In early June 2026, the Financial Conduct Authority confirmed it will not draft new legislation specifically for artificial intelligence. Instead, it expects firms to apply existing regulatory frameworks to their automated systems[1].
For the owner of an advice firm, this removes a major excuse for delaying implementation. The rules of the game are not going to change just because the technology has. Under the Senior Managers and Certification Regime, accountability for an automated decision remains exactly where it was for a manual one: with the designated human leader.
The market now shows clear evidence of how this is playing out. Financial services currently leads all other sectors in moving AI agents from pilot phases into active production, hitting a 21 per cent deployment rate this summer[2]. But as the technology moves from internal testing to handling live client data, the compliance risks multiply.
Why the focus is moving to client-facing work
Firms are shifting their automation budgets from the back office to the front office because the return on investment is immediate. Until recently, most investment concentrated quietly on internal operations. Firms used language models to extract data from provider statements or to draft internal meeting summaries.
Now, systems are touching the client directly. Digital onboarding processes are proving highly effective for advice firms that want to scale. Research from the University of Edinburgh in 2023 showed that automated onboarding reduces KYC processing time by 34 per cent in regulated financial services, though this data may now be outdated[3]. It achieves this by routing identity documents and flagging discrepancies before a human administrator ever needs to look at the file.
However, as soon as an automated system interacts with client data or onboarding processes, regulatory scrutiny automatically increases. The European Central Bank has noted that customer-facing AI presents substantial risks of customer discrimination if the systems lack proper validation[4]. You can no longer treat an automation project as a purely technical exercise. When a system dictates how quickly a client gets through onboarding, or how their risk profile is evaluated, it is a compliance event that falls squarely under the Consumer Duty.
The hidden risk of granting system access
The primary security threat in modern automation is giving an AI agent too much access to your internal data without human oversight. Recent industry tracking shows that 54 per cent of enterprises have already experienced an AI agent security incident, usually because systems were allowed to share credentials across different software tools[5].
The market is moving rapidly toward agentic AI, where the system does not just answer a question, but executes a multi-step workflow across different applications. While 75 per cent of businesses express interest in these autonomous agents, a vendor study by Digital Applied found that 40 per cent of such projects are cancelled due to deployment and integration challenges[6]. The failure point is frequently governance.
Risk does not disappear because a process is automated. It simply changes addresses.
When you connect an AI model to your CRM, your document storage, and your email client, you create a new attack surface. The FCA, alongside the Bank of England and HM Treasury, has warned that frontier AI models now exceed baseline cyber resilience expectations[7]. If an automated workflow has permission to read a client file, write an email, and send it without a human checking the output, you are carrying unnecessary risk.
Any automated workflow handling regulated data must include clear breaks where a staff member reviews the action. The system flags the missing information or drafts the suitability paragraph, but a qualified human makes the final decision.
How to align your automation with regulatory expectations
If your firm is using AI tools to handle regulated data, you need to understand exactly what those systems can see and do. You do not need to pause your operations, but you do need to formally assess them.
1. Map your tool access. List every AI assistant or automated workflow your team currently uses. Check whether these tools have read-only access to your data or if they can execute actions, such as sending emails or updating client files on their own.
2. Determine the level of integration. Categorise your tools using a simple framework to understand your exposure. Level 1 (education) includes basic prompts and standalone tools, which require user input for every step. Level 2 (integration) covers connected applications using platforms like Zapier to pass data between your systems. Level 3 (custom build) involves bespoke pipelines and autonomous agents. The higher the level, the more rigorous your security controls and compliance checks need to be.
3. Insert mandatory human review. Ensure that no automated system can finalise a regulated document, approve a new client, or make a suitability decision without human intervention. The AI can prepare the groundwork, but a person must click the button to approve it.
The regulators have made their position clear. You do not need to wait for a new AI rulebook to start modernising your firm, provided you govern the technology with the same discipline you apply to your human advisers. If this is the situation your firm is in, a discovery call with Cordrey Consulting is a good place to start.
This article is for informational purposes only and does not constitute regulated financial advice or a compliance opinion. Consult a qualified compliance professional for advice specific to your firm.
Sources
[1] Financial Conduct Authority, ‘Approach to AI in financial services’, Financial Conduct Authority, 9 June 2026. Available at: https://www.fca.org.uk/news/blogs/ai-financial-services-approach [2] Zen van Riel (2026) ‘Why 78% of AI Agent Pilots Never Reach Production’, AI Engineer Blog. Available at: https://zenvanriel.com/ai-engineer-blog/ai-agent-scaling-gap-pilot-production-2026 [3] University of Edinburgh (2023) ‘Digital onboarding reduces KYC processing time by 34% in regulated financial services’, University of Edinburgh. [4] European Central Bank (2024) ‘Customer-facing AI in financial services presents substantial risks of customer discrimination’, European Central Bank. [5] VentureBeat, ‘The agent security gap: 54% of enterprises have already had an AI agent incident’, VentureBeat, 17 July 2026. Available at: https://venturebeat.com/ai/the-agent-security-gap-54-of-enterprises-have-already-had-an-ai-agent-incident-and-most-still-let-agents-share-credentials [6] Digital Applied (2026) ‘Why Agentic AI Projects Get Canceled (and How to Ship)’, Digital Applied. Available at: https://www.digitalapplied.com/blog/agentic-ai-project-cancellations-gartner-40-percent-2026. Vendor-sourced. [7] Financial Conduct Authority, ‘FCA, PRA and Bank of England joint statement on frontier AI and cyber resilience’, Financial Conduct Authority, 25 May 2026. Available at: https://www.fca.org.uk/news/statements/fca-boe-treasury-joint-statement-frontier-ai-models-cyber-resilience