What are the FCA's rules on AI for UK wealth firms and advisers? (2026)
The FCA has no separate AI rulebook. It regulates AI through the rules a firm already holds: the Consumer Duty (PRIN 2A), the Senior Managers and Certification Regime, SYSC 9.1 record-keeping, the COBS 4.2 financial-promotion rules, and UK GDPR enforced by the ICO. This guide explains each, neutrally, so you can map your AI use to it.
This is a plain rules explainer, not a list of mistakes. If you want the ten most common failures and their fixes, read the AI mistakes UK financial advisers make. Here we set out what the FCA's framework actually says and where AI sits inside it.
Does the FCA have a specific AI rulebook for wealth firms?
No. The FCA has been explicit that it does not plan to introduce extra regulations for AI and will rely on existing frameworks instead. That is a deliberate choice, not a gap. It means AI use is judged against the rules a firm already holds, so there is no separate compliance regime to wait for and no grey area. An AI workflow run outside the existing rules is inside those rules' scope whether the firm has acknowledged it or not.
For a UK wealth firm or adviser, the practical consequence is that five familiar bodies of rules already govern AI: the Consumer Duty, the Senior Managers and Certification Regime, SYSC systems-and-controls record-keeping, the financial-promotion rules, and UK GDPR under the ICO. The rest of this guide takes each in turn.
What does the Consumer Duty (PRIN 2A) require when a firm uses AI?
The Consumer Duty sets a cross-cutting obligation, in PRIN 2A, to act to deliver good outcomes for retail customers: to act in good faith, avoid foreseeable harm, and support customers in pursuing their financial objectives. The Duty applies to how a firm uses AI in the same way it applies to any other tool: the test is the outcome for the client, not the efficiency for the firm.
Two of the Duty's outcomes bear directly on AI. The consumer-understanding outcome requires communications that equip clients to make informed decisions, which reaches any AI-drafted client message. And the good-faith-and-foreseeable-harm obligation means an AI tool that delivers faster but shallower service, or pushes clients toward a standardised output that does not fit their objective, can produce a worse outcome even when it feels efficient. The Duty asks the firm to judge AI by the client result, and to write down how a tool supports a good outcome and where it could cause harm.
How does the Senior Managers and Certification Regime (SM&CR) apply to AI?
SM&CR works by assigning accountability to named individuals, and the FCA applies it to a firm's use of AI. A senior manager remains responsible for the outcomes AI produces; the regime does not recognise "the AI did it" as a transfer of responsibility. Accountability for an AI-assisted output sits with a person, before and after the tool is involved.
In practice this means a firm using AI needs a named individual who owns the AI approach: the policy, the tool inventory, and the review of outcomes. The FCA has reported that most firms using AI already have an individual accountable for their approach, which makes the firms without one the outliers a supervisory review is likely to notice. SM&CR is the reason AI governance has to have an owner, not just a document.
What records does SYSC 9.1 require for AI-assisted work?
SYSC 9.1 requires a firm to keep orderly records of its business, sufficient to enable the FCA to monitor the firm's compliance and to check it has met its obligations to clients. That obligation does not soften because a model did the drafting. An AI-assisted client communication is a business record like any other, and it has to be reconstructable after the fact.
Concretely, if a client complaint or an FCA review asks how a communication was produced and reviewed, the firm needs to show the tool used, the material inputs, the output, and the named reviewer. A firm that used an AI tool but kept no record of the prompt, the output, or the sign-off has a record-keeping gap under SYSC 9.1 that stands on its own, separate from whatever the content said.
Do the financial-promotion rules (COBS 4.2) apply to AI-generated marketing?
Yes. A financial promotion must be fair, clear, and not misleading under COBS 4.2, and that test applies to the words, not to who or what produced them. AI is built to generate persuasive copy, and persuasive copy is exactly where unqualified terms like "guaranteed", "protected", or an implied return can appear. COBS 4.2 requires that where such terms are used, the firm presents all the information needed, with clarity and prominence, to make their use fair, clear, and not misleading.
