Wall Street Priced the Wrong Risk. Now a Regulator Agrees.

By Lynn Räbsamen, CFA | Advisory Board Member, CFA Institute | Author, Artificial Stupelligence

In June I argued that Wall Street was pricing the wrong risk in AI financial advice. While the industry debated whether AI would replace the $500,000 advisor, clients had already moved on to unregulated chatbots. I did not expect a regulator to agree with me quite so quickly. On 138 pages.

Roughly 11 million UK adults, 1 in 5, say they are likely to use AI that acts autonomously on their finances within goals they set.

That figure comes from a nationally representative survey of 5,026 UK retail finance consumers, commissioned by the Financial Conduct Authority (FCA) and conducted by Yonder Consulting in April 2026. It sits at the heart of the Mills Review, published July 6, 2026.

Recommendation Before Regulation

Led by FCA executive director Sheldon Mills and commissioned by the FCA Board, the Review is described as the first of its kind initiated by any regulator worldwide. It draws on 140 written submissions and the Yonder survey. It names four AI-driven shifts reshaping retail finance: the transformation of firm operations, the evolution of consumer journeys, the reshaping of competition and market power, and the amplification of fraud and cyber risks.

One clarification before anyone panics or celebrates. The Review makes recommendations to the FCA Board. It is not new regulation. Nobody is required to do anything (yet). Which is precisely why the findings deserve attention.

This is a regulator thinking out loud, before the rules exist.

And the sharpest finding is not that AI is coming to retail finance. It is where the risk sits.

The Unregulated Chatbot Vs. …

The FCA regulates activities. Advising on investments is a regulated activity. Managing a pension is a regulated activity. Asking a general-purpose chatbot whether to consolidate your pension pots is not.

So a consumer using ChatGPT or Claude for pension or mortgage decisions operates largely outside the FCA’s perimeter. They may have no formal route to recourse when the answer is wrong.

The Review’s own survey found that 26% of consumers already trust general-purpose tools for financial advice. Only about two in five correctly understood what protection applies. The rest either misunderstood it or were unsure.

The biggest AI risk to consumers sits outside the regulator’s reach. The regulator says so itself.

The Review’s first recommendation to the Board is accordingly blunt: secure and adapt the regulatory perimeter, and examine how far general-purpose AI tools are shaping financial decisions beyond formal oversight. A regulator asking how much of its market has quietly relocated outside its jurisdiction.

… The Regulated Senior Manager

For regulated firms, the Review is equally clear, and considerably less comfortable. The Senior Managers Regime (SMR) continues to apply as AI systems become more autonomous. No firm that responded argued the accountability model should change. The Review agrees the SMR still applies, and notes that firms now need to work out how it operates when model behavior and updates sit partly outside their control.

In other words: You can outsource the model. You cannot outsource the accountability.

A senior manager remains accountable for outcomes produced by a system built by a vendor, updated on the vendor’s schedule, and running on infrastructure the firm does not own.

If the model drifts, the accountability does not.

Anyone pricing operational risk in a regulated firm should read that sentence twice, then re-read their vendor contracts once.

The Inconvenient Question

Now put the two sides of the market next to each other.

On the firm side: the Cloud Security Alliance reported in June 2026 that 62% of financial services firms have deployed AI agents, and 93% of those firms have granted the agents some level of autonomy. The report’s authors summarized their own data plainly:

Financial institutions have deployed AI faster than they have secured it.

On the consumer side: 1 in 5 UK adults ready to delegate, per the FCA-commissioned survey.

Both sides of finance handed over the keys in the same year. The supervised side has an accountability regime, imperfect but named, with a human who signs. The consumer side has a gap. When the free chatbot misreads a pension transfer, there is no senior manager, no ombudsman, no compensation scheme. There might be a chat log.

As a CFA charterholder, I keep returning to the same question: who bears the loss when the model is wrong? Inside the perimeter, the answer is written down. Outside it, the answer is currently “the person who asked.” Both are inconvenient.

This Is Not a UK Story

Swiss and European institutions should resist the comfortable reading that this is a British problem. Delegation behavior is jurisdiction-agnostic. Clients in Zurich use the same chatbots as clients in London, myself included. Though I like to think, with a little more skepticism.

FINMA’s Guidance 08/2024 sets out supervisory expectations for institutions using AI. Note the verb: FINMA expects. It cannot reach the unsupervised tools clients use on their own time, on their own phones, about their own portfolios. No supervisor anywhere can, yet.

Which leaves wealth managers with a competitive question, in addition to the compliance one. When the client’s free AI contradicts your advisor, whose explanation survives the meeting?

The client’s chatbot does not need to be right. It only needs to be confident. Your advisor needs to be both.

The Question I Actually Want Answered

The Mills Review confirms the direction of travel with regulator-grade evidence. What it cannot tell us is what is happening in meeting rooms right now.

So, practitioners: has one of your clients already arrived with an AI-generated critique of their portfolio? Not a hypothetical. An actual printout, screenshot, or recited chatbot verdict. And what did your firm do with it? Rebut it, absorb it, or quietly check whether the machine had a point?

I read the survey data. I would rather read your answers.

If you want the next installment before everyone else, subscribe to my newsletter “AI, Work and Money.”


For more insights about what AI can or cannot do, check out my book “Artificial Stupelligence: The Hilarious Truth About AI“.

Subscribe here to be the first to receive my insights


Discover more from Lynn Raebsamen, CFA

Subscribe to get the latest posts sent to your email.

Love this content? Get updates in your inbox.

Subscribe now to keep reading and get access to the full archive.

Continue reading