Alan Bainbridge
Partner

Alan Bainbridge is a corporate lawyer based in London and global head of the firm’s Banks sector. Alan focuses on strategic M&A and corporate advisory for banks and other financial institutions and regularly advises on bank-specific legislation.

Prior to becoming a partner in 2007, Alan spent a number of years in our Hong Kong office. Alan regularly advises bank boards on governance matters and bank specific legislation and has frequently contributed to academic publications such as A Practitioners Guide to Individual Conduct and Accountability in Financial Services Firms and the UK chapter of Global Legal Insights guide to Banking Regulation.

Simon Lovegrove
Senior Manager

Simon is global head of financial services knowledge and is based in London. He has a degree in law and a master’s degree in business law. Simon focuses on financial services and markets regulation and is responsible for financial services knowledge globally and manages a team of financial services knowledge professionals within the London office.

Before joining the practice in January 2006, Simon worked for several years in the funds and financial services team of another city practice. During his time there he acted on the MBO of a London listed Guernsey property fund which was the first ever takeover of a Guernsey listed company.

AI in UK Financial Services: Navigating the Regulatory Landscape

Introduction

Innovation is everywhere in financial services – 75% of UK financial services firms are already using artificial intelligence (AI)1According to the 2024 joint Bank of England–FCA survey, (published November 2024 and updated by the FCA in December 2025).. With such widespread adoption, regulators and policymakers face a difficult problem, maintaining a healthy balance between harnessing the benefits of innovation while mitigating the risks. In America, policymakers have tended to focus more on the opportunities, with a regulatory environment that’s more flexible and conducive to business innovation. In Europe and the UK, the regulators have often taken a different approach and focussed on the risks and call for regulation. But given the speed of AI-adoption among institutions in the financial sector the more cautious approach risks stifling AI-driven innovation and thereby reducing institutions’ competitive edge.

UK regulatory policy approach

In January of this year, the House of Commons’ Treasury Committee (Treasury Committee) issued a report on AI in UK financial services arguing that the financial services regulators were not doing enough to guide firms on their regulatory responsibilities towards AI. Unlike the EU, the UK has no AI-specific legislation or financial regulation and instead the Financial Conduct Authority (FCA) and the Prudential Regulation Authority (PRA) have asserted that the existing regulatory framework is sufficient – with, in particular, the Senior Managers and Certification Regime and Consumer Duty (Duty) providing, quote, “enough regulatory bite.” Notwithstanding the FCA’s introduction in 2025 of its AI Live Testing service alongside its new Supercharged Sandbox, industry stakeholders expressed concern that the FCA’s approach was reactive rather than proactive, leaving firms with little practical guidance on how to apply existing rules to their AI usage. In response the Treasury Committee has recommended that by the end of this year the FCA publish comprehensive, practical guidance on how consumer protection rules apply to AI, and what accountability looks like for senior managers.

Following the Treasury Committee report the FCA announced an initiative called the Mills Review2The Mills Review is an FCA-led initiative announced on 27 January 2026, headed by Sheldon Mills. Sheldon Mills is a senior regulatory figure in UK financial services. He serves as the Executive Director for Consumers and Competition at the FCA, a position he has held since December 2020. which will look into the long-term impact of AI on retail financial services, looking towards 2030 and beyond. Importantly, the review is examining what the FCA calls a potential “inflection point” in how AI technology interacts with financial services. However, at the moment the review doesn’t envisage new AI-specific rules. Rather than rewriting the current regulatory framework the review is to consider how their application may need to adapt as AI changes the pace, scale, and nature of markets.

Whilst the Mills Review is inviting debate on some quite fundamental questions about consumer protection, market structure, and regulatory design there remains the question of what firms should be thinking about now.

Boards

What is clear is that the demands placed on financial institutions’ boards have risen as the landscape in which they operate has become more complex with the advent of AI, underscoring the need for them to have robust governance frameworks in place. Although there are many instances of guidance from the broader governance landscape on the impact of AI for boards3See for example the IoD Business Paper: AI Governance in the Boardroom., the unique challenges and risks in financial institutions makes the need for boards to focus on AI even more acute.

