Architectural Blueprints for AI-Native Regulated Banks: Establishing the Governance and Minimum Viable Human Oversight Paradigm under UK Regulation The retail financial services landscape is undergoing a structural shift from human-led, episodic financial activity towards services that are continuous, automated, and delegated. This transition fundamentally changes the nature of regulatory risk, shifting the focus of compliance from localized, firm-level human failures to systemic, machine-accelerated vulnerabilities and automated market contagion. Under this new operational paradigm, emerging challenger institutions are being re-architected from the ground up around artificial intelligence foundations rather than merely bolting automated features onto fragile, legacy cores. To construct a licensed, AI-native retail bank in the United Kingdom, founders must resolve the operational and legal challenge of establishing a Minimum Viable Human Oversight model. This framework defines the absolute baseline of human headcount, supervisory mechanisms, and legal accountability required to satisfy the UK's rigorous regulatory regimes—specifically the Senior Managers and Certification Regime and the Consumer Duty—while allowing transaction volumes and customer interactions to scale exponentially without a proportional increase in back-office headcount. Evolution of AI-Native Banking: Open-Source and Startup Initiatives A distinct cohort of fintech startups, specialized technology providers, and transitioning licensed institutions is actively establishing the architectural precedents for AI-native banking. These organizations treat autonomous agents as core, load-bearing infrastructure rather than marginal assistants. Catena Labs and the Agent Commerce Kit Catena Labs, led by Circle co-founder Sean Neville, has secured forty-eight million dollars in funding—including an eighteen million dollar seed round in May 2025 and a thirty million dollar Series A in May 2026—to construct the financial rails for the emerging agentic economy. Operating under the thesis that traditional credit card networks and payment models are structurally unsuited for stochastic AI actors, Catena Labs has developed the open-source Agent Commerce Kit. The Agent Commerce Kit is built upon open W3C Web Standards, utilizing Decentralized Identifiers and Verifiable Credentials to solve the fundamental challenges of machine-to-machine transactions and identity. The kit is split into two complementary protocols: * ACK-ID: Establishes cryptographically verifiable agent identities, ownership chains, and compliance authorization. This protocol allows an external counterparty or regulator to verify exactly which real-world legal entity or individual controls and is liable for an executing agent. * ACK-Pay: Provides a transport-agnostic framework for initiating transactions, processing automated payments across multiple rails, and generating cryptographically secure payment receipts. To demonstrate these capabilities, Catena Labs launched a developer preview known as "ACK-Lab" on testnets. This platform utilized a proxy for stablecoins, "testUSD," to prove how autonomous agents can securely exchange credentials, fetch real-time pricing from oracles, and execute token swaps or data-purchase negotiations within strict policy bounds such as daily spending limits and minimum balances. BEYLA BEYLA is building the first AI-native business and financial operating system tailored for small and medium-sized enterprises. Supported by prominent institutional backers including PXN Ventures, Lloyds Banking Group, and Nationwide, BEYLA has transitioned from a pure guidance layer to a regulated neobank builder. At the center of BEYLA's platform is "The Hive," a continuous, real-time "living memory" that ingests and contextualizes every invoice, payment, and financial communication within a business's daily operations. Running on top of this memory is a "Digital C-Suite" of specialized "Digital Humans" that proactively forecast cash flow, optimize invoice reconciliation, and prepare regulated transactions. During its participation in the Financial Conduct Authority's Supercharged Sandbox, BEYLA utilized a specialized subscription hiring model with W Talent to scale its full-stack engineering team, refactoring its entire backend architecture from Google Cloud Platform to Amazon Web Services to meet the strict technical and operational resilience standards required for live regulatory testing. To further solidify its legal and compliance frameworks, BEYLA was inducted into Travers Smith's "Fintech Amplifier" cohort, receiving structured training and advice on critical UK payment and banking regulations. Solaris Solaris is executing a comprehensive corporate transition under CEO Steffen Jentsch to establish itself as an AI-native banking-as-a-service provider. The firm is rebuilding its entire operational workflow around autonomous agents and large language models, drawing direct operational inspiration from automated German manufacturing plants where a handful of human supervisors oversee robotic workforces. In this