
The FCA’s Mills Review is presented as an examination of artificial intelligence in retail financial services. Its more consequential conclusion is that the sector is moving from periodic, human-led interactions towards continuous financial services in which decisions are increasingly delegated to software. The firms that understand this as an infrastructure shift, rather than another technology implementation, will define the next operating model of financial services.
Introduction
Most discussion about artificial intelligence in financial services begins with the model.
- Which provider should the firm use?
- How accurate is it?
- Can it draft suitability reports, summarise documents or answer client questions?
- Where should a human remain in the loop?
These are reasonable questions. They are also questions about the present.
The FCA’s Mills Review is concerned with what comes next. Published in July 2026, the review examines how artificial intelligence could reshape retail financial services by 2030 and beyond. Its central proposition is that AI will not remain a tool that sits beside human decision-making. It will increasingly become an active participant in the financial system: interpreting information, recommending actions, initiating transactions and, within agreed limits, executing decisions on behalf of consumers and firms.
That transition is considerably more important than the adoption of generative AI itself.
It changes when financial decisions are made, who or what makes them, how authority is granted, where responsibility sits and what evidence must exist when something goes wrong. It changes the economics of advice, the structure of distribution and the relationship between consumers and institutions.
Most importantly, it changes the value of information.
In an episodic financial system, incomplete information creates inefficiency. In a delegated financial system, incomplete information creates incorrect action. The distinction is fundamental.
The Mills Review is therefore not primarily a report about better algorithms. It is a report about the trusted infrastructure those algorithms will require.
From Episodic Finance to Continuous Finance
The review describes the defining change with unusual clarity: retail financial services are moving from human-led and episodic activity towards services that are AI-enabled, continuous and delegated.
Every word matters.
Financial services today remain overwhelmingly episodic. A consumer applies for a mortgage, renews an insurance policy, attends an annual review or seeks advice after a significant event. Information is assembled for that particular interaction, a decision is made and the relationship returns to a largely dormant state until the next scheduled review or customer request.
This model has produced familiar weaknesses.
Only 9% of consumers receive traditional financial advice. Just 30% hold life or income protection. Around 900,000 people remain unbanked. Approximately £300 billion sits in low-interest accounts, despite the availability of more suitable alternatives.
These are not simply product gaps. They are engagement gaps.
Consumers do not continuously review whether their savings are optimised, their protection remains appropriate, their pensions reflect their objectives or their financial arrangements have adapted to changes in health, family, employment and property. Institutions do not usually possess a live enough understanding of the consumer to do this on their behalf.
AI changes the practical economics of that relationship.
A system capable of continuously interpreting a person’s circumstances could identify an emerging protection gap, recommend that excess cash be moved, flag that a pension contribution is falling behind a stated objective or recognise that a change in family circumstances has made existing estate planning obsolete.
Eventually, it may be authorised to act.
This is the destination implied by the Mills Review: not a better annual review, but the gradual replacement of the annual-review model with a persistent financial-management capability.
Advice becomes continuous. Monitoring becomes continuous. Suitability becomes something that must be maintained rather than demonstrated at isolated points in time.
The traditional fact-find was designed for an episodic system. Agentic finance will require a living record.
The Autonomy Spectrum
To explain the transition, the review introduces an autonomy spectrum based on the changing role of the human.
- At the first stage, the human is the operator. AI assists with a defined task: searching, summarising, analysing or drafting.
- The relationship then progresses through collaborator and consultant. AI becomes more active in planning, comparing options and recommending actions, but the human remains closely involved.
- At the approver stage, AI prepares or initiates an action and the human authorises it.
- At the observer stage, the system acts continuously within permissions and boundaries set in advance. The human monitors outcomes rather than approving each decision individually.
The progression sounds incremental. It is not. Moving from operator to observer changes the nature of control.
When AI drafts a report, a professional can inspect the output before using it. When an agent continuously reallocates savings, switches products, initiates payments or manages a portfolio within a mandate, control no longer resides primarily in reviewing each output. It resides in the quality of the rules established before the action occurs.
- Who granted the authority?
- What information was the decision based upon?
- Was that information current?
- What limits applied?
- Could the mandate be revoked?
- Which organisation was responsible for the outcome?
- Can the complete chain of reasoning, permissions and actions be reconstructed?
The further AI moves along the autonomy spectrum, the less meaningful a conventional “human in the loop” assurance becomes. A human cannot realistically inspect every decision made by a system whose economic value comes from operating continuously and at scale. Governance therefore moves upstream.
The critical work becomes establishing identity, authority, data provenance, permissions, monitoring, escalation and redress before an agent is allowed to act.
