The FCA's Mills Review reveals that regulators will now supervise AI systems as rigorously as they supervise humans. Firms deploying AI without governance architecture in place are building on sand.
AI Governance  Trovix ReachLegal · Financial Services · Insurance · Accountancy

The FCA's Mills Review, published in July 2026, crystallises a regulatory reality that many UK firms have sidestepped: the agency will soon supervise AI systems as rigorously as it supervises humans. The review recommends seven regulatory evolutions, including an 'AI-enabled agentic supervisory model' that will examine governance, accountability and consumer outcomes at scale. For mid-market law firms, insurers, financial services providers and accountancy practices, this is not a future scenario — it is the baseline assumption for 2027 onwards. The review identifies four systemic shifts driven by AI: how firms operate internally, how consumers experience services, how markets compete, and how fraud risk evolves. Each shift creates supervisory exposure for firms that have bolted AI onto existing processes without rebuilding the governance architecture underneath.

This story is part of a broader pattern across UK regulation. The FCA is not alone. The ICO's recent guidance on GDPR and generative AI, the SRA's emerging position on AI use in legal services, and the FRC's ISA UK auditing standards have all signalled the same message: regulators will hold firms accountable for what their AI systems do, not just what their humans do. The EU AI Act's influence is also visible in the Mills Review's emphasis on risk tiering and human oversight. Unlike previous regulatory cycles, which moved slowly and required lengthy industry consultation, this one is accelerating. Firms that wait for prescriptive rules will find themselves in breach of principles that are already embedded in Consumer Duty PS22/9 and PRA SS1/23. The window for voluntary compliance is closing.

Here is what we believe: AI governance must precede AI deployment, not follow it. Too many firms are using tools like Microsoft Copilot, Luminance or Harvey as if they were plug-and-play productivity boosters, with accountability retrofitted afterwards. This approach will fail under the FCA's new supervisory model. The Mills Review makes clear that firms must demonstrate documented decision-making about why an AI system was chosen, how it was validated, who owns its outputs, and how consumer detriment is prevented. This requires three things: a continuous audit trail of AI decisions (not just a glossy dashboard), explicit traceability of accountability between the system, the user and the firm, and proactive testing of failure modes under stress. Generic AI assistants struggle with this because they were not built for regulated environments. Purpose-built solutions like Trovix Audit create the governance spine first, then layer AI capability on top. This is not semantic difference — it determines whether you pass FCA examination or face enforcement action.

What should a mid-market firm do now? First, conduct an honest audit of every AI system currently in use. Document the business case, the validation process, and the accountability owner. This is not bureaucracy — it is evidence. Second, do not expand AI deployment until governance is in place. This includes client-facing tools like Trovix Reach, which embed transparency and traceability by design. Third, build a cross-functional steering group with compliance, risk, operations and the business. The Mills Review makes clear that AI governance is not a compliance department function — it requires operational ownership. Finally, engage with your regulator early. The FCA is actively inviting dialogue on AI implementation. Firms that wait for enforcement to understand their obligations have already lost.

Source: Deloitte UK

Related Trovix product:

Trovix Reach →Book a demo →