architecture, autonomous AI agents handle high-volume, low-level transaction processing, anti-money laundering alert screening, and customer inquiries, while a lean team of human managers acts as compliance controllers and escalations handlers. By deploying these agents directly into its modular, API-first architecture, Solaris aims to achieve a massive explosion in back-office productivity, filtering out sanctioned accounts and suspicious transactions with high precision before routing the structured files to human analysts for final sign-off. Intellect Design Arena Intellect Design Arena has launched an AI Digital Banking platform designed specifically for UK and European challenger banks. The platform structures the entire bank across seven cognitive design dimensions—engagement, business, operations, risk & compliance, knowledge, intelligence, and tech for speed—enabling new challenger institutions to operate autonomously under a "Zero-Error Mandate". By transitioning from traditional rule-driven middleware to fully cognitive processing, challenger banks using the platform aim to reduce their cost-to-income ratios by up to twenty percent while achieving return on equity targets of twenty-two to twenty-eight percent, creating a highly compounding operational advantage that is difficult for legacy institutions to replicate. Structured Regulated Environments: The FCA Sandboxes and Testing Cohorts The FCA has established structured, highly competitive testing environments to co-develop regulatory standards alongside market participants, shifting its posture from a bureaucratic gatekeeper to an active co-developer of financial technology. The Supercharged Sandbox Initially launched in partnership with NVIDIA, the Supercharged Sandbox provides participating firms with access to high-performance accelerated computing, specialized AI Enterprise Software, and curated synthetic datasets under direct regulatory supervision. The showcase of the inaugural cohort (Cohort 1) occurred on January 29, 2026, demonstrating advanced wholesale and compliance innovations built by prominent fintechs and established banks. Participant (Cohort 1 - Day 2 Showcase) Project Name / Focus Core Innovation Tested Aveni Ltd. Agent Assure. Post-production conduct risk and compliance monitoring for customer-facing AI agents. BEYLA Transforming Finance through Collective Intelligence. Refactored AWS-native automated commercial assessment and cash-flow orchestration. FinregE FCA Handbook LLM. Natural language mapping and regulatory compliance automation. Impax Asset Management Agentic-engage. AI-mediated institutional investor engagement and portfolio analysis. MillTech FXOmniSight. Multi-modal AI for currency risk management and real-time execution. multifi Automating Commercial Assessments. Real-time automated underwriting and credit decisions for SMEs. Napier AI Theseus. Network-based financial crime and transaction monitoring across banking boundaries. Opsen AI AI-Powered Continuous Operational Oversight. Real-time model drift, latency, and degradation monitoring. Shawbrook Bank Enhanced Alert Management for Financial Crime Risk. AI-driven triage and false-positive reduction in transaction monitoring. SymphonyAI Training Specialised Agents for Financial Crime Detection. Supervised financial-crime-specific agent training methodologies. Virgin Money A Scalable Validation Framework for Generative AI. Dynamic model verification, bias testing, and back-testing infrastructure. The AI Live Testing Initiative Running in parallel with the Supercharged Sandbox is the FCA's AI Live Testing initiative. Supported by the regulator's technical partner, Advai, this initiative is scheduled to run until the end of 2026, with a comprehensive evaluation report scheduled for publication in the first quarter of 2027. The program was designed to transition from early-stage proofs-of-concept to live, production-grade monitoring, exploring risks around model drift and real-time intervention across two distinct cohorts. Cohort Phase Launch Date Core Participants Focus and Use Cases Cohort 1 December 2025. NatWest, Monzo, Santander. Retail financial services, conversational banking, and basic transaction summaries. Cohort 2 April 2026. Barclays, Experian, Lloyds Banking Group / Scottish Widows, UBS, Aereve, Coadjute, Palindrome, GoCardless. Complex customer-facing and B2B use cases, including anti-money laundering, consumer credit scoring, agentic payments, and KYC. The UK Regulatory Paradigm and the Autonomy Spectrum The UK financial regulatory architecture is principles-based and outcomes-focused, designed to flex across changing business models without requiring constant rewrites of the rulebook. However, the rise of autonomous and agentic AI systems is testing this framework, particularly where human oversight becomes highly distributed or disappears entirely. The Mills Review and the Autonomy Spectrum The landmark Mills Review, commissioned by the FCA Board and published on July 6, 2026, analyzes the systemic implications of AI in retail financial services. The review frames the transition of the human role