← Insights · September 17, 2026

The Mills Review and the adviser who is waiting to be told

Article card reading: the Mills Review: no new rules yet. Not a reason to wait.

On 6 July 2026 the Financial Conduct Authority published the Mills Review, 147 pages on how AI will reshape retail financial services by 2030. It changed no rules. Not one Handbook provision moved.

Plenty of advice firms will read that as the important fact. The rulebook is unchanged, the FCA has promised more guidance, so the sensible thing is to wait until someone tells you what is expected. I understand the instinct. It is also the wrong reading of the document, and I want to set out why, because the review says quite plainly what the regulator intends to look for, and none of it needs a new rule to arrive first.

First, the status. The Mills Review is a report to the FCA Board by an executive director, Sheldon Mills, not a policy statement. Its seven recommendations are for the Board to consider. The most time-bound one asks the FCA to review, within three to six months of publication, how consumers are using general-purpose AI tools for savings, investments, pensions, mortgages and debt outside the regulatory perimeter, and then decide whether to amend guidance, recommend perimeter changes to government or hold its position. That window runs to early January 2027. Separately, the FCA has said it will publish an AI good and poor practice piece later this year, and the Treasury Select Committee’s January 2026 report asked the regulator to publish practical guidance on senior manager accountability for AI harm by the end of 2026. Verified 14 September 2026, publish date brought forward to 18 September; if you are reading this later, check whether any of those three have landed.

So, three things are coming. Here is the part the waiting strategy misses.

The frameworks that apply are the ones you already have

The review’s conclusion on the regulatory framework is that it is sound. The FCA Chair’s response put it the same way: the principles-based, outcomes-focused approach, “relying on the Consumer Duty and Senior Managers Regime”, is what has let the regulator keep pace so far. The review does not recommend AI-specific regulation. It recommends applying the existing regime harder as AI takes on more of the work.

That matters for an advice firm because the Consumer Duty and SM&CR do not have a switch marked “AI”. They already apply to the Copilot licence your paraplanners are using to draft suitability reports, to the meeting-notes tool that summarises client conversations and to the chatbot on the website that answers questions about pension transfers. The good and poor practice publication, when it comes, will describe how firms are meeting obligations that already bind them. It will not create those obligations.

The review’s own phrase for the standard is the one worth pinning to the wall. On explainability it says a useful answer is not enough if the basis for it cannot be reconstructed. Freshfields’ briefing on the review draws the same conclusion: regulatory scrutiny will increasingly focus on whether a firm can show its AI remains reliable and controlled in practice, not on whether a model performed well at deployment. That is a records question, not a technology question, and it is answerable today.

The spectrum the FCA will use to describe you

The most useful idea in the review is its autonomy spectrum. It describes the human’s role in an AI-enabled process at five points: Operator, where a person uses the tool on demand; Collaborator; Consultant; Approver, where the person signs off what the system proposes; and Observer, where the person monitors outcomes of a system acting continuously within limits set in advance.

The review notes that initial deployments in retail finance have mostly sat at the Operator and Collaborator end, and that the degree of autonomy a firm should permit depends on the risk of the activity, whether a decision can be reversed and the strength of the governance around it. Routine, easily reversed tasks can run with more automation. High-value actions and anything material to a client outcome want stronger human controls.

Two things follow for a small advice firm. The first is that you are already on this spectrum whether you have mapped it or not. A paraplanner pasting a fact-find into a general-purpose model to draft a report is an Operator. A workflow that drafts the report automatically for an adviser to approve has moved the firm to Approver. The second is that the spectrum is very likely to become the shared vocabulary of supervisory conversations, because it is the FCA’s own. Being able to say “these four uses sit at Operator, this one sits at Approver and here is why” is a much better afternoon than working it out in front of a supervisor.

Human in the loop is not, on its own, a control

The review is unusually direct about a comfort blanket plenty of the industry has been clutching. It questions whether human oversight is actually capable of meaningful challenge, and says that review is only effective where the reviewer has the right information and can interrogate what the system produced. Firms, it says, will need to decide where human approval is required, what the reviewer sees and how any challenge is recorded, calibrated to the risk and reversibility of the action.

