Two Regulators, One Requirement

On 8 July 2026, the Financial Conduct Authority published the Mills Review, the first regulator-initiated review of its kind setting out how AI will reshape retail financial services through to 2030. Two weeks later, on 23 July, the EU AI Act’s finalised high-risk classification guidelines reach their compliance milestone. Two jurisdictions, two very different instruments, one converging demand.

Both point at the same obligation. A firm using AI inside a regulated process must be able to show how that process actually operates: which decisions the system makes, which controls constrain it, where the data came from, and who is accountable when it acts.

That is not a model documentation problem. It is a process articulation problem. And most firms cannot meet it today.

What the FCA’s Mills Review Signals for UK Firms

The Mills Review is a review, not a rulebook. It does not introduce binding requirements, and it should not be read as one. What it introduces is a direction of travel, and for a regulator, direction of travel is rarely reversed.

The significance is in its framing. This is the first regulator-initiated review of its kind globally, which tells UK firms that the FCA is not waiting for AI-related harm to accumulate before forming a supervisory position. The review examines how AI is reshaping decisions, resilience, and accountability across retail financial services. Those three themes map directly onto existing supervisory priorities: consumer outcomes, operational resilience, and clear lines of responsibility under the Senior Managers and Certification Regime.

Read the Mills Review as an early indicator of the questions supervisors will ask. When AI shapes a lending decision, a pricing outcome, or a fraud intervention, the FCA will expect firms to explain not just what the system did, but why, and under what controls. The firms that struggle will be the ones treating AI governance as a policy document rather than a live property of how their processes run.

This is where risk and compliance teams should be looking now, ahead of any formal consultation. The gap between a documented control and an executed control is precisely the gap the Mills Review is signalling it intends to close.

The EU AI Act’s 23 July Deadline: Documentation Is Now Mandatory

The EU regime is not a direction of travel. It is a dated obligation.

As analysed by Wolters Kluwer, Pinsent Masons, and JD Supra through July 2026, the high-risk classification guidelines are now finalised, with a hard 23 July compliance milestone. For AI systems that fall into high-risk categories, which includes many uses in creditworthiness assessment, insurance pricing, and employment, the Act imposes immediate documentation and accountability obligations. This is not guidance a firm can defer while it forms a view.

The critical point for risk functions is what conformity actually requires. It is not enough to document the model: its training data, its performance metrics, its intended purpose. Conformity requires documented, traceable control over the process the model sits inside. The Act asks how the AI system is used, monitored, and overseen in operation. That is a claim about process, not about the algorithm.

UK financial services firms operating across both markets now face both regimes at once: the FCA’s forming supervisory expectation and the EU’s dated enforcement. The two do not conflict. They converge on the same evidence requirement, which is why process articulation as EU AI Act evidence is the practical starting point rather than two separate compliance exercises.

Why Compliance Now Starts With Process Articulation

You cannot evidence control over a process you have not articulated. This is the plain fact both regimes expose.

Most firms know what their AI systems are supposed to do. Far fewer can show what the surrounding process actually does: where the human decision points are, which controls fire and when, how a given output was reached, and who authorised the configuration that produced it. Regulators are no longer satisfied with the “what”. They are asking for the “why”: the decisions, the controls, the provenance, and the accountability behind each outcome.

Process articulation closes that gap. IGX360 Insights articulates AI-embedded processes into a documented, traceable record: not a narrative procedure that ages the moment it is written, but a live model enriched with governance and control context. Provenance and decision-logic are captured as the process runs, so the record reflects execution rather than intention.

This is the difference between governance theatre and provable conformity. A policy that asserts control is theatre. A record that demonstrates, for a specific transaction on a specific date, which controls applied and which human gate resolved it, is evidence. When an FCA supervisor or an EU conformity assessor asks how a high-risk process operates, the articulated record answers in the terms they use.

Articulation is the shared foundation both regimes ultimately demand. Build it once, and it serves the FCA’s supervisory questions and the EU’s documentation obligations from the same source. For a fuller account of how this maps to audit and provenance requirements, see the method behind it and the compliance manager view of what evidencing looks like in practice.

Be Ready Before the Deadline, Not After the Audit

The 23 July milestone is close, and supervisory attention only grows from here. The FCA has now shown its hand on direction; the EU has set its date.

Process visibility is the difference between provable compliance and hopeful assertion. A firm that can articulate how its AI-embedded processes operate walks into scrutiny with evidence. A firm that cannot walks in with a policy and an argument.

When the regulator asks how your AI-embedded processes actually operate, will you be reconstructing the answer, or reading it from the record?

Request a diagnostic: evidence how your AI-embedded processes operate, ready for FCA and EU AI Act scrutiny.

This article is commentary on regulatory developments and does not constitute legal advice. Firms should consult qualified counsel on their specific obligations under the EU AI Act and FCA rules.