Every board pack in financial services now has an AI agenda item. Every marketing team is being asked to “do something with agentic AI.” And every CEO knows that the firms who get this right first will have a genuine advantage in cost, speed and customer experience.
The problem isn’t ambition. It’s that AI agents — systems that don’t just answer a question but take autonomous action on a customer’s behalf — collide directly with a regulatory framework that was never designed with autonomy in mind. For insurers, lenders, brokers and advisers, that collision creates real commercial risk long before it creates a competitive edge.
This isn’t a technology briefing. It’s a briefing on why the difficulty sits less in the model and more in the accountability, evidence and governance around it — and why that’s a leadership problem, not just an IT one.
Why this is harder for insurance and finance than almost anywhere else
Most sectors deploying AI agents worry about accuracy and cost. Regulated financial services firms have to worry about those things plus a stack of obligations that were written for human decision-makers:
- The regulatory perimeter is activity-based, not technology-based. UK financial regulation asks what activity is being carried out, not what tool is doing it. That mostly holds up well for AI — but the Mills Review, the FCA’s own long-term look at AI’s effect on retail financial markets, has flagged that influential AI platforms could shape consumer decisions without clearly performing a regulated activity, creating gaps between where financial influence sits and where regulatory protections apply. If your agent nudges a customer toward a product decision, you may be closer to the regulatory line than your build documentation assumes.
- There is no AI rulebook to build against. FCA-authorised firms are expected to demonstrate that existing frameworks — Consumer Duty, the Senior Managers and Certification Regime (SM&CR), the Systems and Controls sourcebook (SYSC), and operational resilience rules — already cover their use of AI, rather than working from a bespoke standard. That sounds like flexibility. In practice it means your compliance, risk and legal teams have to interpret decades-old principles onto a genuinely new kind of system, with no template to copy.
- The regulator has said, repeatedly, it isn’t going to make this easier. The FCA has reaffirmed it will not introduce AI-specific rules, citing the pace at which the technology changes every few months, and is instead deepening its principles-based, outcomes-focused approach — intervening only where failures are “egregious” and not otherwise addressed. Firms are being asked to self-govern against a moving target, with the regulator watching but not prescribing.
- Political and regulatory scrutiny is rising while the guidance lags behind. The Treasury Committee’s inquiry pushed regulators hard on this. MPs called on regulators to run AI-specific stress testing, publish practical guidance by the end of 2026 on how existing consumer protection rules apply to AI, and ensure major AI and cloud providers are formally designated as critical third parties. Guidance is coming — but firms are building agents now, ahead of the rules that will be used to judge them.
None of this means “don’t build.” It means the difficulty is structural, not a matter of finding the right vendor.
The four places agentic AI creates real exposure
1. Consumer Duty doesn’t pause for automation
An agent that handles a claim, recommends a product feature, or triages a customer query is still subject to the four Consumer Duty outcomes: products and services, price and value, consumer understanding, and consumer support. The FCA’s expectation is a pre-deployment risk assessment mapped against those four outcomes, real-time monitoring with documented intervention thresholds, and audit trails at the interaction level — not a sample, every interaction. If your agent can’t produce that evidence trail, the deployment isn’t ready, however good the demo looked.
2. Accountability doesn’t move to the machine
This is the point CEOs most often underestimate. The FCA has confirmed there will be no dedicated Senior Manager Function for AI — responsibility for AI-driven outcomes sits within the existing SM&CR accountability regime, and delegating a decision to an algorithm does not dilute a senior manager’s liability. In practical terms, that means a named senior manager’s Statement of Responsibilities needs to explicitly cover AI oversight — typically mapped across the Chief Operations Function for system integrity, the Chief Risk Function for model risk, data quality and bias, and Compliance Oversight for adherence to Consumer Duty and data protection rules. “The model did that, not me” is not a defence regulators will accept, and it is not one your board should want tested.
3. Explainability and human oversight aren’t optional extras
The lack of explainability in many AI models sits in direct tension with SM&CR’s requirement that senior managers demonstrate they understand and control the risks in their area — a tension the FCA has acknowledged but not yet resolved. Every agentic deployment needs a decision log a human can actually interrogate: what information the agent had, what it decided, and why — not a black box with a friendly interface on top.
4. Third-party and vendor risk doesn’t disappear because “it’s just an API”
Most agentic AI in financial services runs on third-party models and infrastructure. Regulators have been pushed to ensure HM Treasury formally designates major AI and cloud providers as Critical Third Parties under the UK’s new oversight regime, precisely because concentration risk in a handful of AI providers is now a systemic concern, not just a vendor management one. If your agent depends on a single foundation model provider, that dependency belongs in your operational resilience documentation, not just your procurement file.
What “good” looks like right now
Firms that are handling this well aren’t waiting for the FCA’s promised guidance before they act. They’re doing five things in parallel:
- Naming the accountable senior manager before the agent goes live, not after a complaint lands — and updating that person’s Statement of Responsibilities to say so explicitly.
- Mapping every agentic use case against the four Consumer Duty outcomes, in writing, before deployment — with documented mitigations, not assumptions.
- Building interaction-level audit trails from day one. Retrofitting an audit trail after the FCA asks for one is a much worse conversation than building it in from the start.
- Treating explainability as a design requirement, not a compliance afterthought. If risk and compliance can’t interrogate a decision, the product isn’t finished.
- Documenting AI vendor dependency as an operational resilience issue, with a genuine fallback position if a provider is unavailable or changes terms.
The marketing and positioning angle
For CMOs, there’s a second layer to this. Customer-facing content — in-app copy, chatbot scripts, “our AI will help you find the right cover” marketing lines — is itself a Consumer Duty touchpoint. Overpromising what an agent can do, or blurring the line between guidance and advice, creates exposure that has nothing to do with the underlying model and everything to do with how it’s described. Every piece of AI-related marketing content in a regulated firm should go through the same FCA-aware review as a product disclosure, because increasingly, that’s exactly what it is.
The bottom line for boards
Agentic AI is not going to be regulated away, and UK regulators have been explicit that they want financial services to lead on adoption, not resist it. The FCA’s own chief executive has said financial services can provide the capital, infrastructure and trust needed for AI to scale across the wider economy, at a point where more than 80% of firms are already using or adopting AI. The opportunity is real. So is the exposure.
The firms that win this decade won’t be the ones that deployed agents fastest. They’ll be the ones that could show a regulator, a journalist, or an ombudsman — on the day it mattered — exactly who was accountable, what the agent was told, what it decided, and why. That’s not a constraint on ambition. It’s the actual foundation it needs to stand on.
This article draws on the FCA’s Mills Review, Treasury Committee evidence sessions, and current FCA/PRA/Bank of England guidance as at July 2026. The regulatory picture is evolving quickly, and firms should treat this as a starting point for internal legal and compliance advice, not a substitute for it.