Insight

The Risk and Reg Edit: Summer 2026 edition

Financial services are beginning to change how they operate, driven by AI moving from assistant to agent, stablecoins and tokenised deposits nearing widespread acceptance, and a quantum threat that, while still years away from reality, is already demanding action.

Each of these shifts promises real benefits for financial services firms and customers alike, but also raises new questions around accountability, autonomous decision-making, trust in systems that are increasingly difficult to explain to customers, and resilience against novel risks that are reshaping firms’ future strategy.

In this Risk and Reg Edit, we look at how firms are balancing innovation and resilience by embracing new technologies while maintaining trust, managing risk, and meeting rising regulatory expectations. These issues highlight how organisations that tackle these questions with a sense of urgency, rather than waiting for regulatory certainty or market maturity, will be the best placed to benefit from the opportunities they create.

Read on for our experts’ views on:

AI assistants to agents: Customer experience, governance, and conduct risk

Sharmila Subramanian and Thom Hart

AI use in financial services is moving beyond answering simple customer questions. Firms are already piloting more autonomous applications, while consumer-facing AI is evolving from comparing and recommending products towards agents that can switch providers, renegotiate terms, and manage transactions within agreed limits, with varying levels of human oversight.

Consumer appetite for this level of delegation remains mixed: the FCA’s Mills Review found that 36 percent of consumers would use assistive AI, 30 percent would use AI that acts with permission, but only 20 percent would consider using fully autonomous AI, highlighting the continued importance of trust, control, and accountability. As adoption grows, firms will need to serve a broad spectrum of customers, from the digitally literate embracing AI-enabled services to those who require greater support, reassurance, and human interaction.

As customer journeys become AI-mediated, firms may lose visibility into how their communications are being interpreted, compared, and acted on. Many people assume agents are neutral and judgement-free platforms. In reality, agents carry embedded bias, and as they scale and become more commercialised, their neutrality should increasingly be brought into question. This will continue to blur the point where machine ends and human begins in a customer’s journey. For instance, a cheaper insurance policy recommended by an agent may carry a meaningfully different level of cover, leaving a customer exposed when it comes to making a claim if they don’t do adequate research and simply take the agent recommendation at face value.

This raises a number of key questions for firms and regulators:

  • Where do hand-offs happen between machine and human in a customer’s journey, and how visible is that to the customer?
  • Where does liability sit if a customer’s AI agent is targeted by fraud, or acts on a scam? How do firms educate customers of the risks involved in using agents? Does existing reimbursement protection extend to agent-initiated transactions or is a new category required?
  • As AI tools begin to offer increasingly personalised financial recommendations, how should regulators balance the fact that unregulated models may be competing with regulated advice? And if consumers act on unsuitable recommendations, who is responsible for ensuring they are protected?
  • Who is accountable when an agent’s decision leaves a customer worse off than they expected?

While the UK regulator has begun exploring these issues, clear answers will take time to emerge. Firms cannot wait for that certainty. They need to start addressing how customers will be protected and where accountability and liability sit when AI-driven decisions lead to poor outcomes. By observing how AI systems draw their recommendations and scrutinising end-to-end customer journeys, firms can assess the impact of AI-driven customer interactions as closely as marketing teams already study how AI surfaces their products. Comparable shifts, like open banking, took some time to reach the mainstream, but quickly became ubiquitous once they did, so firms need to be prepared in order to stay ahead.

Building consumer trust with AI

Kinjal Shah

AI capabilities are becoming increasingly accessible, making the technology itself a less sustainable source of competitive advantage. Trust, however, is far harder to replicate. As firms accelerate AI adoption, the question is no longer whether systems are governed appropriately, but whether customers are confident enough to rely on them. Firms that can build confidence in AI-enabled decisions, products, and experiences will be better placed to drive adoption, deepen customer relationships, and unlock value from their investment.

But trust cannot be mandated through governance alone. Customers don’t see risk frameworks, control environments, or accountability structures – they experience outcomes. They judge whether interactions feel fair, whether recommendations are relevant, whether explanations make sense, and whether they retain meaningful control when something goes wrong. As AI becomes more deeply embedded across customer journeys, trust is becoming a strategic capability that shapes adoption, advocacy, loyalty, and long-term customer value.

Firms that treat trust as a strategic differentiator, rather than a regulatory obligation, are likely to gain a meaningful advantage.

