Medium angle of digitally rendered orbiting spheres.
Report

The AI Revolution: Navigating the Regulatory Landscape in UK Financial Services

July 21, 2026
As AI reshapes financial services at speed, firms must embrace innovation while finding a route through shifting and uncertain regulatory expectations.

Introduction

Financial services firms are at a critical juncture as the UK government and regulators consider how best to harness AI’s potential while safeguarding consumers and financial stability. Firms must balance the drive for innovation with the need to comply with evolving regulatory expectations. AI is transforming financial services at an unprecedented pace. From automated trading algorithms to customer-service chatbots, and from fraud-detection systems to credit-scoring models, AI is reshaping how financial institutions operate and serve their customers. Yet with this transformation comes a complex web of regulatory considerations that firms must navigate carefully.

The regulators have consistently maintained that existing regulation provides adequate protections, acting “not as a brake but as a stabiliser”. However, the House of Commons Treasury Committee report published earlier this year concluded that the regulators should take a more proactive stance to mitigate unacceptable levels of risk (for more detail, see our blog post). Nevertheless, the recent Financial Services AI Adoption Plan emphasises the importance of scaling AI as a strategic priority within financial services, stressing the opportunities that deeply integrated and widespread adoption will bring. Accordingly, it will be important to observe how the regulators navigate the inherent tension between promoting innovation and ensuring the safe and responsible deployment of AI. This is a pivotal moment for the regulators’ approach to AI, and firms are watching closely to understand the future direction of travel.

This report (i) examines the government’s and regulators’ positions on AI and how they have developed over time, and (ii) outlines practical steps that firms can take now to ensure they are well positioned to address the regulatory compliance challenges presented by the use of AI.

Timeline

Below is a chronological look at key events and publications relating to the government’s and the regulators’ positions on AI. This visual tool shows how the approach to AI has evolved over time.

Key Milestones and Initiatives

Early Exploration of AI in Financial Services 

Regulatory interest in AI within the UK financial services sector has been developing for some time, building steadily over the past decade. Early work by the FCA and the Bank of England (BoE) focused on understanding emerging technologies and their potential implications. The FCA’s work in particular reflected the growing importance of, and focus on, AI technology. The FCA’s Feedback Statement on Big Data in retail general insurance marked one of the first regulatory forays into this area,“FS16/5: Call for Inputs on Big Data in retail general insurance” (21 September 2016) https://www.fca.org.uk/publications/feedback-statements/fs16-5-call-inputs-big-data-retail-general-insurance. followed by a joint FCA and BoE survey on machine learning in financial services,“Machine learning in UK financial services” (16 October 2019) https://www.bankofengland.co.uk/report/2019/machine-learning-in-uk-financial-services. underscoring the importance of AI technologies in the current and future delivery of UK financial services.

By 2021, the FCA had commissioned a dedicated report on AI in financial services, signalling that the debate was shifting from whether AI would transform the sector to how it could be adopted responsibly.“AI in Financial Services” (11 June 2021) https://www.turing.ac.uk/sites/default/files/2021-06/ati_ai_in_financial_services_lores.pdf. The survey on AI and machine learning takes place on a biennial basis, enabling the regulators to better understand developments in AI use and adoption across the sector. The findings from the most recent survey were published in November 2024 and noted that the vast majority of financial services firms were already using AI.“Artificial intelligence in UK financial services — 2024” (21 November 2024) https://www.bankofengland.co.uk/report/2024/artificial-intelligence-in-uk-financial-services-2024. The results of the fourth survey are due to be published later this year.

Establishing a Principles-Based Framework

In July 2022, the government published an AI regulation policy paper, “Establishing a pro-innovation approach to regulating AI”, in which it proposed to develop a set of cross-sectoral principles tailored to the specific characteristics of AI.“Establishing a pro-innovation approach to regulating AI” (18 July 2022) https://www.gov.uk/government/publications/establishing-a-pro-innovation-approach-to-regulating-ai. This was the government’s first clear articulation of its approach to AI, indicating a strong preference for adapting current frameworks rather than creating AI-specific rules.

