Sponsored

Britain’s financial regulator has eight firms running live artificial intelligence inside real UK markets, and it has told them there will be no AI rulebook to follow.

The Financial Conduct Authority opened the second cohort of its AI Live Testing programme to applications between 19 January and 24 March 2026, and testing began in April. The participants are a deliberate mix of incumbents and challengers: Barclays, Lloyds Banking Group through its Scottish Widows arm, UBS and the credit-data group Experian, alongside the payments firm GoCardless and the smaller technology names Aereve, Coadjute and Palindrome. Their tests run to the end of 2026, and the FCA will publish an evaluation report in the first quarter of 2027.

AI Live Testing sits inside the FCA’s AI Lab and answers the government’s AI Opportunities Action Plan, published in January 2025. The idea, set out in an engagement paper on 29 April 2025 and confirmed in feedback statement FS25/5, is that firms can put a model into live use with customers or markets while working directly alongside the regulator’s supervisory and technical teams. The FCA has brought in an outside specialist, the London assurance firm Advai, to help stress-test the systems. A first cohort was assembled after applications closed on 15 September 2025.

The rulebook that is not being written

The striking part is not the sandbox. It is what the FCA has decided to do instead of legislating. In its response to the Prime Minister’s letter to regulators on growth, the FCA said it would avoid additional rules for AI and rely on the frameworks it already has. There is no draft AI chapter of the Handbook, no risk-tiering of models, no registration duty for high-stakes systems.

That is a genuine choice, and it is worth naming what carries the weight instead. Two existing regimes do the work. The Consumer Duty, live since 2023, already requires firms to evidence good outcomes for retail customers rather than merely follow a process, which means an AI pricing or advice tool has to be shown to produce fair results, not just to exist. The Senior Managers and Certification Regime supplies the accountability: a named individual owns the function an AI system sits in, and cannot outsource that responsibility to a vendor or an algorithm. Add the FCA’s technology-agnostic starting point, that a rule about treating customers fairly applies however the decision is made, and the regulator’s claim is that it does not need new law to reach AI.

An evidentiary obligation, not a prohibition

For firms, this shifts the nature of the obligation. The European Union has taken the opposite path. Under the EU AI Act, AI used for credit-scoring and insurance pricing is classified as high-risk and saddled with prescriptive controls, an obligation the bloc’s Digital Omnibus package has now pushed back to 2 December 2027 but has not removed. A European lender knows in advance which box its model falls into.

A UK firm gets no such label. What it gets is a standard it must satisfy on results, tested in the open. The message the FCA is sending through Live Testing, and which its supervisors have put bluntly to the banks, is that firms will have to prove their AI works with evidence rather than assurances. That is a lighter touch at the point of deployment and a heavier one afterwards, because the burden of showing that a model is fair, explainable and controlled sits with the firm, continuously, and can be examined at any supervisory visit.

The FCA is also building expectations without a consultation. It has promised a good and poor practice report for AI in financial services later in 2026, on top of the Live Testing evaluation in early 2027. Those documents will not be rules, but they will function as them. A firm that ignores a practice the regulator has publicly branded as poor will struggle to argue it acted reasonably, and supervisory expectation, once written down, tends to harden into a de facto standard that never passed through the formal rule-making the industry can contest.

What to watch

The approach has clear attractions. It is fast, it avoids freezing a fast-moving technology into a static rulebook, and it plays to a genuine strength: the FCA reports a 49 per cent year-on-year rise in applications to its Regulatory Sandbox and Innovation Pathways, evidence that firms want a supervised route to market. For a government chasing growth, a regulator that says yes with conditions is more useful than one that says wait.

The risks sit on the other side of the same coin. Standards set through practice reports and case-by-case supervision are less transparent and less challengeable than rules, and they can drift. Firms operating on both sides of the Channel face two regimes at once: a prescriptive EU classification and a principles-based UK expectation, with no guarantee the two will judge the same model the same way. And the whole design leans on the Consumer Duty and the senior-manager regime bearing weight they were not built to carry for autonomous systems.

The test of the strategy is not the eight firms now inside the sandbox. It is whether, when the evaluation lands in early 2027, the FCA can show that principles plus evidence caught the problems a rulebook would have. Until then, the UK has made a bet that supervision can do the job of legislation. The bill for getting it wrong would be paid in the consumer harm the existing rules were meant to prevent.

Finance & Markets Correspondent
Covers: Finance, capital markets, technology investing

David Whitmore covers the intersection of capital and code — the funding rounds, market structures and policy moves that shape how money flows through the technology economy.