The Mills Review, published by the FCA on 6 July 2026, does something regulators rarely do: it refuses to play catch-up. Instead of asking whether AI will reshape retail financial services, it declares that it already is—and demands that firms demonstrate they understand the four systemic shifts coming by 2030. For mid-market legal, insurance, financial services and accountancy firms, this is not a thought leadership exercise. The Review signals that the FCA's tolerance for 'we're still exploring' has evaporated. Operational resilience under PRA SS1/23, consumer protection under FCA Consumer Duty PS22/9, and AI governance frameworks modelled on ISO 42001 are no longer nice-to-haves. They are preconditions for holding a licence.
What the Mills Review reveals is a fundamental shift in how UK regulators think about AI risk. Three years ago, the conversation centred on model transparency and algorithmic bias. Today it centres on systemic risk: fraud vectors that AI can both create and defend against, the concentration risk of firms all using the same large language models, the opacity of supply chains when you outsource compliance to vendors using OpenAI or Claude, and the consumer protection gap when AI systems make or influence high-stakes financial decisions. The Review signals that the FCA has stopped waiting for the EU AI Act framework and the ICO's UK GDPR guidance to crystallise. It is moving to a regime of firm-by-firm accountability for understanding and mitigating AI deployment risk—not just in the model itself, but across the entire operational stack.
Here is Trovix's view: the firms that survive this transition will not be the ones that deployed the most AI, or the fanciest AI. They will be the ones that built the most rigorous governance frameworks around AI before they deployed it at scale. This is why we have consistently argued against the 'move fast and patch later' approach that has dominated retail financial services AI adoption. Tools like Copilot for Finance or off-the-shelf compliance automation platforms can be deployed quickly, but they create a governance debt that regulators now explicitly expect you to repay. The Mills Review is telling you to pay it now. What this means in practice is: before you roll out AI for customer journey optimisation, fraud detection, or advice automation, you need visibility into what your AI is actually doing, how it is failing, what it is being trained on, and how you would explain it to your compliance team and your regulator. That requires a governance-first approach—the kind we have built into Trovix Audit, which sits between your AI implementation and your control framework, not as an afterthought bolted on top.
What should a mid-market law firm, insurer or financial services practice actually do this week? First: map your current AI usage across intake, underwriting, advice, and operations. Second: identify which of those use cases touch the consumer journey or material fraud risk. Third: build a simple control map that answers the FCA's implicit question: 'If this AI system failed or drifted, how would you know, and what would you do?' For firms using Harvey for legal research, Luminance for document AI, or in-house models for claims automation, this is non-negotiable. The Mills Review has shifted the question from 'Is our AI compliant?' to 'Can we prove our AI is resilient?' Mid-market firms often lack the in-house regulatory firepower of tier-one institutions. Trovix Watch helps plug that gap by monitoring FCA consultation papers and updates in real time, so you are not reactive when the next guidance lands. But the real work is now: get your governance framework locked in before Q4 guidance season begins.
Source: Financial Conduct Authority