Article

Report issued by the Mills Review—the future of AI in retail financial services

Report issued by the Mills Review—the future of AI in retail financial services
The Financial Conduct Authority (FCA) has published the Mills Review: a detailed report that includes seven recommendations on how the FCA should adapt to the use of AI in retail financial services. 
Summary

The FCA will review the regulatory perimeter within three to six months.

The Senior Managers Regime and Consumer Duty will remain unchanged, albeit we expect clarification on how these regimes will apply in the context of Autonomous AI.

A “good and poor practice” publication is expected later this year.

Mills Review

In January 2026, the FCA launched the Mills Review1 to consider artificial intelligence (AI) in the context of retail financial services. Sheldon Mills spearheaded the review. 

The FCA published the resulting detailed 147-page report on July 62, 2026, with a series of seven recommendations, ostensibly made for the consideration of the FCA Board. Mr Mills positioned the report as follows:

“A roadmap for how industry regulators and government can prepare for the next phase of AI-driven change in our world-leading financial services sector.”

Some of the findings in the report acknowledge well understood views, e.g., at one point, the report suggests that the uptake of AI in this sector will depend on trust, control and access. At another point, the report suggests that, as AI becomes more embedded, its governance becomes increasingly important.

However, the study3 (commissioned by the FCA and published alongside the report) will be of interest to retail facing firms for its analysis into how retail customers currently use and view AI, and helpful to firms interested in expanding their use of AI in retail facing activities.

Some takeaway points from the study:

  • AI is widely visible but not yet widely trusted with money. 16% report using AI to assist them in relation to personal finance, but mainly as an assistive tool-to summarise, explain, simplify, and compare information.
  • There is a sizeable group of consumers resistant to AI-enabled financial services—between a quarter and a third of consumers express negative views.
  • Concerns reflect issues of accountability and protection, e.g., a concern as to a misuse of personal and financial data was at 68%, a lack of protection if something goes wrong was at 67%. There was also a key concern around a concentration of power among large firms—registered at 65% among respondents.
  • Safeguards and control are central to adoption decisions. The most important drivers are protection if something goes wrong (32%) and evidence of accuracy and reliability (30%). Some consumers also focused on the importance of being able to opt out and access human support, and understanding how firms make decisions.

The report identifies four major AI-driven shifts likely to impact retail financial services:

  • Transformation of firm operations
  • Evolution of consumer journeys
  • The reshaping of competition and market power
  • Amplification of fraud and cyber risks

The report discusses and analyses each shift in detail with the last point in particular likely to be a focal point for the FCA, underscoring its ongoing concern about operational resilience and cyber crime.

The report is also candid about the complexities of defining common international standards, acknowledging that a desire for growth and international competitive advantage, national security and technological sovereignty may complicate efforts to this end.

AI autonomy spectrum

Central to the report is a “spectrum of autonomy” framework, which relates to the changing role of humans in a process. The report uses that framework to articulate different benefits and risks. Moving along this spectrum, the role of a human in the process changes, from performing and directing individual tasks towards setting boundaries, granting permissions and overseeing and observing outcomes.

This spectrum is particularly relevant to the analysis of agentic AI, which enables a shift from assistance to delegation, with systems taking on longer tasks and more actions within a particular process. 

The report defines agentic AI as an AI system composed of one or more coordinated AI agents that can autonomously break down tasks, collaborate and pursue complex objectives over extended periods in dynamic environments, with minimal human supervision. 

The report notes that surveys largely did not address agentic AI two years ago, but it is now being piloted or deployed by over half of the respondents to a survey conducted at the end of 2024 (albeit the scope is so far fairly limited). 

This reflects how rapidly the capabilities of relevant models are improving—a recent study of frontier systems found the duration of work they can finish on their own, measured against how long it takes a person, has roughly doubled every seven months, and faster still more recently. However, the picture is mixed in terms of cost. Training the most advanced AI models is becoming more expensive. Overall spending is also rising, as firms embed AI more widely, adapt it to more complex work, and add monitoring to meet regulatory requirements.

In terms of risk management, there are a number of key points, including the following:

  • Retail financial services firms are likely to use a risk-tiered model–permitting more automation for routine or “easy to reverse” tasks; but stronger controls are needed where an action is high value or material, and bearing in mind the spectrum above, firms need to decide where the human sits, e.g., approval before action, supervision during a workflow, review by exception, etc.
  • More delegation makes the reliability of the underlying model more important.
  • Models can become less reliable over time (a concept called model drift), outputs can be plausible without being correct (a concept called hallucination), and models may produce different answers to similar questions, making it difficult to reconstruct what has occurred and why, but also can produce challenges in terms of consistency.
  • Firms need controls around both the model and the system in which it operates.