The policy paper was followed by a government white paper in which the government stated its intention to take an “agile and iterative” approach to regulating AI, harnessing AI’s potential alongside protecting against the inherent risks.“A pro-innovation approach to AI regulation” (20 March 2023) https://www.gov.uk/government/publications/ai-regulation-a-pro-innovation-approach/white-paper. The white paper proposed five central “cross-cutting” principles for AI governance (the AI Principles):

  1. Safety, security, and robustness
  2. Appropriate transparency and explainability
  3. Fairness
  4. Accountability and governance
  5. Contestability and redress

The government published its response to the white paper in February 2024, confirming its approach.“A pro-innovation approach to AI regulation: government response” (6 February 2024) https://www.gov.uk/government/consultations/ai-regulation-a-pro-innovation-approach-policy-proposals/outcome/a-pro-innovation-approach-to-ai-regulation-government-response. In parallel, the government wrote to the regulators asking them to publish an update outlining their strategic approach to AI by 30 April 2024. This consultation process reinforced the government’s commitment to building consensus around a proportionate, sector-led approach to AI regulation.Notably, these papers were published by the previous government. They have not been endorsed or revisited by the current government, although the current government’s strategy does appear to broadly align with previous policy. The AI Opportunities Action Plan and government response indicate support for a regulator-led approach. “Independent report: AI Opportunities Action Plan” (13 January 2025) https://www.gov.uk/government/publications/ai-opportunities-action-plan/ai-opportunities-action-plan; “Policy Paper: AI Opportunities Action Plan: government response” (13 January 2025) https://www.gov.uk/government/publications/ai-opportunities-action-plan-government-response/ai-opportunities-action-plan-government-response#government-response-to-the-ai-opportunities-action-plan.

Meanwhile, the FCA, the PRA, and the BoE published a Discussion Paper on AI and machine learning in October 2022, inviting public comment on the risks and benefits of AI and potential regulatory approaches.“DP5/22 — Artificial Intelligence and Machine Learning” (11 October 2022) https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence. The subsequent Feedback Statement indicated that respondents felt that a regulatory definition of AI would not be helpful, nor would specific regulatory obligations.“FS2/23 — Artificial Intelligence and Machine Learning” (26 October 2023) https://www.bankofengland.co.uk/prudential-regulation/publication/2023/october/artificial-intelligence-and-machine-learning. Instead, respondents called for frequently updated guidance and examples of best practice, as well as greater coordination between regulators to address the fragmented regulatory landscape.

Reliance on Existing Frameworks

When the FCA and the PRA responded to the government’s request to outline their strategic approach to AI, a consistent message emerged: the existing regulatory framework was broadly sufficient to address the challenges posed by AI.“AI Update” (22 April 2024) https://www.fca.org.uk/publication/corporate/ai-update.pdf.BoE/PRA letter to the government (22 April 2024) https://www.bankofengland.co.uk/-/media/boe/files/prudential-regulation/letter/2024/dsit-hmt-letter.pdf. The FCA said that it seeks to “promote the safe and responsible use of AI in UK financial services markets and to leverage AI in a way that drives beneficial innovation” while acknowledging that its rules are not usually technology-specific and therefore apply to firms regardless of how they operate their business. Notably, the FCA remarked that its regulatory approach will evolve in tandem with the speed, scale, and complexity of AI — a signal that the FCA may be prepared to introduce AI-specific rules in the future if necessary.

Similarly, the PRA noted that the adoption of AI remains an area of focus for the BoE and PRA, particularly given ongoing innovation and the potential for AI use to have a destabilising effect on both firms and financial markets more broadly. The PRA also emphasised the need for regulatory collaboration to support the safe adoption of AI.

Both the FCA and the PRA reported that the AI Principles are fundamental to their respective approaches and are addressed by existing areas of their rulebooks.It appears that, although the government papers may have been superseded, they still form the base of the regulators’ current approach. Specifically, the FCA pointed to areas of the FCA Handbook and existing FCA guidance which map to the AI Principles. We capture these areas in the below table.

How the AI Principles Map to Existing FCA Regulatory Frameworks

Principle Map to Existing FCA Regulatory Frameworks

Safety, Security, and Robustness

Under this principle “AI systems should function in a robust, secure and safe way throughout the AI life cycle, and risks should be continually identified, addressed and managed”.

  • FCA Principles for Businesses 
    • Principle 2
    • Principle 3
  • Threshold Conditions
  • Senior Management Arrangements, Systems, and Controls
    • SYSC 4
    • SYSC 7
    • SYSC 8
    • SYSC 13
    • SYSC 15A
  • FCA guidance on outsourcing critical functions – FG16/5
  • FCA guidance on operational resilience – CP23/30

Appropriate Transparency and Explainability

Under this principle “AI systems should be appropriately transparent and explainable”.