across a five-tier Autonomy Spectrum: * Level 1: Human as Operator: The human performs the task, using AI merely as an on-demand tool (e.g., generating summaries of complex product terms). * Level 2: Human as Collaborator: The human and the AI plan and execute actions together, with continuous human input and refinement. * Level 3: Human as Consultant: The AI analyzes options and makes switching or strategy recommendations, while the human retains the final decision-making power. * Level 4: Human as Approver: The AI prepares, formats, and initiates transactions or client communications, which the human must actively authorize before execution. * Level 5: Human as Observer: The AI acts continuously on its own within agreed parameters, logging its activity for retrospective human monitoring. The Mills Review notes that while existing accountability and consumer protection frameworks are robust for Levels 1 to 3, the transition to Levels 4 and 5 introduces deep challenges. As AI systems move from recommending to acting autonomously, the nature of regulatory risk shifts from localized, firm-specific harms towards systemic, system-wide vulnerabilities, algorithmic feedback loops, and highly correlated market positions. At these higher levels of autonomy, tracing accountability becomes complex. The review emphasizes that simply stating a "human remains in the loop" is no longer acceptable; firms must be able to demonstrate precisely what information reviewers receive, how they evaluate it, and how escalations and challenges are recorded. Systemic Financial Risks and Regulatory Coordination This regulatory concern is echoed by the Bank of England's Financial Policy Committee and the Prudential Regulation Authority. In its April 2025 Financial Stability Report, the FPC highlighted four core systemic risks stemming from advanced AI adoption: * Core Financial Decision-Making Errors: If systemic institutions rely on identical underlying models for credit underwriting or pricing, common structural weaknesses could cause firms to misestimate risks collectively, leading to correlated credit misallocation, sudden losses, or the mass exclusion of vulnerable household segments. * Financial Market Amplification: The widespread use of autonomous AI trading strategies could result in highly correlated, pro-cyclical investment positions during market stresses, severely amplifying sudden shocks and reducing liquidity. * Operational Resilience and Third-Party Dependencies: A severe concentration in the AI supply chain—where thousands of regulated firms rely on a small handful of dominant cloud providers and frontier model developers—creates a major single point of failure. A disruption at a single provider could halt vital business services across the entire financial system. * Cyber Security and Malware Exponentiation: AI-native platforms expand the attack surface of financial institutions, enabling malicious actors to carry out automated, highly persuasive social engineering and deepfake campaigns while rapidly discovering and exploiting software vulnerabilities in live banking systems. To mitigate these vulnerabilities, the PRA has designated AI as a key supervisory priority for 2026, integrating AI-specific inquiries directly into its annual supervisory dialogues. The Bank of England, the PRA, and the FCA are collaborating through domestic and international bodies, including the Digital Regulation Cooperation Forum, the Cross Market Operational Resilience Group's AI taskforce, and the Bank of England's AI Consortium (established in May 2025). This coordinated effort focuses on developing real-time monitoring tools, establishing incident response frameworks for AI-related systemic crises, and enforcing the model risk management standards set out in PRA Supervisory Statement SS1/23. Defining the Minimum Viable Human Oversight Model For an AI-native bank, establishing a Minimum Viable Human Oversight model is the only path to achieving commercial scalability while satisfying the Senior Managers and Certification Regime. Under the SM&CR, a designated Senior Manager (typically SMF24 for operational technology, SMF4 for chief risk officers, and SMF16 for compliance) carries personal, non-delegable civil and criminal liability for regulatory failures within their business areas. If an autonomous algorithm causes consumer harm, the Senior Manager cannot deflect blame to the model or a third-party vendor. They must prove they took "reasonable steps" to control the business effectively. The Failure of Traditional Quality Assurance Sampling Traditional compliance models rely on human analysts reviewing a tiny, retrospective sample—typically one to three percent—of completed customer files. While this method is standard in human-led environments, it is mathematically invalid when applied to automated agentic systems. Because AI agents do not exhibit the random, individual variation of human workforces, any underlying model error, prompt bias, or structural drift will execute consistently and at extreme scale across every single transaction. If an AI agent hallucinates an incorrect