10 AI Mistakes UK Financial Advisers Make, and the Compliant Fix
The FCA has said it will not write new AI-specific rules. It regulates AI through the rules you already hold: the Consumer Duty, the Senior Managers and Certification Regime, SYSC record-keeping, and the financial promotion rules, plus UK GDPR enforced by the ICO (FCA, AI and the FCA: our approach). That is the trap. Because there is no separate AI rulebook, an adviser who runs AI outside those existing rules is not in a grey area, they are in breach of rules that already apply. In the FCA's own words: "We do not plan to introduce extra regulations for AI. Instead, we'll rely on existing frameworks." Below are the ten mistakes we see most often in UK advice firms, and the fix for each. The fix is almost always the same shape: a named human, a written basis, and a record.
This article sits inside Serra's AI-for-wealth pillar. For the EU equivalent, see the AI rules every EU wealth-management firm must follow; for why the shared root cause is governance rather than adoption, see the AI gap in wealth is governance, not adoption.
Mistake 1: Putting live client data into a public AI tool
Pasting a client's name, holdings, health, or financial circumstances into a public chatbot is processing personal data under UK GDPR and the Data Protection Act 2018, with no AI exemption. A public tool can retain, log, or train on what you enter. You have no lawful basis for that onward use and no control over where the data sits.
The ICO is explicit that there is no 'AI exemption' to data protection law (ICO, Response to the consultation series on generative AI).
The compliant fix. No live client data goes into any public AI tool, full stop. Work with anonymised or synthetic inputs. If you need AI over real client data, use a tool with a data processing agreement, UK or EU data residency, and training-off by contract, and run a Data Protection Impact Assessment first, which the ICO treats as likely mandatory for AI processing personal data under Article 35 of the UK GDPR (ICO, Guidance on AI and data protection).
Mistake 2: No named human review before AI output reaches a client
The FCA holds a person accountable, not a tool. The Senior Managers and Certification Regime already applies to a firm's use of AI, so a senior manager remains responsible for the outcomes AI produces. "The AI wrote it" is not a defence, and an unreviewed AI output that reaches a client puts the Consumer Duty outcome outside anyone's control.
That accountability position is set out in FCA, AI and the FCA: our approach and the Mills Review, 6 July 2026. Under the Consumer Duty a firm must act to deliver good outcomes for retail customers (FCA Handbook, PRIN 2A.2).
The compliant fix. Every AI-assisted output that touches a client passes a named human before it goes out. Record who reviewed it. Make review a step, not a courtesy: the reviewer owns the content the moment they release it.
Mistake 3: AI content that crosses from information into a personal recommendation
There is a hard line in UK advice between generic information and a personal recommendation, which is regulated advice. An AI tool does not know your client's full circumstances and will generate text that reads as a recommendation to buy, sell, or hold. If that reaches a client, you have given a personal recommendation with no suitability assessment behind it.
The Consumer Duty consumer understanding outcome requires communications that equip clients to make informed decisions (FCA Handbook, PRIN 2A.5). A confident, unsuitable AI paragraph fails that on both counts.
The compliant fix. Scope AI to information, drafting, and summarising, never to the recommendation itself. The suitability judgement stays with the adviser and rests on the client's documented circumstances. Review AI drafts specifically for language that has drifted into "you should", and cut it.
Mistake 4: No record of AI-assisted client communications
SYSC 9.1 requires a firm to keep orderly records of its business, sufficient for the FCA to monitor compliance. If a complaint or an FCA review asks how a communication was produced and reviewed, having no record of the prompt, the output, or the sign-off is a record-keeping failure on its own.
That duty is FCA Handbook, SYSC 9.1, and the failure is separate from whatever the content actually said.
The compliant fix. Keep the record: the tool used, the material inputs, the output, and the named reviewer, filed to the client record like any other communication. Treat an AI-assisted email or report as reconstructable after the fact, because SYSC 9.1 expects you to be able to reconstruct it.
Mistake 5: AI-generated marketing that breaches the financial promotion rules
A financial promotion must be fair, clear and not misleading. AI is built to produce persuasive copy, and persuasive copy is exactly where "guaranteed", "protected", or an implied return sneaks in. AI does not check that a performance or safety claim is properly qualified. It optimises for the sentence.
COBS 4.2 requires that where you use a term like "guaranteed" or "secure", you present all the information needed, with clarity and prominence, to make its use fair, clear and not misleading (FCA Handbook, COBS 4.2).
The compliant fix. Every AI-drafted promotion goes through the same financial promotion sign-off as human-written copy, with a named approver. Strip unqualified performance or safety language. The fair, clear and not misleading test applies to the words, not to who or what typed them.
Mistake 6: Treating the Consumer Duty as separate from your AI decision
The Consumer Duty sets a cross-cutting obligation to act in good faith, avoid foreseeable harm, and support retail customers in pursuing their financial objectives. An AI tool that gives faster but shallower service, or pushes clients toward a standardised output that does not fit their objective, produces a worse outcome even when it feels efficient.
That cross-cutting obligation is FCA Handbook, PRIN 2A.2. The FCA's Mills Review flags precisely this risk: AI reshapes the consumer journey and can amplify harm as well as benefit (FCA, the Mills Review, 6 July 2026).
The compliant fix. Judge any AI tool by the client outcome, not the time saved. Before you adopt it, write down how it supports a good outcome and where it could cause foreseeable harm, and monitor that in practice. If the honest answer is "it is faster for us and no better for the client", that is a Consumer Duty problem.
