Regulation in the age of agentic finance: The Mills Review

Recent FCA research indicates that around 80% of younger investors have used AI to support their investment decisions.  The same research found that 44% mistakenly believe that AI-generated financial information is regulated and 32% wrongly think they would get compensation from the Financial Services Compensation Scheme if the AI advice is wrong.  Therefore, it is unsurprising that the FCA has been seeking to raise awareness about how AI users can protect themselves through advice on its InvestSmart website.

This research supports one of several themes highlighted by the Mills Review, an in-depth review of AI in the retail financial services sector commissioned by the FCA Board. The Review involved extensive expert, industry and consumer engagement, and recognises that AI is rapidly evolving from human-operated tools towards increasingly autonomous agents, bringing both opportunities and risks. If adopted, its recommendations could materially reshape the UK regulatory landscape for financial services.

Overview

Perhaps most notably, the Review identifies the potential for AI to reach parts of the retail financial services market which have long been underserved, including addressing the advice gap (only 9% of consumers use traditional advice) and financial exclusion (around 900,000 people remain unbanked). This represents a "once in a generation chance to close the information asymmetries and frictions that have long left people making poor financial decisions."

However, alongside these opportunities, generative and agentic AI may amplify risks, including systemic risks arising from a high level industry-wide reliance on a small number of service providers, such as cloud platforms. AI is also expected to increase the scale and speed of cyber-attacks and fraud, while making them more persuasive and cheaper to execute, although it may equally enable firms to develop enhanced defences to these threats.

Against this backdrop, the Review makes seven priority recommendations for consideration by the FCA Board:

  1. Secure and adapt the regulatory perimeter;
  2. Strengthen system-wide coordination and oversight;
  3. Monitor the transition to autonomous models and adapt regulatory frameworks;
  4. Scale up the FCA's AI Lab to support AI models and system innovation in financial services;
  5. Enable the foundations for agentic finance;
  6. Build and adopt an AI-enabled agentic supervisory model; and
  7. Develop a trusted public-interest AI-enabled financial capability service.

This article focuses on four themes of particular interest to regulated firms and AI suppliers whose models may operate, by design or otherwise, in retail financial services:

  • Securing and adapting the regulatory perimeter and existing frameworks;
  • New systemic risks;
  • Adoption of AI by the FCA; and
  • Developing a trusted public-interest AI-enabled financial capability service.

Before turning to those themes, it is useful to briefly consider one of the Review’s central concepts: the Autonomy Spectrum.

The Autonomy Spectrum

The Review adopts the following terminology to describe different levels of human involvement when interacting with AI models.

Autonomy Level

Description

Example

Operator

Human uses AI as a tool to support a human-led task.

Analyst requests summaries or charts from internal data and policy documents.

Collaborator

Human and AI plan and act together.

Customer and chatbot co-build a budget or savings plan step-by-step.

Consultant

AI recommends, human decides.

AI recommends SME and specialist lending decisions; underwriters guide edge cases.

Approver

AI prepares, human authorises.

AI agent executes savings switches via open banking; customer authorises each step.

Observer

AI acts within boundaries, human monitors.

AI monitors customer outcomes and selects interventions; committee oversees results.

Although some points on the spectrum overlap, it shows how the role of humans in delivering financial services is evolving beyond that originally envisaged by the current regulatory framework. The Review makes it clear that firms will remain accountable where decisions have been delegated to AI. Effective human oversight, clear documentation of consent and robust governance will therefore be key to a firm's successful transition through the Autonomy Spectrum.

The Review also recognises that existing regulatory frameworks will come under pressure as AI develops. In a Consumer Duty context, for example, firms operating further along the Autonomy Spectrum may find it harder to evidence consumer consent and understanding, particularly where they operate primarily as Observers and issues are identified only after they arise.

The Review recommends AI-specific guidance to help firms assess whether their systems comply with existing rules, and where necessary, recommends adapting existing frameworks to reflect technological developments. One notable proposal, for example, is to develop minimum requirements for AI agents operating in financial services. This would require a new approach to compliance and governance. The Review notes that “validation at the point of deployment” is unlikely to be sufficient; firms will require live monitoring and other robust internal controls to respond to a fast-moving technological environment.

Additionally, the Review anticipates that the FCA will need to adapt its own approach to protect consumers without stifling innovation. This is the core rationale behind the Review’s recommendations.

Securing the regulatory perimeter and adapting frameworks

One of the Review’s most significant recommendations is for the FCA to assess the impact of general-purpose Large Language Models (LLMs), which currently sit outside the regulatory perimeter, on retail financial services. The Review notes that more than a quarter of consumers already trust general-purpose LLMs for financial advice and recognises their potential to produce hyper-personalised advice capable of influencing consumer decision-making.

