FCA AI Governance: What SYSC 8 and Consumer Duty Mean for AI Deployers in 2026
The conversation about AI governance in regulated financial services tends to focus on the EU AI Act. This is understandable. Article 26's August 2026 enforcement date has concentrated minds. But for FCA-regulated firms, the EU AI Act is not the only regulatory framework that matters, and for many firms it is not even the most immediate one.
FCA SYSC 8 and Consumer Duty (PRIN 12) are already in force. They already create AI governance obligations for FCA-regulated firms. And unlike the EU AI Act, they do not require a phased implementation or transitional period. The obligations are live.
This article explains what SYSC 8 and Consumer Duty mean for firms deploying AI, what regulators are actually looking for, and how FCA obligations interact with EU AI Act Article 26 for firms with both UK and EU exposure.
FCA governance obligations under SYSC 8 and Consumer Duty are already in force. This is not a future compliance challenge. It is a current one.
The UK Regulatory Stack for AI Deployers
UK regulated firms using AI face obligations from three directions:
- FCA SYSC 8 and Consumer Duty: in force now, applying to all FCA-regulated firms
- EU AI Act Article 26: coming into force August 2026, applying to firms deploying AI systems in high-risk contexts affecting EU individuals
- UK Data (Use and Access) Act 2025, Articles 22A through 22D: the UK's own framework for automated decision-making, applying to decisions with significant effects on individuals
These are not alternative regimes. They are overlapping obligations that apply simultaneously. A UK retail bank deploying AI in credit decisioning is subject to all three. The governance programme needs to address all three, not just whichever one is generating the most press attention.
This article focuses on the FCA obligations, which are the most immediately actionable for UK-regulated firms.
SYSC 8: What It Requires and Why AI Is Now Within Scope
SYSC 8 governs outsourcing and material third-party arrangements for FCA-regulated firms. Its core requirement is that firms maintain appropriate oversight of activities and functions they have outsourced or obtained from third parties, including the ability to monitor performance, identify failures, and intervene where necessary.
For most of its history, SYSC 8 was applied to conventional outsourcing: processing services, data management, hosted infrastructure. AI changes the landscape because AI systems are increasingly performing functions that, if done by humans, would be clearly within the regulatory perimeter: credit assessments, customer communications, claims triage, fraud detection, pricing decisions.
The FCA's view, set out in its AI and machine learning guidance and reinforced in multiple Dear CEO letters, is that the use of AI systems to perform regulated functions does not diminish the firm's regulatory accountability. If anything, it increases the oversight obligation, because AI systems can operate at scale and speed that make manual oversight challenging.
What SYSC 8 means for AI deployers in practice
For a firm deploying AI systems that touch regulated activities, SYSC 8 creates the following practical obligations:
- Identification of AI systems that perform material functions. You need to know which AI systems are doing regulated-adjacent work
- Assessment of materiality. Not all AI use is material from a SYSC 8 perspective, but anything that affects customer outcomes, credit decisions, or regulated communications is likely to be
- Vendor oversight for third-party AI. Firms procuring AI from vendors must apply the same oversight standards as they would to any other material outsourcing arrangement, including SLAs, audit rights, and contingency planning
- Monitoring and intervention capability. The firm must be able to monitor AI system performance and intervene where necessary. This is not passive oversight. It requires active monitoring with documented evidence
A firm that cannot demonstrate active monitoring of its AI systems, with evidence that monitoring occurred and that issues were identified and acted upon, is not meeting its SYSC 8 obligations, regardless of what its AI governance policy says.
Consumer Duty (PRIN 12) and AI: What the FCA Expects
Consumer Duty (implemented through PRIN 12) requires FCA-regulated firms to act to deliver good outcomes for retail customers. The duty has four outcome areas: products and services, price and value, consumer understanding, and consumer support. AI systems that affect any of these outcomes are within scope.
The AI governance implications of Consumer Duty are significant and underappreciated:
AI in pricing and value assessment
AI systems used in insurance pricing, loan pricing, or product recommendation affect the price and value outcome. The Consumer Duty requires firms to be able to demonstrate that their pricing is fair and that the AI system is not producing outcomes that disadvantage customers in ways the firm cannot justify. This requires monitoring of AI output distributions, not just model validation at deployment.
AI in customer communications
AI systems generating customer-facing communications (whether in emails, chatbots, or documents) affect the consumer understanding outcome. The FCA expects communications to be clear, fair, and not misleading. An AI system generating communications at scale creates consumer understanding risk at scale. Governance of this system is not optional.
AI in claims and service decisions
AI systems used in claims triage, service eligibility assessment, or customer categorisation affect the consumer support outcome. The Consumer Duty requires firms to identify customers in vulnerable circumstances and provide appropriate support. AI systems that make or contribute to decisions affecting these customers require specific governance attention.
What "good outcomes" monitoring requires in practice
Consumer Duty requires firms to monitor whether AI systems are actually delivering good outcomes, not just that they were designed to do so. This means:
- Regular review of AI output distributions for bias, drift, or unexpected patterns
- Human review of a sample of AI decisions on a documented cadence
- Escalation procedures for identified issues, with evidence that the procedures were followed
- Documentation sufficient to show the FCA that the firm understands what its AI systems are doing to customers
What the FCA Actually Asks in a Supervision Visit
FCA supervisors visiting firms on AI governance have been asking a consistent set of questions, drawn from published guidance, Dear CEO letters, and supervisory engagement records. Understanding these questions in advance is the most efficient way to prepare.
