Why the Mills Review matters
Not long ago, AI was widely regarded as a productivity tool – a note-taker, a content creator, a turbo-powered search engine. But as agentic AI begins to take decisions on behalf of both lenders and consumers, it’s clear that financial services will be reshaped in previously unimaginable ways. That’s why the Mills Review has arrived at a welcome time.
Commissioned by the FCA Board and led by executive director Sheldon Mills, the review is not a rulebook but it does set the direction for FCA policy, supervision and enforcement over the coming years.
As the report says, the central shift in the way that AI is now being deployed is “from human-led, episodic financial activity towards services that are AI-enabled, continuous and delegated”. It continues: “AI will operate inside firms, through consumer interfaces, across markets and within regulators. It will affect how products are designed, distributed, monitored and governed. Agentic AI is now being piloted and deployed, allowing AI to take on increasingly complex tasks within firm and consumer workflows. A shift towards greater delegation is emerging, tempered by the constraints of model performance and the continuing need for human oversight.”
The review also describes an ‘autonomy spectrum’ of five elements – Operator, Collaborator, Consultant, Approver, Observer – along which firms and consumers are moving as AI takes on more of the work. The review suggests that the existing regulatory framework works reasonably well at the Operator, Collaborator and Consultant stages, but faces increasing pressure as firms move towards Approver and Observer models – i.e. when AI either prepares actions for human approval or acts within agreed limits monitored by humans. Credit and underwriting are highlighted as areas where accountability and the ability to evidence decisions are more challenging.
More transparency required
In the run-up to the review’s publication, there were several issues we were keen to see addressed – and most of them have been. Firstly – transparency. The Mills Review recommends that firms should be able to demonstrate how AI delivers customer outcomes, how accountability is managed and how systems are monitored once in action. That is a good start, but we'd like to see it to go further by providing an example notice explaining to customers how AI is used. It’s important that firms can standardise disclosures without dumbing them down.
Human intervention
A second concern was that we need clear rules for when a human is required to step in to review automated decisions, especially when there are signs that the customer may be vulnerable. As AI shifts from an efficiency tool to a structural component of decision-making, the long-term implications for fairness, bias and accountability are unclear.
Who is responsible?
It's therefore good to see the review call for greater clarity over who is responsible when AI is used to make decisions. It should also be clearer how senior managers are expected to demonstrate they have taken ‘reasonable steps’, and who is accountable when decisions are made across multiple interconnected AI systems.
The review also recommends stronger controls throughout the life of an AI system, so firms can better manage risks as models are updated or changed. It also calls for a review of the rules covering AI tools that provide highly personalised mortgage and credit guidance, to ensure they are subject to appropriate regulation where necessary.
Striking a balance
So there are a lot of important issues to consider here – and that’s why the Mills Review matters. But I also hope that FCA interventions continue to strike the right balance in terms of supporting innovation. The FCA Innovation Hub has provided useful sandbox and live-testing programmes that allow firms to develop and check new technology in a controlled environment, and it would be good to see more of this focused on AI.
As the review emphasises, future success will depend less on creating entirely new regulation than on ensuring that the existing framework proves effective as AI becomes increasingly autonomous. That’s particularly true in terms of accountability, good governance, consumer protection and trust. And that balance of maintaining consumer confidence while encouraging innovation is in everyone’s interests.