The Mills Review is here: ‘in the loop’ is no longer enough
This morning the FCA published the Mills Review, AI and the future of retail financial services, the 147-page report on how AI will reshape retail financial services by 2030, led by Sheldon Mills at the FCA Board’s request.[1] When the Review launched in January, we wrote that the FCA was quietly shifting from monitoring AI to regulating it. The Review has now reported, on schedule, and it is more consequential for firms using AI in advice than a new rulebook would have been.
Here is the one-line summary: no new rules, and a much higher bar.
No new rules, and why that raises the bar
The Review’s central regulatory conclusion is "progressive adaptation, not wholesale replacement." The Consumer Duty, the Senior Managers Regime, and the conduct framework are judged sound foundations for an AI-enabled financial system, and the firms consulted did not ask for a new regime, they asked for clarity on how the existing one applies as AI takes on more of the work.[2]
That sounds like relief. It is the opposite. New rules come with consultation periods, implementation windows and transition relief. Supervisory interpretation of existing rules comes with none of those. The expectations described in this Review attach to obligations firms are already under, which means the evidence bar rises from the moment supervisors start asking the Review’s questions, not after a rulemaking cycle. The Review explicitly recommends the FCA "strengthen expectations on evidencing outcomes and control": firms should be able to demonstrate how outcomes are delivered, how controls operate, and how accountability is exercised where AI is embedded in decision-making.[3]
The autonomy spectrum is the new common language
The Review’s organising idea is a five-level autonomy spectrum: the human as operator, collaborator, consultant, approver, and finally observer, where AI acts within agreed limits and the human monitors outcomes. Its regime-by-regime analysis finds existing frameworks operate effectively at the first three levels, and come under strain exactly where firms are heading. At the observer level, the Review warns, "meaningful human control [is] likely to be difficult to evidence."[2]
Expect the spectrum to become the shared vocabulary between firms and supervisors. Every AI use case in your advice process now has an implicit question attached: which level is this, where does the human sit, and can you prove it?
‘In the loop’ is officially not enough
The sentence compliance teams should pin to the wall is on page 30:
"It will not be enough to say that a person remains ‘in the loop.’ Firms will need to be clear about what the person is expected to do, what information they receive, when they can intervene, how challenge is recorded and how escalation works."[4]
Read that list again. It is not a description of a policy document. It is a description of evidence infrastructure: reviewer assignment, the material put in front of the reviewer, intervention points, recorded challenge, escalation paths, each one captured, timestamped and attributable. The Review makes the same point about outputs themselves: in regulated activity, "a useful answer is not enough if the basis for it cannot be reconstructed."[5]
On senior manager accountability, the Review is equally practical. It notes that "assurance tools, including pre-deployment and ongoing checks, could better enable senior managers to take ‘reasonable steps’ to prevent regulatory breaches", and that firms will need "senior managers who can evidence reasonable steps in automated environments."[6] The SMF who signs the Statement of Responsibilities needs more than a policy; they need a live record that the controls ran.
Governance is now a competitive advantage
The most commercially interesting passage in the Review is not about risk at all. Discussing firm transformation, it concludes that governance is becoming "an enabler of capability": firms that can demonstrate auditability, explainability, robust testing, clear permissions, effective monitoring and escalation "will be able to deploy AI more confidently," while firms that cannot "may be slower to adopt or may expose consumers and markets to greater risk." And then, pointedly: "acquiring a reputation for trusted AI processes could win business."[4]
These are, in the Review’s words, "not additional safeguards, but the conditions that enable AI to be deployed in regulated environments." The firms that treat oversight evidence as infrastructure, rather than paperwork, get to move further along the autonomy spectrum, sooner, with the regulator’s confidence. The firms that cannot evidence control get to watch.
The Review also resets expectations on model governance: point-in-time validation is no longer enough. Firms will need "live monitoring, tracking drift, model degradation and outliers", governance that "may no longer work through periodic reviews but operate continuously alongside the systems it is designed to control."[4]
What firms using AI in advice should do this quarter
Map your AI use cases to the spectrum. For each one, write down where the human sits, operator, consultant, approver, and what would need to be true, and provable, to move up a level. This is the frame supervisors will use.
Turn oversight into evidence. Work through the page-30 list against your current process. If reviewer decisions live in email threads and shared drives, you can assert oversight but not evidence it, and the Review has just made evidence the standard. Every review should produce a reconstructable record: who, what they saw, what they decided, why, and when.
Extend governance past deployment. A model validated at go-live and never monitored again is exactly the pattern the Review calls out. Drift detection, outlier monitoring and outcome tracking need to run continuously, and leave a trail.
Prepare for structured, continuous reporting. The Review’s recommendation for an AI-enabled "agentic supervisory model" would move supervision from periodic, document-based returns towards continuous, event-driven data flows, and it depends on firms providing "timely, structured, high-quality data."[7] Firms whose compliance records are already structured, verifiable data will find that transition nearly free. Firms whose records are spreadsheets will not.
Where Bedrock fits
We built Bedrock for the world this Review describes. The page-30 list reads almost like a product spec: what the reviewer is expected to do, what they see, when they can intervene, how challenge is recorded, how escalation works. That is, point for point, what Bedrock Review captures on every piece of AI-assisted advice: routing to a qualified reviewer, structured checklists, read-completion and time-on-document, recorded annotations and rationale, and SLA-enforced escalation. The requirement that outputs be reconstructable is what Bedrock Ledger provides: every event immutably recorded, hash-chained, signed, and exportable as a one-click reasoning chain. The shift to continuous model governance is our model registry and drift detection. The pre-deployment checks the Review ties to senior managers’ reasonable steps are our Consumer Duty impact assessments, each anchored to the ledger, each independently verifiable.
The Mills Review has made the case we have been making since we started: in regulated financial services, AI adoption runs at the speed of provable oversight. If you want to see what that infrastructure looks like before your next board discussion of the Review, you can spin up a Bedrock sandbox and put a record through the full loop this afternoon.
References
- FCA, "The Mills Review: AI and the future of retail financial services", July 2026
- The Mills Review, July 2026, Executive summary and "Regulatory implications of AI-enabled finance", pp. 8-9, 79-81 and Figure 16
- The Mills Review, July 2026, Priority recommendation 3, "Monitor the transition to autonomous models and adapt regulatory frameworks", pp. 102-105
- The Mills Review, July 2026, System shift 1, "The transformation of firms", pp. 30-31
- The Mills Review, July 2026, "The systemic driver: advances in AI capability", p. 17
- The Mills Review, July 2026, "Regulatory implications", p. 81 and p. 28
- The Mills Review, July 2026, Priority recommendation 6, "Build and adopt an AI-enabled agentic supervisory model", pp. 110-113
Ready to build your compliance infrastructure?