The FCA's review is not a warning. It is a signal that the regulatory perimeter around AI-delivered financial advice is closing, and mid-market UK firms using chatbots without proper oversight are running a compliance clock they may not have noticed started. The headline is stark: 40% of Britons now use AI for financial guidance, yet most of these tools operate in a zone of regulatory ambiguity that the FCA has now explicitly flagged as unacceptable. The regulator is not proposing these powers as a nice-to-have. It is preparing to make them mandatory, and firms that have deployed generic large language models like ChatGPT or Microsoft Copilot for client advice without documented governance, human review workflows, or audit trails should understand that the grace period is closing.
This story is part of a much larger pattern: the shift from experimental AI pilots to regulated AI infrastructure. We have seen this cycle before with GDPR, with Consumer Duty (PS22/9), with SRA guidance on technology-enabled legal practice. Regulators always allow early adoption to happen loosely, then they tighten. The EU AI Act's definition of high-risk AI systems already includes financial advice systems; the FCA's announcement confirms the UK is following the same logic, not diverging from it. Firms that treat AI as a cost-cutting experiment rather than a material control are making a strategic error. The regulator wants visibility into model selection, training data provenance, decision logic, escalation protocols, and human oversight. That is not coming from a fear of AI. It is coming from enforcement data: they have already seen harm.
Here is what Trovix believes: generic chatbots should never be your client-facing financial or legal advice system, full stop. They hallucinate. They drift. They have no audit trail. They cannot be held accountable under FCA rules or SRA codes. If you want AI in advisory workflows, it should be purpose-built, retrieval-augmented (not freely generative), grounded in your own verified knowledge base, and embedded in a human decision-making process. Trovix Aria works this way: it augments fee-earners with instant access to your verified guidance and precedents, but it does not replace them. The output is attribution-ready and auditable. Compare that to Harvey or other legal-specific LLMs that generate novel text and assume the human will catch errors. They won't always. Or to Luminance, which offers document intelligence but still requires you to define how that intelligence gets used in advice workflows. We think the missing piece is human-in-the-loop advice augmentation, not autonomous AI advice generation.
What should you do Monday morning? Audit your current AI deployments. If you have a chatbot delivering advice—financial, legal, or tax—document exactly how it works, who trained it, what data it was trained on, where it gets its answers from, and most critically, who is accountable if it is wrong. If you cannot answer those questions clearly, remove it or rebuild it. Second, start planning for Trovix Watch to monitor FCA, SRA, ICO, and PRA guidance as these rules crystallise over the next 12 months. Third, if you want to keep AI in your advisory workflows (and you should—it improves speed and consistency), evaluate tools that work within a human-verified knowledge model, not tools that generate freely and rely on human review to catch errors. The firms that move first will not be penalised for this transition. The firms that move last will be building compliance into a legacy system, and that costs three times as much.
Source: City AM