Here is a question almost no broker can answer: if the FCA asked you today how you control your use of AI, what would you actually show them?
Most go quiet.
Not because they are reckless. Because no one has ever asked them to evidence it. They use AI every day, to draft emails, summarise calls, tidy file notes, and it works, so they have never stopped to think about what they would put on the table if someone asked them to justify it.
That is the real exposure, and it is worth being precise about, because it is not the one most brokers think they have.
Using AI is not the problem. Being unable to evidence how you control it is.
The FCA's position, set out in its April 2024 AI Update, is that AI use inside a regulated firm is already governed by the rules you operate under, Consumer Duty, SM&CR, UK GDPR. Nothing new was added. What those rules have always demanded is not just that you behave well. It is that you can show you do.
Consumer Duty asks you to deliver good outcomes and to be able to evidence them. SM&CR asks the senior manager, which in a smaller firm is you, to take reasonable steps to control the business, and the Update is explicit at section 3.41 that this reasonable-steps duty reaches solo-regulated Core and Limited Scope firms, with AI use falling inside it. "Reasonable steps" is not a state of mind. It is something you can point to. A regulator does not accept "I am careful" as an answer. It accepts a document, a record, a process.
That position has just hardened. On 6 July 2026 the FCA published the Mills Review, its landmark look at what AI does to retail financial services out to 2030. It proposes no new AI-specific rules. Its conclusion is that "the regulatory framework remains fit for purpose", and that the principles-based, outcomes-focused approach you already live under, the Consumer Duty and the Senior Managers Regime, is the approach that carries AI too. Nor did the industry ask for anything else. The review records that respondents "did not seek changes to this system. They wanted clarity on how to interpret and govern increasing use of AI within the existing regime."
Read that twice, because it settles the question brokers keep asking. Nobody is coming with a new AI rulebook. The rules you are already accountable under are the rules.
And the review is blunt about where the pressure lands. Firms, it says, will need "senior managers who can evidence reasonable steps in automated environments". As AI spreads through a workflow, it warns, this "makes it more difficult to evidence how outcomes were delivered, demonstrate reasonable steps, or identify the source of errors, bias or harm". Not harder to behave well. Harder to show that you did. The evidence problem, named by the regulator, in a review about the next five years.
So the broker who uses ChatGPT carefully but has nothing to show is not in a better position than the one who is reckless. In the eyes of the rule, they are in the same place: no evidence, no defence.
The instinct at this point is to ask what to bolt on: which policy, which tool, which form. That is the wrong end to start from, because it treats the evidence problem as a shopping list. It is not. It is a change in what the question even is. The regulator is not asking whether you own the right documents. It is asking whether, on any given piece of client work, you could show where your judgement sat and how you stayed in control of the outcome.
That is why the gap stays invisible. A workflow that produces good outcomes and no complaints looks identical, from the inside, to one that could never be defended. The difference only surfaces the day someone asks you to account for it, and by then the record either exists or it does not. You cannot evidence, after the fact, a control you were not exercising at the time.
None of this is a reason to stop using AI, and none of it is new. It is the same standard the Consumer Duty, the Senior Managers Regime and UK GDPR have always set: not that you behaved well, but that you can demonstrate you did. AI has not raised the bar. It has widened the distance between behaving well and being able to prove it, because the tool is fast, the work feels finished, and nothing in the moment tells you the evidence was never captured.
So the honest reading of the Mills Review is not really a warning about AI. It is a warning about memory: the firm's memory of its own decisions. The brokers who can answer the regulator's question in an afternoon are not the ones with the most tools. They are the ones who can show their working. The exposure the review has named is the quiet distance between using AI and being able to account for how you used it, and it was sitting inside the existing rules the whole time.