FCA's Mills Review: ChatGPT Regulation Ahead
UK regulator proposes AI oversight in finance
Model Diplomat8 min readEurope

The FCA's Mills Review makes ChatGPT a UK regulatory problem
The UK's Financial Conduct Authority just proposed pulling general-purpose AI models into the financial services perimeter — a quiet break with London's principles-only orthodoxy.
The Financial Conduct Authority's Mills Review, published on July 6, 2026, does something the UK regulator spent the previous 18 months insisting it would not do: it lays the groundwork to pull OpenAI's ChatGPT, Anthropic's Claude, and Google's Gemini into a financial services perimeter designed for banks. That is the story buried inside seven anodyne recommendations — an outcomes-based regulator, cornered by 26% of UK adults now taking financial advice from chatbots, quietly proposing the largest expansion of its supervisory scope since crypto. Consumers, cloud vendors, and large advice platforms benefit. UK mid-tier advisers and the government's own "no new rules" AI orthodoxy do not.
What Sheldon Mills actually recommended
The review, led by FCA executive director Sheldon Mills and commissioned in January 2026, drew on nearly 140 written submissions and a survey of more than 5,000 UK consumers, according to industry trade Portfolio Adviser. Its four-part forecast for retail finance by 2030 — firm transformation, new consumer journeys, reshaped competition, amplified financial crime, and cyber risk — is unremarkable. The seven priority recommendations are not.
Read against the FCA's own January launch document, which stated flatly that "the FCA does not plan to introduce AI-specific regulation," the July output is a pivot. Mills recommends that the FCA "monitor autonomous AI transitions," "adapt regulatory perimeters," strengthen system-wide oversight, scale the AI Lab into agentic-finance testing, build an "AI-enabled agentic supervisory model," and stand up a public-interest AI financial-capability service, according to the summary carried by
JURIST. "Adapt regulatory perimeters" is the phrase that matters. In FCA vocabulary, the perimeter is the statutory line between activities that need authorisation and everything else — the same instrument used to sweep in cryptoassets, buy-now-pay-later, and ESG ratings, as catalogued in the
March 2025 perimeter meeting record between HM Treasury and Nikhil Rathi.
Mills himself was blunt with the Financial Times that regulators face an "arms race" to keep pace with AI use in consumer finance and explicitly urged UK authorities to review whether large language models such as ChatGPT should sit inside financial regulation. The trade press caught the signal:
Credit Connect framed the report as a call for "tighter oversight" and expanded scope, and
Beinsure led on the LLM question directly.
Why this is a policy break, not a continuation
Six months ago, the official line from Rathi, in his February 2026 performance meeting with Economic Secretary Lucy Rigby, was that "industry was not currently in favour of extensive new regulatory guidance." That aligned with the Treasury Select Committee's
January 2026 report on AI in financial services, in which FCA officials told MPs the Senior Managers regime and Consumer Duty gave the regulator "enough regulatory bite that we don't need to write new rules for AI." The Bank of England's
February 2026 AI roundtables with regulated firms reached the same conclusion — most participants "did not see the need yet for detailed AI-specific regulatory guidance or rules."
The Mills Review does not tear that framework up. It does something subtler: it tees up the primary legislation and Treasury-level perimeter changes that would let the FCA act on chatbots as regulated advice providers if generative models move — as adoption trends suggest they will — from casual consumer curiosity to material investment decisions. The Bank of England's own Financial Stability in Focus, reaffirmed in the FPC's April 2026 Record, has flagged four AI risk vectors including "greater use of AI in banks' and insurers' core financial decision-making" and "the changing external cyber threat environment," giving Mills institutional cover.
The context that makes this politically viable arrived on May 15, 2026, when the Bank of England, FCA, and HM Treasury issued a rare tri-authority joint statement on Frontier AI models and cyber resilience, warning that frontier models "represent a step-change in capability, with significant implications for cyber security and operational resilience." Once the state has said frontier AI is a systemic risk vector, the argument that consumer-facing LLMs delivering de facto financial advice should remain unregulated becomes harder to defend in front of the Treasury Committee.
The seven recommendations, decoded
The recommendations that will echo longest are not the headline-friendly ones. Numbers three, four, and five — system-wide coordination, scaling the AI Lab, and the "AI-enabled agentic supervisory model" — commit the FCA to a technology-intensive supervision programme that will require serious hiring and infrastructure. The AI Lab, launched in 2024 with an NVIDIA-backed "Supercharged Sandbox," is detailed in the FCA's Secondary International Competitiveness and Growth Objective report. Scaling it up so the regulator can supervise agentic AI at machine speed is a live admission that human-in-the-loop supervision is failing.
The February 2026 minutes of the Bank of England's AI Consortium put the problem crisply: "maintaining a 'human in the loop' may become increasingly strained as firms adopt agentic AI and move from back office to market-facing applications." Consortium members warned that agentic AI "may compress decision-making latency in ways that challenge traditional escalation and oversight mechanisms such as kill switches and circuit breakers." A regulator supervising at human speed cannot police markets running at model speed. Mills's recommendation five concedes the point.
Recommendation six — the "public-interest AI-enabled financial capability service" — is where the review makes its most interventionist move. The proposition is a state-endorsed alternative to ChatGPT for financial guidance. It follows directly on the FCA's April 2026 launch of targeted support, reported by the BBC, under which banks can make investment recommendations to groups of customers with similar characteristics. Deputy chief executive Sarah Pritchard called that regime "game-changing." Together they represent the FCA's answer to the advice gap: allow firms and, eventually, a public utility to do what only expensive human advisers used to do, while corralling ChatGPT out of the space where it can hurt consumers.