interest rate or fails to identify a vulnerable customer, that failure spreads across the entire customer base instantly. This relationship can be modeled mathematically to illustrate the systemic risk exposure of unmonitored algorithmic execution. Let the total financial and regulatory risk exposure, \mathcal{R}_{\text{exposure}}, be formulated as: \mathcal{R}_{\text{exposure}} = V \cdot \left[ (1 - P_{\text{audit}}) \cdot T_{\text{QA}} \cdot P_{\text{harm}} + P_{\text{audit}} \cdot T_{\text{realtime}} \cdot P_{\text{drift}} \right] \cdot C_{\text{impact}} Where: * V represents the continuous transaction or interaction volume processed by the bank per unit of time. * P_{\text{audit}} represents the proportion of interactions subjected to compliance auditing. * T_{\text{QA}} represents the latency of traditional manual QA, typically measured in weeks or months. * T_{\text{realtime}} represents the latency of automated, real-time machine shadow assurance, typically measured in milliseconds. * P_{\text{harm}} represents the probability of a non-compliant outcome occurring under unmonitored human or machine execution. * P_{\text{drift}} represents the probability of an algorithmic drift or boundary breach. * C_{\text{impact}} represents the average financial, remediation, and punitive cost associated with a single regulatory or compliance violation. Under traditional QA architectures, where P_{\text{audit}} \approx 0.03 and T_{\text{QA}} \gg 0, the mathematical limit of \mathcal{R}_{\text{exposure}} as interaction volume V \to \infty is unbounded: \lim_{V \to \infty} \mathcal{R}_{\text{exposure}} = \infty This demonstrates why traditional sampling is fatal for an AI-native bank. To maintain an acceptable risk envelope with a minimal human headcount, the bank must transition to an automated architecture where P_{\text{audit}} \to 1.00 and T_{\text{realtime}} \to 0. The Core Mechanism: Machine-Led Shadow Assurance To resolve this mathematical reality, the AI-native bank must implement machine-led shadow assurance, decoupling the execution of customer transactions from the auditing of those transactions. As pioneered by Aveni's Agent Assure platform during its pilot inside the FCA Supercharged Sandbox, this pattern relies on a parallel compliance architecture. A bank cannot rely on its primary execution models to audit their own outputs, as this creates a structural conflict of interest. Instead, the bank deploys specialized, lightweight Small Language Models—such as Aveni's FinLLM, which is trained specifically on UK financial regulations and transaction histories—to act as independent real-time compliance assessors. These secondary SLMs sit completely outside the primary transactional flow, observing and validating one hundred percent of live interactions. [Customer Interaction / Payment Request] │ ▼ ┌──────────────────────────────────────┐ │ Primary Execution Engine │ └──────────────────┬───────────────────┘ │ ├──────────────────────────────┐ │ (Transaction Copy) │ (Real-time Audit Log) ▼ ▼ ┌──────────────────────────────────────┐ ┌──────────────────────────────────────┐ │ Deterministic Core Ledger │ │ Independent Assessor SLM │ │ (Sentinel / Nexus) │ │ (Agent Assure) │ └──────────────────────────────────────┘ └──────────────────┬───────────────────┘ │ [Anomalous Signal?] │ ┌────────────────┴────────────────┐ No │ Yes │ ▼ ▼ [Standard Log Only] [Trigger Real-Time] [Escalation Loop ] The Real-Time Evidence Pack and Handover Interface When the assessor SLM detects an anomaly—such as a subtle cue of customer vulnerability, an adversarial prompt injection, or a conversational drift toward unregulated advice—it triggers an immediate compliance intervention. For low-level risks, the system dynamically injects required disclosures or steers the primary model back to safe flows. For high-level risks, the system immediately suspends the agent's execution authority, freezes the transaction, and escalates the case to a human officer. This handover is facilitated by a real-time, unified dashboard that presents the human supervisor with an automated "evidence pack". This pack includes the precise prompt inputs, the step-by-step reasoning trace used by the primary agent, and the assessor model's compliance verification logs. By utilizing this continuous, machine-led auditing layer, the bank's human headcount is minimized. Human operators no longer perform manual file-checking; instead, they operate as high-level "observers" and "approvers" who manage exception queues, refine the automated rulesets, and sign off on the evidence packs that provide the legal proof of "reasonable steps" required under the SM&CR. Technical and GRC Blockers and Operational Resolutions Operating an AI-native financial institution under the strict supervision of the FCA and PRA requires resolving several technical, structural, and regulatory barriers at the architectural level. Blocker 1: Stochastic Execution vs. Deterministic Ledgers The core of any regulated bank is its ledger, which must operate on strict, immutable, double-entry accounting principles. AI models are fundamentally