Importantly, the report considers that the rise of agentic AI (where AI moves from recommending to acting, and firms and consumers delegate more) means that risks move from harm within a single firm towards system-wide harms, e.g., shared reliance on similar models, datasets and infrastructure providers could generate correlated behaviour, herding, opacity and common points of failure across the financial services system. A change or failure in a widely used model or service, or interactions between AI agents across firms, could spread rapidly through firms and markets.

One key comment is frank and telling: 

“Practically speaking, we don’t know how far this goes and full autonomy seems unlikely to sit well with the current regulatory framework or UK societal appetites.”

At the same time, the perceived potential benefits are meaningful. The report identifies AI as having the potential to address various weaknesses in retail financial services, including the advice gap (only 9% of consumers use traditional advice), the protection gap (just 30% hold life or income protection), and low switching. 

The report also highlights financial exclusion (around 900,000 are unbanked) and suboptimal saving (GBP300 billion sitting in low-interest accounts). AI is identified as having the potential to help consumers make better decisions, access more suitable products and manage their finances more effectively, bringing both personal and societal benefits.

Key points for firms to note

The report is incredibly rich in detail, but the following points will be of considerable interest to UK licensed firms.

Governance

Unsurprisingly, the report underlines the importance of aligning governance frameworks with developments in AI.

Some key points to note:

As AI becomes a core operational capability for a firm, its model risk management (MRM) and other governance frameworks will need to evolve.

General purpose and frontier AI models can introduce various challenges (including model drift and degradation) requiring more than a traditional “point-in-time” validation approach. Firms will increasingly need a more dynamic approach to model governance, monitoring and assurance, supported by end-to-end controls across the AI lifecycle.

This is particularly important for dual-regulated firms already subject to PS6/23 (Model risk management principles for banks)4.

As one of its seven recommendations, the report also suggests the FCA (and PRA) support the development of more effective approaches to MRM as it relates to conduct risk.

Senior Managers Regime and accountability

The report observes that, in engagement with industry, no firm argued that the senior managers’ accountability model should change, but:

Many are considering how to continue to comply as AI use evolves.

Clearer guidance from the FCA could provide more confidence to firms in adopting new use cases.

One very interesting comment in the report on this subject was as follows:

“In a technological arms race scenario, the personal accountability regime could serve as an important mitigant against firms adopting a ‘growth at all costs’ strategy and internalising regulatory sanctions as a priced risk rather than a constraint. Under the Senior Managers Regime, individuals, not firms, remain personally accountable.”

Bearing these points in mind, a key recommendation of the report was for the FCA to take a proactive approach, providing clarity for firms in terms of how the Senior Managers Regime applies in the context of increasingly autonomous AI.

Consumer duty

The FCA has concerns about a two-tier market developing (those who have access to and/or use AI and those who do not). 

It also noted the challenge of compliance (and demonstrating compliance) as levels of autonomy increase and noted stakeholder feedback that firms need clearer views from the FCA, e.g., how to evidence outcomes in dynamic journeys, how to ensure consent remains meaningful where systems act continuously and with increasing autonomy, and how to apply consumer protection standards as delegation increases.

Again, this has resulted in a key recommendation of the report—for the FCA to take a proactive approach in providing clarity and guidance for firms in these types of areas.

Advice/guidance boundary and targeted support

Some consumers are already using AI to support financial decisions in ways that resemble guidance or advice. As AI becomes more embedded and models evolve, functionally similar activity to what we recognise as regulated activity may occur.

This also creates a practical question as to when AI-mediated interactions move from the provision of information (in principle non-FCA regulated), into activity that resembles regulated advice, arranging or promotion.

These types of points will presumably be factored into the perimeter review recommended by the report. For more on this, see below.

Operational resilience

The report considers that firms that have under-invested in fundamental cyber security are likely to become progressively more exposed, quoting one firm as saying that the era of AI-powered attacks at scale has arrived.

The report also highlights new systemic risks:

  • Shared model dependencies may create correlated, system-wide risks. That is, if multiple firms depend on the same model provider, an outage, security risk or model degradation could affect all relevant firms at the same time.
  • If a large number of firms use similar models for similar activities, they may end up behaving in a similar way, amplifying market risks.
  • Regulators may have limited visibility of concentration in model provision and infrastructure, making it harder to identify an issue or respond effectively until a problem has actually occurred.

