Sector: FCA
The FCA's Mills Review points to a future of more AI and more autonomy in financial services. That raises the bar on one question in particular: can you prove what your AI actually did?
14 July 2026 · 6 min read
On 6 July 2026 the Financial Conduct Authority published the Mills Review, its landmark look at the long-term impact of artificial intelligence on retail financial services. It is a strategic document rather than a new rulebook, but the direction it sets is unambiguous, and it has a direct bearing on how regulated firms will need to account for their use of AI.
For firms already wrestling with an AI policy, the Review is worth reading for one reason above all: it describes a future in which the question "can you prove what your AI did?" gets harder to answer, not easier.
The headline picture is one of acceleration. On the Bank of England and FCA's most recent joint survey of AI in UK financial services, 75% of firms said they were already using AI, up from 58% two years earlier. The Review's central theme is a shift towards delegation: in its own words, retail financial services are "moving from human-led, towards AI-enabled, continuous and delegated services". AI is no longer just drafting a suggestion for a person to check, it is increasingly taking on longer tasks and more actions on a firm's or a customer's behalf. This is agentic AI, and the Review treats it as the defining change of the next few years.
That shift is happening on the customer side too. FCA-commissioned research cited in the Review suggests around a fifth of people, roughly 11 million UK adults, are likely to use AI that can act autonomously within goals they set, while remaining concerned about trust and control.
The Review groups the impact into four shifts: how firms operate, how consumer journeys evolve, how competition and market power are reshaped, and how fraud and cyber risk are amplified. It then makes seven recommendations to the FCA and government, beginning with securing and adapting the regulatory perimeter and running through stronger system-wide oversight, monitoring the transition to autonomous models, and building a more AI-enabled approach to supervision.
Strip out the strategy and one practical consequence stands out. As firms delegate more to AI, and to in-house agents in particular, the accountability question changes shape.
When a member of staff uses an approved chat tool, you can at least reconstruct what happened by asking them. When an in-house agent runs a task end to end, calling a model dozens of times without a person in the loop, "ask the member of staff" stops being an answer. The record has to come from the system itself.
The existing expectations do not go away while this unfolds. Under the Consumer Duty and SYSC 9, firms are already expected to keep adequate records and to show that oversight is real rather than asserted. Under the Senior Managers and Certification Regime, a senior manager is expected to be able to evidence reasonable steps, not merely describe them. The Mills Review is a signal that the volume and autonomy of AI use, and therefore the amount you may be asked to account for, are set to rise.
A written policy tells a reviewer what was supposed to happen. As more work is delegated to autonomous systems, the gap between that and what actually happened is exactly where scrutiny will land.
This is the same gap we have written about before: a policy is a promise, and increasingly firms are being asked for proof. The Mills Review sharpens the point by making clear that a growing share of AI activity will come from systems acting on their own, which is the hardest kind of activity to reconstruct after the fact.
Closing that gap means being able to answer three questions with records rather than recollection:
This is the problem Evaident is built for. It keeps one record across the three ways AI enters a firm: approved tools such as ChatGPT, Claude, Gemini and Microsoft 365 Copilot, connected through their own audit interfaces; in-house agents and API tools, pointed at the Evaident gateway; and unapproved shadow AI, discovered from the firewall, proxy or SIEM logs a firm already collects. The agentic use the Mills Review foregrounds is precisely the middle category, and it is the one vendor dashboards tend not to cover.
For those in-house agents and API tools, the gateway does more than record. It enforces policy in real time before a request leaves the firm: approved vendors and models, supported UK PII, common credentials and customer-defined blocked terms such as client names or matter codes, out-of-hours rules and an organisation spend cap. It is honest to say what this does and does not do. Real-time blocking applies to traffic routed through the gateway; use of approved chat tools, the browser extension and shadow-AI discovery are detect-and-evidence rather than block. Evaident is an accountability and evidence layer, not a full data-loss-prevention system, and customer-defined terms are matched as case-insensitive text, a meaningful guardrail rather than a guarantee.
Every event, whether an allowed call or a blocked one, is sealed to the one before it using HMAC-SHA256, so any later change to the record is detectable. When you need to show your work, Evaident produces a stamped evidence pack with a chain-integrity certificate that a client, board or regulator can verify independently. By default it records metadata, who used what, when, on which model, with which risk flags, rather than the content of prompts, which keeps the data-protection footprint small.
You do not need to act on every recommendation in a strategic review aimed at the regulator and government. But the Mills Review is a useful prompt to ask a simple internal question: if the amount of AI our firm relies on doubles, and more of it runs autonomously, could we still show a supervisor, a client or our board what actually happened?
If the honest answer is "only for the sanctioned chat tools, and only by asking people", that is the gap to close now, while the volume is still manageable.
Evaident supports your governance and compliance functions; it does not provide legal advice, and no tool makes a firm compliant on its own. What it does is turn your AI policy from a statement of intent into a record you can stand behind. To see where your firm is exposed today, start with the free AI exposure check, or see how this maps to the rules on the FCA page.
The free AI Exposure Check gives you an instant score across visibility, shadow AI, evidence, governance and data-leak risk — no data connection needed.