The UK’s plan for AI in financial services is ostensibly about technology, but its most important observation concerns something more prosaic: how work gets done inside regulated firms.

Published on GOV.UK by HM Treasury in July 2026, the Financial Services AI Adoption Plan was developed by the government’s independent financial services AI Champions, Harriet Rees and Dr Rohit Dhawan. It calls for wider, faster use of AI while maintaining consumer trust and operational resilience, covering regulation, financial advice, third-party risk, skills and agentic payments. Yet the argument running through the report is that firms are not being held back by a simple lack of ambition, nor necessarily by a lack of regulation.

The problem is translation.

Financial institutions have rules, principles, governance structures and innovation programmes. What many lack is a dependable way to convert them into everyday decisions about real AI use cases. That distinction matters. A firm can be enthusiastic about AI at board level and still leave its teams waiting for approval to use it in a customer communication, campaign workflow or internal process.

The report is right to support the UK’s principles-based, outcomes-focused regulatory model rather than calling for a separate rulebook for every new AI capability. But principles only support adoption when people can apply them with confidence. Otherwise, regulatory flexibility feels remarkably similar to uncertainty.

For marketing and compliance leaders, this is where the next phase of AI adoption will be won or lost.

The real barrier to AI in financial services is operational clarity

The report acknowledges that UK regulators have already established useful initiatives, including the FCA AI Lab, AI Live Testing and the Supercharged Sandbox. Firms generally value direct engagement with regulators, especially when they can discuss genuine use cases rather than abstract principles.

Access and application remain uneven, however. Guidance is distributed across different regulators and sources. Smaller firms can find innovation pathways difficult to enter. Even well-resourced organisations struggle to determine how established requirements on Consumer Duty, model risk, explainability, data protection and senior management accountability apply to a particular AI system.

The plan proposes more joined-up regulatory support, potentially through a Financial Services AI Adoption Support Hub. This could combine a central information portal with access to supervisory and subject-matter expertise.

That would be useful, but firms should not mistake better external guidance for a complete operating model. A regulator can clarify an expectation; it cannot redesign the internal process through which a campaign, model or customer journey is reviewed.

This is particularly relevant to marketing. The legal permissibility of an AI tool is only one of several questions a team must answer. It also needs to know which data the tool may use, how its claims will be substantiated, whether outputs need human review, what evidence must be retained and who is accountable when the work moves between functions.

If those decisions begin from scratch each time, adoption will remain slow regardless of how sophisticated the technology becomes.

Principles need to become repeatable decisions

Regulated firms are accustomed to working with principles. They allow rules to remain relevant as products, channels and customer behaviours change. The alternative, an exhaustive set of instructions for every possible AI application, would be obsolete before publication.

Principles also place a greater burden on institutional judgement. Two firms can read the same regulatory guidance and develop very different levels of confidence about what is acceptable. Within a single organisation, separate teams may interpret the same requirement differently.

This produces a familiar pattern. A promising AI pilot succeeds in a controlled environment. Extending it into live work introduces new stakeholders, data questions and approval requirements. The project slows while teams reconstruct the relevant policy position, determine what precedent exists and decide whose opinion carries authority. The technical trial worked; the organisation surrounding it did not.

Governance is often discussed as a control layer placed around AI. In practice, good governance should also be an enabling system. It should help a team identify the right policy, apply earlier decisions, involve the correct specialists and preserve a clear record without turning every use case into a committee meeting.

The strongest firms will turn regulatory interpretation into institutional knowledge. They will record not only the final decision, but the reasoning behind it. They will know which conditions made an earlier use acceptable and whether those conditions apply again. Over time, decisions that once required lengthy discussion can become routine without becoming careless.

That is how principles become operational.

AI-powered financial advice exposes the regulatory asymmetry

The sharpest section of the plan concerns financial guidance produced by general-purpose AI tools.

The plan, drawing on FCA evidence, says traditional regulated financial advice is used by only around 9% of UK adults. Meanwhile, consumers are already using widely available AI systems for help with savings, debt, pensions and investments. FCA-commissioned research for the Mills Review, based on 5,026 UK adults, found that 26% regarded general-purpose tools such as ChatGPT as completely or somewhat reliable sources of financial information or advice. The review also identified limited awareness that formal routes to recourse may not apply.

This creates an uncomfortable imbalance. A regulated firm faces obligations concerning suitability, accountability and consumer outcomes. A general-purpose AI service can produce something that looks remarkably like personalised guidance without carrying equivalent responsibilities.

The plan recommends that the FCA review the consumer and competitive effects of these advice-like outputs. It also proposes a consistent voluntary disclosure to help consumers distinguish regulated AI services from unregulated ones.

Disclosure is sensible, although a label cannot carry the full weight of consumer protection. The deeper issue is that horizontal AI tools do not understand the specific permissions, products, risk appetite or evidential standards of the organisation in which their output may be used.

The distinction is important for marketing teams too. A fluent answer is not necessarily an approved answer. It may be factually plausible but inconsistent with product terms, current policy or the firm’s interpretation of Consumer Duty. General-purpose tools can help produce and organise work, but confidence comes from connecting them to trusted sources, defined controls and accountable review.

AI-powered financial advice could help address a persistent advice gap. Doing so responsibly will require more than a capable model. It will require a system that knows when it is providing information, when it is approaching regulated advice and when a human must take over.

Third-party assurance could remove a great deal of duplicated work

One of the plan’s more commercially useful proposals is an industry-led assurance framework for third-party AI providers.