Who wins, who loses
The biggest short-term winners are the frontier model providers themselves. If the FCA follows the perimeter path, OpenAI, Anthropic, and Google DeepMind will face regulatory scrutiny in the UK — but scrutiny is legibility, and legibility is a moat against smaller entrants who cannot afford compliance. Second-tier winners are the largest UK banks and platforms already investing heavily in AI: Santander's people-trafficking detection model, Lloyds's agentic assistant, and JPMorgan's Moneyball tool, all documented by the Financial Times, all benefit from a regime that regulates outputs rather than architectures.
The losers are more instructive. The UK's mid-tier IFA sector — the roughly 5,000 firms whose value proposition rests on personalised human advice — now faces a regulated ChatGPT alternative and a public-interest capability service both aimed at the same underserved consumers. St James's Place chief executive Mark FitzPatrick told the Financial Times his firm's 5,000 advisers were poised to benefit from a "massive retirement wave"; the Mills recommendations quietly accelerate the demand-side attrition too.
The other loser is the Kyle-era orthodoxy that the UK's competitive advantage lies in doing less than Brussels. The EU AI Act, whose main general-purpose AI obligations take effect on August 2, 2026, was until recently the UK's negative template — comprehensive, prescriptive, extraterritorial. The Mills Review moves the UK closer to a sector-specific version of the same logic: a de facto AI-in-finance regime enforced through the FCA perimeter rather than a horizontal law. That is a smaller policy footprint than Brussels but a larger one than Washington, where the
Brookings comparative analysis notes regulators still rely on principles-based enforcement of pre-existing rules. London is inching toward the middle ground.
The historical parallel
The closest analogue is the FCA's 2019–2023 cryptoasset trajectory. Britain began with a light-touch regime, moved to mandatory financial promotions rules in June 2023, and — as the perimeter meetings record shows — has been progressively expanding scope ever since, most recently with the
draft cryptoassets statutory instrument covering stablecoin payments. Each step was framed as narrow. Together they moved crypto from unregulated to fully perimetered in under five years. Mills's recommendations mark the equivalent starting gun for consumer-facing generative AI.
The other precedent is the Rachel Kent Investment Research Review, whose outcome report in July 2023 produced a set of recommendations that industry initially received as modest and that HM Treasury then converted into substantive regulatory reform. The pattern — commission an independent review, absorb the recommendations, legislate — is now the standard UK route to change without primary consultation. Mills fits the mould.
What to watch next
- Late 2026: the FCA's promised "good and poor practice" publication on AI, according to
JURIST — the near-term deliverable and the first indication of how prescriptive the regulator will be.
- August 2, 2026: the EU AI Act's general-purpose AI obligations take effect, per
Brookings. UK firms selling into the EU face the compliance test first; FCA-only firms watch to see whether Whitehall follows.
- Autumn 2026 Treasury response: whether HM Treasury commits to legislative changes to the FCA perimeter for AI-mediated advice. The
FCA response to the Treasury Committee already promised comprehensive AI guidance by end-2026.
- Bank/FCA fourth biennial AI Survey: results expected late 2026, the primary quantitative evidence base the FPC will use to escalate or de-escalate its AI risk framing.
- Frontier AI Bill: the Kyle bill giving the AI Safety Institute statutory powers, first reported by
RAND. If it lands in the King's Speech, the Mills perimeter recommendations become far easier to legislate as a package.
Diplomat View
The Mills Review is the moment the UK stopped pretending that "principles-based, outcomes-focused" regulation could survive contact with agentic AI. The FCA has quietly conceded four things: that 26% consumer trust in general-purpose LLMs for financial advice is a market failure, not a curiosity; that human-in-the-loop supervision cannot police agentic systems; that the perimeter is the instrument of choice; and that a state-backed AI advice utility is politically preferable to leaving the field to ChatGPT. Our forecast: by end-2027, HM Treasury will consult on bringing at least some AI-mediated personal recommendations inside the FCA perimeter, and the FCA's own supervisory agents will be operating in production. What would change that forecast: a Conservative-led government reversal of the AI Growth Lab agenda, a serious LLM-driven mis-selling scandal that forces emergency primary legislation, or a Trump-administration deregulatory push that makes the UK regulatory-arbitrage case irresistible to a Rachel Reeves Treasury. None of those look likelier than the perimeter path.
The Bottom Line
The Mills Review is not a discussion paper — it is the FCA's licence application to regulate ChatGPT as a financial services actor. The recommendations look modest because the regulator learned from crypto that ambition should be sequenced, not signalled. Anyone reading it as a continuation of the UK's light-touch AI stance is reading the wrong document.
Discover more

India
Congress Accuses Modi of Stalling Women's Law
Congress accuses Modi of stalling women's reservation law by linking it to delimitation, revealing a deeper electoral strategy.

US Politics
SNAP Food Assistance Faces Legal Challenges
In 2026, SNAP faces stricter eligibility rules and mounting legal challenges, threatening food assistance for the millions of Americans who rely on the program.

India
Delhi CM Rekha Gupta Blasts Opposition's Delm
Delhi CM Rekha Gupta's remarks on women's quota defeat reveal BJP's strategy for the 2029 Lok Sabha elections, focusing on delimitation.

Conflict & Security
West Africa Food Crisis: Three Shocks in 2026
Conflict, climate extremes, and the Strait of Hormuz closure drive a severe food crisis in West and Central Africa, with fertilizer prices surging 80% and millions displaced.