This presents a rare opportunity to enable greater consumer access to financial services and potentially significant cost savings. Nevertheless, there remains the risk that consumers may rely on AI-generated advice without appreciating that it may fall outside FCA oversight and that standard consumer remedies might not apply.

The Review therefore recommends an urgent assessment of the role of general-purpose LLMs in retail financial services to identify consumer protection gaps and prevent regulatory arbitrage by unregulated AI suppliers. It also proposes considering whether to strengthen the FCA’s powers under the Critical Third Party (CTP) and Designated Activities regimes, supplementing them with new powers under the Digital Markets, Competition and Consumers Act 2024.

Although the FCA's approach to general-purpose LLMs will depend on the findings of any subsequent analysis, the Review suggests that the FCA should be prepared to "recommend perimeter changes to government" where gaps are identified. General-purpose LLM providers should therefore monitor developments closely to assess their potential impact on their businesses. Providers should also continue to consider whether their LLM models create compliance risks under the current regime.

New systemic risks

The Review treats widespread AI adoption as a double-edged sword: while it may improve consumer access to financial information and increase competition, it could also introduce wider systemic risks.

A key concern is that many firms may rely on the same AI suppliers. This is already evident in the general-purpose LLM market, which is dominated by a small number of large, well-capitalised providers. Given the capital and expertise needed to build advanced AI models, this concentration is likely to persist.  For regulated firms, the Review warns that shared reliance on a limited number of models could create systemic dependency and single points of failure. Defects such as model bias could also spread more easily across the system, worsening consumer outcomes.

These risks would usually be addressed through the CTP and Operational Resilience regimes. Under the former regime, HM Treasury can bring systemically significant third parties under direct oversight. Under the latter framework, firms must, among other things, notify the FCA of material outsourcing arrangements. Firms should therefore assess their existing supplier relationships against the relevant thresholds to ensure that the FCA has been duly notified and that appropriate contractual protections are in place. To further support these frameworks, the Review also calls for greater cross-sector and cross-border cooperation between regulators through working groups such as the AI Consortium, Digital Regulation Cooperation Forum and Bank for International Settlements.

Adoption of AI by the FCA

As firms adopt AI to meet consumer expectations and improve efficiency, the Review recommends that the FCA keep pace by integrating AI across its processes, from authorisation through to enforcement. If successful, this could materially change how the FCA deploys its regulatory powers.

The Review suggests that the FCA could use AI at almost every point on the Autonomy Spectrum. This could streamline the administrative aspects of processing authorisation applications and other requests, while enabling the FCA to monitor firms more efficiently. Agentic AI could also support real-time market data collection and strengthen systemic oversight, enabling issues to be identified earlier. If implemented, firms should expect a significant operational shift in how they engage with the FCA.

However, the Review advises the FCA not to adopt AI in a way that would place humans at the Observer level. Instead, the Review highlights the importance of human supervisors remaining responsible for key decisions and exercising their judgement. This suggests caution about outsourcing certain aspects of regulatory functions to AI.

It also raises an important question for firms: if the FCA considers that critical decision-making and the exercise of judgement should not be delegated to AI at the Observer end of the spectrum, will it apply the same approach to activities carried out by regulated firms? This is very likely to be the case given the Review's emphasis on human accountability. Firms will need to consider carefully which tasks cannot be performed by AI and how any restrictions may affect their wider business and compliance plans.

Developing a public-interest AI-enabled financial capability service

One of the Review's notable recommendations is for the FCA to work with government agencies and the wider industry to develop a sovereign-style or public-interest AI model that uses trusted information to provide consumers with free, reliable financial guidance.

If successfully implemented, it could improve financial literacy and significantly change how consumers engage with financial services. For example, the Review recognises that appropriate use of AI could enable consumers to submit more sophisticated complaints. By extension, access to a free public-interest model could increase the number of consumers seeking redress by raising greater awareness of consumer rights. Firms may therefore require greater preparation and additional resources to ensure that any complaints are handled fairly. This is just one of many ways in which firms will be required to adapt to a more informed and independent consumer base.

Looking ahead

The FCA has not yet announced its strategy in light of the Review, but the adoption of AI in retail financial services is very likely to drive significant industry and regulatory change. Businesses operating in the sector should therefore consider the issues raised in the Review as indicative of the direction of travel.

If you would like advice on how these developments could affect your business, please contact a member of our team below.

Get in touch

Related