AI governance in financial services is often reduced to a reassuring phrase: keep a human in the loop. The Mills Review suggests that this is no longer an adequate description of control. As AI moves from producing drafts to recommending or preparing actions, firms must define what the human is there to do, what they can see and when they are expected to intervene.

That sounds like a governance concern. It is also an operating question for marketing, compliance and every other team trying to use AI in consequential work.

The distinction matters because regulated organisations face a more demanding challenge than adopting a useful new tool. They must decide how to delegate parts of a process without delegating accountability for the result.

What the Mills Review is, and what it is not

The Mills Review: AI and the future of retail financial services was led and authored by Sheldon Mills, then an FCA executive director, following a commission from the FCA Board. It was published by the Financial Conduct Authority on 6 July 2026, with support from a named review team.

It should not be described as an independent report, government policy, regulatory guidance or a new set of binding requirements. Its seven priority recommendations are proposals for the FCA Board and Executive to consider. The FCA’s publication page for the Mills Review and its publication announcement welcomed the review and noted that its recommendations build on existing work, but did not say that every recommendation had been adopted or implemented.

That status does not make the review commercially remote. Its value lies in the operating model it describes.

The review sets out an “autonomy spectrum”. A human may act as an operator using AI as a tool, a collaborator working alongside it, a consultant receiving its recommendations, an approver authorising prepared actions, or an observer monitoring a system operating within established limits.

Not every activity will travel the full distance. The review explicitly recognises that few parts of financial services are likely to become entirely autonomous. The spectrum is useful because it forces a more precise question than whether a process contains AI: what responsibility does the system carry, and what responsibility remains with the person?

AI governance in financial services cannot rely on presence alone

A human can be technically “in the loop” and still exercise little meaningful control.

They may receive too much material to review properly. They may not know which sources produced an answer. They may see a recommendation without the assumptions behind it. Their approval may be routine because rejecting the output is difficult or poorly understood. An escalation route may exist on paper but not within the workflow.

The Mills Review is unusually direct on this point. It says firms will need to establish what a person is expected to do, what information they receive, when they can intervene, how challenge is recorded and how escalation works.

This is the human test for AI governance. Oversight is not the presence of an employee at the end of a process. It is a designed capability.

Human oversight is not a seat in the workflow; it is a system of permissions, evidence, challenge and escalation.

For marketing and compliance teams, that changes the implementation brief. The work is not finished when an AI-generated claim, campaign or communication is routed to an approver. The system must provide enough context for that approval to be informed: the applicable product, audience, channel, permissions, evidence, policy constraints and previous decisions.

The person must also be able to challenge the work without reconstructing the entire process manually. Otherwise AI may accelerate production while leaving the slowest and most consequential part of the workflow untouched.

Marketing and compliance share the same operating problem

Marketing wants to move while an opportunity is still valuable. Compliance needs to understand what is being said, to whom, on what evidence and in what regulatory context. Neither objective is served by a system that produces more material than the organisation can assess responsibly.

This is why the review’s argument about governance is commercially important. It treats governance not merely as a restriction on capability, but as one of the conditions for using capability with confidence.

That principle applies directly to content and campaign approval. If every proposed communication arrives as an isolated document, compliance must repeatedly recover its context. The team checks product terms, substantiation, audience, channel restrictions and relevant policy from the beginning. Marketing experiences this as delay. Compliance experiences it as necessary reconstruction.

AI does not solve that problem simply by writing the first draft faster. It may make the problem worse if it increases the volume and apparent polish of material entering review.

The better opportunity is to improve the quality of the workflow around the draft. Approved information should be retrievable. The origin of important claims should be visible. Known restrictions should travel with the work. Previous decisions should be available as context, without being treated as permanent precedents when circumstances have changed.

This is where collaboration becomes concrete. Marketing gains earlier visibility of the boundaries within which it can work. Compliance receives a better-formed case for review. Human judgement remains at the points where interpretation, proportionality and risk appetite matter.

Institutional context is the missing layer

A general-purpose AI model, used on its own, does not know an organisation’s current products, permissions, approval policies or risk appetite. Nor does it inherently know why a similar claim was accepted in one context and rejected in another.

It may generate fluent material from broad patterns in its training or from the information supplied in a prompt. Fluency is not evidence that the output reflects the firm’s actual position.

This limitation becomes more important as systems move from drafting towards recommendation and execution. The Mills Review notes that models can change over time, depend on third-party inputs and produce probabilistic outputs. It argues that governance therefore needs to extend beyond validation at launch towards live monitoring for drift, degradation and outliers.

The same logic applies at workflow level. A system supporting regulated marketing needs controlled access to relevant institutional knowledge, along with rules governing which information can be used and how conflicts or gaps are escalated.

Institutional memory is not a substitute for current review. Previous approval does not automatically make a claim suitable for a different audience, product or channel. Used carefully, however, previous decisions can reduce repeated research and reveal where professional judgement is genuinely required.

