The FCA and Consumer Duty
The Financial Conduct Authority's Consumer Duty, which came into force for open products and services in July 2023 and reached full force, including closed products, from July 2024, is the most consequential AI governance development for UK financial services firms in recent years. Its four outcome requirements, products and services, price and value, consumer understanding, and consumer support, create a framework that reaches AI systems across the customer lifecycle without explicitly naming AI. An AI pricing system that charges loyal customers significantly more than new customers may fail the price and value outcome. An AI communication system generating product information that customers cannot understand may fail the consumer understanding outcome. An AI-driven customer service system that fails to provide accessible support to vulnerable customers may fail the consumer support outcome.
The FCA has been explicit that Consumer Duty applies to AI. Its supervisory expectations include that firms understand how their AI systems affect customer outcomes, monitor those outcomes regularly, and take action when outcomes are poor. The Duty's proportionality principle, that firms must take reasonable steps relative to their size and resources, means that smaller firms have some flexibility in implementation, but not in the obligation to understand and manage AI's impact on customer outcomes. In June 2026 the FCA opened CP26/23, a consultation on Consumer Duty scope and proportionality, proposing to remove non-UK business from the Duty's scope and to clarify how it applies in wholesale markets and distribution chains. The consultation remains open for comment until 18 September 2026, with the FCA expecting to finalise new rules in the first quarter of 2027, so firms should watch for changes to how proportionately the Duty applies to them.
PRA model risk management: SS1/23
The Prudential Regulation Authority's Supervisory Statement SS1/23 on model risk management applies to UK-incorporated banks, building societies, and PRA-designated investment firms with internal model approval for regulatory capital (it does not apply to insurers). The statement explicitly addresses AI and machine learning models and establishes that the core model risk management requirements, model definition, ownership, validation, use, and control, apply to AI models as they do to traditional statistical models, with appropriate adaptations for AI-specific characteristics.
The key SS1/23 requirements for AI: firms must maintain a model inventory that includes AI systems used in material decisions. Models must be developed with appropriate documentation. Independent validation must be conducted before deployment and after significant changes. Performance must be monitored in production. Model risk must be reflected in the firm's risk appetite framework. And there must be clear accountability, a named model owner, for each material model. The challenge of applying SS1/23 to AI models is the explainability gap: traditional validation methodology assumes models that can be fully understood and mathematically validated. AI models cannot always be validated in this way, and the PRA expects firms to adapt their validation methodology accordingly, documenting the limitations and uncertainty in AI model validation and applying additional safeguards where validation methodology is constrained. The PRA has continued to engage industry on these questions, including through roundtables on model risk management for AI and machine learning technologies on 20 and 22 October 2025 (the PRA published the presentation slides it used, setting out its own thinking, rather than a readout of what firms said), and it finalised LIAF01/26 in April 2026, amending SS3/18 to align stress-testing model risk self-assessment with SS1/23's principles.
Bank of England: financial stability and AI
The Bank of England's focus on AI is primarily through its financial stability mandate, the risk that widespread AI adoption in financial services creates correlated behaviours that amplify systemic risk. If many financial institutions use similar AI models for trading, credit, or risk management decisions, those models may respond similarly to market events, amplifying volatility rather than diversifying it. The Bank's supervision of this risk manifests through its stress testing programmes, where its April 2025 Financial Stability in Focus report lists future operational resilience stress testing focused on AI-enabled threats, and potential future system-wide exercises exploring AI-related risks, among the tools it may add rather than ones already in use, its oversight of financial market infrastructure, and its participation in international AI governance discussions through the FSB and BIS. Domestically, the Bank and the FCA co-chair the Artificial Intelligence Consortium, launched in May 2025 as a standing forum for public-private dialogue on AI capabilities, risks, and safe adoption in UK financial services.
Related reading
- AI in UK Insurance: FCA Consumer Duty, PRA Expectations, and What Insurers Must Do Now
- FCA Consumer Duty and AI: What UK Financial Services Firms Must Do Now
- AI Governance for UK Small Businesses: What the ICO, ACAS, and UK GDPR Actually Require
- UK AI Governance: The Pro-Innovation Approach, ICO Guidance, FCA Expectations, and What It Means Post-Brexit
Further reading: ICO AI guidance