Summary
- Durham University research argues that financial institutions need a dedicated regulatory framework for AI to reduce consumer risks rather than relying solely on existing financial rules.
- The intervention cuts across the UK’s current sector-led approach, under which the FCA and Bank of England have largely applied existing obligations to AI.
- The debate is becoming more practical as agentic and multimodal systems move towards product design, customer interaction, decision-making, and financial transactions.
New research from Durham University Business School is challenging one of the central assumptions behind Britain’s approach to artificial intelligence in finance, arguing that financial institutions need a dedicated regulatory framework for AI if consumers are to be adequately protected. The intervention comes as regulators and government are simultaneously trying to accelerate AI adoption across financial services while relying largely on rules written before generative and agentic systems became commercially viable.
The UK does not currently have AI-specific financial regulation, and the Financial Conduct Authority and Bank of England have instead applied existing obligations covering areas such as consumer protection, governance, operational resilience, accountability, and risk management. Durham’s research argues that this may leave gaps as AI systems become more capable and more deeply embedded in financial products, particularly where automated systems influence decisions or interactions that directly affect consumers.
That disagreement has become more consequential as AI moves beyond relatively contained uses such as fraud detection, document processing, and internal analytics. Financial institutions are exploring systems that can generate personalised information, assist with product selection, automate customer interactions, analyse large volumes of personal data, and carry out multi-step tasks with less direct human intervention. The regulatory question is therefore shifting from whether existing rules technically apply to AI towards whether those rules provide sufficiently specific controls for systems whose behaviour can be difficult to predict or explain.
The argument from Durham runs against a position repeatedly advanced by Britain’s financial authorities. A Treasury Committee report published in January noted that the FCA and Bank of England considered the existing framework capable of dealing with AI risks, with the FCA pointing in particular to Consumer Duty and individual accountability rules. The committee itself was less comfortable with that position, concluding that rapid adoption was exposing risks to consumers and financial stability that required closer attention.
Existing rules meet a different kind of system
Much of UK financial regulation is deliberately technology-neutral, meaning a lender, insurer, investment company, or payments provider cannot avoid its obligations simply because a decision is made with a new type of software. Consumer Duty still requires companies to deliver appropriate outcomes, data protection law still governs personal information, senior managers remain accountable for regulated activity, and operational-resilience requirements do not disappear when an AI model is introduced into a process.
Technology neutrality has obvious advantages because regulators do not need to rewrite the rulebook every time a new model or software architecture reaches the market. It can also reduce the risk that highly prescriptive rules become obsolete before companies have implemented them. The approach becomes harder to sustain, however, when the technology introduces behaviours that existing control frameworks were not designed to interrogate, particularly where an AI system changes its outputs according to context, chains actions together, or operates through models supplied by a third party.
The FCA has been examining precisely those issues through its Mills Review into the longer-term impact of AI on retail financial services. Published in July, the review considers how advanced, multimodal, and agentic AI could alter the design and distribution of products, market structures, and the way consumers interact with financial institutions by 2030. The shift towards agentic finance raises a different supervisory problem from conventional chatbots because software may increasingly be able to make or execute decisions rather than merely provide information.
One difficulty is establishing responsibility when an automated outcome involves several layers of technology. A financial institution might use its own customer data, a third-party foundation model, an external cloud service, proprietary risk software, and an agentic layer that coordinates actions across them. Existing regulation may still make the regulated institution accountable, but determining whether a harmful outcome resulted from poor data, model behaviour, deficient controls, supplier changes, or an inappropriate instruction can be substantially harder than establishing responsibility for a conventional rules-based system.
Consumer protection becomes an engineering question
AI can affect consumers without making a formal lending or investment decision. Personalised interfaces may influence which products people see, automated assistants can determine how information is framed, and models can infer characteristics from large datasets that customers never consciously supplied. In financial markets, small changes to how choices are presented can alter borrowing, saving, insurance, and investment decisions, particularly where consumers assume that an apparently sophisticated automated system is more authoritative than it really is.
Technical controls consequently become part of the consumer-protection architecture. Financial institutions need to know which systems are permitted to make recommendations, what information they can access, when outputs must be reviewed, how decisions can be reconstructed, and whether customers can challenge automated outcomes effectively. Testing also has to cover more than average model accuracy because a system that performs well overall can still create unacceptable outcomes for particular groups or fail unpredictably when market conditions change.
Government policy is moving in the opposite direction from any presumption that AI adoption should slow while those questions are settled. Its Financial Services AI Adoption Plan, published in July, calls for the sector to move beyond isolated pilots and deploy AI more widely, reflecting a broader economic policy that treats adoption as a route to productivity and competitiveness. The FCA is likewise operating testing programmes intended to help companies experiment with AI while maintaining regulatory oversight.
A principle-based framework can create flexibility, yet ambiguity becomes expensive when compliance teams, model-risk specialists, lawyers, and product managers repeatedly have to interpret how older obligations apply to new capabilities. More specific AI rules could reduce some of that uncertainty, although badly designed requirements could equally freeze assumptions about technology that will change again.
Durham’s intervention therefore lands during a period in which Britain is already reconsidering how its financial rulebook should respond to increasingly autonomous software. The FCA’s reviews, government’s adoption programme, and the Treasury Committee’s earlier concerns approach the same implementation problem from different directions: AI is moving deeper into regulated activity before there is agreement over whether technology-neutral supervision is sufficient. As deployment expands, that disagreement will be tested by cases in which an automated system produces an outcome that existing rules can identify as harmful but struggle to explain, audit, or prevent.












