Friendly AI robots collaborate in a modern financial technology room with glowing dashboards, citrus-yellow accents, and lemon-inspired details, illustrating FCA guidance on AI for UK financial firms.
What Is FCA Guidance on AI for UK Financial Firms?
Lem, AI blog Writer Last Updated: July 29, 2026 17 min read 2 views

FCA AI Guidance: How UK Financial Firms Can Use AI Responsibly

Quick Answer

FCA guidance on AI for UK financial firms starts with existing rules, not a separate AI rulebook. Therefore, firms must apply Consumer Duty, governance, accountability, record-keeping, and supplier oversight to AI use. The FCA focuses on customer outcomes and controls, rather than the label on a tool. Consequently, firms should treat AI adoption as a regulated business change from day one.

What This Guide Covers

  • What the FCA has said about AI regulation in UK financial services.
  • How technology-neutral, outcomes-based regulation works in practice.
  • Who owns accountability when an AI-supported process fails.
  • Which governance, record, review, and supplier controls matter most.
  • How smaller firms can take proportionate action now.
  • Where LaunchLemonade can support controlled AI work without replacing firm accountability.

What Does FCA Guidance on AI for UK Financial Firms Mean?

FCA guidance on AI for UK financial firms means existing regulation still applies when AI supports, informs, or automates work. Therefore, a firm should not wait for a new AI handbook before it sets controls.

The FCA has taken a technology-neutral approach. In simple terms, it judges the customer and market outcome, not whether a human, spreadsheet, workflow, or language model created it. Consequently, the same core expectations apply when AI is involved.

The FCA Does Not Plan a Separate AI Rulebook

The FCA has said it does not plan to add a separate set of AI-specific rules. Instead, it expects firms to use existing frameworks to manage AI-related risk.

That position matters because it removes a common reason for delay. A firm cannot reasonably say it is waiting for an AI compliance deadline. Existing obligations already apply, and they apply whenever the AI use affects a regulated activity, a customer, or the firm’s operations.

Existing Rules Provide the Starting Point

For most firms, the key rules and expectations will include:

  • The Consumer Duty, particularly customer understanding, products and services, price and value, and consumer support.
  • The Principles for Businesses, including integrity, skill, care, diligence, and customer interests.
  • SYSC requirements for sound systems, controls, governance, and risk management.
  • SM&CR duties that assign clear senior responsibility.
  • Record-keeping, data protection, outsourcing, and operational resilience requirements.

However, not every rule will apply to every AI use case. A meeting-note assistant presents different risks from an AI tool that drafts client communications or supports investment decisions.

Suggested Visual: A simple flowchart showing AI use cases feeding into existing FCA obligations, including Consumer Duty, SYSC, SM&CR, records, and supplier oversight.

Technology-Neutral Does Not Mean Risk-Neutral

Technology-neutral regulation gives firms room to choose suitable tools and controls. However, it does not lower the required standard of care.

For example, a misleading client email remains misleading if AI drafted it. Similarly, an unsuitable recommendation remains unsuitable if a model suggested it. Therefore, firms need to assess the effect of an output, not merely the technical quality of the AI.

AI Risk Depends on Context

A low-risk internal use might include summarising a public document or drafting an internal agenda. By contrast, a higher-risk use could influence customer understanding, financial promotions, suitability, affordability, complaints, or fraud controls.

AI Use Case Typical Risk Level Main Control Need Example Review
Internal meeting summary Lower Data handling and accuracy checks Team member checks summary
Drafting public marketing copy Medium Financial promotion review Approved reviewer signs off
Client email drafting Medium to high Privacy, accuracy, and tone controls Adviser reviews before sending
Suitability or investment support High Human judgment, testing, records, and governance Qualified person reviews every material output
Automated customer decision High Fairness, explainability, monitoring, and escalation Ongoing control testing

Which Existing FCA Rules Apply to AI Use?

UK financial services AI compliance relies on the same rules that govern other business processes. Therefore, the right question is not “Is this an AI issue?” but “Which existing duty could this AI use affect?”

Consumer Duty Applies to AI-Supported Customer Outcomes

The Consumer Duty requires firms to act in good faith, avoid foreseeable harm, and help retail customers pursue their financial objectives. Consequently, a firm must assess whether its AI use could confuse customers, create unfair outcomes, or reduce support quality.

An AI assistant can speed up customer service. However, speed has little value if the answer is wrong, unclear, or unsuitable for a customer’s circumstances. Firms should also consider whether an automated process makes it harder for vulnerable customers to get help.

