AI Governance in 2026 – new frontiers
We are helping multiple organisations develop AI governance frameworks and review existing policies.
Clients are increasingly asking us how existing legal and regulatory obligations apply when AI becomes part of their business.
- Can a chatbot stray into financial product advice?
- What happens when employees upload client information into an AI tool?
- Who is accountable for AI generated customer communications?
- How should boards and senior management oversee increasingly AI enabled businesses?
The UK Financial Conduct Authority’s recently published Mills Review is one of the most thoughtful attempts yet by a regulator to grapple with those issues. Although written from a UK perspective, it contains important lessons for Australian financial services licensees. The Review examines what happens when AI systems move from supporting decisions to making and implementing them, and what that means for firms, consumers and regulators.
The Review is particularly interesting because of what it says is not required. It does not ask for an entirely new regulatory framework is required before AI can be used in financial services. Instead, existing frameworks remain relevant, while recognising that they become harder to apply as AI becomes more capable, more autonomous and more deeply embedded within business processes.
What this means is regulators think that AI doesn’t change your general financial services obligations, it doesn’t change your privacy obligations, it doesn’t fundamentally change the rights and obligations of employees. Directors’ and officers’ obligations still apply. AI instead creates both new ways of meeting those obligations and new ways of breaching obligations.
Although aimed at the UK regulatory system there are many lessons for Australia. It reviews a more fundamental question of what happens when AI systems move from supporting decisions to making and implementing them? These are not uniquely Australian questions.
Historically, technology has largely supported human decision making. However, the Review believes we are moving from systems that provide information and recommendations to systems that are increasingly capable of taking actions, implementing decisions and operating within agreed parameters. Firms are already piloting and deploying more autonomous use cases across customer service, underwriting, compliance, claims handling and product design.
The Review describes this as an “autonomy spectrum”. As AI systems become more capable, people move from being direct decision makers to becoming collaborators, approvers and ultimately supervisors of systems that perform tasks on their behalf. That shift has obvious implications for governance, accountability and regulation.
Although written from a UK perspective, the Review is worth reading for Australian financial services businesses. It is one of the most ambitious attempts yet by a regulator to consider how AI may reshape financial services over the next decade. ASIC will undoubtedly be watching closely.
Four predictions
The Review identifies four major shifts that it expects to reshape retail financial services over the coming years.
-
AI becomes embedded throughout firms and transforms them
The Review predicts that AI will become integrated into almost every function within financial services firms, from customer support and compliance through to underwriting, claims handling and product development. In some organisations, AI may become the primary means by which information is processed and decisions are evidenced.
-
Consumer journeys become increasingly agent led
Perhaps the boldest prediction is that consumers will increasingly delegate financial tasks to AI systems acting on their behalf. The Review envisages a future where AI agents help consumers manage finances, compare products, switch providers and optimise financial decisions on an ongoing basis.
Whether that prediction proves correct remains to be seen. However, it forces regulators and firms to think about what happens when consumers increasingly rely on AI generated recommendations and actions.
-
Competition changes
The Review suggests AI may lower barriers to entry and create opportunities for new participants, while simultaneously increasing dependence on a small number of technology providers. It identifies the possibility that control of customer interfaces and AI infrastructure may become a significant source of market power.
-
Amplified financial crime and cyber risk
Regulatory risk becomes more systemic as AI adoption increases. The concern moves beyond errors within individual firms towards common (and therefore systemic) failures arising from reliance on the same models, datasets and infrastructure. The Review raises concerns about correlated concentration risk and shared points of failure across the financial system.
Why this matters in Australia
Although this is a UK regulator, many of the questions are equally as applicable. The questions the FCA asks are the questions that ASIC will be asking.
The practical takeaway
One of the most interesting aspects of the Mills Review is what it does not require. The Review does not propose a wholesale rewriting of financial services regulation to accommodate AI. Instead, it states that existing regulatory framework remains highly relevant. The challenge is that those frameworks become harder to apply as AI becomes more capable, more autonomous and more deeply embedded within business processes
Questions about AI are rarely just questions about AI in financial services. They are often questions about how existing legal and regulatory obligations apply when AI becomes part of the process.
The most important lesson for Australian firms is the fact that governance cannot wait. There are not going to be wholesale rule changes – instead ASIC (like the FCA) will be asking questions and will expect you to have thought about these things.
- Where AI systems influence customer distribution and outcomes, how do you ensure obligations like DDO is met?
- If a chatbot starts providing personalised guidance, where is the line between customer service and financial product advice?
- If an employee uploads client information into an AI tool, what are the privacy and confidentiality implications?
- If an AI generated complaint response contains incorrect legal analysis, who is accountable?
- If a compliance team relies on an AI generated summary of regulatory developments, what level of review is required?
- How do directors and senior management discharge oversight obligations when increasingly important processes involve AI systems
They are questions arising under existing laws, existing regulatory obligations and existing governance frameworks. Questions on the boundary between personal and general advice, consumer outcomes and DDO, privacy are questions that firms grapple with today. These are not new regulatory problems. They are existing regulatory problems viewed through an AI lens.
That is why the most practical lesson from the Mills Review is not that firms should wait for governments and regulators to develop new AI legislation. It is the opposite.
Your employees are already using AI (whether sanctioned or not by internal policies). Customer facing systems increasingly incorporate AI. Businesses are already relying on AI generated outputs in operational and compliance processes.
The governance challenge exists now.
That means firms should be considering:
- where AI is currently being used;
- whether an AI governance framework is required;
- who is accountable for approving and overseeing AI use;
- how AI interacts with privacy, cyber security and compliance obligations;
- what level of human review is required; and
- how incidents involving AI will be identified, escalated and managed.
The organisations that derive the greatest value from AI are unlikely to be those that simply adopt it fastest.
They are more likely to be the organisations that understand the risks, implement effective governance and recognise that AI is no longer a technology issue alone. It is a governance issue.
Get in touch if you’d like to talk to us about how to implement this.
| Contact Us | Our Expert Team | Our Training |
Author: Greg Patton (Special Counsel)
