UK · Financial services · GLACIS guides · Updated August 2026

UK financial services AI: FCA and PRA, August 2026

How Consumer Duty, SM&CR and PRA SS1/23 Model Risk Management apply to AI in banking, insurance and investment management. Refreshed for August 2026 with the published FCA Mills Review, AI Live Testing cohort 2, and the Bank of England’s agentic-AI focus.

By Joe Braidwood 15 min read Updated 26 August 2026
23 Apr 2026
PRA SS1/23 current published version
6 Jul 2026
FCA publishes Mills Review and seven recommendations
Feb 2026
Bank of England AI roundtables summary published
Apr 2026
FCA AI Live Testing cohort 2 selected (8 firms)
What changed since January 2026
Executive summary

The FCA and PRA regulate AI in UK financial services through existing frameworks rather than a standalone AI rulebook. When the FCA published the Mills Review on 6 July 2026, it reaffirmed the importance of its principles-based, outcomes-focused approach, including Consumer Duty and the Senior Managers Regime.

Key frameworks: Consumer Duty (good customer outcomes), SM&CR (senior management accountability), and PRA SS1/23 (model risk management for banks using internal models). The FCA’s 2024 survey found 75% of firms already using AI, with 84% having an accountable individual for their AI approach.

Key finding: firms still need to assess AI-driven outcomes against existing regulatory expectations, particularly consumer outcomes and accountable management. The published Mills Review identifies four shifts and offers seven recommendations for FCA leadership to consider; those recommendations should not be read as rules already in force.

75%
Firms using AI (FCA 2024 survey)
84%
Have AI accountable person
17%
Using foundation models
8
Firms in AI Live Testing cohort 2

FCA approach to AI

The FCA published its AI Update in April 2024, setting out how it expects firms to manage AI within existing regulatory frameworks. The core message: outcomes-focused regulation applies equally to AI.

Existing frameworks and the published Mills Review

In December 2025 FCA CEO Nikhil Rathi confirmed the FCA will not introduce AI-specific rules:

“We do not plan to introduce extra regulations for AI. Instead, we’ll rely on existing frameworks… The technology evolves every three to six months, making prescriptive rules impractical.”

On 6 July 2026 the FCA published the Mills Review, led by Executive Director Sheldon Mills. It describes four shifts that could reshape retail financial services to 2030 and beyond and gives the FCA Board and Executive seven recommendations to consider. The FCA’s response says its principles-based, outcomes-focused approach, which relies on Consumer Duty and the Senior Managers Regime, remains critical. Publication of the review did not itself change binding requirements.

Key regulatory frameworks

  • Threshold conditions: firms must remain fit, proper, and capable of being effectively supervised
  • Consumer Duty: firms must deliver good outcomes for retail customers
  • SM&CR: senior managers are accountable for AI governance within their responsibilities
  • Principles for businesses: including Principle 6 (customers’ interests) and Principle 7 (communications)
  • DUAA 2025: new ADM lawful basis in force from 5 February 2026; section 103 right to complain commenced 19 June 2026
Enforcement approach

There is no single prescriptive AI compliance checklist for financial services. Firms should assess AI use against the FCA rules and principles that already apply to the use case. The Mills Review offers recommendations for FCA leadership to consider; it is not itself an enforcement standard.

Consumer Duty and AI

The Consumer Duty (in force since July 2023) is the FCA’s primary lens for assessing AI in retail financial services. It requires firms to act to deliver good outcomes across four areas:

1

Products and services

AI used in product design, recommendation engines, or personalisation must produce products that meet customer needs. Algorithmic bias that leads to unsuitable recommendations violates this outcome.

2

Price and value

AI pricing algorithms must deliver fair value. Dynamic pricing or personalised offers must not exploit behavioral biases or create unfair outcomes for vulnerable customers.

3

Consumer understanding

AI-generated communications must be clear and understandable. LLM-drafted content must meet the same standards as human-written materials.

4

Consumer support

AI chatbots and automated support must provide equivalent quality to human support. Customers must be able to access human assistance when needed.

Practical implications

  • Test AI systems for discriminatory outcomes before deployment
  • Monitor AI-driven customer outcomes on an ongoing basis
  • Document how AI contributes to (or risks undermining) good outcomes
  • Ensure human oversight of AI decisions affecting customers

SM&CR accountability for AI

The Senior Managers and Certification Regime (SM&CR) drives individual accountability for AI governance. The FCA’s 2024 survey found 72% of firms report executive leadership as accountable for AI use cases.