The FCA expects firms to have robust governance arrangements, which encompass not only effective oversight at board and senior management level but also the implementation of effective systems and controls. This includes in relation to the firm’s deployment and use of AI tools. If a firm’s systems and controls are found to be inadequate individuals with responsibility for these areas may be held personally accountable. This could include, for example, the Chief Technology Officer, Chief Risk Officer, or any senior manager with oversight of technology, risk, or compliance functions. This highlights the need to continually reassess the firm’s responsibilities map to ensure that there are no accountability gaps and the relevant individuals have responsibility for such deployment.

Whilst there may not yet have been FCA enforcement actions based specifically on the deployment of AI there are plenty of earlier decisions relating to other forms of technology and systems and controls which offer useful insights for boards about what can go wrong and how they can avoid some of the common pitfalls. It is well worth boards re-examining these.

Consumers

The Treasury Committee noted that it received substantial evidence about how AI could bring both considerable harm as well as benefits to everyday people using financial services. From a regulatory perspective, the bottom line for firms is that they need to be able to withstand scrutiny from the regulator in relation to how it ensures AI does not undermine consumer protection.

The Duty includes three cross-cutting rules which set out how firms should act to deliver good outcomes for retail customers. One of these rules is that firms act in good faith towards retail customers. In its guidance on the Duty4Finalised Guidance 22/5 Final non-Handbook Guidance for firms on the Consumer Duty – para 5.12 the FCA provides certain examples where a firm is not considered to be acting in good faith at the product or service design phase:

Using algorithms, including machine learning or AI, within products or services in ways that could lead to consumer harm. This might apply where algorithms embed or amplify bias and lead to outcomes that are systematically worse for some groups of customers, unless differences in outcome can be justified objectively.

The important point is that the differences in outcome need to be justified objectively. The firm needs to provide a clear, evidence‑based, reasonable, non‑self‑serving explanation for why the AI‑driven approach is appropriate and fair for consumers. This may be no easy thing. Also, the Duty requires ongoing monitoring of outcomes and in this regard AI presents certain challenges in that models drift over time and data changes can introduce new bias.

Third party providers

Where firms deploy AI capabilities through external suppliers – including cloud-based AI, model-as-a-service offerings, or AI tools embedded within outsourced IT arrangements – they must treat the AI dependency as part of the relevant third-party service.

In the regulatory space there are certain rules and guidance to consider including the following. First, for banks and insurers, PRA Supervisory Statement 2/21 (SS2/21) sets out lifecycle expectations for third-party dependencies covering materiality assessment, data security, audit/access, sub‑outsourcing, business continuity planning and exit planning. Second, FCA Finalised Guidance 16/5 (FG16/5), which generally applies to FCA authorized firm,5The guidance in FG16/5 does not apply to credit institutions and investment firms subject to the Capital Requirement Regulations i.e. banks, building societies and IFPRU investment firms as defined in the FCA Handbook; and payment and electronic money institutions to whom the EBA Guidelines on outsourcing arrangements are addressed. clarifies conduct expectations when using cloud/other IT services and its requirements for due diligence, risk assessment, contractual safeguards, ongoing monitoring, and exit planning apply for AI-related outsourcing. There are challenges in applying SS2/21 and FG16/5 to third parties using AI including demonstrating that regulatory due diligence obligations have been discharged and agreeing liability in contracts where there is no settled industry standard for AI performance against which to measure negligence.

Operational resilience is another important issue6There are a number of important papers from the PRA and FCA in addition to SS2/21 and FG16/5. For instance, the PRA’s supervisory statements (SS) 1/21 – Operational resilience: Impact tolerances for important business services and SS2/21 – Outsourcing and third-party risk management, as well as the FCA’s PS21/3 – Building operational resilience and SYSC 15A. with the rules under SYSC 15A and PS21/3 applying to AI used in ‘important business services’ through the same framework as any other technology or process dependency. An important business service is defined as a service provided by the firm (or by another person on behalf of the firm) to one or more clients which, if disrupted, could: (1) cause intolerable levels of harm to any one or more of the firm’s clients; or (2) pose a risk to the soundness, stability, or resilience of the UK financial system or the orderly operation of the financial markets. Where AI systems or tools are embedded within services that meet this threshold, firms must identify those services as important business services.

Given the trajectory of AI adoption, the expanding use of AI in customer-facing and core functions, it is increasingly likely that AI will underpin ‘important business services’ for many firms. As such, firms should be assessing whether their AI systems support services that meet the threshold for important business services. They should also be mapping their AI dependencies, including third-party providers and testing AI-specific failure scenarios against impact tolerances.