I have watched this fail in regulated environments for years, long before generative AI. An approval step where the approver sees a summary and a green tick is not oversight, it is a signature. The honest test is whether the person approving could explain to a client, or to the Ombudsman, why the system reached that output and what they checked before agreeing with it. If the answer is “I trusted it”, the loop is decorative.

What consumers told the FCA, and why it lands on you

The research commissioned for the review is the freshest UK evidence on how clients feel about this. Yonder Consulting surveyed more than 5,000 UK retail financial services consumers in April 2026, with quotas set to make the sample representative on age, gender, ethnicity, region, housing tenure and internet ability. The headline the FCA led with is that 20% would be likely to use AI that acts autonomously within pre-set goals. The numbers that should interest an advice firm are the ones underneath it. As A&O Shearman’s summary of the same research notes, 16% already use AI for personal finance, mainly to summarise, explain and compare; 68% are concerned about misuse of their personal and financial data; 67% are concerned about a lack of protection if something goes wrong; and the two things most likely to drive adoption are protection if something goes wrong (32%) and evidence of accuracy and reliability (30%).

Read that as a client of yours. The person across the desk is more likely than not to be worried about what happens to their data and whether anyone is accountable when the machine is wrong. A firm that can answer both questions, specifically, before being asked, is offering something the review says clients actively want. A firm that cannot is relying on the client never asking.

Five things to do this quarter

None of these need a new rule, a large budget or a technology decision. They need a few afternoons and a person who owns the result.

Write down every AI use in the firm, including the unofficial ones. The ones nobody sanctioned are the ones that matter most, because they are the ones with no record. Ask, do not assume. Then place each one on the autonomy spectrum. For a typical small advice firm this list runs to a handful of tools and a page of text.

Apply the reconstruction test to anything that touches a client. For each use, ask whether you could reconstruct the basis of a given output six months later: the inputs, the version of the tool, the prompt or configuration and what the human did with it. Where the answer is no, that is the gap. Consumer Duty outcome evidencing will increasingly turn on exactly this record.

Decide, in writing, where human approval sits and what the approver sees. For each use at Approver level or beyond, name the role that approves, list what they are required to check and say how a disagreement is recorded. This is the paragraph the review says firms will need, and it is also what a senior manager’s “reasonable steps” will look like when the guidance arrives.

Name the senior manager who owns it. The review observes that no firm it spoke to argued the accountability model should change, and points out that under SM&CR it is individuals, not firms, who remain personally accountable. Ambiguity about which SMF holds AI is a risk to a named person. Resolve it before someone else does.

List your dependencies. Which model providers, which platforms, what happens if one of them changes a model or goes down. The review’s system-level worry is that many firms depending on the same few providers creates correlated failure, and it raises the prospect of major AI providers being designated critical third parties. You cannot control that. You can know what you depend on.

The adviser who is waiting to be told

The FCA has said, in its own review and in the Chair’s response to it, that the regime it will apply is the one already in force, and that what it wants to see is a firm that understands, controls and can account for what its AI does. The guidance coming later this year will describe good and poor practice against that standard. Waiting for it to arrive before starting means arriving at the conversation with nothing written down, at the point the regulator has just published examples of firms that did.

That is the cost of waiting, and it is not hypothetical. It is the same pattern I wrote about earlier this year on regulatory uncertainty: the rules being unfinished is the reason to build the record now, not the excuse for not building it. The five steps above are the record. They are also, not by coincidence, the first two phases of how we approach any AI deployment: identify what is actually in use and discover what it touches before deciding how much autonomy it deserves. The minimum viable autonomy question the review asks of the whole industry is one a single firm can answer for itself in a fortnight.

If you would rather have that done with you than to you, our fixed-scope AI Adoption & Governance Assessment produces exactly this: the inventory, the spectrum map, the approval design and the accountability line, written in the vocabulary the FCA now uses. Nothing in this article is legal advice; for the regulatory position of your own firm, speak to your compliance adviser.

Insights

Occasional, useful notes on applied AI.

What's actually working, what to ignore, and what the new regulation means for UK businesses. No spam.

We’ll only use your email address to send you these Insights notes. We never share it, and you can unsubscribe from any email. See our Privacy Policy.

AI Services

Where we work

Company

Latest writing

AI Applied Ltd, Technology House, 9 Newton Place, Glasgow G3 7PR. Registered in Scotland SC806963. support@aiapplied.uk · +44 141 465 5233