UK compliance hub

The FCA’s AI approach: no new rulebook, existing rules apply

AI and the FCA: our approach

Issued by
Financial Conduct Authority
Published
AI Update, 22 April 2024
Updated
Approach page updated 13 February 2026
We reviewed
17 July 2026
In one minute

The FCA has deliberately not written an AI rulebook. Its position, set out in the April 2024 AI Update and restated on its current approach page, is that existing frameworks — the Consumer Duty, the Senior Managers and Certification Regime, and existing data and operational-resilience rules — already apply to AI. That is not a lighter regime; it is a heavier one for individuals, because SM&CR means a named senior manager is accountable for AI-driven outcomes, and the Consumer Duty asks whether AI use delivers good customer outcomes. The FCA’s AI Live Testing programme runs alongside, supporting firms deploying AI — its second cohort was announced in April 2026.

What the guidance says

We do not plan to introduce extra regulations for AI. Instead, we’ll rely on existing frameworks, which mitigate many of the risks associated with AI.
Financial Conduct AuthorityThe position is explicit on the FCA’s current approach page.
Many risks related to AI are not necessarily unique to AI itself and can therefore be mitigated within existing legislative and/or regulatory frameworks.
Financial Conduct AuthorityThe April 2024 AI Update reasons that AI risks are rarely unique to AI.
The Senior Managers and Certification Regime (SM&CR) emphasises senior management accountability and is relevant to the safe and responsible use of AI.
Financial Conduct AuthorityAccountability is personal: the AI Update names SM&CR as directly relevant.

The AI Live Testing programme (part of the FCA’s AI Lab) supports firms deploying AI — cohort 2, announced 21 April 2026, includes eight firms from major banks to fintechs.

What this means for your firm

  • For a regulated financial firm, "can we use AI?" is the wrong question — "which senior manager owns the AI risk, and what evidence do they hold?" is the FCA-shaped question.
  • Customer personal data entering AI tools sits under both UK GDPR and the Consumer Duty lens — a data leak through a prompt is also a customer-outcome failure.
  • Evidence is the currency of SM&CR: technical controls that log what was protected before AI processing give the accountable manager something to stand on.
  • The absence of an AI rulebook means there is no waiting game — the obligations are already live.

Guidance → control, line by line

How each expectation maps to a NeutralAI control. The full cross-regulator table lives on the UK guidance map.

Consumer Duty: good outcomes when AI touches customer data

Mask before send

Customer identifiers, account references, and payment details are masked before prompts reach external AI providers — reducing the exposure that turns into a customer-outcome failure.

SM&CR: named accountability for AI use

Audit trail + DPIA evidence pack

Exportable logs of the control running give the accountable senior manager concrete evidence of the safeguards in place.

Operational control over data flows

BYOK + on-prem

Firms can keep the gateway inside their own environment and use their own provider contracts — the data flow stays within the firm’s documented perimeter.

Common questions

Has the FCA banned or restricted generative AI?

No. The FCA has chosen not to write AI-specific rules and instead applies the existing framework — Consumer Duty, SM&CR, and existing data and resilience requirements — to AI use. Its AI Live Testing programme actively supports firms deploying AI.

Who is accountable when AI goes wrong at a regulated firm?

Under SM&CR, a named senior manager. That is why evidence matters: the accountable individual needs to show reasonable steps, and technical controls with audit trails are exactly that kind of evidence.

Does masking customer data help with FCA expectations?

It addresses the data-exposure slice of the risk: masking reduces what external AI providers receive, and the audit trail documents the control. It does not by itself satisfy Consumer Duty or SM&CR — those are broader regimes about outcomes and governance.

This page summarises third-party guidance for convenience and is not legal advice. Summaries can go stale — always read the original at the source link above before relying on it. Last reviewed: 17 July 2026.

See what this control looks like in practice

The AI Confidentiality Checklist walks through usage discovery, exposure, policy, controls, and evidence in about 20 minutes — or bring one low-risk workflow to a live review.

The control

detect → mask → send → restore → audit

Reversible vault, 15-minute TTL. The model only ever sees placeholders.