Skip to content
Regulation and policy

FCA's Colin Payne says UK can lead applied financial AI

The FCA's head of innovation says the UK can lead trusted AI deployment in finance despite lagging in frontier AI. The data shows high adoption but little true autonomy.

By

Published
A giant bolted bank vault door stands shut while a small hinged flap near its base is propped open with a wooden wedge.

The Financial Conduct Authority's head of innovation has told a Scottish fintech audience that the UK can lead the way artificial intelligence is applied inside financial services, even though he believes the country has already lost the broader race to build the technology itself. Colin Payne made the remarks at Barclays' Glasgow office during a FinTech Scotland festival event, reported by Scottish Financial News on 2 October 2026.

The claim matters because it is really a question about regulatory tolerance for AI that acts with less human sign-off at each step. Payne reportedly predicted that 2027 would be the year AI agents go mainstream — software that does not just suggest an answer but carries out a task, such as initiating a payment or adjusting a portfolio. If regulated firms are moving from AI that helps a human decide to AI that decides, the industry needs to know what the regulator expects before deployment, not after.

Payne's argument rests on a combination: a large financial-services sector, an established fintech industry and, in his telling, regulation firms find trustworthy enough to build on. No comparative international data in the available record confirms this combination puts the UK ahead of other jurisdictions in applying AI to finance; the claim is Payne's attributed view, not an independently verified ranking.

Frontier models versus applied AI

Payne's distinction, as reported, separates two contests: building AI models themselves — large-scale systems originating mostly outside the UK — and applying AI reliably inside a regulated industry such as lending, fraud detection and portfolio management. His reported view is that the UK "missed the boat" on the first contest but can still win the second, because that takes sector expertise in risk and compliance, and a regulator willing to let firms test ideas under supervision.

The report does not make clear what Payne meant by saying the UK had "given away a lot of our crown jewels" in the wider AI race — whether he meant companies, researchers, intellectual property or computing capacity. That point should be read as unexplained, not filled in.

What the evidence already shows

The clearest test of the "trusted application" argument is how much AI UK-regulated firms already run, and how much operates unsupervised. The Bank of England and FCA's joint 2024 survey, published 21 November 2024, drew 118 responses from regulated firms, with international banks answering for their UK operations — a snapshot of respondents, not a census of the sector.

Measure2022 survey2024 survey
Firms using AI58%75%
Firms planning adoption within three years14%10%
Use cases with third-party implementation17%one-third

Adoption is high and rising among respondents, and the median number of use cases per respondent was expected to grow from nine to 21 within three years. But the survey draws a sharp line between automation and autonomy: 55% of reported use cases involved automated decision-making of some kind, yet only 2% were fully autonomous. Most financial AI in use today assists a human decision rather than replacing it.

Governance looks more complete on paper than in practice: 84% of respondents named an accountable person for their AI framework, yet only 34% reported complete understanding of the technologies they used, against 46% reporting only partial understanding.

The survey also found concentration risk in the AI supply chain: a third of use cases relied on third-party implementations, up from 17% in 2022, and the three most-named providers accounted for 73% of cloud providers, 44% of model providers and 33% of data providers cited. HM Treasury's July 2026 Adoption Plan flags this as a resilience and sovereignty issue.

The FCA's bargain: no new rulebook, same old duties

The FCA's stated position, set out in an industry-engagement update published 8 June 2026, is that it does not plan to introduce AI-specific rules. Instead, it says it will apply what already exists: the Consumer Duty, the Senior Managers and Certification Regime (SM&CR), and established governance and control expectations. This is the regulator's position as of that date, not a closed question — HM Treasury's July 2026 Adoption Plan calls for a review of the regulatory perimeter and says some AI and agentic-AI uses may need targeted clarification or adaptation of how existing rules apply.

That is not the same as AI being unregulated. The Consumer Duty requires firms serving retail customers to act in good faith, avoid foreseeable harm, and enable customers to pursue their financial objectives. It has applied to open products and services since 31 July 2023 and to closed products and services since 31 July 2024. Under SM&CR, a named senior manager remains accountable for an activity even where an AI system contributes to the outcome. PRA-regulated firms within the scope of Supervisory Statement SS1/23 — covering specified UK-incorporated banks, building societies and PRA-designated investment firms with relevant internal-model approvals — must apply the same model-risk management duties to AI and machine-learning models as to any other model. The current version of SS1/23 took effect on 23 April 2026.

Payne's reported confidence that this approach leaves room to innovate sits against a more cautious note from the FCA's Mills Review, published 6 July 2026, which names autonomous decision-making, outsourcing, hyperscale cloud reliance and unclear accountability chains as issues the regulator will need to anticipate specifically.

