2026-08-11

The End State Is Not a New Rulebook

In July 2026 four cloud providers came under Bank of England and FCA supervision without a single new AI statute being passed. The direction of travel in financial services regulation is not towards new AI rules, but towards proving your data.

On Monday 13 July 2026, four companies that have never held a UK financial services licence came under the supervision of the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority. HM Treasury designated Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd and Oracle Corporation UK Limited as Critical Third Parties, and the three regulators began overseeing them that morning. No new artificial intelligence statute was passed to make it happen.

That is the single most useful fact for anyone trying to work out where the regulation of data and AI in financial services actually ends up. The end state is not a new rulebook. It is the existing rulebook, pointed at new places, and enforced against evidence rather than assertion.

What the record actually says

It is worth being precise here, because the facts matter more than the noise around them.

On 20 January 2026 the Treasury Select Committee published its report on AI in financial services (HC 684). Its language was unusually direct: the Bank of England, the FCA and the Treasury were, in the Committee's view, exposing the public and the financial system to potentially serious harm through a wait-and-see approach. Dame Meg Hillier, the Committee's chair, said she did not feel confident the financial system was prepared for a major AI-related incident. The Committee made three recommendations with end-of-2026 deadlines: that the FCA publish practical guidance on how consumer protection rules and senior manager accountability apply to AI, that the Bank and the FCA conduct AI-specific stress testing, and that the Treasury use its powers to designate critical AI and cloud providers. On that last point the Committee noted something awkward: the Critical Third Parties regime had been established for more than a year and nobody had been designated under it.

Six months later, four were. The Critical Third Parties (Designation) Regulations 2026 came into force on 13 July. Sarah Breeden, Deputy Governor for Financial Stability, framed the rationale plainly, saying that as critical third parties become increasingly embedded in the operations of financial institutions they can introduce new forms of systemic risk. Nikhil Rathi made the concentration point directly: when the same providers serve thousands of firms, a single failure can reverberate across the system. The Bank has been explicit that this is a rolling programme, and that further designations will follow.

The European Union arrived at the same destination earlier and by a different road. The Digital Operational Resilience Act has applied since January 2025, and on 18 November 2025 the European Supervisory Authorities published their first list of designated critical ICT third-party providers, bringing the same category of company under direct oversight. In January 2026 UK and EU regulators signed a memorandum of understanding to coordinate that oversight between them.

So in the space of eight months, on both sides of the Channel, the regulatory perimeter moved outward from the licensed firm to the firms it depends on. That is a structural change, and it happened quietly.

The strongest case that the opposite is true

There is a serious argument that 2026 was the year the regulatory tide went out, and it deserves to be stated properly before it is answered.

The EU blinked. The AI Omnibus, proposed on 19 November 2025 and agreed between Council and Parliament on 7 May 2026, entered into force on 27 July 2026 as Regulation (EU) 2026/1744. Its headline effect is delay. The high-risk obligations in Annex III, which cover credit scoring and insurance risk assessment, now apply from 2 December 2027 rather than 2 August 2026. High-risk AI embedded in physical products under Annex I moves to 2 August 2028. Sixteen months of relief on precisely the rules that bite hardest in financial services.

The UK never had those rules to delay. The FCA told the Prime Minister it would avoid additional regulations for AI and rely on existing frameworks, and it has been consistent since. Ashley Alder, the FCA's chair, reaffirmed the position in July: a principles-based, outcomes-focused approach resting on the Consumer Duty and the Senior Managers Regime. On 14 July the Treasury published and accepted an AI Adoption Plan written by two industry practitioners, Harriet Rees of Starling Bank and Dr Rohit Dhawan of Lloyds Banking Group, whose ten recommendations are largely about removing friction from adoption.

Read together, a reasonable person could conclude that the regulators have chosen growth over caution and that the compliance burden is receding.

I think that reading gets one thing right and one thing badly wrong.

What was actually postponed

What the Omnibus delayed was conformity assessment: the documentation, the registration, the technical file, the paperwork of proving a system belongs to a category. It postponed nothing about liability. The Consumer Duty applies today. The Senior Managers and Certification Regime applies today. Neither has a commencement date that can be moved, and neither contains an exemption for harm caused by a model rather than a person. A firm that mis-sells through an agent in 2027 is in exactly the position it would have been in had it mis-sold through a human, and the FCA has now said so often enough that nobody can claim surprise.