The challenge is that trust becomes harder to earn as AI systems become more autonomous. Customers may not distinguish between a firm’s own technology, a third-party model provider, or an AI agent acting on their behalf. While regulators expect firms to remain accountable for customer outcomes, consumers are often less concerned with where responsibility sits and more with whether they can understand, question, and challenge the decisions that affect them.

This raises a number of important questions for firms:

  • How do you measure consumer trust in AI before it is lost?
  • What evidence demonstrates that customers are confident using AI-enabled products and services?
  • How much control should customers retain when AI increasingly influences or executes decisions on their behalf?
  • What level of transparency genuinely builds confidence, rather than simply satisfying disclosure requirements?
  • As decision-making becomes increasingly distributed across AI systems, third-party providers, and frontline teams, how do firms ensure accountability remains clear to both regulators and customers?

What firms should do to foster trust

Trust must be designed into customer experiences, not bolted onto governance frameworks. Firms should focus on:

  • Explaining decisions, not models.Customers rarely need technical detail; they need clear explanations of how AI influenced an outcome, why a decision was made, and what actions they can take next. The greater the impact of a decision, the stronger the explanation and review process should be
  • Making accountability visible. Customers need to know where responsibility sits, whether with the firm, a technology provider, or an AI system. Regulated firms must remain clearly accountable, with accessible human review and redress where appropriate, particularly as AI becomes more autonomous and decision-making becomes more distributed across organisations
  • Monitoring outcomes continuously. Rather than relying solely on periodic assurance activities, firms should actively test for unfair outcomes, recurring failures, data drift, and look for any signs that vulnerable customers may be excluded or disadvantaged
  • Creating live feedback loops. Governance should connect customer experience, frontline insight, risk oversight, and model improvement. Frontline teams need the confidence to challenge AI outputs, while firms need mechanisms to continuously learn from real customer interactions and improve outcomes over time.

Once trust is lost, it’s difficult to rebuild. As AI capabilities become more widely available, competitive advantage won’t just come from the technology itself, it will come from customers’ confidence in how the technology is used. Firms that successfully combine AI-driven efficiency with transparency, accountability, and human-centred experiences will be better positioned to create the confidence needed for customers to embrace more autonomous services.

AI and the future of third-party risk management

Max Topp

AI is reshaping third-party risk management from two directions at once – as a source of new risk in the supply chain and as a tool to manage that risk more effectively. While the financial services market is slightly behind the curve on both, firms need to start by distinguishing between instances where AI is used for low-risk purposes, such as enhancing coding capabilities, and where it is a fundamental, business critical component such as client facing capabilities. The two uses carry distinct due diligence obligations, with the latter potentially cascading down to a fourth or fifth party in the supply chain.

That distinction can be difficult to grasp, especially where AI isn’t visible, such as a third-party supplier using a personal AI chatbot outside of any formal governance and feeding in commercially sensitive information without a firm ever knowing.

Fortunately, the same technology that creates this risk can also help manage it, provided firms treat AI as an augmenter of existing capability, rather than a replacement. For example, AI-driven due diligence tools can analyse a 200-question assessment and produce a clear gap analysis within minutes. But its use comes with risks. Automation bias means AI can be exceptionally good at giving you the wrong answer with full confidence. Accountability should therefore sit with a human for scrutiny, review, and approval, rather than leaving accountability to the AI tool itself.

Additional steps firms should take to minimise risk include:

  • Establishing which suppliers materially use AI as part of their service now and how significant that risk is. The issue should be treated with the same rigour as other aspects of operational resilience, so any risk can be flagged appropriately
  • Ensuring your underlying processes, questionnaires, data requirements, and assessor expertise are robust enough to layer AI on top. Any underlying weakness or risk will be amplified, not reduced, by AI additions
  • Applying proportionate assurance. AI risk varies by service and use case so governance needs to be tailored accordingly.

As reliance on AI grows, so will AI-related third-party incidents. The real test for firms will be whether their governance and control frameworks can mature fast enough to keep pace with the changing nature of risk, or whether incidents outstrip the controls intended to catch them.

Stablecoins, tokenisation, and the GBTD

Edward Tout

Next year is shaping up to be a pivotal moment for tokenisation, particularly in the UK. The FCA’s full cryptoasset regime will come into force in October 2027, the Bank of England is finalising its rules on the use of stablecoins, and a group of major UK banks (including HSBC, Barclays, Nationwide, and Lloyds) are joining forces to create the world’s first national tokenised deposit system, dubbed the Great British Tokenised Deposit (GBTD).