stochastic; they operate on probabilities and can generate slightly different outputs given identical inputs. If an AI agent has direct write-access to a core ledger or payment engine, it introduces the risk of transaction hallucinations, unauthorized cash movements, or reconciliation failures. Resolution The bank must implement an architectural bifurcation that completely decouples the stochastic intelligence layer from the deterministic execution engine. This is achieved by utilizing middleware frameworks such as Backbase's Banking OS, which connects to core systems of record through an orchestration layer (Nexus) and a decision authority layer (Sentinel). The AI agent cannot directly write to the ledger or execute a payment. Instead, it must construct an explicit payment payload and request authorization from Sentinel. Sentinel evaluates the request against rigid, hard-coded GRC rules, validates the customer's state, and issues a single-use, cryptographically secure "Decision Token". The deterministic engine will only execute transactions that are accompanied by a valid, authorized Decision Token, ensuring that every financial movement remains traceable, verifiable, and subject to hard, non-negotiable limits. Blocker 2: Conversational Perimeter Overstepping and the "Advice Gap" Under the FCA's COBS 9A guidelines, providing a customer with a "personal recommendation" regarding savings, investments, pensions, or mortgages constitutes regulated financial advice, requiring formal suitability assessments and licensed human sign-off. If a conversational retail banking agent inadvertently answers a customer's query with advice-like outputs, the bank is instantly liable for unauthorized advising and severe Consumer Duty violations. Resolution The bank must deploy specialized, domain-specific language models with built-in semantic guardrails rather than generic, off-the-shelf LLMs. The system must implement a real-time semantic monitoring engine. When a user asks a query that sits on the boundary of an advised journey, the assessor model must detect the boundary overstepping, steer the primary agent back to informational guidance, and dynamically insert a consistent, simple consumer disclosure that explicitly distinguishes the automated informational guidance from regulated financial advice. If the customer demands a personalized recommendation, the system must freeze the session, gather structured suitability data, and route the package to a licensed human advisor for final approval. Blocker 3: Financial Crime Detection and Threat-to-Control Latency Money launderers and automated fraud networks operate with extreme speed and sophistication, using synthetic identities and cloned voices to bypass bank controls. Traditional transaction monitoring and AML systems rely on rigid, static rulesets that are slow to adapt, with change-management cycles that can take months to design, test, and deploy into production. This latency creates a high risk of systemic exploitation. Resolution The bank must build a dynamic, network-based financial crime detection loop utilizing agentic platforms such as Sardine, Unit21, Hawk AI, or the Anthropic-powered Financial Crimes Agent built with FIS. These systems replace static, point-in-time alerts with real-time behavioral analytics. Upon detecting anomalous transaction velocity or relational patterns, compliance agents automatically assemble a complete evidence package across all core systems and evaluate the activity against known criminal typologies. The system generates an audit-ready, human-readable case summary with clear reasoning traces, reducing alert triage times from days to minutes. This allows a small compliance team to dynamically update, test, and deploy new risk scoring rules into production within hours, compressing the threat-to-control cycle to match the speed of the attackers. Blocker 4: Critical Third-Party Concentration and Model Drift Most financial institutions deploying AI rely heavily on a small number of dominant US hyperscalers for model hosting and compute. This creates severe concentration risks, exposing the bank to systemic outages, model deprecations, or sudden API pricing changes that could compromise operational resilience and violate DORA and UK outsourcing guidelines. Additionally, financial models are prone to "drift," degrading in accuracy over time as customer behavior and market conditions shift. Resolution The bank must adopt an "AI Factory" model on sovereign, specialized infrastructure. Rather than relying on external API calls to third-party providers, the bank must self-host open-source foundation models—such as DeepSeek or Mistral—on private, air-gapped cloud infrastructure. This allows the bank to maintain absolute data privacy, control its infrastructure costs, and protect its unique institutional knowledge by fine-tuning model weights using its own transaction history. To combat model drift, the bank must implement continuous drift monitoring with automated alert triggers, combined with a deterministic, rule-based fail-safe system that can automatically take over core banking operations if