← All editions

Weekly Edition

19 July 2026 · 8 min read

#42: The FCA and MAS just wrote the first rules for agentic finance. Who supervises the agent?

#42: The FCA and MAS just wrote the first rules for agentic finance. Who supervises the agent?
Edition #42 · 20 July 2026

The FCA and MAS just wrote the first rules for agentic finance

Agentic finance · Tech sovereignty · Frontier AI and cyber risk · EIOPA on the AI Act · SupTech

By Andres Lehtmets · 20 July 2026
Editor’s note

Some personal news before the analysis. Lightspark Payments Europe, where I serve on the supervisory board, has received its authorisation under the EU’s Markets in Crypto-Assets Regulation (MiCA) together with an electronic money institution licence from Estonia’s Financial Supervision Authority. It is the first standalone MiCA licence granted in Estonia and a real step toward making global money movement instant, open and simple. If your organisation moves money across borders, happy to make an introduction to the relevant team members.

I also joined Evelin Org’s podcast to talk about the journey from policymaker and supervisor to running my own practice with clients around the world. One number stood out: around 95 per cent of my clients today come from outside Estonia, and almost all of them found their way to me through LinkedIn. The episode is in Estonian. For my international readers, the story travels well beyond Estonia, and I am happy to share it in English, on a podcast, at an event or in an advisory setting.

And twice a year I get a little nostalgic. A new Council presidency has begun, and I remember what that felt like from the inside during Estonia’s turn. Ireland’s eighth presidency runs to the end of December, built around competitiveness, values and security. The ECOFIN priorities are clear: advancing the Savings and Investments Union and the digital euro, deepening EU capital markets and strengthening the competitiveness of Europe’s banking sector. One thread I will follow closely is the savings and investment account, where Ireland has just opened its own domestic discussion. Estonia’s investment account model has been quietly doing this job for individual investors for years, and the lessons are there for the taking. Presidency programme.

Article 01

Two supervisors sketch the rules for agentic finance

On 6 July the FCA published the Mills Review, its examination of how AI could reshape retail financial services for consumers, firms, markets and regulators by 2030 and beyond. It is the first review of its kind initiated by a regulator anywhere. The review makes seven recommendations to the FCA Board:

  1. Secure and adapt the regulatory perimeter.
  2. Strengthen system-wide coordination and oversight.
  3. Monitor the transition to autonomous models and adapt regulatory frameworks.
  4. Scale up the FCA’s AI Lab to support AI model and system innovation.
  5. Enable the foundations for agentic finance.
  6. Build and adopt an AI-enabled agentic supervisory model.
  7. Develop a trusted public-interest AI-enabled financial capability service.

Note how much of that list is about agents. Three of the seven recommendations assume a world where AI acts on behalf of consumers, firms or the supervisor itself.

Three days earlier, on 3 July, the Monetary Authority of Singapore (MAS) published SAFR, Safeguards for Agentic Finance at Runtime, a white paper developed with eight industry members including HSBC, J.P. Morgan, Mastercard and Visa. SAFR describes a governance checkpoint that sits between an AI agent and the systems it acts on, evaluating every proposed action before it executes: how actions are authorised, when a human steps in, what gets logged at every decision. Insurance gets a look in, with some early thinking on agentic advice.

Two supervisors on two continents, working independently, reached the same conclusion in the same week: agentic finance is close enough that it needs supervisory infrastructure, not just discussion papers. I follow everything related to generative AI and advice closely, from both a risk and an opportunity perspective, and this is the fastest-moving corner of the field right now.

Sources: FCA Mills Review, MAS SAFR white paper.

Article 02

The switch-off, the sovereignty package and the 2 per cent

On 13 June the United States government, citing national security authorities, ordered Anthropic to suspend all access to its Fable 5 and Mythos 5 models by any foreign national, inside or outside the United States. To comply, the company disabled both models globally within hours. Access was restored on 1 July after the US Department of Commerce removed the export controls, and the episode ended almost as quickly as it began.