The UK has taken longer than the EU or US to finalise its regulatory approach, following a period of extensive consultation. Over that time, regulators’ stance has shifted from an approach that cautioned the risks to one more focussed on the opportunities it presents. In doing so, the UK has aligned more closely with the US approach of integrating these digital assets into existing rules, rather than the EU’s approach that treats them as an entirely new asset class.

All firms wishing to offer cryptoasset services will need to apply for registration under the FCA. Firms have a tight application window between October 2026 and February 2027. Firms that miss the deadline will be unable to offer these services beyond October 2027.

Existing FSMA regulated firms will need to justify how cryptoassets fit within their existing business model and risk profile. Non-FSMA regulated fintech firms face different requirements. They will need to update their internal operating model and controls environment to meet Consumer Duty, SMCR, resilience, and ESG requirements.

Firms looking to offer cryptoasset services must:

  • Complete and submit the FCA application on time, and engage with the regulator early
  • Focus on building the infrastructure needed to support ledger technology capable of supporting digital clearing, system interoperability interoperability routes between tokens, and resilience protocols
  • Be able to clearly articulate how digital assets and tokenised products fit into existing product offerings and benefit customers
  • Adjust the risk environment to specifically cater to risks posed by digital assets, rather than treating them as an extension of existing asset categories.

Tokenisation and distributed ledger technology is best understood as evolution, not revolution, albeit with major market impact. Firms that move early on infrastructure and interoperability and have a clearly defined value proposition will be best placed to benefit.

Quantum computing: Preparing for the next systemic technology risk

Matthew Folkes

The UK’s National Cyber Security Centre (NCSC) has given financial services firms until 2035 to prepare for a threat that has not yet arrived: a quantum computer capable of deriving private encryption keys from public ones and able to break the cryptographic certificates that secure everything from VPNs to online banking. While no such quantum-capable computer exists yet, the 2035 deadline issued in March 2025 remains, requiring firms to fully migrate to a post-quantum cryptography (PQC) world by then. Central to that transformation is the development of ‘crypto agility’, a firm's ability to swap out cryptographic algorithms as standards evolve.

The most discussed risk associated with quantum cryptography is the idea of ‘harvest now, decrypt later’, when data stolen today can later be decrypted in future.

A less obvious but potentially more serious concern, however, is the threat quantum capability poses to zero-trust systems built on certificate-based authentication. The ‘trust now, forge later’ phenomenon would allow malicious actors to forge digital certificates or sign software updates as though they came from a trusted provider, undercutting firms’ ability to do business. Both risks share the same root cause stemming from a cryptographic system that was never designed to survive a quantum-capable adversary.

Firms should consider the following steps to prepare and not get out caught when quantum arrives:

  • Start your cryptographic discovery exercise now to identify where cryptography is used across your systems. Get help using the necessary tools for the discovery process, including less obvious areas like transaction logging and prioritise protection by data sensitivity
  • Build ‘crypto agility’ into any migration so algorithms can be swapped as standards evolve and budget for the extra processing power and memory PQC algorithms will require to run
  • Push PQC readiness into supply chain conversations and new IT contracts now, rather than retrofitting later
  • Treat this as a C-suite transformation project, not a technological change. The risk should be regarded as an existential threat to the business and organisational trust.

Legacy IT estates, especially in banking, often find migration challenging, leading some to even abandon their efforts due to the complexity. But deferral will only push these challenges down the line. Firms are already familiar with navigating serious regulatory pressure so they should treat quantum preparedness in the same way, placing it high on their list of priorities.

Can innovation and resilience genuinely co-exist?

Whether it’s an AI agent negotiating on a customer’s behalf, a supplier quietly integrating AI into its own operations, or a quantum threat that has yet to arrive, the hardest questions rarely concern the technology itself. The biggest challenge firms face when assimilating AI into their operations is establishing who is accountable when something goes wrong and how firms build genuine trust. Regulators have largely chosen to extend existing frameworks, leaving firms to make their own judgement calls.

Firms that wait for clear regulatory mandates or wait for these risks to fully materialise, are likely to find themselves playing catch-up. Those that start engaging now will be the ones equipped to turn innovation into genuine, lasting advantage.

People trust us because of our deep knowledge of the regulatory system. Our experience working with regulators, banks, insurers, building societies, and others means we’ll give you advice that works in the real world. If you’d like to discuss any of the issues below in depth with our experts, you can do so here.

The Risk and Reg Edit

Expert insights to help you navigate the evolving financial landscape with confidence.

Explore more

Contact the team

We look forward to hearing from you.