What happened
Compliance Week reported on 14 September that experts believe the U.K.'s principles-based approach to financial services regulation should remain fit for purpose in an age of AI, on one condition: the framework has to be reviewed regularly.
That caution sits on top of a position the Financial Conduct Authority has already published and has not moved from. The regulator describes its approach as principles-based and focused on outcomes, states that it does not plan to introduce extra regulations for AI, and says it will rely instead on frameworks it already has, including the Consumer Duty and the Senior Managers and Certification Regime.
The evidence base behind that stance is substantial. The FCA's review into how AI will reshape retail financial services, led by executive director Sheldon Mills and published in July 2026, identified four likely shifts: the transformation of how firms operate, a change in consumer journeys, a reshaping of competition and market power, and an amplification of fraud and cyber risk. Research commissioned for it found around a fifth of U.K. adults, about 11 million people, likely to use agentic AI acting on their behalf. The regulator's 2026/27 work programme also commits it to using AI to speed up authorisations and review documents from firms.
Why this is a GRC story
Principles-based regulation moves work from the regulator to the firm. There is no prescribed control list to tick, only outcomes you have to be able to demonstrate, which means the burden of proof lives in your own documentation. For AI, that is a demanding place to be, because the thing you are being asked to evidence is not a process that runs the same way every time.
Accountability is the part that already applies. The Senior Managers and Certification Regime was written for this situation. If a model is making or shaping decisions about customers, someone senior has to be answerable for how it was validated, what it is allowed to see, and how a bad outcome gets corrected. Consumer Duty adds the parallel test: can you show the outcome is fair and the customer was not disadvantaged. Neither framework needed an AI amendment to bite.
The "regular review" caveat is the real headline. The argument is not that today's rules are wrong, it is that this is a temporary judgement. Experts are describing a bet that existing frameworks stretch far enough, held on the condition that the regulator keeps reassessing whether they still do. That is a reasonable position, and it is also one that can be withdrawn, which matters if you are building an AI programme on the assumption that the goalposts are settled.
What to watch
Watch whether the FCA publishes more specific expectations on the areas where principles are hardest to evidence: audit trails, human oversight of automated decisions, and how firms document the logic behind a model's output. Those are the details that decide whether a principles-based approach stays workable in supervision.
Watch for the point at which a market incident forces the question. Principles-based regimes tend to hold until a failure tests them, and then everyone discovers that the expectation was always higher than the published guidance implied. Firms that treat documentation as the control now will be the ones with less to reconstruct later.
Attribution: Analysis based on Compliance Week's reporting and the FCA's own published guidance on AI in financial services. This article is original commentary, not a repost of the source material.
