UK financial firms face diverging AI rules
UK financial services firms are facing a shifting AI oversight regime as regulators try to support adoption while containing risks to consumers, firms and market stability. The FCA, PRA and Bank of England have largely relied on existing rules, mapping AI governance to principles such as safety, transparency, fairness, accountability and redress, while signaling that the approach could evolve as AI use becomes faster, broader and more complex.
Regulatory pressure is increasing. The House of Commons Treasury Committee criticized regulators for taking a wait and see stance and urged clearer guidance by the end of 2026, AI-specific stress testing and designations for major AI and cloud providers under the Critical Third Parties Regime. The Mills Review found that AI could reshape retail financial services from as early as 2030, affecting firm operations, customer journeys, competition, fraud and cyber risks without recommending new AI-specific regulation.
The government’s Financial Services AI Adoption Plan adds 10 recommendations to encourage safer deployment, including clearer regulatory expectations, scrutiny of advice-like outputs from general purpose large language models, third-party assurance and preparation for agentic payments. Cross-border firms also face a sharper compliance challenge from the EU AI Act, whose prescriptive framework contrasts with the UK’s principles-based model and applies to some UK firms where systems or outputs are used in the EU.