5 MCP servers live now What’s live ›
Real Biz Digital logo Real Biz Digital

United Kingdom

AI governance in UK financial services: what the regulators actually require

There is no AI-specific rulebook from the FCA or the PRA, and none is planned. The Bank of England said so plainly in its response to the Treasury Select Committee on AI in financial services on 1 April 2026, while explicitly rejecting a "wait and see" posture. The supervisors consider themselves already equipped, through the Senior Managers and Certification Regime, model risk management, operational resilience and the critical third parties regime — and they will, in their words, "continue to monitor AI adoption closely and will not hesitate to act when justified". The compliance question is therefore not which new rules are coming. It is which existing ones your AI deployment has already engaged without anyone recording that it did.

How Barzel applies here Start free with BarzelVault

Is a UK AI rulebook for financial services coming?

No — and the reasoning matters more than the conclusion. Firms that have deferred AI governance work on the grounds that the regime is unsettled have misread the signal. The Bank did not say it was waiting; it said the opposite. It named four existing frameworks as sufficient, which is a statement that supervisory questions will be asked now, under instruments already in force, rather than after some future consultation closes.

The FCA's contribution has been infrastructure rather than rules: the AI Lab, AI Live Testing and the Supercharged Sandbox, launched in May 2025 alongside FS25/5. These are places to test. They are not a regime. The operative controls remain the Consumer Duty, SM&CR, SYSC and operational resilience — the same set that governed everything else the firm does.

Which deadline is actually live?

This is where a great deal of published material is now wrong. FCA PS21/3 and SYSC 15A, with PRA PS6/21 and SS1/21, required in-scope firms to be able to operate their important business services within impact tolerances by 31 March 2025. That deadline has passed. It is a baseline supervisors assume you meet, not a programme still in flight, and material still describing it as forthcoming is describing a world that ended eighteen months ago.

The live forward deadline is FCA PS26/2, the operational incident and third-party reporting rules, published 18 March 2026 and in force 18 March 2027.

InstrumentDateStatus
FCA PS21/3 / SYSC 15A; PRA PS6/21 / SS1/21 — impact tolerances31 March 2025Passed; now a baseline
FCA PS24/16 / BoE PS16/24 — critical third parties1 January 2025In force
PRA SS1/23 — model risk management, updated version23 April 2026In force
HM Treasury — first CTP designations13 July 2026Effective
FCA PS26/2 — operational incident and third-party reporting18 March 2027Forthcoming

Why do the critical third parties designations matter for AI?

The CTP rules were published on 12 November 2024 in FCA PS24/16 and Bank of England PS16/24 and came into force on 1 January 2025. The mechanism is worth stating precisely, because it is often described the wrong way round: HM Treasury designates; the regulators recommend.

On 10 July 2026, HM Treasury made the first designations, effective 13 July 2026: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd and Oracle Corporation UK Limited.

This is the concrete development most firms have not absorbed, and it bears directly on AI because that is where the models run: almost every material AI deployment in a UK firm sits on at least one of those four providers. Designation does not transfer the firm's responsibility — the outsourcing and third-party risk obligations remain exactly where they were — but the concentration risk in your AI stack is now supervised from both ends.

What does PRA SS1/23 require of an AI model?

For banks, this is the most directly applicable instrument. SS1/23, "Model Risk Management Principles for Banks", was published on 17 May 2023 and took effect on 17 May 2024; an updated version was published and took effect on 23 April 2026. It applies to UK banks, building societies and PRA-designated investment firms with internal model approval. It is technology-agnostic by design, and it expressly covers artificial intelligence and machine learning in modelling.

The consequence is simple and frequently resisted: an AI model is a model. It inherits the entire framework — identification and inclusion in the model inventory, validation before use, independent review with development separated from validation, and ongoing monitoring for drift. Firms that have stood up a separate AI governance committee running in parallel to model risk have usually built a second-best copy of a framework they already had, and created a gap between the two where the interesting failures happen.

How does the UK compare with Switzerland and the United States?

United KingdomSwitzerlandUnited States
AI-specific rule?No, and none plannedNo binding AI regulationNo AI-specific FINRA rule
Operative instrumentSM&CR, SS1/23, operational resilience, CTP regimeFINMA Aufsichtsmitteilung 08/2024 (18 Dec 2024)FINRA Regulatory Notice 24-09 (June 2024)
What it demandsNamed individual accountability; model validation and independent review; impact tolerances; third-party oversightSeven expectation areas: governance; inventory and risk classification; data quality; testing and monitoring; documentation; explainability; independent reviewExisting rules apply to generative AI: Rule 3110 supervision, Rule 2210 communications, Rule 4511 books and records, Reg BI

One point of precision on Switzerland. An Aufsichtsmitteilung is a supervisory communication of FINMA's observations and expectations. It is not a Rundschreiben and not binding regulation, and describing it as a circular overstates it. FINMA's own framing is "same business, same risks, same rules". Its survey of roughly 400 institutions, published 24 April 2025, found that half use AI or have applications in development and a further quarter plan to within three years; 91% of AI users use generative AI, and only about half have a formal AI strategy. Note also what the Risikomonitor 2025 of 17 November 2025 does not say: it names nine principal risks, of which the non-financial ones are money laundering, sanctions, outsourcing, cyberattacks and ICT risks. AI is not listed as a separate principal risk. See the Swiss analysis of Art. 21 DSG and FINMA.

