Marrow
Back to blog
·Marrow

What the FCA's Mills Review Means for AI and Insurance Distribution

What the FCA's Mills Review Means for AI and Insurance Distribution

The FCA published the Mills Review on 6 July 2026. According to the FCA, it's the first review of its kind by a financial regulator anywhere in the world and, amongst lots of interesting findings, it names a few problems that bear specifically on insurance. AI systems give plausible but incorrect answers about products. Control of the AI customer interface is becoming a source of market power. And there's ambiguity about exactly where regulatory perimeters should be drawn when consumer agents are in the loop.

The review was led by Sheldon Mills at the FCA Board's request. It drew on 140 written submissions and a nationally representative survey of 5,026 UK adults, run by Yonder in April 2026, looks out to 2030, and sets out four shifts AI will drive across retail financial services: how firms operate, how consumers decide, how competition is structured, and how fraud and cyber risk are amplified. It makes seven priority recommendations and, while we'll have to wait and see exactly how the FCA responds to them, the direction of travel is clear.

What does the review say about AI accuracy?

The review is blunt about the limits of the technology. As anyone who's spent time using them knows, AI outputs are often plausible - without necessarily being correct. In the review's own words, a model may give a customer incorrect information, misread a policy term, or support a decision a firm cannot properly evidence - all of which are situations which present clear risk of customer harm.

It backs this with a live example from a different corner of financial services: debt advisers told the review about consumers who had already been to a general-purpose AI tool, been given wrong information, and had to be walked back to a safer course by a human. Interestingly, the review notes why that correction's much harder than it sounds: misinformation keeps shaping decisions after it has been corrected, and the risk is amplified where consumers treat a fluent answer as a reliable one.

The research also outlines some useful stats on the scale of this exposure, making the point that this is not a niche issue in 2026:

  • Around 26% of UK adults trust general-purpose tools such as ChatGPT, Claude or Gemini for financial advice.
  • Only about two in five correctly identify what protection they actually have when they use those tools for financial advice. The rest either get it wrong or don't know.
  • One in five are already open to AI making financial decisions for them, which the FCA puts at around 11 million UK adults.

For the insurance market, the risk implications of the above should be quite clear and it's already happening. What a model says about an excess, an exclusion, or a claims process is now read by customers as the answer, not as one answer among fifty in a forum thread.

Why does the review matter for how insurance is sold?

The third of the review's four system shifts is about competition, and thinking through the implications raises obvious questions for how consumers access insurance. Control of the AI-mediated customer interface may become a major source of market power which, in itself, is not necessarily an issue - but coupled with the issues above and the current lack of visibility into how such channels are operating - it's something that creates real concern. If the owner of that layer influences, in the review's words, which products are visible, how choices are ranked, and where value is captured - then there are real market and consumer implications.

Unsurprisingly, the review names insurance directly as a market where this plays out, through embedded cover, automated quote comparison, claims triage, and platform steering of discovery.

To address these concerns, there are seven priority recommendations made:

  1. Secure and adapt the regulatory perimeter
  2. Strengthen system-wide coordination and oversight
  3. Monitor the transition to autonomous models and adapt regulatory frameworks
  4. Scale up the FCA's AI Lab to support AI model and system innovation in financial services
  5. Enable the foundations for agentic finance
  6. Build and adopt an AI-enabled agentic supervisory model
  7. Develop a trusted public-interest AI-enabled financial capability service

All of the above make sense, but point to current conspicuous gaps and uncertainties. Marrow exists to address many of these, but it's a full ecosystem change that's required. Recommendation one has the shortest fuse: the FCA has been asked to decide within three to six months whether general-purpose LLMs operating outside the perimeter should stay outside it. Deloitte's read of the review makes the same point about timing, noting that none of the seven is FCA policy yet but that together they show where supervisory scrutiny is going to land.

What should insurers do now?

Insurers are treating AI visibility as the problem to solve, and that's certainly part of the picture. Given the topics touched on by the review, though, the more urgent question is what role, and how, the agent actually plays in product discovery and purchase.

