Introduction
UK AI governance moved from strategy towards implementation in July 2026, with financial services providing the clearest test case. HM Treasury and the Financial Conduct Authority both set out how AI should develop within existing regulatory structures, while the Bank of England treated frontier AI capability as a live financial stability concern rather than an operational one. Underneath that, the government opened a broader question about whether the UK's data regulation framework remains suitable for data-intensive AI.
Executive snapshot
HM Treasury published the Financial Services AI Adoption Plan on 14 July, accepting the recommendations directed at government and prioritising an agentic payments trust framework.
The Financial Conduct Authority published the Mills Review on 6 July, the first regulator-initiated review of how AI could reshape retail financial services, with seven priority recommendations and no proposal for AI-specific rules.
The Department for Science, Innovation and Technology opened a call for evidence on data regulation in the age of AI on 15 July, closing on 9 September 2026.
The Bank of England's Financial Stability Report of 7 July concluded that rapid advances in frontier AI have increased cyber and operational resilience risks to the financial system.
HM Treasury designated the first critical third parties on 10 July, with supervisory oversight of four major cloud providers beginning on 13 July.
UK Government and Parliament
HM Treasury published the Financial Services AI Adoption Plan on 14 July, prepared by its independent AI Champions for financial services, Harriet Rees of Starling Bank and Dr Rohit Dhawan of Lloyds Banking Group. The plan makes ten recommendations across five themes covering the regulatory framework, AI-powered financial advice and the regulatory perimeter, resilience, skills and talent, and agentic payments. Its highest-priority recommendation asks government, regulators and industry to develop an agentic payments trust framework including a 'Know Your Agent' standard, an unusually concrete ask for a UK adoption document and one that presupposes identity and accountability infrastructure that does not yet exist. The government accepted the recommendations directed at it and confirmed that implementation will proceed through existing regulators alongside the Mills Review, rather than through new institutions or AI-specific legislation. The Department for Science, Innovation and Technology opened a call for evidence on data regulation in the age of AI and other data-intensive technologies on 15 July. It seeks practical evidence rather than position papers on how existing legal frameworks affect AI development, deployment and data reuse, and asks whether the government should respond through guidance, targeted change or more fundamental reform. Parliamentary activity was limited but directionally useful. The House of Lords considered an oral question on artificial intelligence legislation on 16 July, during which the government restated its preference for context-specific regulation and pointed to a forthcoming 'Regulating for Growth' Bill creating cross-economy sandbox powers, which had not been introduced by the end of the month. The Treasury Committee took oral evidence from the Governor and Financial Policy Committee members on the Financial Stability Report on 14 July, placing frontier AI risk before parliamentary scrutiny for the first time in that forum. Separately, the UK Jurisdiction Taskforce published a legal statement on liability for AI harms under the private law of England and Wales on 7 July, concluding that established principles of negligence, contract and product liability are generally adequate without a new AI-specific regime, while identifying unresolved questions about whether product liability law reaches standalone AI software and about harms occurring where negligence cannot be evidenced.
Regulators and enforcement
The Financial Conduct Authority published the Mills Review on 6 July, led by Sheldon Mills, its Executive Director for Consumers and Competition. Drawing on 140 written submissions and a commissioned survey of just over 5,000 UK retail consumers, it sets out seven priority recommendations, including securing and adapting the regulatory perimeter, monitoring the transition to autonomous models, enabling the foundations for agentic finance and building an AI-enabled supervisory model. The review declines to recommend AI-specific regulation, but its perimeter finding is the sharper point: it asks the FCA to examine within three to six months the scale and impact of general-purpose large language models operating outside the perimeter, on evidence that around a fifth of UK adults are likely to use AI acting autonomously within pre-set goals, often without appreciating that formal redress routes will not apply. The FCA also opened the second cohort of its Supercharged Sandbox on 13 July, extending supervised experimentation capacity that the Mills Review expressly recommends scaling up. Taken together with the Adoption Plan, the practical regulatory posture for the coming year is testing and supervisory capability building rather than rulemaking. Data protection supervision continued to consolidate rather than expand. All data protection provisions of the Data (Use and Access) Act 2025 were in force from 19 June, following the principal commencement on 5 February under the Commencement No. 6 and Transitional and Saving Provisions Regulations 2026, which replaced Article 22 of the UK GDPR with new Articles 22A to 22D and reframed solely automated decision-making from a prohibition with narrow exceptions to a permission subject to safeguards.
Security and resilience
The Bank of England published its Financial Stability Report on 7 July, concluding that recent rapid advances in frontier AI capabilities have increased financial stability risks related to cyber and operational resilience. The accompanying Financial Policy Committee record sets out the mechanism: frontier models are increasingly able to identify and exploit software vulnerabilities at scale and across multiple stages, compressing the time firms have to identify, patch and mitigate. The Committee's second-order finding is the more striking one, namely that accelerated patching could itself become a source of systemic operational risk by increasing the likelihood of errors and outages across interconnected services. It reinforced the importance of firms acting on the joint statement issued with the FCA and HM Treasury in May, and signalled that expectations on deep cyber-recovery capability and the resilience of key technology providers would be revisited. That concern acquired institutional form days later. HM Treasury announced the first designations under the critical third parties regime on 10 July, with oversight by the Bank of England, the Prudential Regulation Authority and the FCA commencing on 13 July under the Critical Third Parties (Designation) Regulations 2026. Four cloud and technology providers were designated: Amazon Web Services EMEA, Google Cloud EMEA, Microsoft Ireland Operations and Oracle Corporation UK. The regime originates in the Financial Services and Markets Act 2023 and was not designed for AI, but it is now the principal supervisory tool addressing the concentration of AI and cloud capability that both the Adoption Plan and the Financial Stability Report identify as a structural exposure.
Key dates and open calls
The DSIT call for evidence on data regulation in the age of AI closes at 11:59pm on 9 September 2026.
HM Treasury's consultation on modernising payment services regulation, published alongside the Adoption Plan, closes on 6 October 2026.
The FCA is to report on the scale and impact of general-purpose large language models operating outside the regulatory perimeter within three to six months of the Mills Review.
Conclusion
July's developments show a governance model consolidating around existing institutions rather than building new ones. Two regulators and one department independently concluded that the current framework can absorb AI, while simultaneously identifying the pressure points where it cannot, namely the regulatory perimeter for general-purpose models, liability where negligence is unprovable, and concentrated dependence on a handful of technology providers. The critical third parties designations and the frontier AI findings in the Financial Stability Report suggest that operational resilience, rather than AI-specific regulation, is where UK supervisory effort will concentrate next.
Sources: HM Treasury, Financial Conduct Authority, Bank of England, Department for Science, Innovation and Technology, UK Jurisdiction Taskforce, Information Commissioner's Office, UK Parliament