Thought Experiment

Can you build a UK-regulated bank with
fewer than ten humans?

This page is an evolving investigation into the architectural, regulatory, and operational feasibility of creating an AI-Native UK Bank — a licensed retail bank operating with the smallest legally permissible human headcount, where all other functions are performed by autonomous AI Agents under a Minimum Viable Human Oversight model.

The research draws on the FCA Mills Review, the Bank of England's Financial Policy Committee analysis, live regulatory sandbox programmes, and emerging industry architecture from Catena Labs, Aveni, BEYLA, Solaris, and others. This page will be updated as the investigation progresses.

Last updated: 2026-07-20

The Premise

Minimum Viable Human Oversight.

Under the UK's Senior Managers & Certification Regime (SM&CR), a designated Senior Manager carries personal, non-delegable civil and criminal liability for regulatory failures in their business areas. If an autonomous algorithm causes consumer harm, the manager cannot deflect blame to the model or a third-party vendor — they must prove they took reasonable steps.

This creates the central question: what is the absolute minimum human footprint required to satisfy the SM&CR, the Consumer Duty, and the PRA's model risk management standards (SS1/23), while allowing transaction volumes and customer interactions to scale exponentially without a proportional increase in back-office headcount?

The Mathematical Challenge

Why traditional compliance sampling fails.

Traditional models rely on human analysts reviewing 1–3% of completed customer files. For AI-native banks this is mathematically fatal:

Rexposure = V · [ (1 − Paudit) · TQA · Pharm + Paudit · Trealtime · Pdrift ] · Cimpact

As volume V → ∞, the limit of Rexposure is unbounded under traditional sampling. The resolution: transition to an architecture where Paudit → 1.00 and Trealtime → 0 — machine-led shadow assurance on 100% of transactions.

The Mills Review

The Autonomy Spectrum (Levels 1–5)

The landmark Mills Review (FCA, July 2026) frames the transition of the human role across a five-tier autonomy spectrum. Levels 1–3 are well-served by existing frameworks. Levels 4 and 5 — where this investigation operates — introduce deep challenges for accountability, consumer protection, and systemic risk.

Level 1 · Established

Human as Operator

The human performs the task, using AI merely as an on-demand tool (e.g. generating summaries of complex product terms).

Level 2 · Established

Human as Collaborator

The human and the AI plan and execute actions together, with continuous human input and refinement.

Level 3 · Established

Human as Consultant

The AI analyses options and makes recommendations, while the human retains final decision-making power.

Level 4 · Frontier

Human as Approver

The AI prepares, formats, and initiates transactions or client communications, which the human must actively authorise before execution.

Level 5 · Frontier

Human as Observer

The AI acts continuously on its own within agreed parameters, logging its activity for retrospective human monitoring.

Architectural Barriers

Four Core Blockers to AI-Native Banking

Operating an AI-native financial institution under FCA and PRA supervision requires resolving four structural barriers at the architectural level. Each blocker has a defined resolution path emerging from industry pilots and regulatory sandbox programmes.

Stochastic Execution vs. Deterministic Ledgers

The problem: AI models are probabilistic and can generate different outputs given identical inputs. Direct write-access to a core ledger introduces risk of transaction hallucinations, unauthorised cash movements, or reconciliation failures.

Resolution: Bifurcate the architecture: decouple the stochastic intelligence layer from the deterministic execution engine using a middleware gateway that requires a cryptographically signed, single-use Decision Token for every transactional action.

Conversational Perimeter Overstepping & the Advice Gap

The problem: Under FCA COBS 9A, providing a "personal recommendation" constitutes regulated financial advice requiring formal suitability assessments and licensed human sign-off. A conversational agent could inadvertently cross this boundary.

Resolution: Deploy domain-specific SLMs with built-in semantic guardrails. Implement a real-time semantic monitoring engine that detects boundary overstepping, steers the agent back to informational guidance, and escalates suitability cases to licensed humans.

Financial Crime Detection & Threat-to-Control Latency

The problem: Money launderers and automated fraud networks operate at machine speed. Traditional AML systems rely on rigid rulesets with change-management cycles that take months, creating a critical latency gap.

Resolution: Build a dynamic, network-based financial crime detection loop using agentic platforms that replace static alerts with real-time behavioural analytics, compressing threat-to-control cycles from months to hours.

Critical Third-Party Concentration & Model Drift

The problem: Reliance on a small number of US hyperscalers for model hosting creates severe concentration risk. Financial models are also prone to drift, degrading accuracy over time as customer behaviour and markets shift.