Governance Rules Apply to AI Projects

SYSC expects firms to maintain adequate systems and controls. Therefore, a material AI project should follow a documented approval path, with risk assessment, named owners, control testing, and periodic review.

This does not require every firm to create a large AI committee. Instead, the process should match the firm’s size, risk profile, and use case. A small advice firm may use a concise assessment and partner review. A large bank may need formal model governance and specialist oversight.

Record-Keeping Remains Essential

A firm needs evidence of what it approved and why. Moreover, it should be able to show how people reviewed important AI-supported work.

Useful evidence can include:

  • The intended use of the tool.
  • The data types users may enter.
  • The named business owner.
  • The initial risk assessment.
  • Supplier due diligence.
  • Test outputs and known limitations.
  • Human review steps.
  • User guidance and training records.
  • Changes, incidents, and remediation actions.

A future reviewer should understand the decision path. “The AI produced it” is not a useful explanation on its own.

Financial Promotions Need Particular Care

Financial promotions must be clear, fair, and not misleading. Therefore, firms should not publish AI-generated content without the same approval process used for human-written communications.

This includes posts, emails, web copy, customer messages, presentations, and scripts. AI can help produce a first draft. However, it cannot replace accountable sign-off.

Suggested Visual: A two-column checklist showing “AI drafts content” and “A qualified reviewer confirms compliance before publication.”

Who Is Accountable When AI Gets It Wrong?

A relevant senior manager remains accountable when AI contributes to a failure. Therefore, outsourcing a tool or buying a model does not transfer regulatory responsibility away from the firm.

The FCA considered whether AI needed a dedicated senior management function. It did not create one. Instead, responsibility sits with the senior manager who owns the affected business area.

SM&CR Still Sets the Ownership Model

The Senior Managers and Certification Regime requires clear accountability. Consequently, each material AI use should have an owner within the relevant part of the business.

For example, an AI tool supporting customer service may sit with the senior manager responsible for operations. An AI tool used in advice processes may sit with the person responsible for advice governance. The right owner depends on the activity and its risk.

Vendors Do Not Carry Your FCA Responsibility

A supplier can provide terms, support, security information, and technical safeguards. However, the supplier cannot take the regulated firm’s responsibility for customer outcomes.

Contracts can allocate commercial loss. They cannot remove the firm’s duty to supervise the service, assess its risks, or respond when it fails. Therefore, supplier oversight must continue after procurement.

Accountability Must Be Clear Before Launch

FCA guidance on AI for UK financial firms requires clear ownership before a system reaches live use. A practical ownership record should answer four questions:

Governance Question What the Firm Should Record
Who owns the use case? The relevant senior manager and operational lead
What can the AI do? Clear scope, users, tasks, and excluded activities
What can go wrong? Customer, conduct, data, operational, and supplier risks
Who checks it? Reviewer role, escalation path, and review frequency

Human Review Must Have Real Authority

Human review is useful only when the reviewer can challenge the result. Therefore, firms should avoid a process where staff simply approve AI output because it looks polished.

Reviewers need enough context, training, time, and authority to correct or reject a result. They should also know when to escalate uncertainty. A control that exists only on paper will not protect customers.

How Should Firms Build Regulated AI Governance?

Regulated AI governance for UK firms starts with visibility. Therefore, firms should first find every place AI is already being used, including unofficial tools and personal subscriptions.

This work often reveals a gap between policy and practice. Staff may use AI to summarise notes, draft emails, analyse spreadsheets, or research topics. The goal is not to punish honest disclosure. Instead, the goal is to make safe use easier than unapproved use.

Start With an AI Use Register

An AI use register is a simple list of tools, use cases, owners, data types, risks, and controls. Consequently, it gives a firm a practical baseline for oversight.

The register should include both approved and proposed use. It should also flag any tool that handles client information, influences a customer outcome, or supports a regulated process.

Assess Data Before It Enters a Tool

Data protection should shape the design of AI workflows from the start. Therefore, firms need to know whether users might enter personal data, special category data, commercially sensitive material, or confidential client records.

A consumer AI tool may not be suitable for protected client information. The firm must check privacy settings, supplier terms, retention arrangements, user permissions, and its own data policies. In addition, staff need clear guidance on what they must never paste into an unapproved tool.

Build Controls Around the Risk

The control should match the risk. For instance, an internal writing assistant may need clear usage rules and occasional checks. A tool that helps prepare advice content needs stronger review, evidence, testing, and escalation.

