AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← News
Research2026-07-17

UK FCA Mills Review Mandates Independent Annual AI Safety Audits with Attorney General Enforcement and Public Disclosure

Source

The Week AI Governance Stopped Being Optional

techletter.co

Via techletter.co

What happened

The UK Financial Conduct Authority published the Mills Review on July 6, 2026, establishing a mandatory requirement for companies operating under FCA oversight to submit their existing AI safety plans to independent auditors on an annual basis. The review mandates public disclosure of those audit outcomes, meaning that gaps or deficiencies in a firm's safety documentation will be visible to regulators, investors, and the public rather than remaining internal. Critically, the Mills Review does not introduce new substantive AI safety standards; instead, it operationalizes the validation of commitments firms have already made. Enforcement authority sits with the Attorney General, elevating the consequence of non-compliance beyond financial penalty into potential legal proceedings. The instrument sits within the broader UK AI Regulation Framework and reflects the FCA's shift toward governance-through-transparency as a primary supervisory tool.

Why it matters

  • ·The Attorney General enforcement mechanism transforms AI safety plan deficiencies from a regulatory fine risk into a potential legal liability, requiring legal, compliance, and audit functions to treat AI safety documentation with the same rigor applied to financial statements.
  • ·Because the Mills Review audits existing plans rather than imposing new standards, firms that have produced AI safety documents primarily for internal or marketing purposes will face immediate exposure when those documents are subjected to independent scrutiny and public disclosure.
  • ·Annual independent auditing creates a recurring assurance cycle that must be integrated into existing internal audit planning calendars, vendor selection processes, and board reporting rhythms, particularly for financial services firms already navigating UK AI Regulation Framework obligations.

Governance controls affected

What to do now

  • Conduct a substantive review of all existing AI safety plans and supporting documentation to assess whether they would withstand independent audit scrutiny, identifying gaps before an external auditor does.
  • Map the Mills Review audit cycle into your internal audit planning calendar and assign ownership to a named function, ensuring the annual submission timeline is treated as a hard compliance deadline equivalent to financial audit obligations.
  • Assess whether current AI safety documentation meets a public-disclosure standard, and remediate any language that is aspirational, vague, or unsupported by evidence of actual controls in operation.
  • Engage legal counsel to evaluate the firm's exposure under the Attorney General enforcement mechanism and determine whether existing indemnities, D&O coverage, or legal privilege arrangements need to be updated.
  • Initiate a vendor selection or scoping process for an independent AI safety auditor, establishing qualification criteria and conflict-of-interest standards before the first annual submission deadline.

What to watch next

Compliance teams should monitor the FCA for supplemental guidance clarifying the scope of entities covered by the Mills Review, particularly regarding non-financial firms with significant FCA-regulated activities and multinational organizations with UK operations. The intersection of this requirement with incoming EU AI Regulation Framework conformity assessment obligations will create dual-audit pressure for firms operating across both jurisdictions, and regulators may issue coordination guidance. Attorney General enforcement actions, if any are initiated in the first annual cycle, will set important precedents for what constitutes an adequate safety plan and a compliant audit process, making early enforcement signals a critical monitoring priority.

Stay ahead of stories like this

Get every UK AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Enforcement2026-08-05

Federal Reprimand Over Medicare AI Prior-Auth Puts Healthcare Automation Controls on Notice

A federal reprimand has been issued following failures in Medicare's AI-driven prior-authorization pilot, which produced automated delays and disputed denials without adequate clinical oversight or appeal pathways. The action, reported by the AI Failure Index, signals that regulators will hold healthcare organizations accountable for automated benefit decisions that lack meaningful human review and auditability. The case establishes a concrete enforcement reference point for any organization using AI in utilization management or claims adjudication.

Enforcement2026-07-31

EU AI Act Enforcement Begins: 38 New Staff, Fines, and Whistleblower Tools

The EU AI Act entered force on July 31, 2026, and the European Commission simultaneously expanded its AI Office in Brussels with 38 additional staff. The expanded office is empowered to monitor AI companies worldwide for compliance violations, issue substantial fines, and revoke EU market access for non-compliant firms. New obligations include watermarking AI-generated content, maintaining model documentation, and managing systemic risks such as cybersecurity threats and harmful manipulation.

Research2026-07-30

Kriv AI Case Study Shows Quarterly Review Cadence and Risk Register as Baseline for Financial Services AI Governance

Kriv AI published a case study documenting how it built a centralized AI governance framework for a regional US financial services firm that lacked structured AI oversight. The engagement produced a formal risk register, a quarterly review cadence, and a continuous compliance monitoring function. Financial services compliance teams can use the documented approach as a template for model inventory, periodic assurance, and regulator-ready governance programs.