In one paragraph

There is no UK AI statute for financial services and, on the current evidence, there is not going to be one soon. The regulators have held a technology-agnostic, principles-based line, and in July the Treasury's Financial Services AI Adoption Plan confirmed the same posture. Boards reading that as breathing space are misreading it. "No new rules" means the existing rules apply in full, unmodified, to a technology they were not written for, and the burden of working out how falls on the firm. Parliament's Treasury Committee has said so in terms, criticising the FCA for pushing firms to go through the handbook and work out for themselves how it applies to AI. Meanwhile the critical third parties regime went live in July, HM Treasury has declined to commit to bringing AI providers into it before the end of 2026, and any firm scoring consumer credit or pricing life and health cover for EU customers is inside the EU AI Act's high-risk regime. The governance question is not "when will we be regulated". It is which of the five regimes that already apply have we actually mapped our AI against.

The UK has decided not to legislate

The direction has been consistent since the 2023 pro-innovation white paper. No cross-sector AI statute, no AI-specific regulator, existing sectoral regulators applying existing rules within their remits.

Two things this year confirmed it holds for financial services.

On 16 April 2026 the Treasury Committee published the regulators' responses to its report on AI in financial services. The Bank of England confirmed plans to test AI agents in financial trading markets and to investigate the potential impact of AI agents exhibiting correlated behaviour, or herding. It agreed the Financial Policy Committee should monitor HM Treasury's use of the Critical Third Parties regime. The FCA committed to sharing best-practice examples for AI usage with firms, to give clearer guidance on aligning AI with existing rules. Neither regulator committed to writing AI-specific rules.

HM Treasury declined to commit to bringing major AI and cloud providers into the Critical Third Parties regime before the end of 2026. The Committee's chair, Dame Meg Hillier, said she remained "perplexed at the apparent inertia shown by the Treasury".

On 14 July 2026 HM Treasury published the Financial Services AI Adoption Plan, which maintains the UK's principles-based, outcomes-focused approach while addressing the novel questions AI raises. Its commitments are enabling and not restricting: an AI Adoption Support Hub with a regulatory information portal, an FCA review of consumer impacts from general-purpose LLMs providing financial guidance, assessment of critical AI and cloud providers under the CTP regime, a sector skills plan, and industry-led work on agentic payments standards and a voluntary AI incident-sharing repository.

For a compliance function used to reading across from a rulebook, this is an uncomfortable posture. There is no clause to map to. There is a set of existing regimes the regulators consider already adequate, and an expectation that firms will work out the application themselves and evidence that they did.

The five regimes that already bind your AI

SS1/23, model risk management. For banks in scope this is not a principles-based aspiration. The PRA's supervisory statement on model risk management principles took effect on 17 May 2024. Principle 2 provides that "the board should set a model risk appetite that articulates the level and types of model risk the firm is willing to accept", requires that "the model's performance is monitored against the firm's board-approved risk appetite", and requires firms to "ensure the firm's aggregate model risk remains within the board approved risk appetite".

Read that against a machine-learning estate and the implication is direct. Every material AI system is a model. There is already a supervisory expectation that your board has set an appetite for it, is monitoring against it, and can show the aggregate position. That is more specific and more demanding than anything in the EU AI Act about internal governance, and it has been in force for over two years.

Most firms' model risk appetites were written for traditional statistical models, where behaviour is stable and the appetite that governed a model last year governs it this year. AI does not behave that way. A model degrades while nobody acts, and the same model at the same accuracy is prudent in one deployment and reckless in another. Extending a model risk appetite to cover AI is not a drafting exercise, because the structure itself has to change. Setting an AI risk appetite sets out what that looks like in practice, and the risk appetite glossary entry covers the underlying distinction between appetite, tolerance and capacity.

SS1/23 is the single most on-point UK obligation for AI governance, and it is routinely absent from AI governance programmes. It is owned by model risk teams who do not think of themselves as AI governance, and staffed by people who were not in the room when the AI strategy was written.