the AI layer degraded or experienced a latency spike. Comparative Evaluation of AI-Native Initiatives and Regulated Cohorts To provide a clear view of the current landscape, the following table evaluates the key characteristics, testing environments, and GRC approaches of the primary open projects, fintechs, and regulated cohorts currently pioneering AI-native financial infrastructure. Project / Cohort Architectural Strategy GRC and Compliance Mechanism Testing and Sandbox Integration Core Resolution of Blockers BEYLA "The Hive" real-time living memory paired with specialized Digital Humans. Cryptographically verifiable consent and mandatory human approval for all money movements. Cohort 1 participant in the FCA Supercharged Sandbox. Refactored from Google to AWS to satisfy strict UK payment and transaction security standards. Catena Labs Open-source Agent Commerce Kit (ACK-ID and ACK-Pay) built on W3C standards. Verifiable AI identities and integrated spending limit compliance rules. Sandbox testing utilizing testUSD on hosted testnets. Cryptographically links autonomous agents to physical, real-world legal entities to resolve liability. Aveni Proprietary FinLLM suite of specialized financial Small Language Models. "Agent Assure" and "Agent Approve" 100% continuous machine-led shadow auditing. Completed Agent Assure pilot in the FCA Supercharged Sandbox. Solves the manual QA sampling problem by replacing retrospective audits with continuous SLM verification. Solaris Rebuilding core BaaS processes around autonomous AI agents acting as robotic workers. Humans acting as high-level controllers overseeing automated transaction and AML files. Internal staging and production rollouts for co-branded clients ADAC and Boerse Stuttgart. Overcomes legacy IT rigidity by deploying agentic workflows directly into modular, API-first architectures. FCA AI Live Testing (Cohort 2) Diverse models including agentic AI, SLMs, and neurosymbolic AI. Real-time risk management, live monitoring, and automated KYC/AML verification. Structured regulatory live testing supported by Advai, running until late 2026. Enables large incumbents (Barclays, Lloyds) to test high-risk AI deployments within a controlled environment. Napier AI "Theseus" network-based financial crime and AML detection engine. Automated alert triage, graph-based network visualization, and audit-ready case summaries. Cohort 1 participant in the FCA Supercharged Sandbox. Combines broad cross-border datasets and massive compute to pinpoint money laundering across institutions. Strategic Blueprint for Securing UK Licensure To successfully secure authorization from the FCA and PRA and launch an AI-native regulated bank in the UK, founders should execute a structured, five-phase blueprint designed around the principles of Minimum Viable Human Oversight. Phase 1: Core System Isolation and Deterministic Decoupling Before engaging with the regulators, the bank must construct a bifurcated backend architecture that completely decouples the stochastic intelligence layer from the deterministic double-entry ledger. All conversational channels, underwriting models, and agentic workflows must interface with core systems through an immutable middleware gateway. This gateway must require a cryptographically signed, single-use Decision Token for every transactional read or write action, ensuring that no AI agent can modify customer balances or execute payments autonomously without hard-coded, rule-based verification. Phase 2: Implement Machine-to-Machine Trust and Verification Protocols The bank must build its identity and payment layers around open, vendor-neutral web standards, such as the open-source Agent Commerce Kit. Every autonomous agent deployed by the bank, as well as those used by its clients, must be assigned a Decentralized Identifier and a Verifiable Credential through ACK-ID, linking the agent cryptographically to its designated human controller and establishing an audit trail that satisfies KYC and AML guidelines. All automated transactions must utilize ACK-Pay to generate verifiable cryptographic receipts, ensuring that every automated money movement is auditable and subject to strict, pre-configured spending rulesets. Phase 3: Secure Entry into the FCA's Innovation Sandbox Cohorts The bank must apply for and participate in the FCA's Supercharged Sandbox and AI Live Testing initiatives, utilizing these controlled environments to test its models alongside the regulator. By partnering with the FCA's technical coordinators and utilizing the sandbox's synthetic datasets and high-performance computing, the bank can safely stress-test its conversational agents and underwriting models against real-world adversarial prompt injections, model drift, and vulnerable customer indicators. The successful completion of these pilots establishes a baseline of regulatory trust and provides the foundation for the bank's formal licensing application. Phase 4: Deploy the Automated Machine-Led Compliance Layer To operationalize the Minimum Viable Human Oversight model, the bank must deploy a parallel shadow assurance platform powered