Bearing these points in mind, a key recommendation of the report was for the FCA to take a proactive approach, providing clarity for firms in terms of how the Senior Managers Regime applies in the context of increasingly autonomous AI.
Consumer duty
The FCA has concerns about a two-tier market developing (those who have access to and/or use AI and those who do not).
It also noted the challenge of compliance (and demonstrating compliance) as levels of autonomy increase and noted stakeholder feedback that firms need clearer views from the FCA, e.g., how to evidence outcomes in dynamic journeys, how to ensure consent remains meaningful where systems act continuously and with increasing autonomy, and how to apply consumer protection standards as delegation increases.
Again, this has resulted in a key recommendation of the report—for the FCA to take a proactive approach in providing clarity and guidance for firms in these types of areas.
Advice/guidance boundary and targeted support
Some consumers are already using AI to support financial decisions in ways that resemble guidance or advice. As AI becomes more embedded and models evolve, functionally similar activity to what we recognise as regulated activity may occur.
This also creates a practical question as to when AI-mediated interactions move from the provision of information (in principle non-FCA regulated), into activity that resembles regulated advice, arranging or promotion.
These types of points will presumably be factored into the perimeter review recommended by the report. For more on this, see below.
Operational resilience
The report considers that firms that have under-invested in fundamental cyber security are likely to become progressively more exposed, quoting one firm as saying that the era of AI-powered attacks at scale has arrived.
The report also highlights new systemic risks:
- Shared model dependencies may create correlated, system-wide risks. That is, if multiple firms depend on the same model provider, an outage, security risk or model degradation could affect all relevant firms at the same time.
- If a large number of firms use similar models for similar activities, they may end up behaving in a similar way, amplifying market risks.
- Regulators may have limited visibility of concentration in model provision and infrastructure, making it harder to identify an issue or respond effectively until a problem has actually occurred.
Recommendations
The report’s recommendations are particularly interesting and represent what can be considered a “call to arms” for what the FCA can and should do by way of next steps to ensure it, and the UK regulatory regime generally, keeps pace with the rapidly developing technology.
On this subject, the report is thoughtful and likely to be welcomed by industry.
Recommendation 1: “Secure and adapt the regulatory perimeter”
The report recommends a review of the perimeter within the next three to six months on various topics (including the scale, nature and impact of general-purpose LLMs outside the perimeter), but at its heart is a question as to how the regulatory regime may need to evolve when retail customers use AI increasingly to act, rather than just for information, assistance or advice.
Alongside this, the report recommends ongoing monitoring, market engagement, and a consideration of tools for intervention, as risks emerge. The report also recommends the FCA consider requesting the government boost its existing powers under the critical third party (CTP) regime and the designated activities regime (DAR) to meet the challenges of AI.
Recommendation 2: “Strengthen system-wide coordination and oversight”
Among other things, this would focus on resilience, data, competition, security, safety risk, consumer protection, supervisory approaches and standards-setting. It would also reflect the way that AI may concentrate certain risks that may therefore emerge at a systemic level, as explained above, and links to the point about CTPs mentioned above.
Recommendation 3: “Monitor the transition to autonomous models and adapt regulatory frameworks”
Among other things, this would involve the FCA (and the PRA) supporting the development of more effective approaches to AI model risk management, e.g., to improve explainability, assurance, governance and oversight.
It would also include the FCA providing clarity on how existing frameworks apply in AI-mediated contexts, e.g., the Consumer Duty, the Senior Managers Regime and expectations on governance. In particular, it would cover how senior managers demonstrate reasonable steps, how firms exercise accountability across interconnected systems, and how the FCA should strengthen expectations on evidencing outcomes and control.
Most importantly, this recommendation would require the FCA to assess when it may need further “adaptation” of the regulatory regime (whether to clarify existing requirements or do something more) as AI autonomy increases, and to “improve the pace and responsiveness of regulatory adaptation”.
Recommendation 4: “Scale up the FCA’s AI Lab to support AI models and system innovation in financial services”
The recommendation centres around the idea that the FCA needs to develop an independent capability to understand and evaluate model and system behaviour in practice, rather than relying solely on firms’ or providers’ own assessments. It includes building core capabilities within the FCA, engaging earlier in the development cycle, using structured partnerships, making outputs public, and continually reviewing and scaling.
Recommendation 5: “Enable the foundations for agentic finance”
The report recommends that the FCA develop “a trusted framework for AI agent participation in financial services, clarifying how agents can be authorised, identified and held accountable. This should help establish clear expectations for consent mandates, identity, control and liability, creating the conditions for safe adoption of more autonomous AI-enabled services”.
Some of the more detailed recommendations made here include defining requirements for AI agents acting in financial services, clarifying accountability and liability frameworks, developing standards for evidencing control and auditability, enabling interoperability across data, identity and payments, and engaging with government on “digital identity for individuals” initiatives.
For more on this, see below.
The useful and pragmatic recommendation is as follows: “This should be developed as a targeted, principles-based framework, built on existing regulatory foundations rather than creating a new regime. The objective is to enable adoption while ensuring that accountability remains clear and enforceable.”
Recommendation 5 has particular relevance because the UK government has recently announced that agentic payments form part of certain measures it foresees as improving growth and innovation in the UK.
The report notes that this is a subset of agentic finance, which encompasses a broader range of AI agents that may help consumers manage their financial lives. It is defined as finance in which at least one party to the allocation, intermediation, or use of capital is an autonomous AI agent capable of independent economic action.
The report notes, however, that agentic finance requires enabling infrastructure to support the safe and accountable delegation to AI agents. To this end, the report identifies a number of building blocks as follows. These are briefly stated in the body of the report, with more detail and analysis in Annex VII (Infrastructure for agentic finance).