On the US side, FINRA's 2026 Annual Regulatory Oversight Report is the more useful document for anyone deploying agents. It names autonomy without human validation, scope creep beyond intended authority, auditability of multi-step reasoning, sensitive-data disclosure, domain-knowledge gaps and misaligned reward structures; it recommends human-in-the-loop protocols, tracking mechanisms and behavioural guardrails, and states that supervisory systems relying on AI must themselves evaluate "the integrity, reliability and accuracy of the AI model". The US automated decision-making picture runs alongside it.

What does this mean for agentic systems?

Three regulators, three vocabularies, one control. SM&CR means a named individual is accountable for what an automated system did. FINRA's auditability point and FINMA's independent-review expectation both require that a specific past decision can be reconstructed. None of that is satisfied by a policy document; it is satisfied by a record showing the inputs, the model or configuration version in force at the time, the action taken and who authorised it — see what an AI agent audit trail has to contain.

Where an agent makes decisions about individuals, the data protection layer engages in parallel: UK GDPR Articles 22A–22D after the DUAA impose their own reconstruction requirement, and it is the same evidence.

Frequently asked questions

Is the FCA or PRA writing an AI rulebook?

No, and none is planned. The Bank of England confirmed this on 1 April 2026 while rejecting "wait and see". Existing frameworks are the regime.

Has the operational resilience deadline passed?

Yes — 31 March 2025. It is now a baseline. The live forward date is FCA PS26/2, in force 18 March 2027.

Which firms are designated critical third parties?

AWS EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd and Oracle Corporation UK Limited, effective 13 July 2026. HM Treasury designates; the regulators recommend.

Does SS1/23 cover AI?

Yes. It is technology-agnostic but expressly covers AI and machine learning in modelling. The updated version took effect 23 April 2026.

Is the FCA's AI Lab a regulatory safe harbour?

No. AI Live Testing and the Supercharged Sandbox are testing infrastructure. The Consumer Duty, SM&CR and SYSC continue to apply throughout.

Related

BarzelVault enforces the approval threshold in front of the agent and records the inputs, model version and approver for each action before it executes — the evidence SM&CR accountability and SS1/23 independent review both rest on. FinOps Atlas covers what the same automated workflows cost.

In practice

Permission before the action. Evidence after it.

The duties on this page attach to the moment an automated system acts: who permitted it, on which data, under which policy version, and what a person saw before approving. Barzel enforces that decision before execution and writes the record an auditor, a regulator or a data subject can be shown.

BarzelVault

The AI action firewall: decide what an agent may do before it does it.

  • Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
  • Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
  • Credential isolation, spend and action limits, and an emergency kill switch.

Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Barzel FinOps Atlas

Intelligent financial operations for AI agents and automation.

  • Cost per action, workflow and business outcome, allocated as it happens.
  • Spend limits and anomaly detection before the bill, not after.
  • Financial evidence tracing and close-readiness for SOX, SOC 2 and external audit.

Free tier: 500 calls a monthPaid plans from $29 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Enterprise: written quote by email within two business days. No sales call.

Sources

  1. Bank of England, response to the Treasury Select Committee on AI in financial services, 1 April 2026.
  2. FCA PS21/3 and SYSC 15A; PRA PS6/21 and SS1/21 — operational resilience, impact tolerances from 31 March 2025.
  3. FCA PS26/2, operational incident and third-party reporting, published 18 March 2026, in force 18 March 2027.
  4. FCA PS24/16 and Bank of England PS16/24, critical third parties, 12 November 2024; in force 1 January 2025. HM Treasury designations of 10 July 2026, effective 13 July 2026.
  5. PRA SS1/23, Model Risk Management Principles for Banks, 17 May 2023, effective 17 May 2024; updated version published and effective 23 April 2026.
  6. FCA FS25/5; AI Lab, AI Live Testing and Supercharged Sandbox, launched May 2025.
  7. FINMA, Aufsichtsmitteilung 08/2024: Governance und Risikomanagement beim Einsatz Künstlicher Intelligenz, 18 December 2024; FINMA AI survey, 24 April 2025; Risikomonitor 2025, 17 November 2025.
  8. FINRA, Regulatory Notice 24-09, June 2024; 2026 Annual Regulatory Oversight Report.

This article is for information and does not constitute legal, regulatory or investment advice. Position as at 2 September 2026.