FCA's Mills Review and EU AI Act transparency rules create a dual-layer compliance challenge for AI use in retail financial services
Two overlapping regulatory events are reshaping how AI is governed in retail financial services across the UK and EU. The FCA published its Mills Review into AI and retail financial services, described by legal commentators as the first work of its kind initiated by a regulator globally. Simultaneously, the EU AI Act's transparency obligations came into force on 2 August 2026, creating binding requirements for firms deploying certain categories of AI system that interact with consumers. The Mills Review, led by FCA Executive Director Sheldon Mills, examines how AI could reshape retail financial services for consumers, firms, markets, and regulators by 2030 and beyond. The review highlights four areas where firms need to act: governance frameworks, accountability structures for AI-driven decisions, fraud defence systems, and inclusive product design that does not disadvantage vulnerable customers. The EU AI Act's transparency obligations, now in force, require firms deploying AI systems in consumer-facing contexts to disclose that the consumer is interacting with an AI system, and to ensure AI-generated content is labelled as such. For firms authorised by the FCA that also operate in the EU or sell into EU markets, the result is a dual compliance framework: UK supervisory expectations set by the Mills Review and binding EU obligations under the EU AI Act. Legal commentators, including those at TLT, have framed the Mills Review as an immediate prompt to act rather than a distant regulatory signal, noting that governance, accountability, fraud defence, and inclusive design are the four pillars requiring attention.
Why this matters
The simultaneity of the Mills Review and the EU AI Act's transparency activation is not coincidental. Both reflect a broader regulatory consensus that AI in financial services has moved from experimental to mainstream fast enough to require governance frameworks now, before binding rules fully catch up. For UK firms, the Mills Review functions as a supervisory expectation-setter: it tells the market where the FCA's attention will go in its next cycle of supervisory work. The EU AI Act's transparency obligations add a binding layer for internationally active firms, meaning non-compliance carries enforcement risk rather than merely reputational exposure. Together, the two signals mark the clearest moment yet at which AI governance in retail finance transitions from voluntary best practice to a regulated discipline.
On the Ground
Financial services regulatory practices at City firms are the primary beneficiaries of this demand. Clients across retail banking, insurance, payments, and wealth management need AI governance policies that satisfy both FCA supervisory expectations and EU AI Act transparency requirements. Specifically, firms need data processing agreement reviews covering AI vendor arrangements, AI governance policy drafting, regulatory impact assessment memos mapping existing AI deployments against the Mills Review themes, and vendor due diligence questionnaires for third-party AI providers. A trainee working on this would assist by preparing compliance gap-analysis memos and drafting sections of AI governance policy documents for partner review.
Interview prep
Question you might get
“How should a UK-authorised retail bank operating in EU markets structure its AI governance framework to satisfy both the FCA's Mills Review expectations and the EU AI Act's transparency obligations?”
Sign up free to see the full answer
A model answer you can lift into an interview — how to frame this story for a partner.
Sign up freeMy notes
saved