The Mechanics of Agentic Finance Regulation: How the FCA's 'Mills Review' Proposes a Roadmap and Expanded Powers Over AI's Critical Third Parties
The UK's Financial Conduct Authority has unveiled a landmark framework to regulate 'agentic finance'—where AI systems autonomously execute trades and manage savings. The Mills Review proposes expanding regulatory powers over the tech giants providing the underlying AI models.
By Factlen Editorial Team
- Regulatory & Supervisory Bodies
- Focus on systemic risk, market integrity, and expanding oversight perimeters to include Big Tech.
- Legal & Compliance Advisors
- Focus on liability frameworks, existing rules, and corporate governance for AI adoption.
- Industry & Fintech Innovators
- Focus on closing the advice gap, operational efficiency, and the infrastructure needed for agentic commerce.
- Consumer Protection Analysts
- Focus on redress, transparency, and ensuring users are not harmed by autonomous errors.
What's not represented
- · Retail investors who have already suffered losses from algorithmic trading errors.
- · Executives at Big Tech foundation model companies facing new regulatory perimeters.
Why this matters
As artificial intelligence moves from giving financial advice to actively executing trades and managing savings, regulators are racing to ensure consumers are protected from autonomous errors. The FCA's new framework signals that the tech giants building these AI models will soon face direct financial oversight, fundamentally altering how digital wealth management is built and governed.
Key points
- The FCA's Mills Review outlines a regulatory roadmap for 'agentic finance,' where AI autonomously executes financial decisions.
- Research shows 11 million UK adults are already open to using autonomous AI for savings and borrowing.
- The regulator is pushing to expand its oversight to include Big Tech AI model providers, designating them as 'critical third parties.'
- Financial firms are warned that they cannot outsource liability; a human executive must remain accountable for AI actions.
- The FCA plans to build its own AI-enabled agentic supervisory model to police the rapidly evolving financial markets.
The era of the financial chatbot is already giving way to something far more autonomous. For the past three years, artificial intelligence in retail finance has largely functioned as a sophisticated conversationalist, summarizing market trends or explaining mortgage rates. Now, the industry is crossing a critical threshold into "agentic finance"—a paradigm where AI systems do not just advise, but actively execute transactions, rebalance portfolios, and sweep cash across accounts on behalf of consumers.[4]
Recognizing that this shift is already underway, the UK's Financial Conduct Authority (FCA) has published the "Mills Review," a landmark regulatory roadmap led by executive director Sheldon Mills. The report represents the first comprehensive attempt by a major global financial regulator to grapple with the mechanics of delegated AI financial decision-making.[1]
The review outlines a future where the financial services industry moves away from episodic, human-led activity toward continuous, AI-enabled management. This transition promises to democratize wealth management, potentially closing the persistent "advice gap" that leaves lower-income households without professional financial guidance. However, it also introduces unprecedented questions about liability, systemic risk, and regulatory boundaries.
Consumer appetite for autonomous financial agents is surprisingly robust, running well ahead of existing regulatory frameworks. Research commissioned by the FCA reveals that a fifth of UK adults—approximately 11 million people—are already open to using AI systems that can act autonomously within pre-set financial goals.[1]

This enthusiasm exists despite a glaring lack of consumer protection. Under current rules, if a human financial advisor makes a negligent recommendation, the consumer has clear avenues for redress and compensation. If an autonomous AI agent hallucinates a market signal and executes a disastrous trade, the liability framework is dangerously ambiguous.[1][4]
The mechanics of agentic finance rely on what the Mills Review terms the "AI autonomy spectrum." At the lowest end, humans use AI as a tool to gather information. In the middle, AI acts as a co-pilot, requiring explicit human sign-off for every action. At the highest end—the agentic tier—the human becomes an observer, monitoring outcomes while the AI system executes tasks continuously within agreed-upon boundaries.
