In partnership with

A Conversation That Changed How I See This Problem

A few months ago, I sat across from a Head of Compliance at a mid-tier wealth manager. She was smart, experienced, and visibly exhausted. Her team of six was drowning, not in complex investigations or nuanced regulatory interpretation, but in the sheer volume of screening alerts, repetitive KYC checks, and manual data pulls that consumed 80% of their day. She told me something I haven't been able to shake:

"My best analyst spent three hours yesterday copying data between systems to verify a low-risk client. Meanwhile, a genuinely suspicious transaction sat in a queue because nobody had time to look at it properly."

That's the accountability gap. Not a lack of talent. Not a shortage of intent. A fundamental misallocation of human judgement, and it's a ticking regulatory time bomb.

I've spent the past year working with financial services firms on this exact problem, and what I've seen is consistent: the people who should be making the hard calls, the contextual, experience-driven decisions that regulators actually care about, are buried under work that machines should be doing. And now, with the FCA sharpening its focus on AI governance and individual accountability in 2026, the stakes have never been higher.

This article is both a warning and a practical guide. It's grounded in what I've observed working with wealth managers, fintechs, and mid-tier firms, and in what the regulatory landscape is demanding right now. If you're a Head of Compliance, a COO, or a Senior Manager with your name on a Statement of Responsibilities, this is for you.

For a deeper dive into the framework we've developed, see our full guide: The Accountability Gap.

Smart starts here.

You don't have to read everything — just the right thing. 1440's daily newsletter distills the day's biggest stories from 100+ sources into one quick, 5-minute read. It's the fastest way to stay sharp, sound informed, and actually understand what's happening in the world. Join 4.5 million readers who start their day the smart way.

Part 1: The Regulatory Reality: Why 2026 Is the Year You Can't Ignore This

The FCA Has Made Its Position Unambiguous

Let me be direct about where we stand. The FCA does not plan to introduce extra regulations for AI. Instead, it will rely on existing frameworks, which it considers sufficient to mitigate many of the risks associated with AI. That might sound reassuring. It isn't. What it means is that everything the FCA already expects of you, Consumer Duty, SM&CR, operational resilience, now extends fully to every AI system you deploy.

In recent oral evidence before the Treasury Committee, the FCA confirmed that its approach remains technology-neutral, principles-based, and outcomes-focused. Jessica Rusu, FCA Chief Data, Information and Intelligence Officer, told the Committee that the regulator does not intend to "introduce prescriptive AI rules" but will embed AI oversight within current conduct and prudential standards, focusing on fairness, transparency, and accountability.

Translation: there will be no AI-specific rulebook to follow. You can't wait for one. You must demonstrate compliance now, under frameworks that were designed before AI agents could autonomously process thousands of client interactions per hour.

Individual Accountability Is Personal. Literally.

This is where it gets uncomfortable. When the House of Commons Treasury Committee published its report on AI in financial services in January 2026, it included a statement from FCA Executive Director David Geale that should concentrate the mind of every senior manager. Individuals within financial services firms, Geale told the Committee, are "on the hook" for harm caused to consumers through AI. Not firms. Individuals. Not at some point in the future when new rules arrive but now, under existing rules. The regime Geale was referring to is SMCR.

I've watched that statement land in rooms full of senior managers. The silence is deafening. Because most of them know, quietly, uncomfortably, that they couldn't currently demonstrate reasonable steps of oversight over the AI tools already operating in their business areas.

Senior Managers need to be able to show they took reasonable steps to prevent the use of AI breaching any regulatory requirements otherwise they can be held personally accountable. That's not a future aspiration. It's a current legal obligation.

The Enforcement Direction of Travel Is Clear

Look at what the FCA did in 2025. In December 2025, Nationwide was fined £44 million for serious weaknesses in financial crime systems and controls, including customer due diligence and monitoring. In July 2025, Monzo was fined £21 million for inadequate controls during a period of rapid growth. Barclays received a £42 million fine for failures in handling clients linked to money-laundering risks.

These weren't cases of intentional wrongdoing. They were systems and controls failures, precisely the kind of gap that unaccountable AI deployment creates at scale.

The FCA has moved decisively away from a framework that relied heavily on lengthy enforcement investigations to secure outcomes. In its place, it has adopted a more assertive, supervision-led approach designed to intervene earlier, contain risk, and secure outcomes at greater speed. Therese Chambers revealed that the FCA is pursuing more criminal prosecutions than ever before.