Accountability expectations

Firms should consider which Senior Management Functions (SMFs) are accountable for:

  • AI strategy and governance: often the CEO (SMF1) or a designated SMF
  • AI risk management: Chief Risk Officer (SMF4)
  • AI in customer outcomes: relevant business line SMFs
  • AI model risk: SMF responsible for internal models (PRA-regulated firms)
  • AI data governance: often linked to operations or technology SMFs
FCA finding

84% of surveyed firms have an accountable individual for their AI approach. Accountability is often split. Most firms report three or more accountable persons or bodies, which can create gaps. The published Mills Review recommends that the FCA monitor the transition to autonomous models and develop its own supervisory capabilities; FCA leadership must decide how to take those recommendations forward.

PRA SS1/23: model risk management

Supervisory Statement 1/23 sets out the PRA’s model-risk-management expectations for regulated UK-incorporated banks, building societies, and PRA-designated investment firms with internal-model approval to calculate regulatory capital. The current April 2026 version took effect on 23 April 2026 and expressly excludes insurers and reinsurers. Its model definition can encompass AI and machine-learning techniques used in models; it does not make every use of AI an SS1/23 model.

Current supervisory statement

The PRA’s current SS1/23 sets expectations for model identification and risk classification, governance, development and validation, and risk mitigation. Boards and senior management should understand aggregate model risk and how inter-related models and data structures affect safety and soundness. The statement does not prescribe Glacis, automated monitoring, or a particular evidence technology.

Scope

SS1/23 applies to UK-incorporated banks, building societies, and PRA-designated investment firms with internal model approval for:

  • Credit risk (IRB approach)
  • Market risk (IMA approach)
  • Counterparty credit risk (IMM approach)

The five principles

Principle AI / ML implications
1. Model identification and classification In-scope firms should apply their model definition, identification, and risk-classification process. AI/ML techniques are covered to the extent they are used in models within that scope.
2. Governance Clear ownership and accountability for AI models. Board oversight of material model risks; the 2026 PRA cycle is asking for aggregate, not just per-model, understanding.
3. Development, implementation and use Development, implementation, and use should follow documented, risk-proportionate controls, including sufficient understanding of limitations and appropriate use.
4. Independent validation Models should receive independent validation proportionate to risk; AI/ML techniques may require methods tailored to their design, data, and use.
5. Risk mitigants Firms should apply appropriate model-risk mitigants, monitoring, and restrictions. SS1/23 does not prescribe real-time automated monitoring as a universal control.

Foundation models and LLMs

  • A foundation-model use that meets the firm’s model definition should enter its identification and inventory process; not every LLM use is automatically in scope
  • Risk classification should reflect the particular downstream application and materiality
  • Validation methods may need to reflect model complexity, data, limitations, and intended use
  • Vendor models used by an in-scope firm are not excluded merely because a third party developed them

Bank of England agentic-AI focus

The Bank of England’s Financial Policy Committee record (April 2026) concluded that financial-system participants had not yet adopted advanced or agentic AI in ways that posed systemic risk, while noting that risks could increase as deployment expands. The FPC asked the Bank and FCA to do further work on agentic AI in payments and financial markets. That request should not be treated as a new SS1/23 requirement before the authorities publish one.

FCA AI Lab and the Mills Review

The FCA launched its AI Lab in October 2024 to help firms develop AI safely and responsibly. It comprises five initiatives and is part of the existing work referenced in the FCA’s response to the published Mills Review.

Supercharged Sandbox

Test AI innovations with real consumers in a controlled regulatory environment.

AI Live Testing cohort 2

Eight firms selected April 2026: Aereve, Coadjute, Barclays, Experian, GoCardless, Lloyds (Scottish Widows), UBS, Palindrome. Use cases include AI-enabled targeted support for investments, credit-score insights, agentic payments, AML, KYC. Testing through end-2026; FCA evaluation report Q1 2027.

AI Live Testing cohort 1

Confirmed September 2025; participating from October 2025. Feedback statement FS25/5 published.

AI Spotlight

Analysis of emerging AI trends and their regulatory implications.

AI Sprint

Time-limited initiatives addressing sector-wide AI challenges. Feedback published April 2025.

AI Input Zone

Channel for industry feedback on AI challenges. Open November 2024 to January 2025.