This is the first strategic conclusion for firms: greater autonomy does not reduce the importance of control. It moves control into the architecture.
Consumer Adoption Has Already Begun
It would be easy to dismiss agentic finance as speculative. The FCA’s consumer research suggests otherwise.
Sixteen per cent of consumers already use AI for at least one personal-finance activity. Among those users, 72% use it to summarise or simplify information, 61% ask it for suggestions, 24% upload personal data or documents such as bank statements, and 14% give AI ongoing access to personal data, accounts or software.
One in five UK adults is already open to AI making financial decisions for them. Interest is particularly strong in areas perceived as complicated or consequential, including debt, pensions and investments.
Consumers are therefore beginning to construct the future system themselves.
They are copying financial information into general-purpose models, uploading documents and requesting recommendations outside the controlled environments of regulated institutions. Some are doing so without understanding where their data travels, how an answer was produced or whether formal rights of complaint and redress exist.
Around 26% of consumers already regard general-purpose AI tools as a reliable source of financial information or advice. Yet only 40% correctly understand that there may be no formal recourse when advice from such a service produces a poor outcome.
This creates an immediate competitive and regulatory problem.
Consumers will not wait for the industry to produce a perfect framework before using AI. They will use whichever interface removes friction, explains complexity and appears to understand them.
The relevant question is therefore not whether consumers will use artificial intelligence to manage their finances. It is whether they will do so through trusted, accountable infrastructure or through systems that sit beyond the conventional regulatory relationship.
Trust Is an Operating Model
The word “trust” appears throughout the Mills Review. It would be a mistake to interpret it as a matter of brand reputation or consumer sentiment alone.
Trust in agentic finance must be engineered.
A consumer may trust an adviser because the adviser is qualified, regulated and personally accountable. They may trust a bank because it has custody of their money, an established complaints process and obligations enforced by the regulator.
An AI agent possesses none of those characteristics inherently.
Its trustworthiness must therefore be established through verifiable properties: the identity of the agent, the identity of the person it represents, the scope of its mandate, the provenance of the information it uses, the boundaries governing its conduct and the record of actions it has taken.
This is why the review identifies trust, control and access as the decisive conditions for adoption.
Consumers must be able to understand what an agent is permitted to do, challenge its decisions, withdraw authority and obtain redress. Firms must be able to evidence what occurred. Regulators must be able to inspect outcomes across individual firms and the wider market.
Trust cannot be supplied by a disclaimer beneath an AI-generated answer.
It requires an auditable chain running from the individual, through their information and permissions, to the agent, the action and the resulting outcome.
That chain is the real product.
Data Is the Binding Constraint
The Mills Review identifies six building blocks for agentic finance: data, identity, authorisation and delegation, execution, liability, and supervision and audit.
The first is data, and the review is explicit about its importance: data quality and availability remain a binding constraint on scale.
This deserves more attention than it is likely to receive.
The financial-services industry is investing heavily in models while much of the information required to make those models useful remains incomplete, fragmented, stale and difficult to verify.
A firm may hold a client’s pension in one system, identity records in another, correspondence in email, estate-planning documents in a document store and details of held-away assets in a fact-find completed eighteen months ago.
An AI system can retrieve those records more quickly. It cannot make the missing information exist.
Nor can it reliably infer whether a document remains current, whether a relationship has changed, whether an account has been closed or whether the client possesses assets the firm has never seen.
The problem becomes more serious as autonomy increases.
A human adviser can recognise that a fact-find appears incomplete and ask another question. An autonomous agent may act upon the available record. Fluency can conceal uncertainty, and automation can convert one informational defect into thousands of consistently executed poor decisions.
The review notes that, in regulated financial services, decisions must increasingly be based on information that is trusted, attributable and auditable. As systems become more delegated, tolerance for error falls while the importance of precision, lineage and governance rises.
This reverses a common assumption about AI.
More capable models do not make information architecture less important. They make it more important, because the cost of unreliable data increases with the speed, confidence and scale at which the system can act upon it.
The limiting factor in agentic finance will not be whether an AI can reason about a pension, mortgage or protection policy.
It will be whether the system has permissioned access to a complete and current record of the person whose interests it is expected to serve.
The Personal Record Becomes Strategic Infrastructure
Financial institutions have traditionally constructed records about customers for their own purposes.
A bank holds the information required to operate an account. An insurer holds the information required to underwrite a risk. An adviser holds the information required to provide advice. A solicitor holds the information required to conduct a matter.
Each institution sees a partial representation of the same person.
Agentic finance requires something different.
An agent acting in an individual’s interests must be capable of understanding the individual across institutional boundaries. It may need to consider income, debt, savings, investments, insurance, property, dependants, health, legal arrangements and long-term objectives simultaneously.
