FCA's Mills Review and EU AI Act transparency rules create a dual-layer compliance challenge for AI use in retail financial services
Two overlapping regulatory events are reshaping how AI is governed in retail financial services across the UK and EU. The FCA published its Mills Review into AI and retail financial services, described by legal commentators as the first work of its kind initiated by a regulator globally. Simultaneously, the EU AI Act's transparency obligations came into force on 2 August 2026, creating binding requirements for firms deploying certain categories of AI system that interact with consumers. The Mills Review, led by FCA Executive Director Sheldon Mills, examines how AI could reshape retail financial services for consumers, firms, markets, and regulators by 2030 and beyond. The review highlights four areas where firms need to act: governance frameworks, accountability structures for AI-driven decisions, fraud defence systems, and inclusive product design that does not disadvantage vulnerable customers. The EU AI Act's transparency obligations, now in force, require firms deploying AI systems in consumer-facing contexts to disclose that the consumer is interacting with an AI system, and to ensure AI-generated content is labelled as such. For firms authorised by the FCA that also operate in the EU or sell into EU markets, the result is a dual compliance framework: UK supervisory expectations set by the Mills Review and binding EU obligations under the EU AI Act. Legal commentators, including those at TLT, have framed the Mills Review as an immediate prompt to act rather than a distant regulatory signal, noting that governance, accountability, fraud defence, and inclusive design are the four pillars requiring attention.
Sign up to read →