AI & Compliance
The FCA Isn't Writing AI Rules. Here's What It's Doing Instead
No AI-specific rulebook, no bespoke licensing regime — the FCA has said twice now that it isn't planning one. That's not regulatory neglect. It's a deliberate bet, and it puts more weight on judgment a compliance team already has to have, not less.
July 24, 2026 · 8 min read
Compare two regulators looking at the same problem. The EU has written a horizontal, cross-sector AI statute — the AI Act — that classifies AI systems into risk tiers and attaches specific, enumerated obligations to each tier: documented risk management for high-risk systems, conformity assessments, human oversight built into the design. The UK’s Financial Conduct Authority has looked at the same underlying risk and, as recently as December 2025, had its chief executive reaffirm that it will not be introducing AI-specific rules at all. Two serious regulators, same technology, opposite instruments.
The FCA’s actual reasoning, not a caricature of it
It’s tempting to read “no new AI rules” as light-touch regulation or a wait-and-see punt. That’s not the stated logic, and it’s worth taking the stated logic seriously rather than assuming the gap is an oversight. The FCA’s argument is that AI capability is moving on a three-to-six-month cycle — materially faster than any rulebook can be drafted, consulted on, and finalized — and that writing specific rules now risks locking in assumptions about a specific generation of the technology that will be obsolete before the rules are even in force. Instead, the position is that existing frameworks already reach the risks that matter: the Senior Managers and Certification Regime for accountability, Consumer Duty for outcomes, and existing model risk management expectations for how any model — AI or otherwise — gets validated and monitored. The bet is that outcomes-based, technology-neutral regulation ages better than a rulebook written against today’s systems.
Alongside that, the FCA runs an AI Lab, and in 2025 ran a consultation on an “AI Live Testing” pilot — a mechanism for firms to test AI deployments in closer collaboration with the regulator rather than in isolation, then face examination only where something has gone genuinely wrong. That’s a meaningfully different posture from “wait for the AI Act’s obligations to bite on the date specified in the regulation.”
What this actually demands of a compliance function
A principles-based regime with no AI-specific checklist puts more interpretive weight on the compliance function, not less. There’s no enumerated list of “high-risk AI use cases” to walk through and tick off, the way Annex III of the EU AI Act gives you one. There is an existing, familiar set of questions that now has to be asked of every AI deployment with the same rigor previously reserved for material model changes: who is the accountable senior manager, what’s the evidence that the outcome is fair and monitored, and would this hold up to scrutiny if a customer complained or a transaction went wrong. The absence of an AI-specific rulebook is not the absence of a standard — it’s a bet that the existing standard, applied honestly, already covers it.
Why the comparison matters even for firms outside EU AI Act scope
A UK-only firm isn’t bound by the AI Act’s classification tiers, but the Act is still useful as a reference model precisely because it’s explicit about distinctions the FCA leaves for firms to work out themselves — the fraud-detection-versus-AML split described elsewhere on this site is one example: the EU had to legislate the boundary; a UK firm has to reason it out under a principles-based duty to get the outcome right regardless of whether a specific rule spells it out. Treating the EU’s enumerated categories as a diagnostic checklist — even without being bound by them — is one of the more useful ways to stress-test whether a UK firm’s own AI governance would survive the kind of scrutiny a more prescriptive regime forces by default.
The honest summary: the FCA is trusting compliance functions to apply judgment to a fast-moving problem instead of handing them a fixed answer key. That’s either the right call or a gap waiting to be exposed, and which one it turns out to be depends entirely on whether firms treat “no new rules” as permission to relax, or as confirmation that the judgment they were already supposed to be exercising now has to stretch further than it used to.