  • FCA Principles for Businesses
    • Principle 7
  • Consumer Duty and related guidance
    • PRIN 2A.2.2R
    • PS22/9
    • FG22/5

Fairness

Under this principle “AI systems should not undermine the legal rights of individuals or organisations, discriminate unfairly against individuals or create unfair market outcomes. Actors involved in all stages of the AI lifecycle should consider descriptions of fairness that are appropriate to a system’s use, outcomes and the application of relevant law”. 

  • FCA Principles for Businesses 
    • Principle 6
    • Principle 7
    • Principle 8
    • Principle 9
  • Consumer Duty and related guidance
    • PRIN 2A.2.2R
    • PS22/9
    • FG22/5
  • Threshold Conditions
  • FCA guidance on the treatment of vulnerable customers – FG21/1

Accountability and Governance

Under this principle “governance measures should be put in place to ensure effective oversight of the supply and use of AI systems, with clear lines of accountability established across the AI life cycle”.

  • FCA Principles for Businesses
    • Principle 3
  • Threshold Conditions
  • Consumer Duty and related guidance
    • PRIN 2A.2.2R
    • PS22/9
    • FG22/5
  • Senior Management Arrangements, Systems, and Controls
    • SYSC 4
  • SMCR

Contestability and Redress

Under this principle “where appropriate, users, impacted third parties and actors in the AI life cycle should be able to contest an AI decision or outcome that is harmful or creates material risk of harms”.

  • Dispute Resolution: Complaints

Fostering Innovation Through Collaboration

In parallel with the development of the regulatory framework, the regulators have launched a number of practical initiatives to foster collaboration and facilitate the safe deployment of AI.

Digital Regulation Cooperation Forum

The Digital Regulation Cooperation Forum, which brings together the FCA, the Information Commissioner’s Office, Ofcom, and the Competition and Markets Authority, was formed in July 2020 to deliver a coherent approach to digital regulation and consider how best to coordinate regulatory approaches.https://www.drcf.org.uk/. In its latest workplan, the Digital Regulation Cooperation Forum stated that it is keen to explore and develop a deeper understanding of consumers’ attitudes to the risks of generative AI and the adoption of agentic AI tools.

AI Lab

The FCA launched its AI Lab in October 2024, which includes a number of initiatives, encompassing input on AI from a variety of stakeholders (via the AI Sprint and AI Input Zone) and showcasing projects experimenting with AI in the financial services sector (AI Spotlight). The AI Input Zone recently reopened to gather further views and insights on what safe and responsible AI development looks like, and the FCA plans to publish a good and poor practice document for AI in financial services later in 2026.

AI Live Testing and the Supercharged Sandbox

The FCA also highlighted its intention to enhance the digital sandbox infrastructure to experiment with AI and launched AI Live Testing and the Supercharged Sandbox in 2025 to enable firms to test innovative AI-driven products in a controlled environment. AI Live Testing, which allows firms with developed proofs of concept to trial their solutions, has proved popular with firms; it is now on its second cohort, with testing due to conclude by the end of the year and a feedback report due in early 2027. Meanwhile, the Supercharged Sandbox, which enables firms to test early-stage ideas, recently launched a second cohort, which is also due to conclude by the end of the year.

Artificial Intelligence Consortium

In May 2025, the BoE and the FCA set up an Artificial Intelligence Consortium, chaired by Sarah Breeden, Deputy Governor for Financial Stability.https://www.bankofengland.co.uk/research/fintech/artificial-intelligence-consortium. The Consortium meets on a quarterly basis and seeks to gather input from stakeholders on the capabilities, development, deployment, and use of AI in the financial services sector — and, ultimately, inform the regulators’ approach to the use of AI. The Consortium is carrying out specific work on: (i) concentration risks, including from third-party model providers; (ii) the evolution of AI “edge cases”, as adoption moves into use cases more relevant for financial stability such as credit risk assessment and trading; (iii) explainability and transparency in generative AI; and (iv) AI accelerated contagion in financial markets, as well as discussions on emerging trends such as the rise of agentic AI. The Consortium plans to publish a report on its work this year.

