Written by a human

Full steam AI-head: What’s the U.K. government and FCA AI adoption plan?  

The U.K. government and FCA AI adoption plan has laid out 10 recommendations for how regulators and the industry can reinforce governance as increasingly advanced models become accessible and integrated into core operations.

8 mins read 21 August 2026

In brief:

  • AI adoption is accelerating, with firms steadily moving from pilot to production phases – though regulators are still determining the best approach to maintaining effective oversight
  • The U.K. government and FCA AI Adoption Plan has outlined the key themes and issues facing the industry, from regulatory clarity to third-party risk to skills and talent
  • The plan includes 10 practical recommendations to both support and accelerate responsible AI adoption, which build on the existing regulatory frameworks

The industry has seen a constant dance between innovation and regulation as the use of artificial intelligence (AI) in financial services accelerates. As firms move from pilot to production stages and roll out advanced AI tools to optimize complex workflows, the need for clear, adaptable, and actionable guidance is evident. 

In the U.K., firms are implementing AI at rapid rates, with a survey from the Financial Conduct Authority (FCA) finding that 75% of firms were already reporting adoption – a figure that sits above the wider economy average.

With the U.K. government and FCA having set out 10 recommendations to address common barriers and provide clarity on AI using existing regulatory principles, what can compliance and surveillance teams do now to prepare?

Scaling AI successfully: High-priority actions, strategic initiatives, and long-term resilience

In July, the U.K. government’s Treasury ministry released an independent report on its AI Adoption Plan for the financial services industry. This report was also released alongside, and partially shaped by, the FCA Mills Review that was published earlier in the month.

Both reports have acknowledged how AI is already reshaping the industry and will continue to transform it by 2030 and beyond. In response, they also outlined what’s changing regulation-wise, what the FCA will do differently, and what firms should be doing now.

As part of its adoption plan, the U.K. government set out three main categories to safely and effectively maximize AI’s potential. These are:

  1. immediate actions to support wide-scale adoption;
  2. structural enablers to maintain consistent adoption, and;
  3. strategic actions to uphold resilience and remain competitive long-term.

Immediate actions to support wide-scale adoption

Repurposing the rulebook, not rewriting it

As the report identified, an absence of regulatory support is not the main challenge firms are facing. Instead, it’s the accessibility, consistency, and practical application of existing guidance. One of the immediate recommendations is for regulators to work together to confirm how they’ll keep a “principles-based, outcomes-focused” approach using existing rules.

With industry feedback revealing that it can “be challenging to navigate the regulatory landscape across regulators,” from the FCA to Prudential Regulation Authority to Information Commissioner’s Office, a joined-up regulatory front will help make expectations more cohesive and navigable.

Regulators are also expected to clarify how frameworks like Consumer Duty or the Senior Managers and Certification Regime will apply to AI use cases and build out experimentation programs like the FCA’s AI Lab to support industry collaboration and the safe deployment of new models. As regulators make moves to enhance clarity, firms should be prepared to evidence how their governance strategies apply to existing AI frameworks.

Enabling capability and avoiding compliance headaches

Generative AI (GenAI) tools like large language models (LLMs) present firms with the opportunity to transform productivity by “streamlining operations, enhancing decision-making, and enabling new products and services.” All these benefits can help improve consumer outcomes and support economic growth within the U.K.

In today’s digital age, consumers are already utilizing LLMs and AI chatbots to ask for financial guidance, even though generated outputs must be reviewed for accuracy. According to data from the FCA’s Mills Review, released alongside the U.K.’s AI adoption plan, “around 26% of people trust tools such as ChatGPT, Claude, or Gemini for financial advice.”

Beyond this, firms are deploying generative and even agentic tools to assist with complex internal processes, such as optimizing risk detection, drafting client communications, or even executing payments. To manage oversight of these use cases, the FCA and others have highlighted the need for model governance and risk management frameworks to ensure solutions are performing as expected.

One of the report’s immediate action recommendations is for the FCA to conduct a review of consumer, competition, and wider impacts of advice-like outputs from LLMs. Similarly, firms are encouraged to adopt a “consistent consumer disclosure” for guidance that has been AI-generated.

