The rapid adoption of artificial intelligence in financial services has triggered an “arms race” between innovation and oversight, with a top UK regulator warning that authorities need expanded powers to protect millions of consumers now relying on tools like ChatGPT for money decisions.
Sheldon Mills, an executive director at the Financial Conduct Authority (FCA), said regulators must urgently embrace AI internally to keep up with the “speed, pace and scale of change” sweeping through the industry. His landmark review, published Monday, found that more than a fifth of UK adults—roughly 11 million people—are open to using AI models to guide savings, borrowing and other financial choices, even though these services fall outside the current regulatory perimeter.
“It is an arms race,” Mills said in an interview with the Financial Times. “Some firms have said to us that they feel that this could be an economically equivalent type of service that isn’t regulated and sits outside of the regulatory perimeter.”
The New Frontier of Financial Advice
The review paints a picture of a financial landscape on the cusp of transformation. General-purpose large language models—including OpenAI’s ChatGPT, Anthropic’s Claude and Google’s Gemini—are increasingly used by consumers for financial guidance. Yet these interactions exist in a regulatory gray zone. While traditional financial institutions must follow “reasonably strict” rules when offering investment recommendations, AI chatbots face no such constraints, and consumers have no recourse to compensation if things go wrong.
Mills raised a fundamental question that regulators must now grapple with: “Is the fact that the chat model might be able to respond to prompts and have a conversation something closer to a recommendation, or guidance?”
The FCA-commissioned report recommends that within the next three to six months, the watchdog should conduct a systematic review of companies providing AI-driven financial services outside its remit and assess the potential for consumer harm. The review would examine whether the regulatory perimeter needs to be “secured and adapted” to capture general-purpose AI tools that currently escape oversight.
Promise and Peril
The report identifies a dual reality. On one hand, AI could “democratise” finance by making sophisticated advisory services accessible to lower-income households. Mills pointed to the prospect of someone earning £20,000 a year receiving the kind of financial advice typically reserved for individuals with £10 million in savings or assets. “I mean what’s not to like about that?” he said.
On the other hand, the same technology enabling hyper-personalization could fuel algorithmic bias, opaque pricing and personalized manipulation. The review warns that deepfakes, synthetic identities and highly tailored social engineering attacks are “taking fraud and cyber risks into a new era.”
A recent global survey cited in the review found that 81% of financial firms are adopting AI at some level, with 40% at more advanced stages of scaling or transformation. While most use cases remain concentrated in lower-risk back-office functions, British firms are increasingly deploying AI in customer-facing roles, including handling complaints and providing investment guidance.
The report also flags systemic risks. Widespread reliance on a handful of technology providers for critical operational capabilities could create “correlated behaviour, herding and common points of failure across the financial system.”
Pushing for Regulatory Muscle
To address these challenges, Mills’ report lays out a roadmap for expanding the FCA’s toolkit. It calls on the government to boost the watchdog’s powers under the “critical third parties” regime, which allows regulators to supervise key technology providers to the financial sector. Companies that could fall under this expanded oversight include Anthropic, OpenAI, Amazon (AMZN), Google (GOOGL) and Microsoft (MSFT).
Once designated under this regime, tech giants could face more robust disclosure requirements, annual self-assessments and “scenario testing” of their ability to withstand severe operational disruptions. The UK government has not yet decided which big tech groups to designate.
The report also suggests that the FCA could seek additional authority under the “designated activities regime,” which would allow it to regulate specific AI-related financial activities without requiring the firms carrying them out to be fully authorized.
FCA Chair Ashley Alder said: “We need to keep pace with a rapidly changing environment and the principles-based, outcomes-focused approach we’ve taken on AI.”
Accountability and the Human Factor
As financial services companies pilot AI agents capable of autonomously executing transactions, Mills emphasized that accountability must remain with people, not machines. “You need a human on the hook for what they’re doing,” he said, stressing that senior management must bear ultimate responsibility for AI model behavior.
The report also recommends that the FCA convene public and private sector groups to develop an “AI-enabled financial capability service” that would provide free information and guidance to the British public on financial choices.
Political Friction Over Palantir Contract
The push for expanded regulatory powers comes as the FCA itself faces scrutiny over its own use of AI. The watchdog signed a 12-week contract with US technology company Palantir (PLTR) to test whether its AI systems can assist in fighting financial crime. Some UK lawmakers have raised concerns that the arrangement could give US authorities access to sensitive British financial information. Both the FCA and Palantir have denied this. Mills declined to comment on the contract.
The FCA board is expected to discuss Mills’ report before deciding how to respond to its recommendations. With millions of consumers already experimenting with AI for financial decisions, the clock is ticking on a regulatory framework that was designed long before chatbots started dispensing money advice.