Mistake 7: Shadow AI, no inventory of the tools your team actually uses
You cannot govern what you have not listed. Advisers and paraplanners quietly adopt free AI tools inside a firm, and each one is an uncatalogued route for client data to leave and for unreviewed content to reach clients. An unknown tool is an ungoverned tool.
Because the FCA regulates AI through existing frameworks rather than a new rulebook, every one of those tools sits inside SYSC systems-and-controls and the Consumer Duty whether the firm has acknowledged it or not (FCA, AI and the FCA: our approach).
The compliant fix. Keep a written inventory of every AI tool in use, what it does, what data it touches, and who owns it. Approve tools before use, not after discovery. An inventory you review on a set cadence turns shadow AI into governed AI.
Mistake 8: No documented lawful basis for a live-data AI workflow
If an AI workflow processes client personal data, UK GDPR requires a lawful basis under Article 6, and the ICO treats a DPIA as likely required before the processing starts. Firms often deploy the workflow first and reach for a lawful basis later. That is backwards.
The ICO's guidance treats a DPIA as likely required for AI systems that process personal data (ICO, Guidance on AI and data protection), and its position is that data protection law applies to AI with no exemption (ICO, Response to the consultation series on generative AI).
The compliant fix. Before any live-data AI workflow goes live, document the lawful basis, complete the DPIA, and reflect the processing in your privacy notice. If you cannot name the lawful basis, the workflow does not run on live data until you can.
Mistake 9: Trusting AI output without validating it
Generative AI produces confident text that can be wrong. The ICO is direct that accurate training data will not stop models hallucinating, and the accuracy principle requires personal data to be accurate, with higher statistical accuracy where the output drives decisions about people. A hallucinated fund fact or a wrong tax figure that reaches a client is a real harm.
Both points are from ICO, Accuracy of training data and model outputs.
The compliant fix. Validate every material factual claim in AI output against a primary source before it goes out. Treat AI as a first-draft engine, never as a source of truth. The higher the stakes of the decision, the harder you check.
Mistake 10: No policy owner and no review cadence for AI
The Senior Managers and Certification Regime works by assigning accountability to named individuals, and the FCA applies it to AI use. A firm using AI with no named policy owner and no review schedule has an accountability gap: when something goes wrong, no one held the responsibility in advance.
The FCA applies SM&CR to AI (FCA, AI and the FCA: our approach) and reports that most firms with AI have an individual accountable for their approach (FCA, AI in financial services). The ones that do not are the outliers a review will find.
The compliant fix. Name a senior individual who owns the AI policy, and set a fixed review cadence for the policy, the tool inventory, and the outcomes. Accountability that is written down and reviewed is the difference between governed AI and a finding waiting to happen.
Why is governance the fix, not a better AI tool?
The pattern across all ten mistakes is one thing: a named human, a written basis, and a record, applied to existing UK rules. That is governance, and most UK IFAs do not have it written down yet. Buying a better AI tool does not close that gap; building the governance around it does.
The FCA has told firms plainly that it will judge their AI against the rules they already hold (FCA, AI and the FCA: our approach). That is what Serra Education builds. The Regulator Test scores your current AI use against exactly these rules and shows you where an FCA or ICO review would find a gap. The Consulting 1 session (250 EUR, credited in full to a Tier 1 audit) turns the result into a working AI policy: named owner, tool inventory, review workflow, and a lawful-basis and record-keeping process your team can actually run.
See the full offer and run the test at the AI-for-wealth pillar. Book the Regulator Test and Consulting 1 session on the report and booking page.
FAQ
Has the FCA made new rules for AI in financial advice?
No. The FCA has said it will not introduce extra AI-specific regulations and will rely on existing frameworks instead: the Consumer Duty, the Senior Managers and Certification Regime, SYSC record-keeping, the financial promotion rules, and UK GDPR enforced by the ICO (FCA, AI and the FCA: our approach). An adviser running AI outside those rules is in breach of rules that already apply.
Can a UK adviser put client data into ChatGPT or another public AI tool?
No live client data should go into any public AI tool. Doing so is processing personal data under UK GDPR with no AI exemption, and a public tool can retain, log, or train on the input (ICO, Response to the consultation series on generative AI). Use anonymised inputs, or a contracted tool with a DPA, data residency, training-off, and a completed DPIA.
Who is accountable when an AI tool produces a bad client outcome?
A named senior individual, not the tool. The FCA applies the Senior Managers and Certification Regime to a firm's use of AI, so a senior manager remains responsible for the outcomes AI produces (FCA, AI and the FCA: our approach). "The AI wrote it" is not a defence, which is why every client-facing AI output needs a named human reviewer.
Do I need to keep records of AI-assisted client communications?
Yes. SYSC 9.1 requires orderly records sufficient for the FCA to monitor compliance (FCA Handbook, SYSC 9.1). If a complaint or review asks how a communication was produced and reviewed, having no record of the prompt, the output, and the sign-off is a record-keeping failure in itself, separate from the content.
What is the fastest way to make AI use compliant in a small advice firm?
Write down the governance: name a senior policy owner, keep an inventory of every AI tool in use, require a named human review before any AI output reaches a client, document the lawful basis and DPIA for any live-data workflow, and keep the record. The Consumer Duty and SM&CR already apply; the gap is usually that none of this is written down yet.
Serra Education provides process and tooling consulting only, never Serra Wealth investment advice.
This article is general information on AI-adoption process and governance. It is not investment, legal, or compliance advice. Each firm is responsible for its own regulatory compliance and for validating any AI output it relies on. Do not put live client data into any AI workflow that is not contracted and assessed for it. Regulatory references are to FCA and ICO sources current as at 24 July 2026; check the source for the position on the date you rely on it.