Recommendations

The report’s recommendations are particularly interesting and represent what can be considered a “call to arms” for what the FCA can and should do by way of next steps to ensure it, and the UK regulatory regime generally, keeps pace with the rapidly developing technology.

On this subject, the report is thoughtful and likely to be welcomed by industry.

Recommendation 1: “Secure and adapt the regulatory perimeter”

The report recommends a review of the perimeter within the next three to six months on various topics (including the scale, nature and impact of general-purpose LLMs outside the perimeter), but at its heart is a question as to how the regulatory regime may need to evolve when retail customers use AI increasingly to act, rather than just for information, assistance or advice.

Alongside this, the report recommends ongoing monitoring, market engagement, and a consideration of tools for intervention, as risks emerge. The report also recommends the FCA consider requesting the government boost its existing powers under the critical third party (CTP) regime and the designated activities regime (DAR) to meet the challenges of AI.

Recommendation 2: “Strengthen system-wide coordination and oversight”

Among other things, this would focus on resilience, data, competition, security, safety risk, consumer protection, supervisory approaches and standards-setting. It would also reflect the way that AI may concentrate certain risks that may therefore emerge at a systemic level, as explained above, and links to the point about CTPs mentioned above.

Recommendation 3: “Monitor the transition to autonomous models and adapt regulatory frameworks”

Among other things, this would involve the FCA (and the PRA) supporting the development of more effective approaches to AI model risk management, e.g., to improve explainability, assurance, governance and oversight.

It would also include the FCA providing clarity on how existing frameworks apply in AI-mediated contexts, e.g., the Consumer Duty, the Senior Managers Regime and expectations on governance. In particular, it would cover how senior managers demonstrate reasonable steps, how firms exercise accountability across interconnected systems, and how the FCA should strengthen expectations on evidencing outcomes and control.

Most importantly, this recommendation would require the FCA to assess when it may need further “adaptation” of the regulatory regime (whether to clarify existing requirements or do something more) as AI autonomy increases, and to “improve the pace and responsiveness of regulatory adaptation”.

Recommendation 4: “Scale up the FCA’s AI Lab to support AI models and system innovation in financial services”

The recommendation centres around the idea that the FCA needs to develop an independent capability to understand and evaluate model and system behaviour in practice, rather than relying solely on firms’ or providers’ own assessments. It includes building core capabilities within the FCA, engaging earlier in the development cycle, using structured partnerships, making outputs public, and continually reviewing and scaling.

Recommendation 5: “Enable the foundations for agentic finance”

The report recommends that the FCA develop “a trusted framework for AI agent participation in financial services, clarifying how agents can be authorised, identified and held accountable. This should help establish clear expectations for consent mandates, identity, control and liability, creating the conditions for safe adoption of more autonomous AI-enabled services”.

Some of the more detailed recommendations made here include defining requirements for AI agents acting in financial services, clarifying accountability and liability frameworks, developing standards for evidencing control and auditability, enabling interoperability across data, identity and payments, and engaging with government on “digital identity for individuals” initiatives.

For more on this, see below.

The useful and pragmatic recommendation is as follows: “This should be developed as a targeted, principles-based framework, built on existing regulatory foundations rather than creating a new regime. The objective is to enable adoption while ensuring that accountability remains clear and enforceable.”

Recommendation 5 has particular relevance because the UK government has recently announced that agentic payments form part of certain measures it foresees as improving growth and innovation in the UK.

The report notes that this is a subset of agentic finance, which encompasses a broader range of AI agents that may help consumers manage their financial lives. It is defined as finance in which at least one party to the allocation, intermediation, or use of capital is an autonomous AI agent capable of independent economic action.

The report notes, however, that agentic finance requires enabling infrastructure to support the safe and accountable delegation to AI agents. To this end, the report identifies a number of building blocks as follows. These are briefly stated in the body of the report, with more detail and analysis in Annex VII (Infrastructure for agentic finance).

Building blockImplications for agentic financeFurther comments from the report
Data
Agents depend on goal, observation and outcome data. Data quality and availability remain a binding constraint on scale.

Data quality refers to data that is accurate, complete, timely, consistent and traceable, and maintained at a level appropriate to the decision being taken.

The report cites a research facility as stating that data quality is the single most significant barrier to scaling AI in financial services.

AI agents need three categories of data:

  • Goal data—this determines what the AI agent is trying to achieve.
  • Observation data—what the agent can see about markets, products, prices and the consumer’s financial position.
  • Outcome data—the record of what the agent did, what happened as a result, and whether it achieved the goal.