Further, the BoE published a paper in October 2025 setting out its approach to innovation in AI, distributed ledger technology, and quantum computing.“The Bank of England’s approach to innovation in artificial intelligence, distributed ledger technology, and quantum computing” (15 October 2026) https://www.bankofengland.co.uk/report/2025/the-boes-approach-to-innovation-in-ai-dlt-quantum-computing. In this paper, the BoE outlined its approach to delivering the necessary environment to enable responsible innovation. In terms of future work, the BoE stated that it is building out a proactive approach for surveillance of AI adoption and use, engaging with regulated firms to understand how it can support adoption, exploring whether AI-specific guidance for firms could be beneficial, and seeking input from firms as to whether it needs to do more to ensure that firms are training AI models on high-quality, unbiased input data.

Treasury Committee Report and the Mills Review

Treasury Committee Report

In January 2026, the House of Commons Treasury Committee published its report on AI in financial services, following an inquiry launched in February 2025.“Artificial intelligence in financial services Fifteenth Report of Session 2024–26” (20 January 2026) https://publications.parliament.uk/pa/cm5901/cmselect/cmtreasy/684/report.html. The report is critical of the regulators’ approach to AI, concluding that the FCA, the BoE, and HM Treasury are not doing enough to manage the risks presented by AI. The Committee considers that by taking a “wait and see” approach, the regulators are exposing consumers and the financial system to potentially serious harm.

Specific risks highlighted in the report include: (i) lack of transparency in AI-driven decision-making, (ii) AI financial decision-making leading to financial exclusion, (iii) unregulated financial advice from AI search engines, (iv) heightened cybersecurity vulnerabilities, and (v) operational resilience issues arising from reliance on a small number of US technology firms for AI and cloud services. The report also criticises the regulators’ “reactive” approach, stating that this leaves firms with “little practical clarity on how to apply existing rules to their AI usage”.

The Treasury Committee report made three key recommendations: 

  1. By the end of 2026, the FCA should publish comprehensive, practical guidance for firms on the application of existing consumer protection rules (including the Consumer Duty) to their use of AI, together with guidance on accountability and the level of assurance expected from Senior Managers under the SMCR for harm caused through the use of AI.
  2. The BoE and the FCA must conduct AI-specific stress testing.
  3. By the end of 2026, HM Treasury must designate the major AI and cloud providers as critical third parties for the purposes of the Critical Third Parties Regime.

The regulators’ responses to the Committee’s report were published in April 2026.“AI in financial services: Responses to the Committee’s Fifteenth Report” (16 April 2026) https://committees.parliament.uk/publications/52647/documents/292955/default/. They did not agree with the Committee’s characterisation of their approach to AI in financial services and emphasised the extensive work they are doing to monitor developments closely and to help ensure the safe adoption of AI. They said they are continuing to take a risk-based, proactive, and proportionate approach, and are prepared to adapt their approach in future if necessary. They are, however, taking forward the Committee’s recommendations, and the FCA confirmed that it plans to share additional guidance for firms on the use of AI, while both the FCA and the BoE explained their plans for stress- and scenario-testing. Subsequently, in July 2026, HM Treasury made its first designations under the Critical Third Parties Regime.UK financial system strengthened with new safeguards for major technology providers (10 July 2026) https://www.gov.uk/government/news/uk-financial-system-strengthened-with-new-safeguards-for-major-technology-providers.

Mills Review

Shortly after the Treasury Committee report’s publication, the FCA announced a review into the long-term impact of AI on retail financial services (referred to as the Mills Review),“Review into the long-term impact of AI on retail financial services (The Mills Review)” (27 January 2026) https://www.fca.org.uk/publications/calls-input/review-long-term-impact-ai-retail-financial-services-mills-review. which sought views across four main themes: (i) the future evolution of AI technology, (ii) the future impact of AI on markets and firms, (iii) future consumer trends, and (iv) the future regulatory approach to AI. As part of the fourth theme, the Mills Review considered whether existing frameworks, such as the Consumer Duty, the SMCR, the Operational Resilience framework, and the Critical Third Parties regime, remain flexible and sufficiently outcomes-focused.

The findings from the Mills Review were published on 6 July 2026.“The Mills Review: AI and the future of retail financial services” (6 July 2026) https://www.fca.org.uk/publication/corporate/the-mills-review.pdf. Overall, the Mills Review found that AI will transform retail financial services from as early as 2030 in four key ways. It will: (i) transform how firms operate, (ii) reshape consumer journeys, (iii) change market power and competition, and (iv) amplify fraud and cyber risks. 

