Skip to content
AI & Finance

AI's biggest gains in UK finance may sit behind the chatbot

UK survey data show AI deployment is heaviest in operations, internal-process optimisation, cyber security and fraud detection, not chatbots, though customer support has the largest planned adoption. New FCA, automated-decision and reporting rules now apply.

By

Published
An enormous rubber date-stamp towers over a small stack of blank paper forms waiting on a desk.

The biggest effect of artificial intelligence (AI) on UK financial services is likely to be felt first in places customers never see: document processing, fraud screening, compliance review and internal workflow, rather than in the chatbot on a banking app. That is the conclusion supported by the most detailed public evidence on how UK-regulated firms are actually using AI, and it matters now because the Financial Conduct Authority (FCA) has confirmed how it intends to supervise this activity, while new rules on automated decisions, third-party risk and incident reporting are either already in force or due within the next 18 months.

The evidence comes chiefly from a joint survey run by the Bank of England and the FCA in 2024, which drew 118 responses from UK banks, international banks' UK operations, insurers, non-bank lenders, investment and capital-markets firms, financial market infrastructures, payments firms and other regulated businesses. It found that 75% of respondents were already using AI and a further 10% planned to within three years. These are survey results, not an estimate for every UK financial-services business; the Bank of England and FCA caution against treating the sample as a census of the sector.

The case for looking behind the interface is real, but qualified rather than absolute. The same survey shows that customer support, including chatbots, has the largest planned increase in adoption of any use case over the following three years. Dismissing customer-facing AI as a marginal concern would not be supported by the data either.

What the survey actually shows

Adoption varies sharply by sector. Among respondents, 95% of insurance firms and 94% of international banks' UK operations reported using AI, against 57% at financial market infrastructures, the lowest figure in the survey. The median firm reported nine AI use cases in 2024 and expected that to rise to 21 within three years.

By category, operations and IT accounted for about 22% of all reported AI use cases, roughly twice retail banking's 11% share, with general insurance at 10%. Named by current use rather than category, internal-process optimisation was the most widely deployed application, used by 41% of respondents, ahead of cyber security at 37% and fraud detection at 33%.

Use caseAlready in use (2024)Additional planned adoption (within 3 years)
Internal-process optimisation41%31%
Cyber security37%not separately reported
Fraud detection33%31%
Regulatory compliance and reportingnot separately reported32%
Customer support, including chatbotsnot separately reported36%

Source: Bank of England and FCA, Artificial intelligence in UK financial services – 2024.

Foundation models, including large language models, made up 17% of reported use cases, and operations and IT accounted for about 30% of those. Some automated decision-making featured in 55% of use cases, but fully autonomous decision-making accounted for only 2%. Firms classified 62% of use cases as low materiality, 22% as medium and 16% as high, with high-materiality uses concentrated in general insurance, risk and compliance, and retail banking.

Where the gains look clearest

The clearest, best-documented gains sit in document-heavy, rules-governed processes that firms already run at scale. A 2019 UK government case study, built around an anonymised bank, described a sales-quality compliance review that originally needed 120 reviewers, more than ten data sources and 180 data points, taking about four hours per case. AI-assisted document extraction and workflow automation was reported to cut the review's duration by 80%. As an anonymised, single-firm study, this is illustrative rather than generalisable, but it shows the kind of structured, repeatable task where AI has had a measurable effect.

Not every efficiency gain in a back office requires AI; some of what firms report may be achievable with simpler rules-based systems or conventional software, and the sources reviewed for this article do not provide a UK-wide comparison against that non-AI baseline.

Fraud detection: a non-UK data point worth reading carefully

Fraud detection was already in use at a third of 2024 survey respondents, with a further 31% planning to adopt it. The strongest quantified recent example comes not from the UK but from Bank of Ireland, which reported in June 2026 that AI-led payment-fraud controls introduced from 2024 were associated with a 30% reduction in attempted fraud, a 25% reduction in customer losses, an 87.1% fall in false positives, an 85% fall in alert volumes and a halving of case-handling time.

Bank of Ireland operates in Northern Ireland, but the published figures are group-level and are not disaggregated between the Republic of Ireland and Northern Ireland, so they cannot demonstrate UK-specific performance. This is first-party company evidence, not an independently verified study, and should be read as context for the technical opportunity rather than proof of what any UK firm would achieve. A sharp fall in false positives matters beyond cost too: a fraud control that wrongly flags a genuine transaction can delay or block a legitimate payment.

Decision engines: more material, more risk

Lending, underwriting and claims decisions sit in exactly the areas the 2024 survey flagged as carrying the most high-materiality AI use: general insurance, risk and compliance, and retail banking. That concentration supports the view that AI decision engines could be more economically consequential than low-materiality productivity tools, because they influence risk selection, pricing and who gets access to credit or cover.

It does not, however, establish a reliable sector-wide gain. No source reviewed publishes a comparative UK figure for loss ratios, approval rates, pricing accuracy or complaints attributable specifically to AI underwriting rather than conventional statistical models. The FCA's July 2026 Mills Review names algorithmic bias and opaque decision-making among the risks AI may introduce, alongside sophisticated fraud, identity abuse, market concentration and systemic vulnerability, and notes that institutional inertia may make change more incremental than some forecasts suggest.