Control Area Lower-Risk Internal Use Higher-Risk Customer or Advice Use
Approval Team lead approval Formal business and compliance approval
Data No confidential data Strict data permissions and documented safeguards
Review Spot checks Mandatory human review before use
Testing Basic quality checks Scenario testing, bias checks, and ongoing monitoring
Records Tool and policy record Full decision, output, review, and change trail
Escalation Informal correction route Defined incident and customer remediation process

Review Controls When the Use Changes

AI tools change quickly. Likewise, a small pilot can become an important business process faster than expected.

Review the governance record when:

  • A new model or supplier is introduced.
  • The tool receives a new data source.
  • Users expand into a new team.
  • The output becomes customer-facing.
  • The use case starts influencing decisions.
  • An error, complaint, or security issue occurs.

Regular reviews help firms spot “scope creep”, where a useful internal tool quietly becomes a higher-risk service.

What Should Small Financial Firms Do First?

Small firms should take proportionate action now, rather than wait for perfect guidance. Therefore, start with a short register, one accountable owner, clear data rules, and human checks for customer-facing output.

You do not need a six-month transformation programme to make progress. However, you do need evidence that the firm understands where AI is used and how risks are controlled.

Create a Short, Honest Inventory

Ask staff which AI tools they use at work. Then ask what tasks they use them for, what information they enter, and whether the output affects clients.

Make the request practical and non-judgmental. Otherwise, people may hide use that the firm needs to manage. An honest inventory is more valuable than a polished policy that nobody follows.

Set Red Lines for Data and Decisions

Your first guidance should be simple enough for people to remember. For example, prohibit staff from entering client-identifiable information into unapproved tools. Similarly, require human review before AI-generated work reaches a client or supports a regulated decision.

A short set of red lines can stop the most obvious errors. Later, the firm can add more detailed controls as its AI use grows.

Use a Governed Workspace Where It Helps

A controlled AI workspace can make good practice easier to follow. For example, LaunchLemonade lets non-technical teams create assistants by describing what they need in plain English. It also supports multi-step workflows for work that needs more than one action.

Moreover, teams can upload internal knowledge sources, including PDF, Word, Excel, PowerPoint, TXT, Markdown, CSV, HTML, and EPUB files. The platform processes and indexes those documents so an assistant can retrieve relevant material during a conversation.

That approach can help a firm create an internal policy assistant, a compliance research helper, or a document review workflow. However, the firm must still define permitted use, reviewers, data handling rules, and ownership.

If your team wants to assess a controlled rollout, you can book an AI governance discussion. Alternatively, explore how AI tools can support teams or how non-technical staff can build practical AI assistants.

Train People to Challenge AI Output

Training should explain that AI can be useful and wrong at the same time. Therefore, staff need to verify facts, use approved sources, protect data, and escalate uncertain results.

The strongest message is simple: AI may help with a task, but a person remains responsible for the work they submit, publish, or send.

Suggested Visual: A one-page “Small Firm AI Starter Plan” with six boxes: inventory, owner, risk check, data rules, review point, and regular review.

What Should Firms Monitor During 2026?

Firms should monitor FCA AI developments, Bank of England and FCA survey findings, and the use cases emerging from the FCA’s AI Lab. Consequently, they can update controls based on real regulatory focus rather than speculation.

The key is to monitor with purpose. A firm does not need to chase every AI announcement. Instead, it should watch developments that could affect its customer outcomes, controls, suppliers, and business model.

Follow the FCA’s Core AI Position

The FCA’s “AI and the FCA: our approach” page brings together its position on existing regulation and AI. Therefore, it is a useful starting point for regular review.

Check whether the regulator has added examples, supervisory observations, consultation material, or new expectations. Keep a brief record of the review and any action taken.

Watch the Mills Review

The FCA Board commissioned the Mills Review to consider AI and retail financial services. As of July 2026, firms should monitor its published outcomes and the FCA’s response.

Its findings may shape later policy priorities. However, firms should not postpone basic governance while they wait.

Learn From AI Lab Use Cases

The FCA’s AI Lab, including its Supercharged Sandbox and AI Live Testing work, gives useful signals about the issues firms are testing with regulatory engagement. These areas include subjects such as financial crime, customer support, and investment-related decision support.

Smaller firms may never join a cohort. Nevertheless, the published themes can help them see where regulatory interest is developing.

Track Your Own Evidence

External news matters, but your own evidence matters more. Therefore, track internal errors, user feedback, rejected outputs, incidents, customer complaints, control gaps, and supplier changes.

