Search the evidence

Find the signal.

Search titles, impact clusters, countries, organizations and the full text of every analysis.

2 stories found

Work & marketsUnited Kingdom+3 clusters01

FCA Mills Review, “AI and the Future of Retail Financial Services”

The UK Financial Conduct Authority published the Mills Review, a 147-page report on AI in retail financial services. It reports that 81% of surveyed firms are adopting AI, that agentic AI is already being piloted or deployed by more than half of industry respondents, and that by 2030 AI may move from back-office support into consumer-facing systems able to recommend, apply, pay, switch products, or take action under preset goals.

2 min
Glowing vulnerability tickets flood a financial vault and pile up behind a narrow human-controlled repair hatch.
SecurityUnited Kingdom+3 clusters02

Frontier AI can find vulnerabilities faster than financial firms can fix them

The Financial Conduct Authority says frontier AI is moving the cyber bottleneck from discovery to remediation. In a multi-firm review, financial companies reported that advanced models can identify, validate, prioritize, and combine vulnerabilities faster, increasing pressure on the people and processes that must decide which findings are real and how to fix them safely. The constraint is no longer only model capability. It is validation capacity, remediation ownership, engineering resources, patch testing, emergency change control, dependency mapping, evidence of closure, and the ability to keep important business services running while fixes accelerate. Firms also said the surrounding harness matters more than the model label: system context, specialist tools, permission limits, human approvals, risk ownership, and escalation determine whether model output becomes useful defense or an unmanageable queue. The FCA's publication creates no new rules or regulatory expectations, and the observations come from engaged firms rather than a controlled sector-wide test. Still, the institutional lesson is strong. Counting vulnerabilities found can exaggerate progress when the repair system cannot absorb them. Banks and insurers should measure time from discovery to validated closure, backlog quality, cross-system attack paths, service disruption, and who has authority to accept or escalate risk. Frontier AI can make an organization see faster. Cyber resilience depends on whether the organization can act at the same speed without breaking something else.

6 min