Where a decision based on personal data is solely automated and has a legal or similarly significant effect on a person, UK data-protection law imposes specific safeguards; a decision involving meaningful human review falls outside this framework. Since 5 February 2026, under the Data (Use and Access) Act 2025, firms must give the person information about the decision, an opportunity to make representations, a path to meaningful human intervention and a right to contest the outcome. Additional restrictions apply where special-category personal data is involved. This replaced the previous UK GDPR Article 22 regime; it is not a general ban on automated lending or underwriting decisions, but a solely automated significant decision cannot simply be left unchallenged.

Why chatbots still matter

Customer support, including chatbots, has the largest planned adoption increase, at an additional 36% of respondents over three years. FCA research on two 2025 consumer-facing large language model pilots found the technology could simplify complex financial information, improve readability and accessibility, and found user appetite for AI assistance. Validating outputs required combining human judgement with automated tools, and effectiveness depended heavily on how the model was built into the customer journey. A chatbot's value should be judged on comprehension, accessibility and what happens next, not on fluency or speed of reply.

The UK governance test

The FCA restated on 8 June 2026 that it does not intend to introduce AI-specific financial-services rules. It will rely instead on existing, technology-neutral frameworks: the Consumer Duty, the Senior Managers and Certification Regime (SM&CR) and its general governance and control expectations. That is not the same as AI being unregulated; existing conduct, accountability, data-protection and operational-resilience obligations apply to AI use in the same way they apply to any other system or process.

The FCA expects firms to address governance, model testing, outcome monitoring, fair treatment of customers including those in vulnerable circumstances, and the ability to explain AI-driven decisions. Firms should assign accountable ownership for AI systems spanning product, risk, operations and technology teams, mapping SM&CR senior-manager responsibilities onto each use case; requirements depend on the firm's permissions and applicable Handbook provisions. Where AI affects retail products, communications or support within the FCA's perimeter, the Consumer Duty requires firms to assess, test and evidence outcomes for different customer groups, with the board reviewing an outcomes report annually; the first assessment was due by 31 July 2024, following the Duty's phased introduction from 31 July 2023.

A third of reported 2024 AI use cases were third-party implementations, so supplier oversight matters too. The FCA's critical-third-party regime took effect on 1 January 2025, with designation regulations for the first critical third parties in force from 13 July 2026. The regime adds direct oversight of designated systemic providers, but the FCA is explicit that it complements, rather than replaces, a firm's own responsibility for third-party risk, including data access, auditability, resilience and exit planning. New harmonised requirements on reporting operational incidents and material third-party arrangements were published by the FCA, the PRA and the Bank of England on 18 March 2026 and apply from 18 March 2027.

What to watch next

No authoritative, comparable UK dataset measures realised cost savings or productivity by AI use case across banks, lenders, insurers and fintechs, and the 2024 survey's three-year adoption plans are expectations stated at the time, not deployments verified as of 2 October 2026. A reasonable comparison would set any AI system against a non-AI baseline and track cost per case, cycle time, error and override rates, fraud losses, false positives, complaints, and outcomes by customer group, rather than counting use cases alone.

The FCA said in June 2026 that it intended to set out examples of good and poor AI governance practice later in the year; readers should check the FCA's published material directly for whether and when that appears. Guidance from the Information Commission, which replaced the Information Commissioner's Office on 30 September 2026, on AI and data protection is also under review following the Data (Use and Access) Act 2025, so the Act remains the safer reference point until refreshed guidance is published. Anyone affected by an AI-influenced financial decision, including one on credit, pricing, fraud or a claim, should look to the firm's own explanation and, where the decision was solely automated and significant, to the contestability safeguards that have applied under UK data-protection law since 5 February 2026.

Sources

  1. Artificial intelligence in UK financial services - 2024 (opens in a new tab)

    Bank of England and Financial Conduct Authority · Accessed

  2. AI in financial services: shaping our approach through industry engagement (opens in a new tab)

    Financial Conduct Authority · · Accessed

  3. Money talks: Lessons from 2 LLM pilots on consumer guidance (opens in a new tab)

    Financial Conduct Authority · · Accessed

  4. Consumer Duty information for firms (opens in a new tab)

    Financial Conduct Authority · Accessed

  5. PRIN 2A The Consumer Duty (opens in a new tab)

    Financial Conduct Authority · Accessed

  6. Senior Managers and Certification Regime (opens in a new tab)

    Financial Conduct Authority · Accessed

  7. Data (Use and Access) Act 2025, Part 5 Chapter 1 (opens in a new tab)

    The National Archives · · Accessed

  8. AI and data protection risk toolkit (opens in a new tab)

    Information Commissioner's Office · Accessed

  9. How a UK-based bank used AI to increase operational efficiency (opens in a new tab)

    Government Digital Service, Office for Artificial Intelligence and Department for Science, Innovation and Technology · · Accessed

  10. Critical Third Parties: Strengthening UK Financial Services (opens in a new tab)

    Financial Conduct Authority · · Accessed

  11. PS24/16: Operational resilience: Critical third parties to the UK financial sector (opens in a new tab)

    Financial Conduct Authority, Prudential Regulation Authority and Bank of England · · Accessed

  12. PS26/2: Operational incident and third party reporting (opens in a new tab)

    Financial Conduct Authority, Prudential Regulation Authority and Bank of England · · Accessed