The message? Fewer investigations, but faster and harder when they come. The FCA's practical question is whether controls operate effectively day to day, particularly during growth, outsourcing or operational change, rather than whether firms can articulate a compliant framework on paper.

The Mills Review and What Comes Next

The regulator is seeking views on the future direction of agentic AI and its implications for retail finance over the coming decade, including questions of accountability, assurance and market structure. Mills has indicated he will report to the FCA Board in summer 2026, with recommendations expected to lead to comprehensive guidance by the end of the year.

The Treasury Committee has recommended the FCA publish practical guidance by the end of 2026 on how existing consumer protection rules apply to AI, including clarity on senior manager accountability under the SMCR.

And the EU AI Act's high-risk provisions take effect in August 2026 and apply to UK firms that touch EU markets.

The regulatory walls are closing in from multiple directions. The firms that are ready will thrive. The firms that aren't will find out the hard way.

Part 2: Where Judgement Matters Most, and Where It's Being Wasted

In my experience, the problem isn't that firms lack capable people. It's that those people are trapped doing work that doesn't require their expertise, while the decisions that do require human judgement either don't get the attention they deserve or aren't being documented well enough to satisfy a regulator.

Compliance has never been so strategic, and its teams have never been so vulnerable. Regulators are raising their expectations, the volume of alerts is increasing accordingly, and organizations are struggling to recruit the talent needed to absorb this growing workload.

Here's what I've seen across different firm types:

Wealth Managers: Suitability, Ongoing Reviews, and the Advice Gap

I've worked with wealth management firms where experienced advisers spend entire days completing file reviews that amount to little more than data verification. Meanwhile, genuine suitability questions, does this portfolio still align with the client's changed circumstances, is this product truly delivering fair value, get rushed or deferred.

AI may quickly redefine the requisite skills and talents wealth managers must possess. Over time AI tools, including generative and agent-based models, could boost productivity by 25% to 40%, and may eventually assume many of the fundamental tasks now performed by wealth managers. Not that human accountability will go away. On the contrary, regulators and clients will continue to expect clear human supervision over any AI-assisted actions.

The FCA now expects banks and wealth managers to show that advice, products and services consistently deliver good outcomes for customers. Manual reviews and spreadsheets cannot scale to meet regulatory standards.

The workflows where judgement matters most in wealth management:

  • Suitability assessment: AI can compile client data, cross-reference risk profiles, flag inconsistencies. But the decision about whether a recommendation is genuinely suitable for a 72-year-old widow with declining cognitive health? That requires a human who understands context, vulnerability, and nuance.

  • Ongoing portfolio monitoring: AI can track drift, benchmark performance, surface outliers. But the judgement about whether a client's changed circumstances warrant intervention? That's a human gate.

  • Consumer Duty outcomes monitoring: AI touching customer journeys, pricing, underwriting, claims, debt support, advice journeys, must show clear evidence of Consumer Duty aligned good outcomes. AI can aggregate and analyse at scale. Humans must interpret and act.

  • Vulnerable customer identification: Pattern recognition at scale is AI's strength. But the empathetic, contextual response to a flagged vulnerability? That's irreducibly human.

Fintechs: KYC, Onboarding, and the Growth-Control Tension

Fintechs face a particular version of this problem. Growth pressure is intense. Onboarding volumes are high. And the Monzo fine is a cautionary tale: Monzo was fined £21m for onboarding high-risk customers without adequate controls.

I've seen fintech compliance teams where two or three people are manually reviewing hundreds of KYC alerts daily, most of which are false positives from overly conservative screening parameters. The constantly increasing flow of alerts generated by modernized filtering systems, coupled with cautious or conservative settings and intensified monitoring requirements, leads to a massive volume of false positives. Meanwhile, truly critical alerts sometimes have to wait, increasing tension within the teams and raising the risk of errors.

The critical workflows:

  • KYC/CDD at onboarding: AI can aggregate identity documents, run sanctions screening, pull adverse media, and present a structured risk profile. The human at the gate reviews the edge cases, the PEP connection that's ambiguous, the source-of-wealth explanation that doesn't quite add up.

  • Transaction monitoring: AI flags; humans adjudicate. The judgement about whether a pattern is genuinely suspicious or has an innocent explanation requires context that machines can't reliably provide.