by specialized financial Small Language Models, such as Aveni's FinLLM. These assessor models must monitor one hundred percent of live customer interactions and transaction logs, comparing outputs in real time against strict regulatory criteria under the Consumer Duty and COBS 9A. The compliance layer must be configured to automatically generate real-time evidence packs—documenting the customer's inputs, the agent's logical reasoning trace, and the assessor's verification logs—while automatically escalating any anomalies to a lean team of human supervisors, transforming the compliance role from manual auditing to algorithmic exception management. Phase 5: Establish the SM&CR Accountability Map and Governance Framework Finally, the bank must formally align its automated GRC platform with the Senior Managers and Certification Regime. The bank must draft a precise Accountability Map, assigning personal ownership of all algorithmic outcomes and agent behaviors to designated Senior Management Functions (SMF24, SMF4, and SMF16). The automated compliance layer must be directly integrated into the Senior Managers' personal dashboards, providing them with continuous, regulator-ready evidence packs and signed residual risk statements for every automated interaction. This structured documentation provides the legal proof of "reasonable steps" required to secure personal protection for the bank's executives under the SM&CR, enabling the AI-native bank to scale its operations safely, compliantly, and at pace. Works cited 1. The Mills Review: AI and the future of retail financial services - FCA, https://www.fca.org.uk/publication/corporate/the-mills-review.pdf 2. Financial Stability in Focus: Artificial intelligence in the financial system | Bank of England, https://www.bankofengland.co.uk/financial-stability-in-focus/2025/april-2025 3. AI-Native Financial Infrastructure: Rebuilding finance's core systems for the agentic era, https://www.anthemis.com/insights/ai-native-financial-infrastructure-rebuilding-finances-core-systems-for-the-agentic-era/ 4. Intellect Design Arena Launches AI Digital Banking Platform for UK & Europe-based Digital & Challenger Banks, https://www.intellectdesign.com/media/intellect-design-arena-launches-ai-digital-banking-platform-for-uk-europe-based-digital-challenger-banks/ 5. SMCR Compliance for AI Agents | What the FCA Expects - Aveni, https://aveni.ai/blog/smcr-compliance-ai-agent-oversight/ 6. AI in Banking | Accountability & Consumer Duty - Aveni, https://aveni.ai/blog/ai-in-banking-accountability/ 7. Circle co-founder to build new 'AI-native' bank | Banking Dive, https://www.bankingdive.com/news/circle-co-founder-build-new-ai-native-bank/748767/ 8. What the Mills Review says about AI in financial services, Selmin Hakki - The Lens, https://thelens.slaughterandmay.com/post/102nbti/what-the-mills-review-says-about-ai-in-financial-services 9. Catena Labs - Finance/Banking Project | Crypto-Fundraising, https://crypto-fundraising.info/projects/catena-labs/ 10. Agent Commerce Kit (ACK) - GitHub, https://github.com/agentcommercekit 11. agentcommercekit/ack: The Agent Commerce Kit (ACK) - GitHub, https://github.com/agentcommercekit/ack 12. Core Concepts - Agent Commerce Kit, https://www.agentcommercekit.com/overview/concepts 13. ACK-Lab Developer Preview: Building Trust Infrastructure for Agentic Commerce | Catena, https://catena.com/blog/acklab-developer-preview 14. BEYLA — Finance that acts for you, https://beyla.ai/ 15. From AI That Answers to AI That Acts - The Business Show London 2026, https://www.greatbritishbusinessshow.co.uk/seminar-sessions-tbs-2026/ai-answers-ai-acts- 16. Lloyds and Nationwide-backed Aveni raises £12m - FinTech Global, https://fintech.global/2026/06/04/lloyds-and-nationwide-backed-aveni-raises-12m/ 17. Aveni extends market leading wealth and compliance platform into consumer agentic AI for financial services - FinTech Scotland, https://www.fintechscotland.com/aveni-extends-market-leading-wealth-and-compliance-platform-into-consumer-agentic-ai-for-financial-services/ 18. Our members | Insurtech UK, https://insurtechuk.org/membership/our-members?tag=angel+round 19. From Hiring Challenge to FCA Readiness - | W Talent UK, https://www.wtalent.com/uk/beyla/ 20. beyla - From Hiring Challenge to FCA Readiness - | W Talent UK, https://www.wtalent.com/uk/beyla-case-study/ 21. Travers Smith launches a fintech incubator, Fintech Amplifier, https://www.traverssmith.com/knowledge/knowledge-container/travers-smith-launches-a-fintech-incubator-fintech-amplifier/ 22. “Huge wave coming over financial services industry,” says boss of “Europe's first AI-native bank” - Tech.eu, https://tech.eu/2026/06/05/huge-wave-coming-over-financial-services-industry-says-boss-of-europes-first-ai-native-bank/ 23. How the FCA is rewriting the rules on RegTech innovation - FinTech Global, https://fintech.global/2026/06/15/how-the-fca-is-rewriting-the-rules-on-regtech-innovation/ 24. FCA Regulatory Sandbox - ScaleUp Institute, https://www.scaleupinstitute.org.uk/programmes/fca-regulatory-sandbox-2025/ 25. UK FCA Opens AI Sandbox Cohort 2, Barclays, Experian, and