The findings include a series of recommendations for the FCA to consider, representing ways in which the regulator can prepare for AI-driven change in the sector. These include examining the regulatory perimeter and ensuring the regulator is prepared to supervise use of new AI models as the technology develops, as well as considering whether the FCA might need new powers to address system-wide risks that current firm-specific supervision cannot capture. 

Importantly, the Mills Review does not recommend any new AI-specific regulation and aligns with the view that the current regulatory framework provides a sound basis for supervising firms’ use of AI. However, it highlights that areas of the regulatory framework will come under increasing pressure as AI capabilities increase, and that the FCA may need to adapt to respond to the changing landscape. It also emphasises that firms need greater clarity on how to apply the existing rulebook to the use of AI, particularly as AI becomes more autonomous. The FCA Board will now consider whether and how to take forward the recommendations. 

Financial Services AI Adoption Plan

In parallel with the Treasury Committee report, the government announced the appointment of two AI Champions in financial services.“AI Champions appointed to help City safely seize AI opportunities” (20 January 2026) https://www.gov.uk/government/news/ai-champions-appointed-to-help-city-safely-seize-ai-opportunities. This followed a commitment made as part of the July 2025 Financial Services Growth and Competitiveness Strategy. The AI Champions were tasked with helping firms seize the opportunities that AI can offer, while effectively mitigating the risks, and they presented the Financial Services AI Adoption Plan to the government in July 2026. 

The Adoption Plan sets out a vision for widespread adoption of AI across the financial services sector, and details a set of 10 recommendations for the government, the regulators, and industry to help encourage safe adoption of AI. While some of the recommendations overlap with the recommendations of the Mills Review, such as providing further clarity around how the regulatory framework applies to the use of AI and reviewing the regulatory perimeter (in particular in relation to financial guidance and advice-like outputs generated by general purpose large language models), the recommendations range more broadly to cover other topics such as assessing whether significant AI providers should be designated under the Critical Third Parties regime, launching an AI third-party assurance scheme, building AI-related skills in the sector, and preparing for agentic payments.

Further, the Adoption Plan highlights other considerations for the government in its wider approach to AI to help address cross-sector challenges. These considerations include building sovereign AI capability in the UK and strengthening the UK’s resilience to AI-related risks. These recommendations and considerations are expected to feed into the government’s and the regulators’ approaches to AI going forward. 

Dealing With Emerging Risks

The regulators are mindful of the risks AI can pose to firm and market operational resilience, particularly new and emerging AI models. The Cross Market Operational Resilience Group (CMORG) is co-chaired by the BoE and was established to improve the operational resilience of the financial services sector. CMORG set up its AI Taskforce in 2024 and has since published various helpful materials for firms concerning operational risks arising from the use of AI. In particular, its AI Baseline Guidance Review provides insight on managing AI risk in the financial services sector, with key takeaways for firms to consider.“AI Baseline Guidance Review” (15 May 2025) https://www.cmorg.org.uk/sites/default/files/2025-05/CMORG%20-%20AI%20Baseline%20Guidance%20Review%20-%20April%202025%20-%20TLP%20CLEAR.pdf.

More recently, the regulators have turned their attention to the potential risks of highly sophisticated frontier AI models. In May 2026, HM Treasury, the BoE, and the FCA published a joint statement on the potential impact of frontier AI models on cybersecurity and operational resilience, emphasising how firms need to ensure that their response capabilities are calibrated to effectively react to this emerging threat.“The Bank, FCA and HM Treasury joint statement on Frontier AI models and cyber resilience” (15 May 2026) https://www.bankofengland.co.uk/news/2026/may/boe-fca-and-hm-treasury-joint-statement-on-frontier-ai-models-and-cyber-resilience. This was followed by more detailed guidance from CMORG in June 2026.“Firm Guidance for Frontier AI” (9 June 2026) https://www.cmorg.org.uk/sites/default/files/2026-06/CMORG%20-%20Firm%20Guidance%20For%20Frontier%20AI%20-%20Final%20-%20June%202026%20-%20Version%201.0%20-%20TLP%20CLEAR.pdf. The CMORG guidance draws together a collection of leading practices that may assist firms in preparing themselves for the speed at which they need to be able to respond to operational incidents. In addition, the latest Financial Policy Committee Financial Stability Report included a section on the potential risks to financial stability from frontier AI, commenting that the increase in capabilities could materially increase risks through cyber and operational vulnerabilities.“Financial Stability Report — July 2026” (7 July 2026) https://www.bankofengland.co.uk/financial-stability-report/2026/july-2026.

