July recap: AI and financial services in the UK

July has been an eventful month for AI and finance in the UK. Here's a recap of the key government, regulatory and policy developments, and what they mean for the sector.

Key takeaways:

  • The Mills Review, commissioned by the FCA Board, concludes the FCA's framework "remains sound" but must evolve, and floats an Agentic Supervisory Model that pushes supervision beyond individual firms to system-level risks like herding and common points of failure.
  • The Bank of England's Financial Stability Report gives AI two chapters, treating it as a systemic concentration risk (AI names are now around half of the S&P 500) and warning that the pace of frontier AI patching is itself becoming a source of operational risk.
  • The Financial Services AI Adoption Plan sets out 10 recommendations to accelerate safe adoption from the sector's AI champions, including an FCA review of AI-generated guidance, a voluntary incident-sharing repository, a third-party assurance scheme, and a skills commitment. Government accepts them, but the substance is left to industry to build.
  • The Department for Science, Innovation and Technology has been disbanded and its functions dispersed across Whitehall, though the AI minister's promotion to Cabinet indicates AI remains a first-order priority for No.10.

Taken together, July’s developments indicate that Government and regulators want financial services to adopt AI at pace, even as concerns continue to grow around cyber threats, concentration and shared dependencies. 

The Mills Review

Commissioned by the FCA Board, this marathon review deep dives into all things AI and the future of retail financial services. It argues that by 2030, AI will likely have the effect of potentially narrowing advice, switching and protection gaps while amplifying fraud, cyber and consumer-harm risks. Its conclusion is that while "the overall regulatory framework remains sound", it will need to evolve.

One concept that deserves specific attention is the Agentic Supervisory Model. In short, the review argues that the FCA adopting agentic AI capabilities is a necessity, and that the most significant change for the FCA to monitor is at the system level.

This is driven by the novel risks posed by shared reliance on similar models, datasets and infrastructure providers. That reliance could generate correlated behaviour, herding, opacity and common points of failure across the system. For instance, consumers using agents to manage their investments could all exit a fund at the same time, causing a flash crash that ripples through the economy.

Supervision, the review argues, must therefore extend beyond individual regulated firms to the financial ecosystem as a whole. 

That won't come as news to the FCA. A recent speech by Nikhil Rathi, the chief executive, made clear the regulator now expects to use its system-wide competition powers, under the Enterprise Act and the Digital Markets, Competition and Consumers Act, as a regular part of its toolkit rather than an exceptional intervention.

These are market-level tools which allow the FCA examine how a whole market is functioning and impose remedies on it even where no single firm has broken a rule, which is exactly what is needed for system-level risks like herding and common points of failure.

The FCA Board is now considering the Mills Review recommendations, and will provide a formal response later this year.

The Bank of England's Financial Stability Report

The Financial Stability Report is the Bank of England's twice-yearly assessment of the health of the UK financial system as a whole. It's produced by the Bank's Financial Policy Committee, the body set up after the 2008 crisis specifically to watch for system-wide, or "macroprudential", risk.

The report is broad in scope, covering the Middle East supply shock and volatile energy prices, stretched equity valuations and rising hedge fund leverage, weakening private credit markets, and historically high sovereign debt issuance, with the FPC warning these vulnerabilities "could crystallise simultaneously". 

And this time, the Bank's July Financial Stability Report gives AI two full chapters:

The macrofinancial implications of AI

AI has become a systemic concentration risk. AI companies now make up around half of the S&P 500, up from a quarter in 2022, so a repricing of a few names is a global equity event. The FPC models a 45% US correction feeding a 2.2% hit to UK GDP. Debt is the other key issue: the FPC calls the pace of AI investment "unprecedented historically", with hyperscaler capex forecasts jumping past $1 trillion and over half of data-centre build-out expected to be debt-financed.

Frontier AI and financial stability

This chapter sets out that frontier AI is forcing firms to fix security flaws faster and more often than they can safely keep up with, and that pace is itself becoming a source of risk. As the FPC puts it, faster patching "can itself create operational risks if changes are rushed". The driver is asymmetry, as attackers need to find one weakness, while defenders must close them all, with far less time to do it. And the handful of frontier AI vendors that firms lean on to defend themselves become a systemic exposure in their own right.

