The Financial Conduct Authority has drawn a line in the sand for every fintech firm, neobank, and incumbent financial institution operating in British markets. With the publication of The Mills Review: AI and the Future of Retail Financial Services, the FCA has produced what it describes — and what independent observers are already confirming — as the first comprehensive regulatory assessment of artificial intelligence in retail financial services undertaken by any financial regulator globally. The document is not a consultation paper. It is a governance roadmap, and the clock it sets runs to 2030.
The review was led by Sheldon Mills, the FCA's Executive Director for Consumers and Competition, and was explicitly commissioned by the FCA Board — a provenance that signals institutional weight rather than departmental experimentation. Its core argument is deceptively simple but operationally profound: retail financial services are migrating from human-led, episodic interactions toward a world of continuous, delegated, and AI-enabled operations. For compliance officers, chief risk officers, and boards across the UK and, increasingly, the United States, that migration demands structural governance responses — not incremental policy tweaks.
A Spectrum That Reframes the Compliance Conversation
Among the review's most immediately actionable contributions is its formalization of a five-level AI Autonomy Spectrum. At Level 1, humans act as Operators, directing AI as a demand-driven tool for tasks such as summarizing product terms or supporting code development. At Level 2, humans become Collaborators, co-building outputs alongside AI — think a finance team iterating on forecasting models or investigators jointly compiling anti-money laundering case files. Level 3 repositions AI as a Consultant, leading the analysis while a human sets preferences and retains final decision rights. By Level 4, humans have shifted to the role of Approver: the AI independently drafts Suspicious Activity Reports or executes open banking transfers, pausing only for explicit sign-off at defined checkpoints. At Level 5, the human becomes a pure Observer, monitoring fully delegated, continuously optimized operations by exception only.
This taxonomy is more than academic. As Mills notes in the review, "as AI moves from recommending to acting, and firms and consumers delegate more, risks shift from harm within a single firm towards system-wide harms." The spectrum therefore maps directly onto where regulatory accountability must be assigned — and where the Senior Managers Regime (SMR) must be actively invoked by named executives who can demonstrate reasonable steps taken to govern automated workflows, monitor model drift, and audit complex third-party AI supply chains.
Four Structural Shifts With Measurable Stakes
The review documents four structural shifts that will reshape competitive dynamics before the decade closes. The first concerns the transformation of firm architecture: a survey cited in the report shows that 81 per cent of financial firms are already adopting AI at some level, with 40 per cent operating at advanced stages of scaling. By 2030, the review projects that leading institutions will deploy AI as primary infrastructure — not a supplementary layer — for credit underwriting, claims handling, and compliance evidencing.
The second shift concerns consumer behavior. A nationally representative survey of 5,026 UK adults embedded within the review reveals that one in five consumers — 20 per cent — are already open to allowing AI to make autonomous financial decisions for them within pre-set parameters. That figure rises to 28 per cent among individuals who already use AI tools regularly. Demand concentrates most heavily in high-complexity, high-stakes domains: debt advice, pension consolidation, and investment portfolio rebalancing. In the United States, this trajectory is already visible: platforms including Robinhood and Public are permitting clients to connect independent external AI agents directly to their portfolios to execute algorithmic trading strategies based on consumer-defined parameters.
The third shift concerns competition. As consumers migrate toward general-purpose AI assistants and specialised financial agents, whoever controls the AI interface layer captures market power — dictating product visibility, ranking choices, and potentially severing the direct customer relationship from traditional banking brands. Simultaneously, deep upstream dependencies are forming as financial firms grow increasingly reliant on a concentrated cluster of frontier model providers and hyperscalers, creating systemic risks around vendor lock-in and sovereign data control. The fourth and most immediate threat is amplified fraud: the review warns that by 2030, AI will dramatically accelerate financial crime through deepfakes, synthetic identities, and real-time personalized social engineering. The document references recent industry disruptions involving Anthropic's model variants, which required strict operational metering due to fears of cybersecurity exploitation targeting Western banking infrastructure.
Governance Without a New Rulebook — and Seven Priorities That Function as One
One of the review's more strategically significant positions is its explicit rejection of a bespoke AI regulatory framework. The FCA maintains that its existing outcomes-based architecture — anchored by the Consumer Duty and the SMR — provides the correct and sufficient foundation. Accountability, the regulator insists, cannot be delegated to an algorithm. What changes is not the legal basis but the supervisory tooling deployed to enforce it.
To address the systemic risks of correlated AI behavior and market herding that no single-firm rulebook can contain, the review introduces an Agentic Supervisory Model structured around seven interconnected priorities. These encompass securing and adapting the regulatory perimeter to cover large language models conducting financial activities; strengthening cross-sectoral coordination with other regulators; continuously adjusting compliance baselines as autonomous model deployment scales; expanding the FCA's AI Lab for safe innovation; developing trusted agent protocols to underpin agentic finance; building an AI-enabled supervisory system capable of monitoring live market risks in real time; and creating a public-interest AI financial guidance service accessible to all citizens.
What This Means for the Industry
The Mills Review represents a categorical elevation in the sophistication expected of fintech governance. Boards that have tolerated AI oversight as a technology department concern must now treat it as a board-level fiduciary matter. The SMR ensures there is nowhere to hide: named senior managers will be expected to demonstrate command over automated decision chains that, at Level 4 and Level 5 of the autonomy spectrum, may operate entirely without human initiation. The 2030 horizon feels distant; the structural changes required to meet it do not. Firms that treat this review as a compliance checkbox will find themselves architecturally, commercially, and reputationally unprepared for the agentic financial system the FCA has now formally described — and committed to supervising.
Written by the editorial team — independent journalism powered by Codego Press.