Quentin CasaresData and AI leadership for regulated growth
Insights

2026-09-03 / 7 min

Know your agent is now a board question

In July 2026 the FCA and HM Treasury both concluded that AI agents will soon transact on customers' behalf, and that nobody has settled who is accountable when one goes wrong. Here is what a board should be able to evidence before that happens.

In brief: two UK papers published eight days apart in July 2026 accepted that AI agents will act and transact on customers' behalf, and that the liability, identity and authentication rules for that do not yet exist. The FCA put agentic finance and the regulatory perimeter among its seven priorities, and HM Treasury accepted a Know Your Agent standard as one of ten recommendations. Boards should stop treating agentic AI as a 2030 question and start recording which agents already act in their name.

Eight days in July settled a question UK regulators had been circling for two years. On 6 July 2026 the Financial Conduct Authority published the Mills Review, its long-term assessment of artificial intelligence and retail financial services. On 14 July HM Treasury published the Financial Services AI Adoption Plan and accepted every recommendation in it. Read together they say the same thing in two registers: software agents are going to act and transact on customers' behalf, and the rules that decide who answers when one gets it wrong have not been written.

That is an awkward position for a sector that has spent a decade building individual accountability. Under SM&CR, every material activity is meant to sit in a named person's statement of responsibilities. Under Consumer Duty, a firm must be able to show the outcome a customer actually received. Neither framework was drafted for a counterparty that is a piece of software acting on standing instructions from someone else's customer.

What the two papers said

The Mills Review was led by Sheldon Mills at the request of the FCA Board, and sets out how AI could reshape retail financial services by 2030. Its consumer research, conducted by Yonder Consulting in April 2026 across more than 5,000 UK retail financial services consumers, found that a fifth of people, around 11 million UK adults, are likely to use AI that can act autonomously within pre-set goals. That is not a 2030 number. It is a statement of current intent by a fifth of the retail market.

The review made seven recommendations to the FCA Board. Two matter most to firms: secure and adapt the regulatory perimeter, and enable the foundations for agentic finance. A third should concentrate minds in the second line, because the FCA also intends to build and adopt an AI-enabled agentic supervisory model. The regulator plans to read firms' data with machines of its own.

The Treasury plan came from two named industry figures, Harriet Rees, Group Chief Information Officer at Starling Bank, and Dr Rohit Dhawan, Head of AI and Advanced Analytics at Lloyds Banking Group. Its ten recommendations run across the regulatory framework, AI-powered advice and the perimeter, resilience, skills, and agentic payments. The government accepted them and committed to working with regulators and industry on next steps.

PublicationDateWhat it asks forConsequence for a board
The Mills Review (FCA)6 July 2026Perimeter secured and adapted, foundations for agentic finance, agentic supervisory modelAssume the customer journey, not just the model, is what gets supervised
Financial Services AI Adoption Plan (HM Treasury)14 July 2026Trust framework for agentic payments including Know Your Agent, perimeter review of advice-like LLM outputs, assessment of key AI and cloud providers as Critical Third PartiesAgent identity and liability become controls to build, not topics to watch

The accountability gap has a name

Recommendation 10 of the Treasury plan is the one to read twice. It sets out three pillars for agentic payments: legal and liability frameworks that unambiguously assign accountability when autonomous agents transact, Know Your Agent protocols providing standardised identity and verification for AI and autonomous software agents, and authentication standards for safe machine-to-machine interaction.

Know Your Agent is the phrase to take to the next risk committee. Firms already run Know Your Customer as an industrial process, with identity evidence, ongoing monitoring and a clear answer to the question of who they are dealing with. There is no equivalent for a piece of software presenting itself as acting for that customer. Today a firm can usually tell that an instruction arrived through an API. It generally cannot tell whether the thing on the other end was the customer, an agent the customer authorised, or an agent acting on a goal the customer set six weeks ago and has since forgotten.

The perimeter problem sits alongside it. The Treasury plan asks the FCA to review the consumer, competition and wider impacts of financial guidance and advice-like outputs generated by general purpose large language models, noting that only 9% of UK adults access regulated financial advice. The advice gap is being filled by tools outside the perimeter, and the plan also asks industry to agree consistent voluntary disclosure language so consumers can tell regulated AI services from unregulated ones. Firms that assumed the perimeter protected them from unregulated competitors should read that as a warning in both directions.

Resilience closes the loop. Four major cloud and technology providers were designated as Critical Third Parties on 13 July 2026, the day before the Treasury plan was published, and the plan asks government and regulators to accelerate the regime and assess key AI and cloud providers under it. It also proposes a voluntary repository for AI incidents and near-misses across the sector, and a voluntary assurance scheme for third-party AI models and providers.

What a board should already be able to evidence

Little of this needs new legislation before it becomes a board problem. Most of the exposure lands inside frameworks a regulated firm already operates.

Question an agent raisesFramework that already reaches itWhat is still missing
Who is accountable when an agent causes harm?SM&CR statements of responsibilitiesFCA guidance on senior manager accountability for AI-caused harm, expected later in 2026
Did the customer receive a good outcome?Consumer Duty outcomes monitoringOutcome data separated by whether the journey was agent-mediated
Is the model fit for the decision it influences?SS1/23 model risk management principlesCoverage of third-party and general-purpose models the firm did not build
Who is this agent, and is it authorised to act?No current frameworkKnow Your Agent identity, verification and authentication standards
What happens if the provider fails?Critical Third Parties regime and material third-party reportingAssessment of key AI and cloud providers under that regime

Read down the third column and the work becomes obvious. Four of the five rows are answered by data the firm should already hold and mostly does not organise: an inventory of journeys an agent can initiate, outcome monitoring that carries the agent-mediated flag, a model inventory that includes models bought rather than built, and third-party lineage that reaches the AI providers sitting under a customer-facing service. That is Critical Data Elements applied to a new subject, not a new discipline.

The timing is tighter than it looks. The Mills Review recommended that the perimeter review begin within three to six months of its publication, which puts it between October 2026 and January 2027. The FCA has said it will publish AI good and poor practice later in 2026. A board that waits for the trust framework will be reading its first supervisory expectations at roughly the same time it starts building the evidence to meet them.

Questions to ask before the next board meeting

  1. Which of our customer journeys can already be initiated or completed by an agent acting for the customer, and where is that list maintained?
  2. Which named senior manager holds accountability for harm caused by an AI system, and has that been written into a statement of responsibilities since July?
  3. Can we separate Consumer Duty outcome data by whether a journey was agent-mediated, and if not, what would it take?
  4. What would we do today if an agent we cannot identify submitted an instruction on a customer's account: accept it, refuse it, or escalate it?
  5. Which AI and cloud providers would appear on our material third-party register if the Critical Third Parties assessment reached them, and can we produce the lineage to prove it?

None of those questions requires a policy position on artificial intelligence. They require an inventory, an owner, and a record, which is what every durable governance regime has ever asked for. The firms that answer them in 2026 will spend 2027 authorising agents, and the ones that do not will spend it explaining them.

Sources

Executive Data Briefing

A low-volume note for data and AI decisions with consequence.

Consent-based and double opt-in. Governance patterns, board-level data trust, and decision infrastructure - not generic AI commentary.