Structural enablers to maintain consistent adoption

Streamlining third-party management

Firms often rely on third-party providers when adopting new AI tools to optimize business workflows. The report identifies a gap within AI governance, which is that regulated firms are expected to maintain strict liability standards, while unregulated AI providers can scale “without equivalent safeguards.”

Since there is a heavy reliance on a small number of global AI and cloud providers, which introduces sovereignty and concentration risks, the report recommends that the government and regulators assess AI providers under the Critical Third Party (CTP) regime. This would bring systemically important AI infrastructure into direct regulatory oversight.

As regulators take steps to expand oversight around AI providers, firms should be extending third-party and vendor risk assessment beyond traditional outsourcing rules. Doing so will help address AI model and cloud provider concentration as well as verify that governance frameworks are sound, especially where providers may become designated CTPs.

Strengthening AI governance and model autonomy

The Mills review states that model risk management needs to extend “beyond validation at the point of deployment toward live monitoring.” This enables firms to track poor model performance, such as drift or degradation, in real time as opposed to waiting to identify these issues later.

AI is ever-changing, and fixed model validation guidelines won’t keep pace with agentic, consistently updating systems in the same way that cross-industry incident sharing will. The Mills Review laid out an autonomy spectrum for firms to classify AI use cases by risk and necessary human oversight, which firms should use to map out their deployments and reinforce governance.

Developing AI skillsets

AI tools may offer teams transformative capabilities, but without the right skill set and talent, teams won’t be able to fully realize them. The adoption plan recommends that regulatory bodies encourage participation in the Financial Services Skills Compact to secure commitments from firms to invest in AI training and capability-building.

Similarly, the plan recommends that the government collaborates with the industry to develop an AI skills plan that will support investment in AI education focused on equitable access and regional delivery.

Strategic actions to uphold resilience

Reinforcing resilience and risk monitoring

The Mills Review states that as AI advances, it will “amplify fraud and cyber risks, making attacks faster, cheaper, more scalable, and more persuasive” – as proven by frontier models breaking out of isolated testing environments during cybersecurity evaluations. Similarly, deepfakes, synthetic identities, and personalized social engineering are emerging threats, and teams will need to adapt compliance monitoring to effectively detect them.

Thus, resilience is as critical as ever before. The adoption plan outlines several recommendations for resilience as firms continue to test and assess how AI models function within operations, including the creation of both a voluntary AI incident sharing repository and an industry-led AI third-party assurance scheme to share learnings and foster “a culture of collective intelligence” across the industry.

The adoption plan also recommends that the U.K. government and regulators work with the National Cyber Security Centre and the AI Security Institute to create a cross-sector, government-led AI Risk and Resilience Taskforce. This would help break down silos and allow industries to manage fast-evolving vulnerabilities that affect multiple sectors.

AI frameworks and the future of financial services: Key takeaways

As the AI adoption plan suggests, firms can ask themselves the following questions to prepare for industry changes, maintain effective oversight of AI, and enable successful deployment:

  • Are my GenAI and LLM use cases classified on the Mills Review autonomy spectrum? Am I flagging “advice-like” outputs for legal and compliance review?
  • Which AI vendors and providers could be designated as CTPs? Have I performed due diligence on third-party governance frameworks and resilience arrangements?
  • Am I continuously monitoring model performance for inaccuracies, such as drifting and degradation?
  • Have I reviewed internal disclosure practices for AI-generated customer guidance to ensure they fall under “regulated AI outputs”?
  • Have I adapted compliance monitoring to watch for AI-enabled fraud, deepfakes, and synthetic identities?

As firms increasingly scale novel tools and look to external partners to adopt technologies that will help optimize operations, third-party model governance and risk management frameworks are essential. The right provider will make the difference between sound, reliable AI tools that improve business functions and inadequate technologies that intensify risk instead of managing it.

As regulators expand oversight of AI providers, ensure your compliance infrastructure keeps pace. Global Relay’s AI-enabled technology stack gives firms secure, defensible, and adaptable tools to optimize operations and enhance decision-making, from record retention to risk monitoring to eDiscovery.

8 mins read 21 August 2026