Experimentation without endorsement

Where the FCA has moved furthest is in giving firms a supervised place to test AI rather than writing new rules for it. The Supercharged Sandbox, built with NVIDIA, Anthropic and NayaOne, gives participants controlled access to GPU computing, enterprise AI tools, synthetic or curated datasets and expert support. Cohort 1 ran from September 2025 to January 2026, drawing 132 applications for 22 places. Cohort 2 launched on 13 July 2026, runs to 31 December 2026, drew 199 applications — 51% more than cohort 1 — and selected 21 organisations working on agent-led payments, fraud detection, AI governance, financial inclusion and business automation.

The FCA also runs AI Live Testing, supporting market-ready systems operating in real-world conditions with regulatory oversight, and said in June 2026 it would publish learning from the programme's second cohort in early 2027.

The Supercharged Sandbox carries an explicit caveat: participation is not FCA approval, endorsement or authorisation, and does not remove a firm's responsibility to comply with applicable rules. A firm that tests a product in the sandbox still has to satisfy the Consumer Duty, SM&CR and other relevant requirements when it goes to market.

What firms say they still need

HM Treasury's Financial Services AI Adoption Plan — prepared by independent AI champions Harriet Rees and Dr Rohit Dhawan and accepted by the government in July 2026 — names regulatory clarity and a review of the regulatory perimeter, the boundary of what counts as a regulated activity, as immediate priorities. It calls for joined-up guidance from the FCA, PRA, Information Commissioner's Office and Competition and Markets Authority on how the Consumer Duty, model-risk management, operational resilience, third-party risk and senior-manager accountability apply to common AI and agentic-AI use cases.

The plan does not dispute that existing principles should remain the foundation, but says firms find current rules hard to apply consistently to agentic systems, where software rather than a specific human instruction initiates the task. Before scaling a system that acts with less supervision, a firm needs confidence on points the plan flags as unresolved: liability if the agent errs, what consent a customer must give before it acts on their behalf, how to test for bias and foreseeable harm, what audit trail and human override to keep, and how far it can rely on an external provider without losing control of the outcome.

The consumer-protection test

Autonomy raises the stakes for the consumer at the other end of the transaction. An AI-generated recommendation or action can cost someone money, affect their credit standing, or deny them a product or service they were entitled to. What protection applies is fact-specific: Consumer Duty coverage depends on the particular retail product or service involved, and whether a complaint falls within the Financial Ombudsman Service's jurisdiction or a loss within the Financial Services Compensation Scheme's cover depends on the provider's regulatory status, the activity performed, the conduct in question and, for the FSCS, further eligibility conditions. Authorisation alone does not settle any of this. Readers who are unsure whether a given AI-assisted service is covered should check the FCA register and the FOS and FSCS rules directly, rather than assume protection either way.

The Mills Review cites research finding that about one in five UK adults surveyed were open to AI making financial decisions for them, and that roughly 26% said they trusted general-purpose AI tools for financial advice. These figures are specific to that research and should not be generalised beyond it.

Can trust become a UK advantage?

Payne's underlying bet is that regulation firms find trustworthy, combined with the UK's financial-sector depth, will let AI scale here faster and more safely than elsewhere. The evidence in hand is consistent with that being plausible: adoption among surveyed firms is high and growing, the FCA has built dedicated infrastructure for supervised experimentation, and the government has formally endorsed a plan to clarify the rules firms say they are struggling with.

What the record does not contain is proof that any of this currently puts the UK ahead of other jurisdictions. No comparative dataset on AI deployment, investment, productivity or consumer outcomes across countries appears in the material reviewed for this article. High adoption among the 118 survey respondents measures activity, not leadership, and the same survey's third-party concentration findings point to a dependency on a small number of overseas cloud and model providers that could just as easily be read as a vulnerability as a sign of strength.

What to watch next

HM Treasury has accepted the Adoption Plan's recommendations and will work with regulators and industry on next steps, though no implementation timetable has been settled. The FCA will publish learning from AI Live Testing's second cohort in early 2027, and Supercharged Sandbox cohort 2 runs to 31 December 2026 with a showcase scheduled for 25–26 November 2026. Any regulatory-perimeter review arising from the Adoption Plan, and any formal FCA material on good and poor AI practice, would signal whether reliance on existing rules survives contact with agentic AI at scale. Readers wanting the primary detail should consult the FCA's and HM Treasury's own publications rather than commercial summaries.

Sources

  1. Artificial intelligence in UK financial services - 2024 (opens in a new tab)

    Bank of England and Financial Conduct Authority · · Accessed

  2. AI in financial services: shaping our approach through industry engagement (opens in a new tab)

    Financial Conduct Authority · · Accessed

  3. Financial Services AI Adoption Plan (opens in a new tab)

    HM Treasury · · Accessed

  4. Supercharged Sandbox (opens in a new tab)

    Financial Conduct Authority · · Accessed

  5. SS1/23 – Model risk management principles for banks (opens in a new tab)

    Bank of England, Prudential Regulation Authority · · Accessed

  6. AI: Flipping the coin in financial services (opens in a new tab)

    Financial Conduct Authority · · Accessed