UK Watchdog Warns AI Is Outpacing the Rules Meant to Protect Your Money
A government-ordered review says Britain's financial regulator needs stronger powers before AI reshapes banking and lending for millions of ordinary people.

Key points
- The UK's Financial Conduct Authority (FCA) published the Mills review in 2025, examining how artificial intelligence will change financial services from 2030 onwards.
- Financial firms are already replacing human-led services with AI-driven ones for everyday customers.
- Ministers have been urged to expand the FCA's legal powers specifically to cover risks created by AI systems.
- AI will worsen existing dangers, including cyber-crime and financial fraud targeting ordinary consumers.
The FCA, the government body responsible for making sure banks and lenders treat customers fairly, has a problem. Rules it enforces were written for a world run by people. The world it's being asked to police is increasingly run by software.
The Mills review, commissioned to examine how AI will change UK financial services, found that firms are already shifting. Decisions a human adviser or call-centre worker used to handle are now handed to automated systems. That shift will accelerate sharply by the end of the decade.
Should ordinary bank customers be worried?
Yes, in a measured way. The review's core concern is that rules protecting you when you apply for a loan or buy insurance were designed assuming a person made the call. When an algorithm, meaning a set of automated instructions run by a computer, makes that call instead, gaps open up. Those gaps are where fraud and errors hide.
This failure mode is familiar to anyone who's watched a new technology arrive faster than the paperwork. Firms deploy AI tools that cut costs and speed up services. Regulators have no clear authority to examine how those tools work or what data trained them. By the time something goes wrong for a customer, the liability trail is cold.
The review also flags cyber-crime specifically. AI makes it cheaper for criminals to run scams at scale, generating fake documents and targeting people with personalised fraud that looks convincing. The phishing email, where a criminal sends a fake message to trick you into handing over your bank details, gets harder to spot. Our 30 June report found pre-positioned phishing kits built months before the FIFA 2026 tournament, the same infrastructure pattern the Mills review is worried about at financial-services scale.
The ask from the review is direct: give the FCA sharper tools before the gap between what AI can do and what regulators can check gets any wider. First reported by The Guardian Technology, the review stops short of calling for a ban or a slowdown. It wants oversight, not obstruction.
If you use any online financial service, watch for unsolicited messages asking you to confirm account details, even ones that look official. Real banks don't ask for passwords by email or text.
One operational note: if your organisation touches customer financial data, the question isn't whether you use AI. It's whether you can explain to a regulator exactly what your AI decided and why. That answer needs to exist before the regulator comes asking.