Monitoring Area Review Question Suggested Frequency
AI use register Are there new tools, users, or use cases? Monthly
Customer-facing outputs Are reviewers finding repeat errors or unclear content? Monthly
Supplier position Have terms, models, data handling, or security changed? Quarterly
Training Do staff understand approved use and escalation routes? Quarterly
Governance assessment Does the risk level still match the controls? At least annually, and after material change

How Can Firms Apply FCA AI Guidance Step by Step?

The most effective approach is to use existing governance processes and adapt them for AI. Therefore, begin with a narrow, visible use case and improve your controls as evidence grows.

Step One: List Current AI Use

Create an initial inventory of every AI tool, including free tools, trials, embedded software features, and third-party services. Next, identify the business purpose, users, data, and customer impact.

Do not aim for perfect detail on day one. Instead, make the list complete enough to reveal where risk sits.

Step Two: Assign a Named Owner

Give each material use case a business owner and an accountable senior manager. Then document who approves changes, who reviews outputs, and who receives incident reports.

Clear ownership prevents the common problem of everyone assuming someone else manages the risk.

Step Three: Assess Customer and Data Risk

Consider foreseeable customer harm, misleading output, unfair treatment, poor support, confidentiality, privacy, and operational failure. Then decide which controls are needed before use begins.

Where uncertainty is high, reduce the scope. A limited internal pilot is often safer than immediate customer-facing automation.

Step Four: Build Review and Escalation Points

Set mandatory human review for customer-facing content, regulated decisions, and high-impact use cases. In addition, define what staff should do when output is uncertain, incorrect, biased, or outside the approved scope.

Keep the process easy to follow. Complex controls that people bypass do not reduce risk.

Step Five: Record, Test, and Improve

Keep evidence of approval, testing, staff guidance, output reviews, incidents, and changes. Finally, revisit the use case when the technology, supplier, data, or customer impact changes.

Good governance is not a one-time assessment. It is a repeatable operating habit.

Key Takeaways

FCA guidance on AI for UK financial firms is clear in its direction. Existing rules apply, and accountability stays with the firm.

Existing Rules Still Govern AI

Consumer Duty, SM&CR, SYSC, records, supplier oversight, and data protection do not pause when AI enters a workflow.

Customer Outcomes Matter Most

The FCA’s approach focuses on whether customers receive fair, clear, suitable, and properly supported outcomes.

Senior Accountability Cannot Be Outsourced

A vendor can supply technology. However, the regulated firm and its senior managers remain responsible for its use.

Start Small, But Start With Controls

First, find AI use. Next, appoint owners, protect data, set review points, and keep evidence. Then improve the process as your use cases mature.

What Should Your Firm Do Next?

FCA guidance on AI for UK financial firms is not a separate rulebook. Instead, it is a call to apply familiar regulatory standards to new forms of work.

Start by making AI use visible across the firm. Then match controls to the risk, protect client data, assign ownership, and require meaningful human review. Finally, keep evidence that the controls work in practice.

LaunchLemonade can support this work by helping teams build no-code assistants and workflows around approved internal knowledge. Its document retrieval approach can ground assistant responses in the materials your team has uploaded. However, no software creates compliance by itself. Sound governance, accountable people, and consistent review remain essential.

Frequently Asked Questions

Does the FCA Have a Separate AI Rulebook?

No. The FCA’s stated approach is to apply existing rules to AI use. Therefore, firms should map AI risks to the rules they already follow.

Who Is Accountable When an AI System Gets Something Wrong?

A relevant senior manager remains accountable under the SM&CR. Therefore, a vendor or model provider cannot take the firm’s regulatory responsibility.

Do Small Financial Firms Need AI Governance?

Yes. Controls should be proportionate, but small firms still need ownership, review points, records, and safe data handling.

Must a Firm Tell the FCA That It Uses AI?

There is no general AI notification rule. However, firms must still meet existing communication, governance, reporting, and record-keeping duties.

Can a Financial Firm Use a Public AI Tool With Client Data?

Not without careful controls. Firms should assess data protection, confidentiality, permissions, retention, and supplier terms before sharing client information.

What Is the First AI Compliance Step for a UK Firm?

First, create an AI use register. It gives the firm visibility over tools, owners, data, customer impact, and review needs.

✨ Built for the way you work

Your back office, on autopilot.

Build and deploy custom AI assistants for your team or clients — no code required. Save hours each week by letting AI handle the routine so you can focus on growing your business.

💡 Try it free ⚡ Get started in 2 minutes