Scottish Widows Join Regulatory Testing Environment - Tech Jacks Solutions, https://techjacksolutions.com/ai-brief/uk-fca-opens-ai-sandbox-cohort-2-barclays-experian-and-scott/ 26. FCA Allows Firms to Experiment With AI Alongside NVIDIA - Markets Media, https://www.marketsmedia.com/fca-allows-firms-to-experiment-with-ai-alongside-nvidia/ 27. Supercharged Sandbox Showcase (Cohort 1) - FCA Innovation, https://events.fcainnovation.co.uk/supercharged_sandbox_showcase_c1/pages/Participants-day-2 28. FCA unveils eight new participants for next phase of AI Live Testing initiative, https://www.fintechfutures.com/ai-in-fintech/fca-unveils-eight-new-participants-for-next-phase-of-ai-live-testing-initiative 29. The cat won't go back in the box: what the FCA's Mills Review means for firms, https://sicsicadvisory.com/the-cat-wont-go-back-in-the-box-what-the-fcas-mills-review-means-for-firms/ 30. UK Regulators Publish Approaches to AI Regulation in Financial Services | Insights | Skadden, Arps, Slate, Meagher & Flom LLP, https://www.skadden.com/insights/publications/2024/05/uk-regulators-publish-approaches-to-ai 31. FCA publishes landmark review into impact of AI on retail financial services, https://www.fca.org.uk/news/press-releases/fca-publishes-landmark-review-impact-ai-retail-financial-services 32. The future of AI regulation in UK financial services: key insights from the FCA's Mills Review, https://www.deloitte.com/uk/en/blogs/ecrs/the-future-of-ai-regulation-in-uk-financial-services-key-insights-from-the-fcas-mills-review.html 33. The Mills Review and financial crime: mind the autonomy gap | Baringa, https://www.baringa.com/en/insights/mills-review-financial-crime/ 34. FCA publishes landmark Mills Review into AI and retail financial services: what firms need to know | TLT LLP, https://www.tlt.com/insights-and-events/insight/fca-publishes-landmark-mills-review-into-ai-and-retail-financial-services-what-firms-need-to-know 35. The Mills Review: prepare now to keep pace with AI, https://www.hsfkramer.com/notes/fsrandcorpcrime/2026-posts/the-mills-review-prepare-now-to-keep-pace-with-ai 36. The Mills Review: FCA sets out vision for AI-enabled financial services by 2030 - CMS.law, https://cms.law/en/gbr/legal-updates/the-mills-review-fca-sets-out-vision-for-ai-enabled-financial-services-by-2030 37. DP5/22 - Artificial Intelligence and Machine Learning | Bank of England, https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence 38. The Bank of England and PRA set out plans for safe AI innovation: What firms need to know, https://www.tlt.com/insights-and-events/insight/the-bank-of-england-and-pra-set-out-plans-for-safe-ai-innovation-what-firms-need-to-know 39. Boost City regulator’s powers to help protect UK consumers from AI, says watchdog, https://www.theguardian.com/business/2026/jul/06/boost-city-regulators-powers-protect-uk-consumers-ai-cyber-crime-fraud-watchdog 40. FCA AI Paper: Requirements, Who It Applies To & Penalties | FluxForce, https://www.fluxforce.ai/regulations/uk-fca-fca-ai-discussion-paper 41. AI agent stress testing for financial services | What good looks like - Aveni, https://aveni.ai/blog/ai-agent-stress-testing-financial-services/ 42. Aveni - Edinburgh Innovations, https://edinburgh-innovations.ed.ac.uk/case-studies/aveni 43. Future State—FCA Expectations, Governance and Skills - Kroll, https://www.kroll.com/en/publications/financial-compliance-regulation/fca-expectations-governance-skills 44. AI agent oversight gap prompts Aveni to form industry council - FinTech Global, https://fintech.global/2026/03/20/ai-agent-oversight-gap-prompts-aveni-to-form-industry-council/ 45. From FCA guidance to evidence: Operationalising AI accountability - TORI Global, https://www.toriglobal.com/blog/from-fca-guidance-to-evidence-operationalising-ai-accountability/ 46. Built an AI-native banking backend — looking for feedback / early partners Banking and /or Credit : r/fintech - Reddit, https://www.reddit.com/r/fintech/comments/1t5ijq5/built_an_ainative_banking_backend_looking_for/ 47. 8 AI Workflow Tools for Banking and Finance Teams in Regulated Environments - Jinba, https://jinba.io/blog/ai-workflow-tools-banking-finance 48. AI compliance in banking: build governance into architecture - Backbase, https://www.backbase.com/blog/ai-for-compliance-in-banking 49. Financial Services AI Adoption Plan - GOV.UK, https://www.gov.uk/government/publications/ai-adoption-plan-financial-services/financial-services-ai-adoption-plan 50. AML Compliance Software & AI-Native AML Platform | Hawk AI, https://hawk.ai/solutions/aml 51. Best secure AI agents for banking in 2026 - Gradient Labs, https://gradient-labs.ai/guides/new-best-secure-ai-agents-for-banking-in-2026 52. FIS Brings Agentic AI to Banking with Anthropic, Starting with Financial Crimes, https://www.fisglobal.com/about-us/media-room/press-release/2026/fis-brings-agentic-ai-to-banking-with-anthropic-starting-with-financial-crimes 53. AI-powered banks only possible with AI 'factoriesʼ - Compliance Corylated, https://www.compliancecorylated.com/news/ai-powered-banks-only-possible-with-ai-factories%CA%BC/