The UK's Financial Conduct Authority published the Mills Review today, and the headline recommendation is blunt: the regulator needs more power, and it needs it now.
The review, led by FCA executive director Sheldon Mills, found that over 80% of UK financial services firms are already using AI in some form. More striking is what is happening on the consumer side. FCA-commissioned research found that one in five UK adults, roughly 11 million people, are open to letting AI make their financial decisions for them, including on savings, borrowing, and investments.
The problem is that none of the AI tools those consumers are using are regulated. If you take financial advice from ChatGPT and lose money, no regulator can help you. No compensation scheme exists. The FCA cannot touch the company that built the tool. This is the gap the Mills Review is trying to close.
The review asks the government to formally designate major AI companies and cloud providers as "critical third parties," which would give the FCA direct supervisory powers over them. Right now, a bank can be fully regulated while its most important decisions run on software from a company the FCA has no authority over. That is the accountability gap the review identifies, and it is a real one.
Mills also recommended that the FCA itself adopt AI-powered tools to monitor and supervise firms, describing the situation plainly as "an arms race." A regulator using paper-based processes to oversee firms running AI at machine speed is not a functioning oversight system.
The review sits in a broader context that is moving quickly. The UK Treasury Select Committee published its own report earlier this year criticising the FCA, the Bank of England, and HM Treasury for a "wait-and-see" approach that it said exposed consumers and the financial system to serious harm. The committee wants practical guidance from the FCA on how existing rules apply to AI, and it wants it before the end of 2026.
Then there is the Mythos question. Anthropic, the AI company behind the Claude series of products, built a model called Mythos that was designed for coding and autonomous work. During internal testing, it uncovered thousands of previously unknown software vulnerabilities, including weaknesses in every major operating system and web browser. The model can, when instructed, find and exploit those vulnerabilities on its own.
Anthropics response was to create a restricted access programme called Project Glasswing, giving only vetted organisations controlled access to Mythos for defensive testing. Major banks in the US and UK are among the participants, using Mythos to find weaknesses in their own systems before attackers do.
The Trump administration briefly imposed export controls on Mythos in mid-June, blocking access for all foreign nationals including Anthropic's own non-US employees. Those controls were lifted on 30 June after Anthropic agreed to proactively detect security risks and inform the government of malicious activity. Access has been partially restored and is being expanded.
The connection between Mythos and the Mills Review is not cosmetic. The FCA's call for stronger powers over tech companies is a direct response to a world where an AI tool with serious implications for bank security can arrive, be locked down by a foreign government, and be partially restored again, all within a few weeks, with UK regulators scrambling to assess the implications at each step.
The FCA will now decide how to respond to the review's seven recommendations. The most consequential ones, giving the regulator authority over AI and cloud providers and requiring it to regulate AI-powered financial guidance tools, require action from ministers, not just the FCA itself. Whether the government moves quickly enough is the real question.