Your browser does not support JavaScript! Please enable the settings.
↑

Regulators Are Watching Agentic AI: A Practical FCA and Bank of England Briefing for Product Leaders

A practical, action-oriented companion briefing on what fintech product leaders should do now in response to the FCA's and Bank of England's statements on agentic AI.

Regulators Are Watching Agentic AI: A Practical FCA and Bank of England Briefing for Product Leaders

Two statements from UK financial regulators, three months apart, have quietly reset the baseline for what "AI readiness" means in financial services. In June 2026, FCA chief executive Nikhil Rathi delivered a speech titled "Rethinking regulation for the age of AI." In August 2026, Bank of England Governor Andrew Bailey, writing as Chair of the Financial Stability Board, told the G20 that frontier AI's impact on cyber risk is the financial system's most immediate concern.

A companion briefing on this site examines what these statements mean for governance and systemic risk. This piece asks a narrower, more operational question: if you lead a product team at a scaling fintech platform, what should you actually do differently starting this week?

The honest answer is not "wait for the rules." Both regulators have made clear that formal legislation will lag the technology, and that they intend to act, and to expect firms to act, ahead of it.

What Rathi Actually Told Product Leaders to Expect

Read closely, Rathi's speech is less a warning and more an operating manual for how the FCA intends to supervise agentic systems. Four points are worth product leaders' direct attention.

Agentic systems are being treated as a distinct category, not "more AI"

Rathi drew a sharp line between generative AI that "summarise, detect, or automate" and the next phase: "systems that don't just support financial decisions, but coordinate and transact." He called it "a profound step change to the structure and operation of markets." If your roadmap still files agentic features under the same governance process as a chatbot or a document summariser, it is behind where the regulator's own thinking has already moved.

Accountability has to be traceable to a human, by design

The speech was explicit: "Accountability for regulated activities and outcomes must remain clear," with systems "designed with the right human oversight, and in a way that gives consumers confidence to engage." This is a product requirement, not a policy statement. It means every agentic workflow needs a documented answer to "who is accountable if this goes wrong," traceable at the point of design, not reconstructed after an incident.

The FCA is building its own agentic tooling, and expects firms to keep pace

The FCA is exploring agentic AI as a "first responder" for wholesale market monitoring, working across a billion rows of data daily. A regulator this well-instrumented will notice gaps between what firms report and what its own systems observe faster than in the past. Firms whose internal monitoring is manual or periodic will increasingly look slow by comparison.

Sandboxes and structured engagement are open now

Rathi pointed product leaders toward concrete, currently available mechanisms: the FCA's Supercharged Sandbox, where firms test with real-world data and compute; the AI Lab, which recently added a dedicated Agentic Academy; and the AI Consortium run jointly with the Bank of England. He also flagged the forthcoming Mills Review on how AI could reshape retail financial services, and a later publication on good and poor AI practice. None of this requires waiting for a rulebook. It is an invitation to engage now.

What Bailey's Letter Adds to the Operational Picture

The Bank of England and FSB letter is aimed at finance ministers and central bank governors, not product teams directly, but two elements translate directly into product decisions.

Cyber risk from frontier AI is now a named, prioritised concern

The letter states plainly that "the most immediate concern is the potential impact of frontier AI on cyber risk," and that frontier models may "materially alter the speed and scale" of attacks. For a product team, this means threat modelling for agentic features can no longer treat AI purely as a defensive tool (fraud detection, anomaly monitoring). It must also model AI as a capability available to attackers, and design accordingly.

Concentration risk in your own vendor stack is now a systemic-level concern

The letter flags financial services' growing dependence on a small number of AI and cloud infrastructure providers as a source of systemic risk, and notes that many jurisdictions lack adequate protocols to manage frontier model risk. Rathi's speech echoes this from the supervisory side, pointing to the UK's Critical Third Parties regime. Product leaders should treat their model and cloud provider list as a resilience artefact that senior leadership reviews, not a procurement decision made once and forgotten.

A Practical Readiness Checklist

None of the following requires new legislation to exist. It requires product leadership treating the current regulatory direction as a design brief.

1. Classify agentic capabilities separately from generative AI features

Any feature where the system can take an action, initiate a transaction, adjust an account, trigger a payment, without a human confirming it in the moment, should sit in a distinct governance category from a summarisation or chat feature. Rathi's own framing supports this distinction; your internal risk register should reflect it too.