So an AI-drafted promotion is subject to the same financial-promotion sign-off as human-written copy, with a named approver. The rule does not treat an AI-generated advert as a lower category of promotion; it is a promotion, and the fair-clear-not-misleading standard is the standard it must meet.
Where do UK GDPR and the ICO fit into the FCA's AI framework?
UK GDPR sits alongside the FCA's rules rather than inside them, and it is enforced by the ICO, not the FCA. The moment an AI workflow processes client personal data, UK GDPR applies: the firm needs an Article 6 lawful basis, and the ICO treats a Data Protection Impact Assessment as likely required before the processing starts for AI systems that process personal data, under Article 35. The ICO is also explicit that there is no 'AI exemption' to data-protection law.
For a wealth firm this means the data-protection layer is a parallel obligation, not an optional extra. An AI workflow that touches client data needs a documented lawful basis, a completed DPIA where the ICO expects one, and the processing reflected in the privacy notice, before it goes live on real data, not after.
What is the common thread across all five rules?
The same shape runs through all five: a named human owns the output, there is a written basis for the decision, and there is a record. Consumer Duty asks who is accountable for the outcome; SM&CR names that person; SYSC 9.1 keeps the record; COBS 4.2 makes a human approve the promotion; UK GDPR documents the lawful basis. None of the five regulates which AI model a firm picks. They regulate the governance around it.
That is why AI in a UK wealth firm is a governance question, not a technology question. This is the work Serra Education does with wealth firms: mapping each AI workflow to exactly these rules and building the named-human, written-basis, recorded governance that the FCA's framework expects. The entry point is a Consulting 1 session, 250 EUR, credited toward the Tier 1 audit if you go on to the full engagement.
See the full picture at AI for Wealth. For the ten most common failures under these rules, read the AI mistakes UK financial advisers make; for why this is a governance gap rather than an adoption one, the AI gap in wealth is governance, not adoption. Running an IFA or advice firm? Start with the UK IFA compliance finder. To book the Consulting 1 session, use the report and booking page.
FAQ
Is there an FCA AI rulebook I need to read?
No single AI rulebook exists. The FCA regulates AI through existing rules (the Consumer Duty (PRIN 2A), SM&CR, SYSC 9.1, COBS 4.2) plus UK GDPR under the ICO. Read those, and map your AI use to each, rather than waiting for a dedicated AI regulation the FCA has said it does not plan to write.
Who is responsible when an AI tool gets something wrong?
A named senior individual, under SM&CR. The regime assigns accountability to a person, and the FCA applies it to AI use, so "the AI did it" is not a defence. A firm using AI needs a named owner of its AI approach who is responsible for the outcomes the tool produces.
Do I need to keep records of AI-assisted client work?
Yes, under SYSC 9.1. The firm must keep orderly records sufficient for the FCA to monitor compliance, and an AI-assisted communication is a business record like any other. Keep the tool used, the material inputs, the output, and the named reviewer, filed to the client record.
Does the Consumer Duty change how I can use AI?
The Consumer Duty (PRIN 2A) asks you to judge an AI tool by the client outcome, not the time it saves. Before adopting a tool, document how it supports a good outcome and where it could cause foreseeable harm, and monitor that. A tool that is faster for the firm but no better for the client is a Consumer Duty concern.
Does UK GDPR apply on top of the FCA's rules?
Yes. UK GDPR is a parallel obligation enforced by the ICO. Any AI workflow processing client personal data needs an Article 6 lawful basis and, where the ICO expects it, a DPIA under Article 35 completed before the workflow goes live. There is no 'AI exemption' to data-protection law.
Serra Education provides process and tooling consulting only, never Serra Wealth investment advice.
This article is general information on AI-adoption process and governance. It is not investment, legal, or compliance advice. Each firm is responsible for its own regulatory compliance and for validating any AI output it relies on. Do not put live client data into any AI workflow that is not contracted and assessed for it. Regulatory references are to FCA and ICO sources current as at 28 July 2026; check the source for the position on the date you rely on it.