No single provider ordinarily holds this picture.
The strategic asset in an agent-led market will therefore not simply be the firm’s customer record. It will be the consumer’s permissioned personal record: a structured, persistent representation of their circumstances that can be used across products, institutions and life events.
This does not mean transferring uncontrolled ownership of institutional records to the consumer. Nor does it mean creating a central database accessible to every participant.
It means establishing an environment in which information can be maintained at source, verified, permissioned and shared for a defined purpose without repeatedly reconstructing the person from fragments.
Without that layer, personalisation remains superficial. An AI may communicate in a personalised way, but it cannot produce a genuinely personal outcome if it possesses only a narrow and outdated view of the person.
The next generation of financial intelligence will depend upon personal information infrastructure.
Identity & Authority
The review’s fifth priority recommendation is to establish the foundations for agentic finance through a trusted framework governing how agents are identified, authorised and held accountable.
It calls for clear expectations around consent mandates, identity, control and liability. It also recognises that an agent must combine access to data with a trusted identity and the ability to execute an action. If those components remain fragmented, systems cannot move safely from assistance into delegation.
This creates a new form of identity problem.
It is no longer sufficient to verify that the consumer is who they claim to be. The system must also verify that an agent is acting for that consumer, that the instruction remains valid and that the proposed action falls within the authority granted.
A mandate to “help me manage my money” is not operationally meaningful.
A trusted system must know whether the agent may read account data, recommend a transfer, prepare a transfer for approval or execute it without further intervention. It must understand transaction limits, duration, product scope and the circumstances in which authority should pause or terminate.
Permissions must be bounded, structured, verifiable and revocable.
This is considerably more sophisticated than accepting terms and conditions. It is a persistent authority framework capable of governing machine action over time.
The review recommends that this work should align with Open Finance, allowing common standards to develop around data sharing and adjacent actions undertaken by agents.
The implication is significant.
Open Finance has often been understood as an extension of Open Banking: a mechanism for making more financial data portable. Within an agentic system, it becomes the permission and execution layer through which intelligence can operate across the financial life of the consumer.
Data portability was the first phase.
Delegated action is the next.
Distribution & the Consumer Interface
AI will also change where financial relationships are formed.
Historically, firms controlled distribution through branches, advisers, comparison sites, direct marketing and proprietary digital channels. In an agent-led market, consumers may begin their financial journey inside a general-purpose assistant or a personal agent that already understands their preferences and circumstances.
That interface may research products, compare providers, narrow the available options and initiate a transaction.
Control of the consumer interface will consequently become a source of market power.
The institution providing the underlying financial product may become less visible, while the agent that interprets the consumer’s needs and orchestrates the journey becomes more influential. The review explicitly identifies AI-mediated interfaces, access to data, interoperability and the potential power of dominant technology providers as competition concerns.
For incumbent firms, this creates a choice.
They can remain product manufacturers waiting for external agents to direct customers towards them. Or they can build trusted, persistent relationships with customers and make their products, data and services available within the emerging agent ecosystem.
The firms with the strongest position will not necessarily be those with the largest historic database.
They will be those with the most complete, current and permissioned understanding of the customer.
A million dormant records do not constitute a strategic data asset if the underlying information is stale, fragmented and inaccessible to the customer. In an agentic market, a smaller base of actively connected and continuously maintained relationships may be considerably more valuable.
The competitive unit is moving from the product to the relationship, and from the relationship to the information architecture beneath it.
Continuous Regulation
The Mills Review does not only anticipate continuous services for consumers. It proposes that supervision should move in the same direction.
Today, regulation remains heavily dependent on periodic reports, document submissions, thematic reviews and firms assembling evidence in response to requests.
The review proposes an AI-enabled supervisory model capable of examining information across firms, identifying patterns that no individual institution can see and detecting emerging harm closer to real time. It envisages a shift from episodic and document-based supervision towards an approach that is more continuous, risk-based and intelligence-led.
This has a practical consequence for regulated firms.
The standard of evidence will rise.
When supervision is periodic, a firm can assemble a retrospective explanation of its processes and outcomes. When supervision becomes increasingly data-led and continuous, the underlying evidence must already exist in a structured, comparable and accessible form.
A static policy document will not demonstrate that an AI agent remained within its mandate.
The firm will need to show the identity and authority under which the agent operated, the information available at the point of action, the controls applied, the outcome produced and the response to any exception.
Consumer Duty introduced the requirement to evidence good outcomes.
Agentic supervision will make that evidence increasingly granular, operational and continuous.
Firms that cannot establish lineage between data, decision and outcome will find themselves unable to explain their systems to clients, boards or regulators.