Note the scope. SS1/23 applies to banks, and not to every regulated firm.

SS1/21, operational resilience. The financial services hub covers this in more depth, so briefly here. Identifying important business services and setting an impact tolerance for each is the closest thing in existing UK regulation to a pre-agreed threshold with a trigger attached. Two register entries follow directly, AI not mapped to important business services and no impact tolerance for AI-dependent services, and the impact-tolerance mapping control is where the work lands.

The AI-specific failure is subtle. Firms mapped their important business services years ago, before AI was embedded in them. A service whose resilience was assessed on the assumption of a rules engine now runs on a model with different failure characteristics, and nobody re-ran the mapping.

SS2/21 and the critical third parties regime. Outsourcing and third-party risk management under SS2/21 already applies to AI providers. What changed this summer sits above it.

On 10 July 2026 HM Treasury designated four providers as critical third parties: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd and Oracle Corporation UK Limited. The oversight regime went live on 13 July 2026.

Two things follow, and firms tend to get both wrong.

All four designations are cloud providers. None is an AI provider. The Treasury's AI Adoption Plan commits to assessing critical AI providers under the regime and the Treasury Committee recommended designating major AI and cloud providers by end 2026, but HM Treasury declined to commit to that timetable in April. As things stand, the model provider underneath your AI estate is very likely not designated, and your concentration exposure to it is entirely your own to manage.

Designation also transfers nothing. The Bank was explicit that the regime "complements, but does not replace, existing outsourcing and operational resilience rules for regulated firms who remain responsible for managing their own third-party arrangements including due diligence, risk management and contingency planning." The CTP regime reduces systemic risk. It does not discharge vendor due diligence or concentration and exit strategy obligations. Firms reading the designation as reassurance have drawn the wrong conclusion from it.

Worth adding: two suppliers built on the same underlying foundation model are one dependency wearing two coats. Concentration analysis stopping at the vendor layer misses it.

SM&CR, the accountability question nobody has answered. The Senior Managers and Certification Regime attaches personal accountability to named individuals for defined functions. AI raises a question the regime was not designed for. Who is accountable when a system performs a function a human used to oversee, and the human overseeing the system cannot realistically interrogate its output?

The regulators have acknowledged this as an open question. The Treasury Committee went further and recommended the FCA publish, by end 2026, its accountability expectations for senior managers under SM&CR regarding AI-related consumer harm.

A firm cannot wait for that. The regime applies now. The practical response is to name the senior manager accountable for each material AI system, in the same way an outsourced function is allocated, and to make sure their oversight is real and not nominal. That means having the information, the authority and the standing to disagree with the system, which is exactly what inadequate human oversight design describes the absence of.

An oversight arrangement a senior manager could not defend to a supervisor is an accountability gap with a name attached to it.

Consumer Duty, where the retail exposure sits. The Duty requires firms to deliver good outcomes for retail customers. It is outcomes-based, so it applies to AI-driven decisions without needing to mention AI. Guidance on its application to AI-enabled models is expected and not yet published; the Treasury Committee asked for it by the end of 2026.

The FCA's live concerns are visible in what it has chosen to look at. Its perimeter report of 26 March 2026 highlighted unregulated AI-driven financial guidance tools. The Mills Review, launched on 27 January 2026, examines the long-term impact of AI on retail financial services. The Treasury's adoption plan commissions an FCA review of consumer impacts from general-purpose LLMs providing financial guidance. The pattern is consistent. The FCA's primary retail concern is what happens when consumers receive financial guidance from systems outside the perimeter, and by extension what firms inside the perimeter are accountable for when their own tools behave similarly.

What Parliament said, and why it changes the read

On 20 January 2026 the Treasury Committee published Artificial intelligence in financial services, the Fifteenth Report of Session 2024–26. It concluded that the FCA, the Bank of England and HM Treasury are not doing enough to manage the risks AI presents, and that the three authorities are "exposing consumers and the financial system to potentially serious harm" through their "wait-and-see approach to AI in financial services".

