FCA Mills Review puts AI accountability at the heart of fintech

The FCA's Mills Review signals tighter AI governance for financial services as automated systems move from assistance to autonomous action.

A computer monitor displaying system performance data, a keyboard, and a mouse are positioned on a white desk in a brightly lit data center, surrounded by rows of dark server racks featuring blinking blue and green LED lights.

The UK's Financial Conduct Authority has published the Mills Review, a wide-ranging examination of how artificial intelligence could reshape retail financial services by 2030. Drawing on 140 submissions and research involving more than 5,000 UK adults, the Review carries no immediate legislative force but sets out a clear direction of travel for regulatory expectations as AI moves from a supporting tool to an active participant in customer decision-making.

The timing is notable. The Review's publication on 6 July coincided, within a fortnight, with the government's appointment of Kanishka Narayan as the UK's first Minister for Artificial Intelligence with Cabinet-attending status. Taken together, the two developments signal that AI governance is no longer a compliance side-issue for financial services boards, it is a primary economic and public policy concern.

From assistance to delegation

The Review's central tension is the shift from AI as an assistant to AI as an agent. Joe Norburn, CEO of regulatory consultancy TCC Group, characterises the change clearly: a consumer who today uses AI to compare savings accounts may tomorrow delegate the actual movement of funds to the same system. A firm that uses AI to flag customer vulnerability may soon allow it to determine the appropriate support pathway without human sign-off. As Norburn puts it, "as that responsibility grows, accountability, consent and redress become harder."

The FCA has recommended that within three to six months it examine how consumers are already using general-purpose AI tools across savings, investments, pensions, mortgages and debt management. The findings could alter guidance or prompt recommendations to government about the regulatory perimeter, meaning platforms such as ChatGPT or Gemini, which millions of UK adults already consult for financial queries, may soon face new scrutiny even if they sit outside the FCA's current reach. Only 40 per cent of respondents correctly understood they have no formal recourse when acting on advice from such tools, a consumer-protection gap the Review treats as urgent.

Accountability cannot be outsourced

The Review reaffirms that existing obligations, the Consumer Duty, the Senior Managers and Certification Regime (SMCR), and operational resilience frameworks, already apply to AI-influenced outcomes. When an automated system shapes a customer journey, the regulated firm remains responsible, regardless of whether the model was built in-house or procured from a third-party vendor. That position has significant operational implications. A customer interaction may pass through several models, datasets and providers; if something goes wrong, the firm must reconstruct what happened and demonstrate that its controls were functioning at each point.

Norburn argues boards need a practical account of where AI affects decisions, who carries responsibility, and how the organisation knows customers are being treated fairly. Monitoring that relies on periodic sampling alone may be insufficient where AI influences high volumes of interactions at speed.

The cross-sector capital and governance read-across

For investors and strategists watching the broader convergence of AI and regulated industries, the Mills Review is an early test case for a governance framework challenge that extends well beyond UK retail finance. The same accountability questions, model drift, third-party supply chains, autonomous action within preset parameters, apply to AI-assisted clinical decisions in healthcare, algorithmic procurement in defence, and automated credit allocation across emerging-market fintech. Regulators in the EU (under the AI Act's high-risk classification for credit and insurance) and the US (via the Consumer Financial Protection Bureau's evolving model-risk guidance) are moving along parallel tracks.

The commercial implication is significant. Firms that can demonstrate robust AI governance infrastructure, decision records, outcome testing, clear escalation routes, board-level visibility, are likely to gain a competitive advantage as regulatory expectations tighten. Those that cannot will face the prospect of rebuilding controls under duress, at greater cost and with less freedom to deploy AI at scale. The regulatory compliance and RegTech sectors are the immediate beneficiaries, but the second-order effect is a governance-infrastructure arms race that will draw in data management, legal-tech, and model-monitoring vendors across every AI-adjacent vertical.