy & Campaigns and Education Committees
This site uses Akismet to reduce spam. Learn how your comment data is processed.
Enter your email to sign up as a free Associate ShareSoc member and receive our emails. It takes a few seconds — and on the next page you'll have the option to customise your membership.