The Seven Mills Review Recommendations
The Mills Review makes seven recommendations:
- Adapt the regulatory perimeter
- Strengthen system-wide coordination
- Monitor the move towards autonomy
- Expand the FCA’s AI Lab
- Establish the foundations for agentic finance
- Develop AI-enabled supervision
- Explore a trusted public-interest financial capability service.
These should not be viewed as seven separate initiatives, but components of a regulatory architecture.
The perimeter determines which activities and organisations are accountable. Coordination addresses risks that cross firms, sectors and technology providers. The AI Lab builds regulatory understanding. The agent framework establishes identity, authority and liability. Agentic supervision provides visibility. The proposed public-interest service seeks to ensure that access to trustworthy financial intelligence does not depend entirely upon a consumer’s ability to purchase the most capable commercial model. Together, they reveal the FCA’s underlying conclusion.
The existing principles-based regulatory framework remains broadly usable while AI assists people. Pressure emerges when AI begins approving and executing decisions, because accountability becomes distributed across firms, models, platforms, data sources and agents.
The regulatory challenge is therefore not to write a rule for every model. It is to preserve clear responsibility as activity becomes increasingly autonomous. That is the correct diagnosis.
Models will change too quickly for prescriptive regulation to remain current. Identity, consent, auditability, accountability and outcomes are more durable foundations.
What Firms Should Do Now
The Mills Review is a forward-looking document, but its implications are immediate.
Firms do not need to predict which model will dominate in 2030. They need to examine whether their present architecture can support increasingly continuous and delegated services.
- Can the firm establish a complete view of the customer without manually reconstructing it?
- Can the customer verify and maintain their own information?
- Can the provenance and currency of each important data point be established?
- Can permissions be expressed at a sufficiently granular level to govern both human and machine access?
- Can the firm identify when circumstances have changed?
- Can it evidence which information informed a recommendation or action?
- Can authority be withdrawn cleanly?
- Can another trusted professional be given limited access without copying the entire record into another silo?
- Can the organisation monitor outcomes across its customer base rather than reviewing isolated transactions after the event?
If the answer to these questions is no, the constraint is not artificial intelligence. It is architecture.
Adding a model to a fragmented operating environment may improve isolated tasks, but it will not create agentic capability. It may simply automate the movement of poor information through existing processes.
The firms best positioned for the transition will be those that separate the intelligence layer from the information layer.
Models will evolve. Providers will change. Capabilities that appear exceptional today will become commoditised. The underlying client record — identity, information, relationships, permissions, documents, provenance and history — must remain persistent, controlled and portable.
That is the durable infrastructure.
The Infrastructure Before the Intelligence
Lyfeguard’s relevance to this transition is not that it attempts to become the consumer’s financial adviser or replace the regulated institutions serving them.
It is that intelligent financial services require a reliable representation of the individual before they can reason or act in that individual’s interests.
A consumer-controlled record can bring together the information that currently sits across institutions, documents and personal memory. A trusted professional can access the parts relevant to their role. Information can be maintained as circumstances change rather than reconstructed at the next transaction. Permissions can be explicit. Activity can be recorded. AI can interpret the record without becoming its owner.
This establishes a necessary separation.
The individual retains a persistent information layer. Institutions retain control over their regulated services and the records they are required to govern. AI agents operate through defined permissions rather than indiscriminate access. Each party sees what it is authorised to see, and every action can be traced back to the mandate and information that supported it.
The result is not merely a more capable client portal. It is the foundation upon which continuous advice, delegated action and interoperable professional services can be built.
The Mills Review calls this agentic finance.
Its practical prerequisite is personal information infrastructure.
Conclusion
The Mills Review is one of the clearest official statements yet that artificial intelligence will change the operating model of retail financial services rather than simply improve its existing processes.
The central movement is from episodic to continuous, from assistance to delegation and from humans approving each individual task to humans establishing the boundaries within which systems operate.
That movement creates enormous opportunity.
It could widen access to financial support, reduce administrative cost, improve switching, close protection gaps and enable institutions to respond to changing circumstances before those circumstances become financial harm.
But none of those benefits follows automatically from a more capable model.
The system must know who the consumer is. It must possess accurate and current information. It must understand who is authorised to act, within what limits and for what purpose. It must preserve evidence of the decisions made and provide a credible route to intervention and redress.
These are not secondary governance considerations to be added after the AI has been deployed. They are the infrastructure that makes deployment possible.
The firms that lead the next era of financial services will not necessarily be those that adopt artificial intelligence first. They will be those that first create the trusted information, identity and permission architecture through which intelligence can operate safely.
The model is not the transformation. The transformation is the system built around it.