Meanwhile, the rules that did land early were the ones about dependency. That asymmetry is the whole story. Supervisors have concluded, on both sides of the Channel, that the tractable risk is not the algorithm inside the firm but the infrastructure underneath it, and that the tractable question is not whether a model is clever but whether a firm can show its work.

The part that should make every executive sit up

The joint Bank of England and FCA survey of AI in UK financial services, published in November 2024, found that 75 per cent of firms were already using AI, and that 84 per cent had a named individual accountable for it. Those are the numbers that get quoted. Two others rarely are: 34 per cent of firms reported a complete understanding of the AI technologies they use, and 46 per cent reported only a partial understanding.

Accountability has run considerably ahead of comprehension. Roughly half the market has appointed someone to answer for systems that the firm concedes it does not fully understand.

The reason that gap persists is not modelling talent. It is data. The Basel Committee published its principles for effective risk data aggregation and risk reporting in 2013. Its progress report on 31 global systemically important banks, published in November 2023, concluded that nearly a decade after publication and seven years after the expected compliance date, additional work was required at all banks to attain or sustain full compliance. Not most banks. All of them. Among the Committee's added recommendations was that banks should ensure sound data quality as the basis for digitalisation projects, which is a supervisor's way of saying the obvious: you cannot govern what you cannot trace.

Thirteen years of a clear standard, an explicit deadline, direct supervisory pressure, and the largest banks in the world have not closed it. That is the constraint that will determine who copes with the next five years, and it has nothing to do with AI at all. AI governance without trusted data is theatre.

What the end state looks like

Five things follow, and none of them require a new statute.

Accountability sits with a named person and is tested against evidence. The FCA is due to publish practical guidance on how the Consumer Duty and the Senior Managers Regime apply to AI, along with a good and poor practice report. The question in a supervisory conversation stops being whether a firm has a policy and becomes whether the named individual can demonstrate what the system did, on what data, and who checked.

The supply chain is supervised directly, and concentration becomes a board risk with a regulator attached to it. Designation does not transfer responsibility. The Bank was careful to say the new regime complements rather than replaces existing outsourcing and operational resilience rules, and that firms remain responsible for their own due diligence, risk management and contingency planning. Two supervisors now, not one fewer.

Data lineage becomes a regulatory artefact rather than an engineering nicety. Whether the demand arrives through Basel principles, an EU conformity file or an FCA supervisory request, the deliverable is identical: a defensible account of where a number came from.

Supervision becomes continuous rather than periodic. The Mills Review, published by the FCA on 6 July 2026, recommends that the regulator build and adopt an AI-enabled agentic supervisory model. The FCA is already running AI Live Testing with a technical assurance partner, Advai, and a second cohort including Barclays, Experian, Lloyds Banking Group and UBS. Both sides of the conversation are instrumenting. Annual attestation looks increasingly like an artefact of a slower era.

Finally, the perimeter follows the agent. Research commissioned for the Mills Review, conducted by Yonder in April 2026 across more than 5,000 UK consumers, found that 20 per cent, equivalent to around 11 million adults, would be likely to use AI capable of acting autonomously within pre-set goals. When a consumer's agent transacts with a firm's agent, somebody is going to have to be the regulated party, and the Review's first recommendation is to secure and adapt the regulatory perimeter. That work has started.

None of this is exotic. Build a model inventory with honest materiality tiering. Establish lineage for the data feeding your material decisions before someone asks for it. Put one accountable name against each system, and make sure that person can actually answer. Know what happens if one of the four designated providers has a bad week. Keep the evidence as you go, because reconstructing it afterwards is where the cost lives.

Firms have spent three years asking what the AI rules will be. The rules were already there. What changed in 2026 is that the regulators stopped asking whether you have a framework and started asking you to prove it. The question is no longer whether you can explain your models to your board. It is whether you can prove your data to a supervisor. When they ask, what will you hand them?

All posts