To manage this spectrum, the Mills Review outlines seven priority recommendations for the FCA Board. These include securing and adapting the regulatory perimeter, strengthening system-wide oversight, and enabling the foundational infrastructure required for agentic finance to operate safely.
The most consequential of these recommendations involves a significant expansion of the FCA's authority over "critical third parties" (CTPs). Historically, financial regulators have supervised banks, brokers, and insurers. But the AI models powering agentic finance are built by a handful of massive technology companies, including OpenAI, Anthropic, Google, Amazon, and Microsoft.[1][2]

The most consequential of these recommendations involves a significant expansion of the FCA's authority over "critical third parties" (CTPs).
Because financial institutions are increasingly dependent on these foundation models, the models themselves represent a single point of failure for the financial system. If a major language model experiences a localized outage or a subtle degradation in reasoning capabilities, it could simultaneously impact the trading algorithms, risk assessments, and customer service bots of dozens of banks.[2][3]
The Mills Review argues that the FCA needs direct powers to oversee these critical third parties. This would allow the regulator to probe the resilience, cybersecurity, and operational stability of the tech giants providing the underlying AI infrastructure, ensuring they meet the stringent standards required of financial market utilities.[1][2]
Legal and compliance experts note that while the FCA is not proposing an immediate, standalone "AI rulebook," the regulatory expectations are already shifting. Firms deploying AI are expected to manage the technology through existing governance frameworks, such as the Senior Managers and Certification Regime (SM&CR).[3]
Sheldon Mills has been unequivocal on the issue of accountability, stating that even as systems become more autonomous, "you need a human on the hook for what they're doing." This means that financial institutions cannot outsource their regulatory liability to a third-party AI provider; the firm deploying the agent remains ultimately responsible for its actions.[1][3]
The urgency of clarifying this liability is underscored by the rapid deployment of AI in e-commerce and payments. Recent industry data indicates that 58% of UK online merchants believe AI agents have already transacted on their platforms. Yet, only 41% of those merchants express confidence in the liability frameworks governing those automated transactions.

Beyond regulating the industry, the FCA is also overhauling its own internal mechanics. The review recommends building an "AI-enabled agentic supervisory model." In practice, this means the regulator will deploy its own autonomous AI agents to continuously monitor the behavior of financial firms, analyzing product pricing, market abuse, and consumer outcomes in real-time.
This supervisory pivot acknowledges what Mills has described as an "arms race" between regulators and the financial industry. Traditional rule-making and manual supervision are simply too slow to police markets where millions of AI agents are executing micro-transactions and adjusting portfolios by the millisecond.[1][4]
The review also proposes the development of a trusted, public-interest AI financial capability service. This would provide consumers with a free, baseline AI agent designed to offer impartial guidance on debt management, savings, and budgeting, serving as a safe alternative to commercial models that might harbor hidden incentives.

The implementation of the Mills Review will require careful coordination with other regulatory bodies, including the Competition and Markets Authority and the Information Commissioner's Office. Agentic finance sits at the intersection of financial regulation, data privacy, and antitrust law, meaning no single regulator can oversee it in isolation.[3][4]
Ultimately, the FCA's roadmap represents a critical acknowledgment that the architecture of retail finance is fundamentally changing. By moving to regulate the underlying AI models and demanding clear human accountability for autonomous actions, the UK is attempting to build a framework where the efficiency of agentic finance can scale without compromising the stability of the financial system.[4]
How we got here
2023–2025
Financial institutions rapidly adopt AI as conversational assistants and internal co-pilots, keeping humans strictly in the loop.
January 2026
The FCA publishes an Engagement Paper to gather industry feedback on the transition toward autonomous AI systems.
July 6, 2026
The FCA releases the Mills Review, outlining a comprehensive regulatory roadmap for agentic finance and critical third parties.
Viewpoints in depth
Regulatory & Supervisory Bodies
Regulators argue that AI's autonomous capabilities require expanding oversight to the tech giants providing the underlying models.