For brett, this is the relevant product-category question: not whether AI can produce another draft, but whether digital teammates can support accountable work using approved organisational context. Any such system should strengthen the conditions for human decision-making rather than imply that software can certify compliance.

Speed should be earned through workflow design

The pressure to demonstrate a return from AI can encourage organisations to measure what is easiest: drafts produced, tasks completed or time apparently saved.

The wider evidence advises caution. The Cambridge Centre for Alternative Finance’s 2026 global study covered 628 financial institutions, technology vendors and regulatory authorities across 151 jurisdictions. It found substantial AI adoption, but 55% of surveyed industry respondents reported difficulty measuring the value of deployment; that figure rose to 76% among large financial institutions. Reported profitability effects were also uneven.

For marketing and compliance leaders, useful measures should extend beyond production volume. They might examine whether reviewers receive better evidence, whether recurring questions are resolved consistently, whether exceptions reach the right specialist and whether decisions leave an adequate record.

These are not promises of guaranteed efficiency or reduced risk. They are indicators of whether the operating model is becoming more coherent.

A firm can move more quickly without lowering standards when routine retrieval and preparation become easier, while higher-risk decisions receive proportionate attention. That requires boundaries based on consequence and reversibility. A low-risk internal summary should not necessarily follow the same route as a consumer-facing financial claim. Equally, apparent convenience should not move a consequential decision beyond meaningful human control.

Consumer evidence favours assistance over unchecked autonomy

The review commissioned Yonder Consulting to research the views of 5,026 UK retail financial-services consumers online in April 2026. Quotas were used for demographic representation among consumers holding a day-to-day bank account.

When participants were shown conceptual AI-enabled financial services, 36% said they would probably or definitely use assistive AI that reviewed information and made recommendations. This fell to 30% for AI that could take action with permission each time and 20% for AI acting autonomously within pre-set instructions.

The research also found that 26% regarded tools such as ChatGPT, Claude and Gemini as reliable sources of financial information or advice. In the survey scenario, only 40% correctly identified that there was no formal route to recourse if advice from a general-purpose AI service went wrong.

These findings do not prove how consumers will behave as products and protections develop. They do show that interest in AI coexists with concerns about authority, accountability and control.

The commercially mature response is not to present autonomy as the inevitable destination. It is to decide where assistance is useful, where permission should be explicit and where professional judgement must remain central.

Better systems should create more room for judgement

The most valuable contribution of AI in regulated work may be its ability to remove avoidable repetition around a decision, not the decision itself.

If a system can retrieve approved material, assemble relevant context and identify missing information, specialists can spend more time on ambiguity, proportionality and the quality of the communication. Marketing can focus on the idea rather than repeatedly locating the same source material. Compliance can focus on the substance of the risk rather than rebuilding the administrative history.

That is a stronger ambition than replacing reviewers or declaring work compliant. It treats expertise as something to support.

It also offers a more credible basis for collaboration. Marketing and compliance do not need identical incentives, but they do need a shared view of the evidence, the boundaries and the decision being taken. Properly designed AI-supported workflows can help create that shared view. They cannot remove the need for accountable people to decide what the organisation is prepared to say and do.

The standard is accountable delegation

The Mills Review is a set of recommendations and scenarios, not a licence for autonomous financial services. Its most useful lesson for firms is more immediate.

As AI assumes a greater share of the work, human responsibility must become more explicit, not less. Organisations need to know who sets the boundaries, who can approve an action, what evidence they see, how disagreement is recorded and when the system must stop.

That is the real test of AI governance in financial services. The winners will not necessarily be the firms that delegate the most. They will be the firms that know precisely what they are delegating, and can show where human judgement still governs the result.

What teams need to know

What is the Mills Review?

The Mills Review is an FCA Board-commissioned review led by Sheldon Mills and published by the Financial Conduct Authority on 6 July 2026. It examines how AI could affect retail financial services by 2030 and makes seven recommendations for the FCA Board and Executive to consider.

Is the Mills Review new FCA regulation?

No. It is not binding regulation, finalised guidance or government policy. Its recommendations may inform future FCA work, but they should not be described as adopted requirements unless the FCA subsequently confirms that position.

What makes human oversight of AI effective in practice?

Effective oversight gives people clear responsibility, relevant context, authority to act and straightforward routes to challenge or escalate. Systems such as brett can bring the evidence, applicable rules and decision history together at the point of review, helping people make informed decisions without relying on fragmented information or memory alone.

How can AI strengthen marketing compliance?

AI can make regulatory and organisational context available earlier in the creative process. It can retrieve approved guidance, surface missing evidence, preserve decision history and route work to the right people. brett gives marketing and compliance teams a shared, structured view of the work while accountable specialists set the standards and resolve matters requiring interpretation.

Can AI improve consistency in regulated marketing?

Yes. AI can help teams apply approved rules and organisational context consistently, identify where work differs from established standards and preserve a clear record of decisions. Combining that systematic consistency with expert accountability creates a stronger operating model than relying on either software or individual judgement alone.

AI governance, Financial services