Data quality is foundational from a number of perspectives. First, within a model, if the conditions mentioned above are not met, outputs become unreliable. Secondly, data obtained by the FCA is key to its ability to provide effective supervision.

 
Identity
Agents are linked to a consumer and mandate, with verifiable authority over actions taken.
The report considers the matter of verification to be of central importance, and a gateway to useful agentic capability, with a focus on both the consumer’s identity as well as that of the agent.
Authorisation and delegation
Decision-making shifts from point-in-time approval to pre-authorised, bounded and revocable mandates operating over time.
The UK needs a standardised framework through which a consumer can delegate authority to an AI agent across a set of financial actions, with clear limits and accountability, and firms can verify that authority in real-time without requiring customer re-authentication at each relevant step.
Execution (payments)
Existing payment frameworks assume human approval and are not aligned to delegated or autonomous agent execution.
The report notes that payments are pivotal to society’s ability to realise the potential of AI in this area. Without trusted agentic payments, AI in finance remains largely assistive in nature and does not move to the most delegated stages on the spectrum of autonomy.
Liability
Responsibility becomes harder to attribute as actions are delegated, shaping behaviour, trust and adoption.

The report notes this point as particularly key for the industry. A firm that cannot clearly allocate liability for a loss caused by a third-party agent will likely require its own human-authenticated confirmation at each step, and not rely on the consumer’s pre-authorisation alone.

An articulated framework on liability is therefore important to enable the industry to progress along the spectrum of autonomy. Without this, the consumer experience is full of friction and autonomy is not possible.

Supervision and audit
Agent activity becomes traceable, with visibility of authority, actions and outcomes supporting redress and system-wide oversight.
The report observes that regulators and consumers will need to understand what an agent did, on what authority and with what result.

The report leaves the regulator and the market to decide how these foundations can or will evolve. However, it clearly lays down a challenge for the FCA; to take a lead role in helping the UK along this journey, both to shape the outcomes and to enable the industry (and UK consumers) to realise the potential benefits in full.

Recommendation 6: “Build and adopt an AI-enabled agentic supervisory model”

The report makes a case for the increased use of agentic AI by the FCA itself, both for individual firm supervision as well as for broader systemic risks.

Recommendation 7: “Develop a trusted public-interest AI-enabled financial capability service”

Given the breadth of the other recommendations, and the need to find resource to fulfil them, it is not clear that the FCA has effectively made out the business case for this final recommendation, which would need some sort of public funding (given the service it contemplates is intended to be free).

But the concept here is around developing an AI-enabled service for consumers, giving them free access to reliable financial information, guidance and support, built on trusted financial information sources.

Next steps

We expect the FCA to focus from this point on “operationalising” the recommendations in the report.
Beyond this: 

  • As noted above, the report recommends a review of the perimeter within the next three to six months, which regulated firms, and companies involved in the provision of AI, should watch out for.
  • The report recommends the FCA clarify how the regulatory regime applies in the context of certain AI use cases (in particular, in the context of the Senior Managers Regime and the Consumer Duty), which again, firms in scope should watch out for.
  • The FCA has said it will launch an “AI good and poor practice” publication later this year and has been engaging with firms to find out what is working well, where firms are facing challenges, and where clarity from the regulator may be needed on key issues or points. For more on this, see “AI in financial services: shaping our approach through industry engagement5”. The FCA has also previously encouraged firms to provide views via the “AI Input Zone6”.
  • The report foreshadows that further regulatory “adaptations” will need to follow over time, with the idea that the current framework represents a sound foundation but faces increasing strain as AI use cases evolve, particularly around agentic AI

Takeaways

Following the Mills Review, we expect the FCA to take a more proactive and “hands on” approach to firms’ deployment of AI.

Firms should therefore assess their AI frameworks now to ensure they are prepared for any future FCA requests, which we expect will focus on:

  • Evidence of outcomes under the Consumer Duty.
  • Senior manager accountability for AI-enabled processes.
  • Third-party model oversight.

The FCA is also likely to continue to focus on operational resilience and cyber security.

Footnotes

1Review into the long-term impact of AI on retail financial services (The Mills Review)

2AI and the future of retail financial services (The Mills Review)

3Yonder/ FCA AI Consumer Research

4PS6/23 – Model risk management principles for banks Policy statement 6/23

5AI in financial services: shaping our approach through industry engagement

6AI Input Zone

Related capabilities