European Approach 

The EU has taken a different approach to AI, introducing prescriptive regulation with the EU AI Act, which came into force on 1 August 2024 and is being implemented in phases. Implementation of certain aspects, such as the requirements for high-risk AI systems (which include AI systems for creditworthiness assessments or credit scoring of natural persons), is expected to be delayed until December 2027, to allow for implementation standards and guidance to be issued. In addition, as part of the AI Omnibus and broader Digital Omnibus package, further targeted amendments are envisaged to simplify the requirements of the AI Act, facilitate AI development, and clarify the interaction between the AI Act and other regulations.

The AI Act has broad extraterritorial reach and applies to UK firms in several scenarios, including: (i) where they place on the market or put into service AI systems in the EU, (ii) where they deploy AI systems in the EU from an EU establishment, or (iii) where the output of AI systems that they provide or deploy is used in the EU. Accordingly, firms with cross-border operations must be mindful of their obligations. 

The divergence between the pro-innovation approach in the UK and the more prescriptive approach in the EU creates challenges for firms with a presence in multiple jurisdictions to take a consistent approach to compliance. For instance, the definition of an AI system under the AI Act is not straightforward for financial services,As illustrated by the delay of the European Commission’s Guidelines on the definition of an AI system due to the sector challenging the Commission’s proposed inclusion of the statistical technique of logistic regression used for credit scoring. Ultimately, this was expressly excluded from the AI definition, as it constitutes a “well established optimisation method”. “The Commission publishes guidelines on AI system definition to facilitate the first AI Act’s rules application” (6 February 2025) https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application. and recent European Commission draft guidelines on the classification of high-risk AI systems take a relatively broad view of the “essential” financial services implicated in the creditworthiness/credit scoring high-risk category (including general consumer lending and credit extensions, and consumer mortgages).

The EU is also conscious of the need to remain at the forefront of AI innovation and investment. In November 2025, a European Parliament report called on the European Commission and national regulators to promote “consistent interpretations and proportionate application of current regulations” to enable the use of AI in the financial services sector.“Impact of artificial intelligence on the financial sector” (25 November 2025) https://www.europarl.europa.eu/doceo/document/TA-10-2025-0286_EN.pdf. A particular challenge highlighted by the report is understanding how the AI Act interacts with sectoral financial services legislation.

Shortly before the report was published, the European Banking Authority (EBA) shared the outcome of its AI Act mapping exercise, which maps the AI Act against relevant provisions in the EU banking and payments frameworks.“Outcome of EBA’s AI Act mapping exercise” (21 November 2025) https://www.eba.europa.eu/sites/default/files/2025-11/2019d1b5-59f8-4149-ad3b-23cfcd4388a1/EBA%20Chair%20letter%20to%20Mr%20Berrigan%20and%20Mr%20Viola%20on%20outcome%20of%20EBA%E2%80%99s%20AI%20Act%20mapping%20exercise.pdf. The EBA concluded that there were no significant contradictions between the AI Act and these frameworks, rendering them complementary to each other, and that no new guidelines were required. Consequently, guidance for financial services firms navigating application of the AI Act remains limited.

Key Takeaways for Financial Services Firms

Effective oversight of the use of AI requires a coordinated effort across all areas of regulated firms. While firms benefit from the advantages that AI can offer, they must maintain full visibility over the risks AI poses to their business and manage these risks appropriately. Below are a number of considerations for firms regarding their use of AI.

Do We Use AI?

  • Firms should consider the extent to which they use AI, whether any third parties from which they receive services use AI, and any other touchpoints across the organisation with AI. Where AI use is identified, firms should maintain an inventory and note applicable regulatory classifications (e.g., as a high-risk AI system under the AI Act). They should also assess whether their governance structure is adequate to support continued use of AI.

Can We Explain Our AI Use?

  • Firms should be able to explain their use of AI to the regulators and other stakeholders. This includes an explanation of how risks associated with the deployment of AI have been identified, assessed, and managed. It also requires consideration of the firm’s AI governance framework and oversight from the C-suite of the strategic integration of AI.
  • Firms should consider how they will provide an explanation of the outcome from an AI system. This may include using: (i) explainable AI algorithms, (ii) complex AI systems to challenge and fine-tune traditional mathematical AI models, or (iii) supplementary explainability tools that focus on analysing how specific data points within the input data produce a final AI result.

