FCA Mills Review: What AI Means for Insurance Firms

The FCA has published The Mills Review: AI and the future of retail financial services, looking at how AI could reshape financial services by 2030 and beyond.

The Review is not a new rulebook. It is a roadmap. Its central message is that AI is already part of retail financial services and will increasingly move from helping humans complete tasks to recommending, initiating and potentially executing actions within agreed boundaries.

For insurance firms, this is not a distant issue. AI is already relevant to underwriting, pricing, quote comparison, embedded insurance, claims triage, fraud detection, customer service, complaints, conduct monitoring, financial crime controls and operational resilience.

The key question for firms is no longer simply “are we using AI?” It is “where is AI influencing customer outcomes, who is accountable, how do we test it, and what happens when it goes wrong?”

Key Highlights

AI Is Moving from Support to Delegation

The Review sets out an AI autonomy spectrum, moving from humans using AI as a tool, through to AI acting within pre-set boundaries while humans monitor outcomes. As autonomy increases, the risks around consent, accountability, auditability and redress become more complex.

For insurance firms, this means an AI tool that summarises policy wording should not be treated in the same way as a tool that recommends a claims decision, changes pricing, prioritises customers or triggers customer actions.

The Existing Regulatory Framework Still Applies

The Review does not recommend replacing the current regulatory framework. It confirms that the FCA’s outcomes-based approach remains broadly sound, including the Consumer Duty, SMCR, operational resilience, financial crime obligations, governance and systems and controls.

However, the Review is clear that these frameworks will come under pressure as AI becomes more autonomous. Firms will need to evidence how existing rules apply to AI-supported decisions and customer journeys.

Customer Journeys Will Become AI-Mediated

Consumers may increasingly use AI tools to understand products, compare options, switch providers, challenge claims decisions or draft complaints. The Review also identifies risks where consumers rely on general-purpose AI tools without understanding their limitations or the lack of formal protections.

For insurers and intermediaries, customer communications will need to be clear enough for customers and AI tools to interpret accurately. Poorly drafted exclusions, unclear policy limits or inconsistent wording may create new conduct and complaints risks.

Distribution and Competition May Shift

The Review highlights that control of the customer interface could become a major source of market power. AI assistants, operating systems, aggregators or customer-chosen agents may increasingly influence which products customers see, compare and select.

For insurance firms, this has clear implications for brokers, comparison journeys, embedded insurance, platform distribution and product visibility. Firms may need to think about whether product data is accurate, machine-readable and capable of supporting fair comparison.

Fraud and Cyber Risks Will Accelerate

The Review warns that AI could make fraud and cyber-attacks faster, cheaper, more scalable and more convincing. Risks include deepfakes, synthetic identities, impersonation, automated social engineering and AI-enabled scams.

For insurance firms, this is directly relevant to claims fraud, false documents, payment redirection, broker impersonation, complaints fraud and cyber-attacks on delegated authority or outsourced claims systems.

The FCA’s Future Direction Is Clear

The Review makes seven priority recommendations, including securing the regulatory perimeter, strengthening system-wide oversight, monitoring the transition to autonomous models, scaling the FCA’s AI Lab, enabling agentic finance, building AI-enabled supervision, and developing a trusted public-interest AI-enabled financial capability service.

The practical direction is clear: the FCA is likely to become more data-led and AI-enabled in its supervision, with greater focus on patterns, outcomes and system-wide risks.

What Firms Should Do Now

Map AI Use Across the Business

Identify where AI is already being used or planned across underwriting, pricing, distribution, claims, complaints, customer service, fraud, MI, compliance, governance and assurance.

Classify AI by Risk and Autonomy

Assess each use case by customer impact and autonomy level. Higher-risk use cases should have stronger governance, testing, monitoring, audit trails and escalation controls.

Clarify Accountability

Ensure senior managers understand where AI affects their areas of responsibility. AI does not remove firm or SMF accountability.

Review Consumer Duty Impact

Assess whether AI-supported journeys deliver good outcomes, including for vulnerable customers. Firms should be able to evidence how AI affects understanding, fair value, support and decision-making.

Strengthen Third-Party Oversight

Review reliance on model providers, cloud providers, software vendors, data providers, delegated authority platforms, TPAs, coverholders and outsourced claims providers.

Update Fraud, Cyber and Resilience Scenarios

Revisit financial crime, cyber and operational resilience scenarios to reflect AI-enabled threats, including deepfakes, synthetic identities and automated attacks.

Improve Data, Audit Trails and Explainability

Ensure AI-supported decisions can be explained, challenged and reviewed. This is particularly important for claims, underwriting, pricing, complaints and customer support.

The Mills Review is not saying firms should slow down AI adoption. It is saying that safe adoption needs clear ownership, strong controls and proper evidence.

For insurance firms, there are opportunities.  AI can improve efficiency, reduce friction, support customers, strengthen fraud detection and help firms understand outcomes sooner.

But the risks are equally real. Poorly governed AI can create unfair outcomes, unclear accountability, weak redress, cyber exposure and customer harm.

We support insurers and insurance intermediaries in translating regulatory change into practical business controls. In relation to AI and the Mills Review, we can assist with:

  • AI governance reviews;
  • AI use-case mapping;
  • Consumer Duty impact assessments for AI journeys;
  • SMCR accountability mapping;
  • AI risk and control frameworks;
  • Board and senior management briefings;
  • third-party and outsourcing reviews;
  • data governance and MI reviews;
  • claims and complaints AI control reviews;
  • fraud and cyber risk updates;
  • operational resilience scenario planning;
  • policy, procedure and training updates.

 

Our team can help firms treat AI as a governance, conduct and customer outcomes issue, not just a technology project.