The FCA and allied watchdogs view agentic finance as a systemic vulnerability if left unchecked. Because multiple financial institutions rely on the same few foundation models from companies like Anthropic and OpenAI, a single model failure could trigger widespread market disruption. Consequently, regulators are pushing to designate these tech firms as "critical third parties," granting authorities the power to directly audit their operational resilience and cybersecurity protocols.
Legal & Compliance Advisors
Legal experts emphasize that firms cannot outsource their regulatory liability to AI providers.
Compliance professionals warn that the absence of a dedicated "AI rulebook" does not mean a regulatory vacuum. Existing frameworks, such as the Senior Managers and Certification Regime (SM&CR), still apply. If an autonomous agent executes a non-compliant trade or discriminates in pricing, the human executive overseeing that business line remains personally accountable. Advisors are urging firms to build robust "supervisory evidence packs" to prove they maintain control over their delegated AI systems.
Industry & Fintech Innovators
Proponents believe agentic finance is the only viable way to democratize wealth management and close the advice gap.
For years, the cost of human financial advice has priced out lower-income consumers, leaving millions without professional guidance. Fintech innovators argue that autonomous AI agents can deliver continuous, personalized portfolio management at a fraction of the cost. They view the FCA's roadmap—particularly the push to enable the foundations for agentic finance—as a necessary green light to move beyond experimental chatbots and deploy systems that actively optimize consumer wealth.
What we don't know
- How the FCA will practically enforce its rules on multinational tech giants that develop foundation models outside of the UK.
- Whether existing liability frameworks and compensation schemes will be sufficient to cover complex, multi-step errors made by autonomous agents.
- How quickly consumers will actually adopt agentic finance once these tools move from theoretical surveys to live market products.
Key terms
- Agentic Finance
- A financial paradigm where artificial intelligence systems autonomously execute transactions, rebalance portfolios, and make decisions within pre-set parameters, rather than just providing advice.
- Critical Third Parties (CTPs)
- External technology providers, such as cloud hosts and AI model developers, whose services are so essential to the financial sector that their failure could trigger systemic market disruption.
- Regulatory Perimeter
- The boundary defining which firms, activities, and technologies fall under the direct legal oversight and enforcement powers of a financial regulator.
- AI Autonomy Spectrum
- A framework describing the progression of AI from a human-directed tool to a co-pilot, and ultimately to an autonomous agent that executes tasks while humans merely monitor outcomes.
Frequently asked
What is the FCA's Mills Review?
It is a landmark regulatory report led by FCA executive director Sheldon Mills that outlines how artificial intelligence will reshape retail finance by 2030, focusing specifically on autonomous AI agents.
Will AI be allowed to invest my money automatically?
Yes, the industry is moving toward 'agentic finance' where AI can execute trades and rebalance portfolios. However, the FCA is currently building the regulatory framework to ensure these systems operate safely.
Who is liable if an AI agent makes a mistake?
The FCA has clarified that financial firms cannot outsource their liability to AI providers. A human executive at the financial institution remains ultimately responsible for the actions of their AI systems.
Why does the FCA want to regulate tech companies?
Because financial institutions increasingly rely on AI models built by companies like OpenAI and Google, regulators view these 'critical third parties' as potential single points of failure for the entire financial system.
Sources
[1]The GuardianRegulatory & Supervisory Bodies
Crackdown on tech platforms will go ahead despite US intervention, says No 10
Read on The Guardian →[2]Financial TimesLegal & Compliance Advisors
FCA seeks expanded powers over Big Tech 'critical third parties' in AI push
Read on Financial Times →[3]Ropes & GrayLegal & Compliance Advisors
No AI rulebook does not mean no supervision: Navigating the FCA's Mills Review
Read on Ropes & Gray →[4]Factlen Editorial TeamConsumer Protection Analysts
Synthesis by Factlen editorial team
Read on Factlen Editorial Team →
Every angle. Every day.
Get finance stories with full source coverage and perspective breakdowns delivered to your inbox.