Inventory questions
What AI systems are you using? Which ones affect regulated activities? Which affect customer outcomes? How do you know the list is complete? When was it last reviewed?
Oversight questions
Who is responsible for each AI system? What does oversight of that system look like in practice? Can you show me evidence that oversight occurred in the last three months?
Monitoring questions
How do you monitor the AI system's performance? What metrics do you track? What would trigger you to intervene or suspend the system? Has that happened, and if so what did you do?
Consumer outcome questions
How do you know this AI system is delivering good outcomes for customers? What does your outcome monitoring show? Have you identified any customers who experienced poor outcomes as a result of AI decisions, and how were they remediated?
The common thread through all of these questions is evidence. The FCA does not want descriptions of governance programmes. It wants to see evidence that those programmes are operating in practice.
The Overlap Between FCA Obligations and EU AI Act Article 26
For firms with EU exposure (serving EU customers, operating in EU jurisdictions, or using AI systems that affect EU individuals) the FCA obligations and Article 26 obligations overlap significantly. This creates both complexity and efficiency opportunity.
The overlap is substantial: both require an AI system inventory, both require human oversight documentation, both require monitoring evidence, and both require documentation sufficient for regulatory examination. A governance programme designed to satisfy Article 26 will, with modest additional work, also address SYSC 8 and Consumer Duty monitoring obligations.
The gap is in specificity. The FCA obligations are more specific on customer outcomes. Consumer Duty's four outcome areas create monitoring requirements that Article 26 does not prescribe in the same way. And the FCA obligations are already in force. There is no August 2026 equivalent for SYSC 8 and Consumer Duty. They apply now.
What a Defensible FCA AI Governance Position Looks Like
Drawing together the SYSC 8 and Consumer Duty obligations, a defensible FCA AI governance position requires:
- A current AI agent inventory covering all AI systems performing material functions or affecting customer outcomes, maintained on a regular cadence with evidence of currency
- Risk classification for each system documented assessment of which systems are material under SYSC 8 and which affect Consumer Duty outcomes, with reasoning
- Documented human oversight named individuals responsible for each material system, with records of oversight activity
- Monitoring evidence not just a monitoring policy, but records showing that monitoring occurred, what it found, and what actions were taken
- Consumer outcome monitoring evidence that the firm tracks AI system outputs for customer impact, with records of identified issues and remediation
- Signed evidence packs governance artefacts generated at regular intervals, cryptographically signed, that demonstrate the above was in place at specific dates
How AETHER Pulse Addresses FCA AI Governance
AETHER Pulse maps directly to the FCA governance obligations described above. Its cross-platform discovery addresses the inventory question, finding AI agents across Google Workspace, Microsoft 365, Salesforce, OpenAI, and AWS Bedrock, including unsanctioned tools. Its five-dimensional classification framework produces risk assessments with documented reasoning. Its ICO Audit Readiness scorecard maps findings to the ICO AI Governance Framework controls. Its signed evidence packs provide the dated, verifiable governance documentation that FCA supervision requires.
For firms facing the intersection of FCA SYSC 8, Consumer Duty, and EU AI Act Article 26, AETHER Pulse provides a single evidence infrastructure that addresses all three regulatory frameworks from one platform.
Published methodology: aetherpulse.app/methodology
Frequently Asked Questions
Does Consumer Duty apply to AI systems used in business-to-business contexts?
Consumer Duty applies to products and services provided to retail customers. AI systems used exclusively in B2B contexts without retail customer impact are not directly within Consumer Duty scope, though SYSC 8 oversight obligations may still apply.
What is the FCA's current enforcement posture on AI governance?
The FCA has signalled a principles-based approach to AI governance, focusing on outcomes and the effectiveness of firms' governance programmes rather than prescriptive rules. In practice, this means supervisors will look for evidence of active governance rather than specific framework compliance. Firms that can demonstrate they know what their AI systems are doing and are actively overseeing them are in a significantly stronger position than firms that have policies but no evidence of practice.
How does SYSC 8 apply to embedded AI features in SaaS tools?
Where SaaS tools include AI features that perform material functions, those features fall within SYSC 8 scope as part of the third-party arrangement. The firm's outsourcing oversight framework should cover AI features in material SaaS tools, including the ability to identify what those features are doing, monitor their performance, and intervene where necessary.
Does the FCA have specific AI governance rules?
As of June 2026, the FCA has not issued specific AI governance rules but has published extensive guidance on AI and machine learning, including its AI and Machine Learning Guidance and multiple Dear CEO letters. FCA-regulated firms are expected to apply existing principles (including SYSC 8, Consumer Duty, and Principle 3 on management and control) to AI systems. Further regulation is anticipated but existing obligations are already actionable.
Working on Article 26 readiness, deployer-side governance evidence, or AI agent risk at a regulated firm? We'd value 15 minutes of your perspective.
Start a conversation