At present, financial institutions often assess the same major models and suppliers independently. Each firm sends questionnaires, reviews documentation and performs its own analysis of issues such as cybersecurity, data protection, transparency and reliability. Some duplication is unavoidable because risk depends on how a system is used. The plan argues that a shared assurance baseline could reduce unnecessary duplication while preserving firm-specific assessment.

The proposed framework would allow qualified assessors or a central body to evaluate providers against an agreed baseline, somewhat like established assurance standards in other areas of technology. Regulators could eventually recognise certification as evidence contributing to due diligence, while individual firms would remain accountable for their own implementation.

That final qualification is essential. A reliable model can still be deployed badly. Certification of the underlying service says little about whether a firm has supplied appropriate data, designed suitable human oversight or allowed the output to influence customers in ways that create foreseeable harm.

Even so, common assurance could reduce repetitive foundational work and allow risk specialists to concentrate on the context that genuinely differs between organisations. It would be a better use of scarce expertise than asking every compliance team to rediscover the same facts about the same suppliers.

AI governance in financial services cannot belong to one function

The plan calls for AI capability across boards, specialist teams and frontline staff. This is more important than treating AI literacy as a technical training exercise.

A marketing leader does not need to become a machine-learning engineer. They do need to understand the limits of a model, the provenance of information and the point at which an apparently helpful personalisation becomes a material customer decision. Compliance professionals need enough practical knowledge to assess a workflow rather than reviewing AI as an undifferentiated category of risk. Boards need to recognise where concentration, accountability and operational dependency sit.

Training alone will not resolve weak processes. An employee may understand the risks perfectly and still be unable to find the current policy, locate an approved claim or establish who should review a new use case.

Capability therefore has two parts. People need better judgement, and the organisation needs systems that make good judgement easier to exercise.

For marketing and compliance teams, that means shared access to approved knowledge, clear escalation routes and workflows that bring review into the development of an idea rather than attaching it at the end. It also means preserving the reasoning behind decisions so that knowledge survives staff changes and can inform the next piece of work.

The prize is not simply faster approval. It is more time for the work that merits human attention: difficult judgements, unusual customer risks, creative choices and genuinely novel propositions.

Agentic payments will test whether accountability is real

The plan’s final recommendation concerns agentic payments, in which autonomous software acts on behalf of a person or organisation to initiate and manage transactions.

It proposes a trust framework covering legal liability, dispute mechanisms, “Know Your Agent” identity standards and interoperable machine-to-machine authentication. These are sensible foundations. If an autonomous agent purchases the wrong product, exceeds its authority or is manipulated by fraud, neither customers nor firms can afford ambiguity about responsibility.

Agentic payments are also a useful test of the broader governance argument. Many organisations can tolerate a vague policy while AI is drafting internal text. Ambiguity becomes much less charming when software can move money.

Permissions will need to be explicit, actions traceable and exceptions routed to people who can intervene. Organisations will need to know which agent acted, under whose authority, using which information and within which limits. These are not merely technical requirements. They are the practical expression of accountability.

The same discipline should inform less dramatic applications now. Waiting until AI can transact autonomously before establishing dependable records, permissions and escalation would be an expensive way to learn the lesson.

The firms that move fastest will make judgement reusable

The Financial Services AI Adoption Plan is encouraging because it resists the temptation to answer every uncertainty with a new rule. It recognises that the UK’s established regulatory approach can accommodate much of what AI introduces, provided expectations become clearer and support becomes easier to access.

Yet regulatory clarity can only take firms so far. The remaining work sits inside organisations: converting guidance into usable controls, connecting teams to reliable knowledge and ensuring that decisions can be understood and repeated.

This is where purpose-built AI systems and digital teammates may have a useful role, provided they are configured around the organisation’s approved knowledge, controls and accountable review processes. Properly configured tools can support teams in retrieving approved material and relevant precedent, while leaving interpretation, approval and accountability with authorised people. The objective is not to remove scrutiny, but to reduce repeated work where the organisation has already established an applicable position without removing necessary review.

AI adoption in financial services will not be decided by the number of pilots a firm can announce. It will be decided by whether good judgement has somewhere to live.

What teams need to know

What is the UK Financial Services AI Adoption Plan?

It is an independent report developed by the government’s financial services AI Champions, Harriet Rees and Dr Rohit Dhawan. Published on 14 July 2026, it recommends actions for government, regulators and industry to encourage safe AI adoption. The government has welcomed the plan and accepted the recommendations directed at government, but the document is not itself a new set of binding regulations.

Does the plan recommend new AI regulation for financial services?

It does not propose a comprehensive AI-specific regime. It supports the UK’s existing principles-based, outcomes-focused approach, while recommending clearer cross-regulator guidance and targeted responses where AI creates new risks or regulatory gaps.

How could AI affect regulated financial advice?

AI could make financial support more accessible and affordable, particularly for people who do not currently receive regulated advice. However, general-purpose models can produce advice-like answers without the suitability requirements, accountability or redress associated with regulated providers. The plan asks the FCA to examine this imbalance and develop an appropriate response with government.

What is AI governance in financial services?

AI governance is the combination of accountability, policies, controls, evidence and oversight used to ensure AI systems operate safely and consistently with regulatory obligations. Effective governance should help teams make decisions efficiently as well as manage risk.

What are agentic payments?

Agentic payments are transactions initiated or managed by autonomous AI or software agents on behalf of customers or organisations. The plan recommends standards for legal liability, agent identity, authentication, governance and dispute resolution before these systems become widely used.

AI governance, Compliance, Regulated marketing