UK's Financial Watchdog Sounds Alarm Over AI's Unchecked Role in Personal Finance
The Financial Conduct Authority is locked in what one of its own senior officials describes as an 'arms race' with AI. Sheldon Mills, an FCA executive director on his way out after eight years at the regulator, has published a commissioned report warning that artificial intelligence is moving faster than the rulebook can keep up with, and that millions of ordinary people are already making financial decisions with AI tools that sit entirely outside regulatory protection.
Mills told the FT that the FCA needs expanded powers and should urgently review whether tools like ChatGPT, Claude, and Gemini are effectively delivering financial advice without being subject to the regulations that would normally apply. He wants that review done within three to six months.
The numbers make the urgency obvious. Research attached to the report found that roughly a fifth of UK adults would already be comfortable letting an AI model make financial calls on their behalf, things like savings decisions or borrowing choices. None of those interactions are regulated. If an AI chatbot steers someone into a terrible financial product, there is no compensation scheme, no ombudsman, no recourse. Nothing.
Some firms have apparently been quite candid with the FCA about this gap, telling the regulator they believe AI-powered financial guidance occupies a grey zone that falls outside the regulatory perimeter. Mills frames the question bluntly: if a chat model can respond to prompts, hold a conversation, and effectively tailor recommendations to your specific situation, is that really any different from regulated financial advice? Legally, right now, it apparently is. Which is the problem.
The report does not treat AI purely as a threat. Mills makes the case that hyper-personalised financial tools could genuinely open up sophisticated advice to people who currently have no access to it. His example: someone earning £20,000 a year potentially getting the kind of financial guidance that today is only realistically available to people with £10 million in assets. Hard to argue with the appeal of that, even if the risks of getting it wrong at scale are considerable.
On those risks, the report is fairly blunt. Hyper-personalisation cuts both ways: it could match products to needs more accurately, but it could equally enable opaque pricing, embedded bias, and outright manipulation tailored to individual psychological profiles. Fraud is flagged as a particular concern, with deepfakes, synthetic identities, and personalised social engineering described as pushing financial crime into a new era. The prescription is to fight AI with AI, deploying the technology defensively across the system.
Mills also wants the FCA's existing 'critical third parties' regime expanded to bring major AI providers, specifically naming Anthropic, OpenAI, Amazon, Google, and Microsoft, under more robust oversight. That regime can require annual self-assessments and scenario testing, but the government has not yet decided which companies to formally designate under it. The report further suggests the FCA could pursue additional powers through the 'designated activities regime,' which lets it regulate specific activities without requiring full firm authorisation.
One area Mills declined to touch was the FCA's controversial 12-week contract with Palantir, the US data analytics firm, which was brought in to test whether AI could help combat financial crime. Some MPs have raised concerns that the arrangement could expose sensitive UK financial data to American authorities. Both the FCA and Palantir deny this. Mills stayed quiet on the subject.
The FCA board will now sit down with the report and decide what to actually do with it. Given that the regulator is already playing catch-up, the pace of that decision probably matters more than the content of it.