Resolution: Adopt an "AI Factory" model on sovereign, air-gapped infrastructure using self-hosted open-source foundation models. Implement continuous drift monitoring with automated alerts and a deterministic rule-based fail-safe for core operations.

Licensure Pathway

Five-Phase Blueprint for UK Licensure

To successfully secure authorisation from the FCA and PRA and launch an AI-native regulated bank, founders should execute a structured five-phase blueprint designed around the principles of Minimum Viable Human Oversight.

  1. Phase 1: Core System Isolation & Deterministic Decoupling Construct a bifurcated backend that fully decouples the stochastic AI layer from the double-entry ledger. Every transaction requires a cryptographically signed, single-use Decision Token through an immutable middleware gateway.
  2. Phase 2: Machine-to-Machine Trust & Verification Protocols Build identity and payment layers around open W3C standards (DIDs, VCs). Every autonomous agent receives a Decentralised Identifier and Verifiable Credential, cryptographically linking it to its human controller.
  3. Phase 3: Secure Entry into FCA Innovation Sandbox Cohorts Apply for and participate in the FCA Supercharged Sandbox and AI Live Testing initiatives. Use controlled environments to stress-test conversational agents and underwriting models against adversarial inputs and model drift.
  4. Phase 4: Deploy the Automated Machine-Led Compliance Layer Deploy a parallel shadow assurance platform powered by specialised financial SLMs (e.g. Aveni FinLLM) monitoring 100% of live interactions. Automatically generate real-time evidence packs and escalate anomalies to human supervisors.
  5. Phase 5: Establish the SM&CR Accountability Map & Governance Framework Align the automated GRC platform with the Senior Managers & Certification Regime. Assign personal ownership of all algorithmic outcomes to designated Senior Management Functions (SMF24, SMF4, SMF16) with continuous regulator-ready evidence packs.
Industry Context

Who else is building this?

A distinct cohort of fintech startups, technology providers, and transitioning licensed institutions is actively establishing the architectural precedents for AI-native banking. These organisations treat autonomous agents as core, load-bearing infrastructure rather than marginal assistants.

Open-source protocol

Catena Labs

Agent Commerce Kit (ACK-ID & ACK-Pay) built on W3C standards for verifiable AI identities and machine-to-machine payments. $48M raised.

FCA Sandbox participant

BEYLA

"The Hive" real-time living memory with a Digital C-Suite of specialised AI humans. Refactored from GCP to AWS for UK regulatory standards.

Shadow assurance

Aveni

FinLLM suite of specialised financial SLMs providing Agent Assure — 100% continuous machine-led shadow auditing, piloted in the FCA Supercharged Sandbox.

BaaS transformation

Solaris

Rebuilding core banking-as-a-service processes around autonomous AI agents with human supervisors acting as compliance controllers.

Cognitive platform

Intellect Design Arena

AI Digital Banking platform across seven cognitive dimensions targeting 20% CIR reduction and 22–28% RoE.

Financial crime

Napier AI

"Theseus" network-based AML detection combining cross-border datasets with graph-based visualisation and audit-ready case summaries.

Research Sources

References & Further Reading

This investigation is grounded in regulatory publications, live sandbox programmes, and industry architecture. Key sources are listed below.

#TitlePublisherLink
1The Mills Review: AI and the future of retail financial servicesFCAView source →(opens in a new tab)
2Financial Stability in Focus: Artificial intelligence in the financial systemBank of EnglandView source →(opens in a new tab)
3AI-Native Financial Infrastructure: Rebuilding finance's core systems for the agentic eraAnthemis GroupView source →(opens in a new tab)
4SMCR Compliance for AI Agents | What the FCA ExpectsAveniView source →(opens in a new tab)
5AI in Banking | Accountability & Consumer DutyAveniView source →(opens in a new tab)
6Agent Commerce Kit (ACK)Catena Labs / GitHubView source →(opens in a new tab)
7Intellect Design Arena Launches AI Digital Banking Platform for UK & EuropeIntellect Design ArenaView source →(opens in a new tab)
What’s next

This investigation is just beginning.

Future updates will add deep-dive technical analyses for each blocker, an interactive autonomy spectrum, a risk exposure simulator, the SM&CR accountability map, and a dated commentary log tracking how the research evolves with new regulatory guidance.

Axiom Verity

Board-level AI governance advisory built on 25+ years of regulated technology risk, cyber, and cryptography leadership.