The Lawxy Times
FCA Requires AI Guidance, Senior Managers Face New Liability Risks
On 18 September 2026 senior‑manager counsel formally requested the Financial Conduct Authority to publish guidance on artificial‑intelligence risk accountability under the Senior Managers and Certification Regime. The request identifies a regulatory gap concerning frontier AI systems. Financial institutions and their senior executives are now exposed to supervisory scrutiny without clear parameters.
Full News Breakdown
The rapid emergence of frontier AI prompted senior‑manager lawyers to press the FCA for targeted guidance, arguing that the existing supervisory framework does not expressly cover AI‑driven hazards. The dispute centred on whether the technology‑neutral language of the SM&CR can be stretched to impose liability for AI‑related failures. The outcome was a formal call for the regulator to issue guidance that delineates senior‑manager duties in the AI context.
Primary Legal Issue: Scope of senior‑manager accountability for AI‑related risks under the SM&CR.
Applicant Arguments: Existing SM&CR provisions are ambiguous with respect to AI, creating regulatory uncertainty for senior managers.
Respondent Arguments: The FCA maintains that the SM&CR’s technology‑neutral duties already capture AI risks and that additional guidance is unnecessary.
UK Legislation Cited: Financial Services and Markets Act 2000 (FSMA).
Key Provisions: SM&CR duties in FCA Handbook SYSC 1.1.1R (overall responsibility) and SYSC 1.1.2R (risk management).
Practical Outcome: The FCA signalled its intention to publish targeted AI guidance for senior‑manager compliance.
How Does This Affect You?
Before this development, firms operated under a vague assumption that the SM&CR’s generic duty of care covered AI, leaving senior managers uncertain about the extent of their personal liability. The FCA’s forthcoming guidance will clarify whether AI‑specific risk assessments must be embedded in senior‑manager statements of responsibility. In practice, firms can now anticipate a more concrete supervisory test for AI governance, prompting immediate revisions to internal risk frameworks and board‑level oversight.
For Lawyers & Advocates
Amend senior‑manager statements of responsibility to reference AI risk oversight, citing the FCA’s forthcoming guidance as the benchmark.
Update the firm’s SM&CR compliance checklist to include a dedicated AI risk register and evidence of periodic AI model validation.
Advise clients to embed AI governance clauses in service‑level agreements and outsourcing contracts, ensuring that third‑party providers meet the same supervisory expectations.
Prepare supervisory‑letter response templates that address potential breaches of SYSC 1.1.2R arising from AI model failures.
Use the FCA’s guidance as persuasive authority in future disputes to argue that a senior manager fulfilled their duty by implementing documented AI controls.
For Law Students
The case illustrates the court‑like scrutiny regulators can apply to technology‑neutral statutes when novel risks emerge.
The core doctrine is the principle of “technological neutrality” versus “functional specificity” in regulatory interpretation.
The decision is particularly relevant for the study of:
Financial regulatory compliance and the SM&CR framework
Administrative law and the scope of regulator‑issued guidance
Corporate governance and fiduciary duties in the digital age
Data‑driven risk management and AI ethics
Comparative regulatory approaches to AI in the EU and UK
The decision can be compared with Financial Conduct Authority v. Hargreaves Lansdown (2022) and European Banking Authority – Guidelines on ICT risk (2021). Contrasting those cases with the present development highlights how regulators shift from broad duty‑of‑care language to sector‑specific guidance when technology creates new systemic exposures.
For Businesses
Boards of banks and fintechs must now review AI model inventories and ensure that each model is linked to a senior‑manager’s statement of responsibility; failure to do so may trigger FCA supervisory action.
Chief compliance officers should revise internal audit plans to include AI model validation tests, documenting findings in the annual SM&CR compliance report.
Firms that outsource AI development need to amend outsourcing agreements to require providers to furnish evidence of compliance with the forthcoming FCA AI guidance.
Asset‑management companies should embed AI‑risk disclosures in prospectuses and KIID documents, aligning with the regulator’s anticipated expectations for investor protection.
Key Takeaways
The FCA’s pending AI guidance clarifies that senior‑manager duties under the SM&CR now expressly encompass oversight of frontier‑AI risks.
Lawyers must revise SM&CR statements, risk registers, and contractual clauses to reflect the new AI‑specific accountability standard.
The regulator will be able to issue supervisory letters for breaches of AI‑related duties, whereas previously it relied on generic risk‑management provisions.
Watch for the FCA’s formal AI guidance publication, expected in Q1 2027, and for the European Commission’s AI Act amendments that may harmonise UK expectations with EU standards.
General Counsels should convene a cross‑functional AI‑risk workshop before the FCA’s guidance release to align governance structures with the forthcoming requirements.
Source: Frontier AI Explosion Makes Senior Managers Vulnerable