How does the Bank's assessment map to the wider European context? Well, this is very similar ground to what the ECB covered in its 7 July letter to significant institutions, telling banks under its direct supervision to submit concrete action plans on AI-driven cyber risk by 31 October. You can watch Zango’s interview with Pedro Machado, Member of the Supervisory Board, here.

The cyber threat brought to the fore by Anthropic's Mythos has undoubtedly forced supervisors to recalibrate their priorities. And OpenAI's recent disclosure of a case where one of its models left its test environment during internal testing will no doubt keep it at the top of the priority list.

The Financial Services AI Adoption Plan

Not everything this month was about risk. The UK's Financial Services AI Adoption Plan, an independent report drafted by the UK's FS AI Champions, Harriet Rees and Rohit Dhawan, sets out recommendations for government, regulators and industry to accelerate safe AI adoption across the sector. 

There are 10 recommendations, but here are four highlights:

  • An FCA review of AI-generated financial guidance. The FCA should review the impacts of guidance-like outputs from LLMs, feeding into HMT's review of the regulatory perimeter. This is significant on two fronts: it could bring new rules, such as disclosures or consumer education, onto chatbots themselves, and it would give wealth and advice firms greater certainty about where their own AI tools sit relative to the guidance and advice line.
  • A voluntary AI incident and "near miss" sharing repository. Unattributed, and potentially run through the Cross Market Operational Resilience Group, which already coordinates similar intelligence sharing for cyber threats. The aim is a culture of collective intelligence across the sector. Zango's own research found the same problem, with firms tackling AI governance challenges in isolation without a shared understanding. Industry collaboration is the route to closing that gap.
  • An industry-led AI third-party assurance scheme. In practice this could look like ISO 42001, where an independent assessor certifies a model against agreed standards, so firms can rely on the certificate as a baseline instead of running their own questionnaire from scratch. The Plan argues it could operate as a voluntary scheme at first, but in time may be adopted by a central body, with regulators choosing to formally integrate it into supervision. That echoes Nikhil Rathi's own recent words, that regulation "can't be designed first, consulted on later", it needs to be built with industry.
  • An industry commitment to the Financial Services Skills Compact. A joint agreement between HM Treasury and the Financial Services Skills Commission, where signatories commit to upskill staff in AI, maintain entry routes for new talent, and name an accountable senior executive. FSSC research puts the sector's need at around 450,000 people to recruit and train over the next decade, and government research shows the skills gap is largest in risk and compliance. That is a serious risk if the people overseeing AI adoption lack the skills to hold it to account.

The government welcomes the Plan, accepts the recommendations, and will work with regulators and industry on next steps. The thread that runs through all four is sound: government can set the direction, but building the substance, from sharing incidents to standing up assurance and training people, is down to industry.

The demise of DSIT, but a Cabinet seat for the AI minister

                                                  Kanishka Narayan MP, the Minister for AI

The month's governmental news was a mixed bag. The Department for Science, Innovation and Technology has been disbanded by the new prime minister, Andy Burnham, and its responsibilities distributed across Whitehall.

For the sector, the significance is about where AI policy now sits. DSIT was the central point bringing technical specialists together with policymakers, and the single front door for external stakeholders on digital and AI questions. Dispersing those functions risks a more fragmented policy centre.

Reorganisations on this scale are also slow: budgets and public bodies are reallocated and senior officials spend months on transition rather than policy, at a point when execution arguably matters more than structure.

The more encouraging development is the AI Minister - Kanishka Narayan MP - has been promoted to a Cabinet seat. His ministerial role will sit across both Cabinet Office and newly beefed up Department for Business, Innovation, Science and Trade.

Having advised him in my previous role, I share the widely held view that he is good news for the UK's AI ecosystem. Regardless of the departmental developments, a seat at the top table indicates that AI remains a first-order priority for No.10.

Where that leaves us

Taken together, July’s developments indicate that Government and regulators want financial services to adopt AI at pace, even as concerns continue to grow around cyber threats, concentration and shared dependencies. 

In response, they are increasingly turning to industry collaboration, system-wide supervision and broader market-level powers - and we are likely to see more of this as the regulatory framework adapts to the risks posed by AI. 

Zango is the AI compliance layer for financial institutions. For more on UK regulatory developments, follow our blog, or speak with our team.

Continue reading