  • Fraud detection: Real-time pattern recognition is AI's sweet spot. But the decision to block a customer's account, with all the Consumer Duty implications that entails, should pass through a human gate.

Mid-Tier Firms: The Worst of Both Worlds

Mid-tier firms, I'm talking about firms with £5-50 billion AUM, regional banks, specialist lenders, mid-sized insurers, often have the regulatory obligations of large firms without the resources. Nearly 40% of institutions operate with one or two compliance professionals, while 25% of firms with $1 billion to $10 billion in assets have similarly small teams.

These firms are where I see the accountability gap at its most acute:

  • Credit and lending decisions: AI risk scoring is increasingly common, but explainability under Consumer Duty is non-negotiable. When a customer is declined, can the firm explain why in terms a human can understand and a regulator can audit?

  • AML compliance: Sanctions screening, SAR preparation, and ongoing monitoring all involve enormous volumes of routine work punctuated by critical judgement calls. The routine work buries the judgement.

  • Regulatory reporting: Data aggregation and formatting consume analyst time that should be spent on interpretation and escalation.

Manual compliance processes generate seven times more examiner concerns and four times lower staff satisfaction. That statistic alone should be a wake-up call.

Part 3: The Human-in-the-Loop Imperative: Getting the Model Right

Here's what I believe, based on everything I've seen: the answer is not "more AI" or "less AI." It's differently deployed AI, with humans repositioned from manual drudgery to the decision gates where their judgement creates real value.

When mechanical tasks are reduced, compliance professionals can dedicate more time to activities that require judgment, such as complex investigations, contextual risk assessments and decision-making. In practice, this shift is increasingly seen as essential to preserve analytical quality under sustained pressure.

This trend is not about removing the human from the equation. Instead, it marks the rise of the AI-augmented advisor. By delegating research, documentation, and administrative preparation to AI agents, advisors reclaim time and cognitive capacity for what matters most.

What "Human at the Gate" Actually Means

Let me be specific, because I've seen too many firms treat "human-in-the-loop" as a checkbox rather than a design principle.

It means:

  • AI performs the groundwork: data collection, initial screening, pattern detection, document aggregation, research synthesis

  • The workflow pauses at defined decision gates, points where a determination must be made that carries regulatory, ethical, or customer-impact significance

  • A qualified human reviews the AI's output at that gate, applies judgement, and makes (or approves) the decision

  • The decision, the reasoning, and the human's identity are logged in an auditable trail

It does not mean:

  • A human rubber-stamps AI output without meaningful review

  • A human is "available" somewhere in the process but never actually engaged

  • A human reviews a random sample after the fact

As Joe Norburn, CEO of TCC Group and Recordsure, summarises: "Regulators aren't asking firms to slow down innovation. They're asking them to show control. That means being able to explain how decisions are made, evidence outcomes, and demonstrate accountability long after AI systems are live and scaled."

Why This Matters for SMCR Compliance

SMCR compliance has always been about one thing: making sure a named individual can demonstrate they took reasonable steps to control the business they are responsible for. That requirement does not change because the decisions are now being made by AI agents instead of people.

Firms should be able to evidence who owns the AI-enabled process, what approvals were obtained before deployment, what controls apply (including change control), and how performance is monitored and escalated (including for bias, drift, errors, outages and customer harm).

When a Senior Manager has human reviewers positioned at defined gates within an AI-driven workflow, they can demonstrate:

  1. Awareness: They knew AI was operating in their area and understood what it was doing

  2. Design: They approved a governance structure with meaningful human checkpoints

  3. Evidence: Every decision that passed through a gate is logged, attributed, and explainable

  4. Escalation: When the human reviewer identified an issue, there was a clear path to escalation

That's what "reasonable steps" looks like in practice. Without it, you're exposed.

The Anti-Aging Solution Men Actually Use

Over 1,000,000 men have made Particle part of their routine. One product. Multiple premium anti-aging ingredients. Clinically researched and engineered for men's skin. Reduces eye bags, dark spots, and wrinkles without adding complexity to your morning. Easy, effective, worth it. Get 20% off now with the code BH20.

Part 4: What Heads of Compliance Should Do Now

I've distilled this into practical actions based on what I've seen work:

1. Audit Your AI Footprint, Including the Shadow AI

AI is already woven into the fabric of most organisations, often without any deliberate planning. And that is precisely where the risk lies. It is not the technology itself that should concern compliance teams. It is the absence of visibility and control over how it is being used.

