In July 2026 I asked an AI engine how to use AI safely in a regulated firm. The answer was careful. It was measured, it hedged in the right places, and it told me nothing reckless.

Then read who it is written for.

Check whether your firm's compliance team has approved it. Use only a firm-approved account. Record it in your firm's AI or compliance register. Make sure the tool is approved by your firm. Ensure any recommendations comply with your firm's processes.

Every safe path runs through an institution. A compliance team to ask. An enterprise agreement to sit under. A register that somebody maintains. An approvals process that somebody owns.

For a broker who is an appointed representative, or a directly authorised firm of one to five people, or a sole trader, none of those things exists. There is no compliance team. There is no managed account. There is no register, because nobody has ever written one.

The advice is not wrong. It is addressed to somebody who is not in the room.

What was actually said, and when

Those phrases are not invented for the sake of an argument. They were recorded on 9 July 2026, during a run of fixed questions put to AI engines to see what a broker actually gets back.

One engine, one day. That is worth stating plainly, because a single run is a sample and not a fact, and this publication has already learned that the hard way: in the same exercise, four findings were overturned simply by asking again. So this is not a claim about what every engine does today. It is a record of what one engine said on a named day, and it is offered as something to weigh rather than something to accept.

Asked about using AI in a protection fact find, that engine deferred to "your firm" six times in a single answer. Do not enter client data into a public AI tool "unless your firm's policies explicitly allow it". Verify the output complies with "your firm's procedures". Align with "your firm's compliance framework". Ensure the tool is "approved by your firm".

Asked the same territory again under different wording, the pattern held. Be transparent about the use of AI "if your firm's policies or applicable laws require it". Avoid entering personal or sensitive information into AI systems "unless they're approved by your firm". The first step of the workflow it proposed had the AI asking "your firm's approved fact-find questions".

Asked who covers AI compliance for UK brokers, it answered by describing what "most broker compliance teams" are asking for: usage policies for staff, approval processes, risk registers, board reporting. Note whose teams those are.

The sentence worth stopping on

One line does something the others do not.

"remove or anonymize client-identifying information if required by your firm's policy"

Read that as the person it was written to. De-identification, which is the single most protective thing you can do before client information goes anywhere near a general-purpose tool, is offered conditionally. It is made to depend on a policy.

At a firm of one there is no policy to require it. The condition is never met.

I am not going to claim the engine told anyone to skip that step, because it did not, and overstating this would be the same failure as the advice itself. What it did was hang a safeguard on an institution, in a sentence addressed to a reader who does not have one. The people most exposed by that framing are the people least likely to notice it.

The honest counter-evidence

There is a case against the strong version of this, and it appeared the same day.

Asked whether a mortgage broker can use ChatGPT under FCA rules, an engine closed by offering to outline a practical AI policy "if you're a directly authorised firm or an appointed representative". That is the audience's actual regulatory structure, named without being prompted.

So the sweeping form of the complaint does not survive, and it should not. The engine can name a DA firm and it can name an AR. What it still does, in the same breath, is describe governance as something a firm has, rather than something one person has to build. The structure gets recognised. The apparatus is still assumed.

What the regulator actually says

Here is where it gets interesting, because the FCA has already looked at this question, and its answer is not the one that came back from a chat window.

The AI Update considers whether there should be a dedicated Senior Manager responsible for AI, and records that respondents thought existing structures were sufficient. Then, at paragraph 3.40, it describes how technology responsibility normally sits:

"In PRA-authorised SM&CR banking and insurance firms and FCA-authorised Enhanced SM&CR firms (but not Core or Limited Scope SM&CR firms), technology systems are normally under the responsibility of SMF24 (Chief Operations function)."

Read the bracket. But not Core or Limited Scope SM&CR firms. The same paragraph goes on to require dual-regulated firms and solo-regulated Enhanced firms to ensure a Senior Management Function manager has overall responsibility for each activity and business area, which is what makes any use of AI fall within an SMF manager's remit.

That obligation, too, is described for those firms.

Taken alone, paragraph 3.40 reads like a let-off. The governance machinery is for the large and the complex, and the small firm is named as outside it.

Then comes 3.41:

"In addition, all Senior Managers in SM&CR firms (including solo-regulated Core and Limited Scope firms) are required to have a Statement of Responsibilities. This sets out what they are responsible for within the business. They are also subject to the Senior Manager Conduct Rules, including requiring Senior Managers to take reasonable steps to ensure that the business of the firm, for which they are responsible, is effectively controlled."

Including solo-regulated Core and Limited Scope firms.

The two answers, side by side

Put them together and the shape is clear.

The engines assume a department. A function to consult, a process to route through, a register somebody else maintains.

The regulator assumes a person. Someone with a Statement of Responsibilities that says what they are responsible for. Someone subject to the Conduct Rules. Someone who must take reasonable steps to ensure the business they are responsible for is effectively controlled.

Only one of those two descriptions matches who is actually sitting there on a Tuesday afternoon deciding whether to paste a client's circumstances into a chat window.

Note what 3.41 does not say. It does not say reasonable steps to comply with AI rules. It says reasonable steps to ensure the business you are responsible for is effectively controlled. AI is not carved out of that, and it is not singled out within it. It is simply part of the business you are responsible for.

Which means the answer to "who approves this tool" is not that there is no answer. It is that the question was always pointed at you.

Where this piece stops

I am not going to tell you what your register should contain, what your assessment of a tool should cover, or what makes a personal subscription defensible. Not because those are unanswerable, but because a general answer to them would be worth less than the confidence it produced, and because the honest version depends on facts about your firm that I do not have.

What I will say is that the gap is real, and it is not your failure for not having found the answer. The answers that exist were written for somebody else. They assume an apparatus, because the people who write about AI governance are mostly writing for the firms that buy AI governance, and those firms have compliance teams.

The regulator, to its credit, did not make that mistake. It wrote 3.41.

There is nobody else on your Statement of Responsibilities.