Mills Review (published 6 July 2026)

The Mills Review, led by Executive Director Sheldon Mills, was launched on 27 January and published on 6 July 2026. It considers how AI may reshape retail financial services to 2030 and beyond and identifies four major shifts:

  • Firm operations: transformation of how financial-services firms work
  • Consumer journeys: changes to how consumers access and use financial services
  • Competition and market power: potential changes in market structure and concentration
  • Fraud and cyber risk: the potential amplification of existing harms

The review sets out seven recommendations for the FCA Board and Executive to consider, including adapting the regulatory perimeter, strengthening coordination, monitoring the transition to autonomous models, scaling the AI Lab and developing an AI-enabled supervisory model. These are recommendations, not binding rules. The FCA also said it plans a separate good-and-poor-practice publication later in 2026.

AI use cases and regulatory risks

The FCA’s 2024 survey, AI Live Testing cohort 2 use cases, and the BoE FPC’s April 2026 record together flag where deployment is concentrated:

Use case Key regulatory considerations
Credit decisioning Consumer Duty fair value, explainability, bias testing, DUAA ADM rights
Fraud detection False-positive rates, customer impact, operational resilience
Customer service chatbots Consumer understanding and support; section 80 ADM safeguards where applicable; section 103 complaint handling as a separate duty
Robo-advice and AI-enabled targeted support Suitability, disclosure, human oversight and Consumer Duty; monitor any FCA action following the Mills Review
Claims processing Fair treatment, explanation of decisions, escalation to humans
Risk modeling SS1/23 model risk management, validation, documentation, automated monitoring
AML / KYC Effectiveness, false-positive management, human review
Agentic payments and markets BoE FPC priority, with further work commissioned (April 2026); systemic-risk focus tightening through 2026

Top perceived constraints

According to the FCA survey, firms identify these as the largest constraints on AI adoption:

  1. Data protection and privacy (regulatory)
  2. Resilience, cybersecurity and third-party rules (regulatory)
  3. Consumer Duty (regulatory)
  4. Safety, security and robustness of AI models (non-regulatory)
  5. Insufficient talent and skills (non-regulatory)

How GLACIS can support FCA and PRA evidence workflows

Financial-services firms should assess AI use through existing regulatory frameworks, including Consumer Duty, SM&CR and applicable PRA expectations. The Mills Review recommends how the FCA might evolve its approach, but it does not prescribe an evidence format or endorse any vendor. GLACIS can create records of configured controls and selected runtime events; each firm remains responsible for deciding whether those records support its obligations.

Consumer Duty evidence

Selected signed records can preserve covered claims about reported outputs and control outcomes. Firms can use those records as one input to Consumer Duty monitoring and management information; execution, effectiveness, coverage, good customer outcomes, and satisfaction of an FCA request remain separate questions.

SM&CR accountability records

Link AI governance to Senior Management Functions. Bounded control and review records may support a wider reasonable-steps record, but they do not establish the defense or a supervisory conclusion by themselves.

SS1/23 model monitoring

PRA SS1/23 Principle 5 concerns model-risk mitigants and the proportionality of controls. It does not prescribe universal real-time monitoring. Selected records from configured control paths may support monitoring and investigation alongside the firm’s broader model-risk evidence.

Where scoped records can support FCA and PRA work

Regulatory requirement Potential evidence contribution
Consumer Duty: good outcomes Selected records of AI recommendations and configured-control results that a firm can reconcile with customer-outcome data for management information.
SS1/23: model inventory A configured integration can carry supplied model, version and use-case identifiers in selected records. The firm remains responsible for inventory ownership, scope decisions and catalog maintenance.
SS1/23: independent validation Teams can manually assemble selected signed records with validation, testing, coverage and source evidence for internal or external review. Glacis does not currently promise an automated validation-package export.
SS1/23: model-risk mitigants and monitoring Selected records of the monitoring and configured-control events actually captured; whether those records satisfy a supervisory expectation remains system- and pathway-specific.
SM&CR: reasonable steps Bounded control and review records may support a wider reasonable-steps record; they do not establish the legal conclusion by themselves.
DUAA: ADM rights Captured decision and review events may support information, representation, and human-intervention workflows under section 80’s new Articles 22A to 22D. Section 103 is the separate complaints-to-controllers provision.
BoE FPC agentic-AI focus Bounded records from configured agentic-AI control paths may support later investigation; no current BoE work program is treated here as a certification requirement.

Make consequential AI decisions reviewable

Discuss how records of configured controls and selected AI events could support your internal work on Consumer Duty, SM&CR and applicable PRA expectations.

Talk to us

Related guides