Its criticism of the FCA is worth quoting in full, because it describes the position a compliance function is now in: "The effect of the FCA's approach has been to push the burden on to firms to go through the FCA handbook and rules and try to work out how they apply to AI."

The Committee recommended comprehensive FCA guidance on applying consumer protection rules to AI by end 2026, AI-specific stress testing by the Bank and the FCA, and CTP designation of major AI and cloud providers by end 2026.

Hold that alongside the regulators' April responses, because the two do not agree. The regulators consider the existing framework adequate. The parliamentary committee scrutinising them does not, and HM Treasury has already declined the CTP timetable.

The practical inference for a board is not that new rules are imminent, since the July adoption plan suggests otherwise. It is that supervisory attention is rising faster than supervisory guidance, which is the least comfortable configuration for a regulated firm. Expectations are being set through reviews, roundtables and thematic work, and a firm waiting for a rulebook will be answering supervisory questions without one.

The regime that binds you anyway

While the UK declines to legislate, the EU AI Act reaches UK firms directly through their EU-facing business, and two of its high-risk categories are financial services by name.

Annex III point 5(b) covers AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score, excluding systems used for detecting financial fraud. Point 5(c) covers AI systems for risk assessment and pricing in relation to natural persons in life and health insurance.

A UK lender scoring EU consumers is inside the high-risk regime. So is a UK insurer pricing life cover for EU policyholders. Both are also inside the Article 27 fundamental rights impact assessment obligation, which applies to every deployer of 5(b) and 5(c) systems and not only to public bodies. The comparison of DPIA, FRIA and AIA sets out what that assessment requires and the notification duty attached to it. The compliance crosswalk maps the requirement against ISO/IEC 42001 and the NIST AI RMF.

Two timing points. The high-risk regime was deferred by the AI Omnibus to 2 December 2027 for stand-alone Annex III systems, so this is a 2027 obligation and not a live one. Article 50 transparency was not deferred and has applied since 2 August 2026, so a UK firm running a customer-facing chatbot for EU customers is inside a live obligation today, whatever it concluded about the high-risk regime.

What a UK firm should do

Six things, in order, none of which requires waiting for guidance.

  • Find out whether SS1/23 already covers your AI estate, and who thinks they own it. In most firms the honest answer is that model risk and AI governance are separate programmes with separate sponsors and no reconciliation. This is the highest-value question on the list.
  • Ask the board whether it has set a model risk appetite that works for AI. Not whether one exists. Whether the thresholds in it can be breached by an AI system, and what happens when they are.
  • Re-run the important business services mapping on the assumption that AI is now inside services assessed before it existed there.
  • Separate the CTP designation from your own concentration analysis. Designation of your cloud provider says nothing about your model provider, and nothing about several vendors sitting on one foundation model.
  • Name the accountable senior manager for each material AI system, and test whether their oversight is real.
  • Determine EU AI Act scope in writing, per system, distinguishing what is live now under Article 50 from what arrives in 2027 under the high-risk regime and Article 27.

The thought experiment works through a UK-regulated retail bank scenario against exactly these constraints, and is the most concrete illustration on this site of what the answers look like in practice.

Where this is heading

The Treasury's plan is an adoption plan and not a control plan. Its centre of gravity is removing barriers. The regulators have declined to write AI-specific rules and said so recently enough that the position is unlikely to shift this year. The Treasury Committee disagrees, the UK Jurisdiction Taskforce has consulted on whether existing negligence principles cover AI-caused loss, and the FCA is running reviews whose findings will become expectations before they become rules.

When a supervisor asks how the existing rules apply to your AI, the answer has to already exist. The firms that will find that comfortable are the ones that mapped their AI against SS1/23, SS1/21, SS2/21, SM&CR and the Consumer Duty before anybody asked them to.