Start by mapping every AI tool in your organisation, including the ones your teams adopted without formal approval. Classify each by materiality and regulatory touchpoint. Document every AI system currently deployed or planned, classify its materiality, and assign a Senior Manager as accountable owner.

2. Identify Your Decision Gates

For each workflow that involves AI, ask: Where in this process does a determination get made that could harm a customer, breach a regulation, or trigger enforcement interest? Those are your gates. Those are where humans must sit.

3. Redesign Workflows Around Judgement, Not Process

Stop thinking about AI as "automating compliance." Start thinking about it as removing the non-judgemental work so that humans can focus on the judgemental work. Your experienced analyst shouldn't be copying data between systems. They should be assessing whether a complex client relationship presents a genuine risk.

4. Build the Evidence Trail From Day One

Centralised workflow orchestration and structured documentation make it easier to trace decisions, monitor exceptions and demonstrate control effectiveness during audits or supervisory reviews. This level of consistency helps organisations respond more confidently to regulatory scrutiny.

5. Engage With the Regulatory Direction

Engage with regulatory initiatives such as FCA sandboxes, live testing and calls for input (including the Mills Review) to help shape future policy and gain early insight into supervisory expectations. Regulated firms should conduct horizon-scanning exercises regularly and treat compliance as a strategic priority. Reviews, actions taken, enhancements to systems and controls and the accompanying rationales should be documented.

6. Protect Your People

This is something I feel strongly about. Experience gaps are growing. While most compliance staff are highly experienced, many are nearing retirement. At roughly one in four institutions, 25% of personnel may retire within five years, and 9% of institutions risk losing more than half their compliance team.

Your compliance professionals are not infinitely renewable resources. If you burn them out on mechanical work, they'll leave, and they'll take institutional knowledge with them that no AI can replace. Redesigning their work around judgement isn't just a regulatory strategy. It's a retention strategy.

Part 5: How BuildMoat Is Approaching This

I built BuildMoat because I kept seeing the same pattern: firms that wanted to use AI responsibly but didn't have a way to deploy it that satisfied both operational efficiency and regulatory accountability.

Our approach is straightforward:

BuildMoat Agents handle the manual groundwork, the data gathering, the screening, the research, the document aggregation, the initial risk scoring, so that your compliance professionals don't have to.

Human reviewers sit at the gates, the points in the workflow where judgement, context, and accountability matter. They review what the Agent has prepared, apply their expertise, make the call, and that decision is logged with full traceability.

The result: compressed workflows that are faster and more auditable than what most firms have today. Your analysts aren't doing less. They're doing what they were actually hired to do. And your Senior Managers have an evidence trail that demonstrates meaningful oversight under SMCR.

We're currently inviting firms to pilot this approach. Whether you're a wealth manager struggling with suitability file reviews, a fintech scaling KYC without scaling your team proportionally, or a mid-tier firm trying to do more with less, we'll work with you to identify which workflows matter most, where the gates should sit, and what "good" looks like for your regulatory context.

If this resonates, let's talk. Visit buildmoat.co.uk/guides/accountability-gap for the full framework, or reach out directly to discuss a pilot - [email protected]

Final Thought

The message for 2026 is clear: the window for innovation is open, but so is the door to greater scrutiny.

The firms that will navigate this well aren't the ones that avoid AI, and they're not the ones that deploy it recklessly. They're the ones that understand where machines add value and where humans are irreplaceable, and build their workflows accordingly.

Regulatory pressure in 2026 is not simply a compliance challenge. It is a test of capability. Firms that treat governance, documentation, and supervision as strategic functions, rather than box-ticking exercises, will be better placed to move quickly, adapt to change, and build lasting trust with clients and regulators alike.

The accountability gap is real. But it's closable. The question is whether you close it before the regulator comes knocking, or after.

Thanks for Reading

BuildMoat builds AI Agents and the human infrastructure to deploy them responsibly. Agents handle the groundwork. Humans sit at the gates for judgement and decisions. Every action is traceable, accountable, and audit-ready.

That's how firms increase AI adoption, stay compliant, and build a moat.

We're currently piloting with financial services firms. If you want to see what this looks like for your workflows, book a call.

Did someone forward this to you? Subscribe here for weekly insights on AI adoption that actually works in regulated environments.

Keep building,

BuildMoat
AI Agents. Human Gates. Your Moat.