Abstract AI governance and financial regulation concept with digital compliance, risk management, and regulatory technology elements.

Two big themes in 2026 regulation, so far....

September 15, 20263 min read

Two big themes in 2026 regulation, so far....

In January, I wrote about what I was watching for 2026 — not predictions, just areas where I expected the momentum to keep building. Last Tuesday, as the FCA's new non-financial misconduct rules took effect for a wider population of firms, it feels like the right week to check how some of those areas have actually moved.

AI adoption and governance was the one I flagged as "the big one." That's held up, although with some unexpected twists. The FCA's Mills Review, published in July, sets out something I think is genuinely useful: an autonomy spectrum running from Operator through Collaborator, Consultant, Approver, to Observer, replacing the vague comfort of "human in the loop" with a description of what a person is actually meant to be doing at each stage. It turns a values statement into something a firm can be held to. This is the most current thinking in regulation on this control.

However, in the weeks since this review was published, we have seen AI agents operating with an unexpected level of autonomy in the way they respond to tasks, as in the Hugging Face and related cases. This raises the new question, and one which is now seeing research emerge, that the current AI development is creating AI agents that push humans out of the loop**. This poses the very real challenge “that current approaches to the development and deployment of AI agent systems do not support effective human oversight – they contribute

to its degradation”. (paper by Margaret Mitchell et al, AI Agents Push Humans Out of the Loop). If human in the loop is a critical part of our governance and control framework – there is more thinking to be done.

Non-financial misconduct is a topic I also identified in my January letter, and I think may have evolved most in this time. With two key notable changes:

1) Last week, the FCA's new non-financial misconduct rules took effect for a much wider population of financial services firms. Vague assurance about "a good culture" can no longer be the standard in those parts of the financial services sector where NFM was only an HR issue. For senior managers, in NFM cases, did you know (or should you have) and what did you do. A significant change for the non-banks now captured and driving some great conversations across broader financial services, with analysis of how effective implemented controls are, and why NFM continues to take place.

2) In January I wrote that the language was shifting from "culture" as an abstract concept to specific expectations about how firms identify, respond to, and remediate conduct issues. The FMSB's Spotlight Review on non-financial risk, published in August, goes further, treating behavioural risk as something that cuts across every other risk category rather than sitting beside it, and naming specific ways AI adoption is reshaping that risk.

I'm not going to try to tie those two threads together. But there's a phrase sitting in the AI paragraph above that I want to deal with properly, on its own: "human in the loop." I loathe it, and I don't think it has any place in how we talk about how people actually work. I'll be picking that apart on LinkedIn this week — and opening a call for a better term. All suggestions welcome!

All the best,

Emily

Back to Blog