Governance and Oversight 

  • The C-suite should oversee the strategic integration of AI in a way that aligns with regulatory requirements and the firm’s overall risk appetite.
  • Firms should be clear on the use of AI across the organisation and determine at an early stage who is responsible for deploying AI tools and which tools might be appropriate. Notably, the AI and Machine Learning Survey 2024“Artificial intelligence in UK financial services – 2024” (21 November 2024) https://www.bankofengland.co.uk/report/2024/artificial-intelligence-in-uk-financial-services-2024. published by the BoE and the FCA highlights that 84% of firms chose to allocate responsibility for AI processes to a named individual, typically executive leadership (72%), developers and data science teams (64%), and business area users (57%).
  • The Compliance function and Internal Audit should conduct regular audits of AI deployment to ensure that the firm’s AI systems and processes comply with regulatory requirements.

Operations and Finance 

  • Operations may need to adapt processes to accommodate AI systems while ensuring that they meet the requisite regulatory standards. Where relevant, they will also need to manage third-party vendors that provide AI services, ensuring that they also comply with the relevant regulatory standards.
  • Finance will need to allocate budget for compliance-related activities, including AI system audits. They will also need to ensure that financial reporting processes are not adversely affected by the use of AI systems.

Risk Assessments and Risk Ratings

  • The Risk function will need to assess the risks associated with the deployment of AI, including operational, reputational, and cyber risks. They will also need to ensure that they have appropriate processes set up to monitor for anomalies and report risk metrics to the FCA as required.

Compliance and Legal 

  • These functions will need to ensure that AI applications comply with the requisite regulatory requirements, as well as other relevant legislation, such as the UK Data Protection Act and the EU General Data Protection Regulation (GDPR).
  • Firms should consider whether policies and procedures should be updated to govern the use of AI within the firm and whether it is appropriate to provide training to employees on regulatory requirements related to AI.

Technology and IT 

  • Where new AI systems are rolled out, the IT function will need to ensure that the system is designed in a manner that complies with relevant regulations, including those related to data security and privacy. From a business-as-usual perspective, ongoing maintenance will be critical to ensure that the systems remain compliant with regulations as they evolve.
  • The Technology and IT department should consider training to help its workforce upskill and develop their AI understanding.

Customer Services and Marketing 

  • Marketing strategies and product offerings involving AI must comply with regulations on fairness and non-misleading communications, while also obtaining and managing customer consent for data usage in line with privacy regulations. In addition, firms should ensure that AI does not produce biased results and that customer vulnerability is explored fully.
  • Customer service representatives should explain AI decision-making processes to customers and gather feedback to improve systems and address regulatory concerns. Firms should also consider the use of AI during the different stages of the user experience.

Next Steps

This is a fast-moving area, and financial services firms need to stay abreast of key developments. Guidance from other UK bodies, such as the Information Commissioner’s Office, as well as other global initiatives, such as the Financial Stability Board’s proposed Sound Practices for Responsible Adoption of Artificial Intelligence, will undoubtedly affect global financial institutions.“Sound Practices for Responsible Adoption of Artificial Intelligence (AI): Consultation report” (10 June 2026) https://www.fsb.org/uploads/P100626.pdf. Such guidance will also shape positions and responses to the further use of AI. 

With the volume of publications on AI at both a domestic and international level, firms may struggle to navigate this body of information. They may also face difficulties in keeping abreast of what is being published, determining what applies to them, and distilling the core regulatory expectations. Depending on how this guidance is adopted across the market, firms may start to feel as though an informal regulatory framework is taking shape.

While UK sector-specific regulation is not expected in the short term, the regulatory environment remains dynamic. Firms operating across the UK and EU must navigate divergent regulatory philosophies, with the UK favouring a principles-based, pro-innovation approach and the EU taking a more prescriptive stance through the AI Act. Regulatory statements in this area remind firms of the need to keep pace with the development and complexity of AI. We expect such messaging to continue in the coming months and years as AI use cases develop.

Endnotes

    This publication is produced by Latham & Watkins as a news reporting service to clients and other friends. The information contained in this publication should not be construed as legal advice. Should further analysis or explanation of the subject matter be required, please contact the lawyer with whom you normally consult. The invitation to contact is not a solicitation for legal work under the laws of any jurisdiction in which Latham lawyers are not authorized to practice. See our Attorney Advertising and Terms of Use.