There is also the UK’s critical third parties’ regime under the Financial Services and Markets Act 2023. HM Treasury (HMT) has the power to designate certain third parties as critical third parties (CTPs), based on recommendations from the regulators. Once designated, CTPs must comply with minimum resilience standards and fundamental rules set by the regulators. HMT has indicated that it expects CTPs will represent only a small number of the overall third parties to the financial services sector. The consultation paper on the CTP oversight regime, published in December 2023, contained an estimated population of approximately 20 CTPs. So far HMT hasn’t made any designations although that is expected to change this year. Whether AI providers will find themselves caught by the regime remains to be seen. But as financial institutions’ reliance on AI grows this becomes increasingly likely.

Financial crime and market integrity

AI is increasingly being used by criminals to create synthetic identities, deepfakes, and forged documents that can bypass traditional know-your-customer (KYC) checks. In response firms are using AI technology extensively in their anti-money laundering (AML), fraud detection, sanctions screening, and KYC processes.

Whilst AI offers significant advantages over traditional rule-based systems firms need to navigate several critical compliance and operational challenges. For example, the regulators will expect firms to demonstrate how AML decisions are made and this will require them to have adequate audit trails and justifications for AI-generated outcomes. However, many AI models, particularly complex machine learning algorithms, operate as “black boxes” where the decision-making process is opaque. AI systems are only as effective as the data upon which they are trained and if the historical data contains biases the AI may perpetuate or amplify these biases. As such firms need to implement robust data governance frameworks to ensure data is accurate, representative, and regularly updated. And AI models can degrade over time as money laundering typologies evolve and as such there needs to be ongoing monitoring, testing and recalibration.

In October 2024, the Bank of England (Bank) published a speech7 regarding how AI may impact financial stability. For example, the Bank flagged concerns that a trading algorithm, without the proper control environment and human oversight, could influence asset prices in an illegitimate way and/or have the potential to influence another AI system’s actions in the trading ecosystem, thereby leading to a potentially systemic impact on price fluctuations in the market (albeit unintended). The Bank warned that as firms increasingly consider the use of AI in higher impact areas of their businesses such as credit risk assessment, capital management and algorithmic trading, it would expect a stronger, more rigorous degree of oversight and challenge by their management and boards.

AI also presents significant cyber‑related risks and last year the G7 cyber expert group issued a statement8 intended to raise awareness of this issue and provide high-level guidance in the form of key considerations for financial institutions and authorities. Such considerations include whether incident response plans and playbooks are updated to account for AI-enhanced attacks and AI-specific incidents.

The regulators

Like other international financial services regulators, the FCA and the PRA are themselves using AI in multiple ways to enhance their own supervisory capabilities, and to support firms in their adoption of AI. The FCA is focussing on becoming a “smarter regulator”, embedding AI into core supervisory, authorisation, and consumer‑facing processes. For example, the FCA applies advanced analytics to trading data to detect potential misconduct, including cross-market manipulation and other complex forms of market abuse. The FCA has also developed an in-house synthetic data tool for sanctions screening testing that has “transformed” its assessment of firms’ sanctions name screening systems. This capability allows the regulator to test how effectively firms’ systems match names against the UK’s consolidated sanctions list, including whether they handle fuzzy matches, threshold logic, and false positives appropriately. AI undeniably strengthens the FCA’s supervisory toolkit, but it also introduces material risks – many of which the FCA itself has acknowledged in its publications including model error, bias and opaqueness.

Conclusion

The UK’s approach to AI regulation in financial services stands at a crossroads. Whilst the FCA and PRA maintain that existing frameworks provide sufficient regulatory bite, the Treasury Committee’s criticisms and subsequent launch of the Mills Review signal growing recognition that the status quo may not be sustainable as AI adoption accelerates.

But for boards and senior managers, the message is clear: accountability will not wait for prescriptive guidance. Firms must proactively assess their governance arrangements, ensure responsibilities maps reflect AI-related risks, and learn from past enforcement actions involving technology failures. The Duty’s requirement to act in good faith demands that firms can objectively justify AI-driven outcomes, whilst third-party risk management frameworks require adaptation to address the unique challenges posed by AI suppliers. Meanwhile, financial crime and market integrity concerns add further layers of complexity, with regulators expecting robust oversight even as AI systems themselves become harder to explain and audit.