2. Document the accountable human for every autonomous action

For each agentic capability, write down, specifically, who is accountable if it acts wrongly, what the escalation path is, and how a customer or supervisor could trace the decision back to a person and a rationale. If this cannot be answered in a sentence, the feature is not ready to ship.

3. Build a live inventory of AI and cloud dependencies

List every model provider, cloud region, and critical sub-processor behind agentic and AI-driven features. Assess what happens operationally, not just contractually, if any one of them is degraded, changes terms, or is compromised. This inventory should be reviewed at board level with the same seriousness as payment rail dependencies.

4. Extend threat modelling to assume AI-augmented attackers

Security reviews for agentic features should explicitly consider that an attacker may have access to frontier AI capabilities comparable to your own defensive tooling. This is a direct implication of the FSB letter's framing, not a theoretical exercise.

5. Engage the FCA's existing mechanisms rather than waiting

The Supercharged Sandbox, the AI Lab's Agentic Academy, and the joint AI Consortium with the Bank of England are live, structured ways to test agentic products with regulatory visibility before a formal rulebook exists. Platforms that engage now build a track record and a relationship; platforms that wait build neither.

6. Watch for the Mills Review and the FCA's forthcoming AI practice publication

Rathi confirmed the Mills Review on AI's impact on retail financial services was imminent at the time of the speech, along with a later publication distinguishing good from poor AI practice. Product and compliance leads should treat both as required reading on release, not background noise.

Where This Differs From the Governance Conversation

It is worth being explicit about what this piece is not. A companion analysis on this site addresses the governance and systemic-risk framing directly, mapping what the Bank of England's warning means for board-level risk oversight. This piece is deliberately narrower: it treats the same two source statements as an operational brief for product leadership, not a risk committee memo. Read together, the two pieces cover both the "why this matters" and the "what to do" for a fintech platform navigating the same regulatory signal.

Platforms building on embedded finance and digital wallet infrastructure are especially exposed to both dimensions Rathi and Bailey raised: agentic transaction flows sitting close to customer money, and dependency chains running through a small number of AI and cloud providers. Product leaders in this space have the most reason to move first.

Frequently Asked Questions

What did the FCA say about agentic AI specifically?

In his June 2026 speech "Rethinking regulation for the age of AI," FCA chief executive Nikhil Rathi described agentic AI as a step change from systems that support financial decisions to systems that coordinate and transact autonomously. He said accountability for regulated outcomes must remain clear, systems must be designed with appropriate human oversight, and confirmed the FCA is itself trialling agentic AI to monitor wholesale markets.

What should a product team do now, before formal agentic AI rules exist?

Classify agentic capabilities separately from generative AI features, document the accountable human for every autonomous action, build a live inventory of AI and cloud dependencies, extend security threat modelling to assume AI-augmented attackers, and engage the FCA's existing sandbox and consortium mechanisms rather than waiting for legislation.

Are the FCA's Supercharged Sandbox and AI Lab open to fintech platforms now?

Yes. The FCA described both as live mechanisms: the Supercharged Sandbox lets firms test with real-world data and compute, and the AI Lab, which added a dedicated Agentic Academy, supports experimentation and scaling in payments and e-commerce. The FCA also runs a joint AI Consortium with the Bank of England.

How is this different from the Bank of England's systemic-risk warning?

The Bank of England and FSB letter is framed around systemic financial stability risk, particularly frontier AI's impact on cyber risk and concentration in AI infrastructure providers, addressed to G20 finance ministers. This briefing translates that signal, alongside the FCA's supervisory shift, into concrete steps a product team can take operationally.

What is the Mills Review and why does it matter to product leaders?

The Mills Review, referenced by Rathi as imminent at the time of his speech, examines how AI could reshape retail financial services. It is a signal of where FCA thinking on AI-driven retail products is heading and should be treated as required reading by product and compliance leads on publication.

Conclusion

The FCA and the Bank of England have both said, in their own ways, that they are not going to wait for legislation before acting on agentic AI.
Product teams that treat this as a compliance problem to solve later will find themselves reacting to supervisory questions they cannot yet answer.
Product teams that treat it as a design brief, accountable humans, mapped dependencies, live engagement with the FCA's own sandboxes, will be building the same platform either way, just with far less risk attached to it.

‍

Innovify helps fintech platform teams design embedded finance and digital wallet products, and works alongside our AI Labs practice, to build agentic capabilities with accountability, resilience and regulatory engagement designed in from day one. If you want a practical readiness review against the checklist above, speak with our team.

‍