Here are some hard actions we think all market players should be taking:

  1. Test whether an agent can transact. A GEO audit measures whether an assistant names an insurer accurately when a customer asks about cover. That work is worth doing, and the visibility gaps on generic queries are real: Marrow's UK insurer AI leaderboard tracks them across motor, home, travel and pet. Transaction is a separate question: whether an agent can pull an insurer's excess and exclusions, get a live quote from their systems, surface the disclosures the law requires, and reach a bound policy without a human completing the last mile by hand. Publicly, that question has gone largely untested across the UK market.
  2. Shape the standard while it is still being drafted. Agents will only be able to behave consistently and safely in regulated products when they're presented with a clear rulebook for how to do that - as A2A and AP2 already do for agentic payments. Marrow has begun defining these as a set of open standards, and we've established a working group to shape and refine these as the market matures. Taken together, these Agent-Mediated Insurance (AMI) Standards address many of the concerns raised by the Mills Review - but it's early days.
  3. Scope the gap before volume forces the pace. Map your existing stack against what the Standards ask for: consent and authority, disclosure, suitability, and audit. This is a scoping exercise, it's cheap to run, and it'll give you a good idea of how able to operate in the agentic space you are as an incumbent.

Where do the AMI Standards fit?

Recommendation five is the clearest signal yet. It asks the FCA to lead the development of a trusted framework for AI agents participating in financial services: how an agent is authorised and identified, how consent and authority are mandated, and where liability sits when something goes wrong. The review proposes building it through the FCA's Open Finance work, with a separate industry committee convened alongside. The framework is meant to be built with the market rather than dropped on it.

The Standards are an open specification for how an AI agent requests, compares, discloses and binds a regulated insurance policy. They currently cover motor, home, SMB and travel. Two things sit inside the specification:

The first is a canonical request and response for each line. An agent asking for a quote and an insurer answering with one mean the same structured thing everywhere, rather than every integration inventing its own version.

The second is a conduct layer underneath:

  • Consent and authority. Who is allowed to buy or bind, on whose behalf, and how that is proven.
  • Disclosure. What a customer has to see before they commit, and a record that they saw it.
  • Suitability. Matching product to need. The Consumer Duty test.
  • Audit. An immutable record of what happened, for the firm and for the regulator.

The Standards intentionally stop at the interface: they're designed to be agnostic of the agent on the other side, and they don't touch underwriting at all. Insurers and brokers map their existing product and pricing logic to the canonical schema once, and appetite, pricing and risk selection stay entirely theirs.

Marrow has drafted v0.1 and stewards it on behalf of the working group. It is published as a working draft, free to build on, and shaped by the partners and platforms who will operate on it.

The FCA Board is still deciding how to respond to the review. Insurers who underwrite, price or distribute and want a hand in shaping v0.1, before the open questions above are settled, can read the draft and join the working group.

Frequently Asked Questions

What is the FCA's Mills Review?

The Mills Review is the FCA's assessment of how AI will reshape retail financial services by 2030 and beyond, published on 6 July 2026. It was led by executive director Sheldon Mills at the FCA Board's request, drew on 140 written submissions and a survey of 5,026 UK adults, and makes seven priority recommendations. The FCA describes it as the first work of its kind initiated by a regulator globally.

Does the Mills Review change the rules for insurers?

No. The review makes seven recommendations to the FCA Board and none of them is FCA policy yet. It concludes that the existing framework, including the Consumer Duty, the Senior Managers Regime and operational resilience, remains sound, and it recommends no new AI-specific rules. The Board is still deciding how to respond.

What does the Mills Review say about insurance?

The review names insurance directly as a market AI will reshape, through embedded cover, automated quote comparison, claims triage and guidance, and platform steering of discovery. It also finds that control of the AI-mediated customer interface may become a major source of market power, which bears on how insurance gets discovered and sold.

Does the FCA regulate ChatGPT, Claude or Gemini giving insurance advice?

Not currently. General-purpose AI assistants sit largely outside the FCA's activity-based perimeter, so a consumer who uses one for a financial decision may have no formal route to redress. Recommendation one asks the FCA to decide within three to six months whether that should change.

What are the AMI Standards?

The Agent-Mediated Insurance (AMI) Standards are an open specification for how an AI agent requests, compares, discloses and binds a regulated insurance policy. They cover motor, home, SMB and travel, and define a canonical request and response format plus a conduct layer covering consent and authority, disclosure, suitability and audit. Marrow drafted v0.1 and stewards it on behalf of the working group.

Related reading

Best car insurance according to AI · Best home insurance according to AI · Best travel insurance according to AI · Best pet insurance according to AI

Link to the original LinkedIn article here.