The lesson did not end with it. Critical technology can be switched off from another capital, with no notice, and the signal reaches Europe in hours.

Now read that next to two things that landed in the same weeks. On 3 June the European Commission published its Technological Sovereignty Package, flagged briefly in edition #41, with the Cloud and AI Development Act at its core. The proposal aims to at least triple EU data centre capacity within five to seven years and introduces a four-level framework for assessing how sovereign cloud and AI services really are. Its sovereignty requirements could, in specific circumstances, reach private critical entities, banks among them.

And in the European Parliament’s review of the IORP 2 pension fund directive, the rapporteur has proposed that pension funds above 1 billion euro in assets put at least 2 per cent into venture capital. The logic comes straight from Draghi, Letta and the Savings and Investments Union: move European savings into European growth and sovereignty. Except, as drafted, the text says venture capital. Not European venture capital.

Two questions follow. First, a fixed allocation mandate has to live alongside the prudent person principle and fiduciary duty to scheme members. Where does a mandated 2 per cent really belong? Second, and this is the reason to keep linking these stories: if the aim is to reduce Europe’s dependence, why does the rule not say European?

Sources: Anthropic statement, Anthropic on restoring access, European Commission, IPE on the IORP 2 proposal.

Article 03

A formal warning, a CEO letter and the underwriting question

On 7 July the European Systemic Risk Board (ESRB) published a warning, dated 25 June, on systemic cyber risks stemming from frontier AI models. The substance is short: frontier models are changing the cyber threat landscape for the EU financial system, they may increase the speed, scale and sophistication of attacks, and authorities should reflect these risks in their supervisory and oversight work.

Two things make this more than another paper. A warning is a formal ESRB instrument, not a discussion document. And the ESRB’s rating of systemic cyber risk jumped from elevated to severe in a single quarter. On the same day, ECB Banking Supervision wrote to the CEOs of significant institutions, asking them to assess the evolving threat landscape without delay and to develop concrete action plans with resources, responsibilities and timelines, due to their supervisory teams by 31 October 2026. Macro warning and micro letter, landing together.

The insurance angle arrived the same week. The IAIS set out its supervisory themes for 2026, with AI and cyber resilience as the headline. The part worth watching sits further down, in the workplan for the full-year Global Insurance Market Report: how insurers underwrite AI liabilities, and how they underwrite liabilities arising from digital assets while investing in those same assets.

The financial system is now looking at frontier AI from both sides of the balance sheet: as a threat to its own operations and as a risk it is being asked to underwrite. Worth watching this space.

Sources: ESRB warning, ECB letter to bank CEOs, IAIS mid-year GIMAR.

Article 04

EIOPA asks the Commission to exclude GLMs and GAMs from high-risk AI

EIOPA has told the European Commission that systems fully based on generalised linear models (GLMs) and generalised additive models (GAMs) should not be classified as high-risk AI under the AI Act. The letter and technical annex, building on EIOPA’s note to legislators earlier this year, lay out the technical case for excluding these long-established actuarial workhorses.

The core argument is simple. As long as GLMs and GAMs are used in life and health insurance with human oversight, they do not pose the kind of risk that justifies a high-risk label. They are not autonomous, they operate strictly according to predefined instructions and their outcomes are readily corrigible.

The real risks in pricing and risk assessment come from data selection, data governance, underwriting and pricing policies. Not from the model architecture itself. And those risks are not AI-specific: they are already covered by existing insurance, conduct, prudential, data protection and operational resilience frameworks.

Source: EIOPA letter and technical annex.

Article 05

SupTech appetite is everywhere. Capability is not.

On 18 June the International Organization of Securities Commissions (IOSCO) published a survey of 49 jurisdictions on how authorities use technology to supervise markets. The direction is no surprise: SupTech is moving out of side projects and into core supervisory functions, driven by efficiency, faster information and sharper analysis.

The most useful signal is the gap. Over 75 per cent of authorities report active SupTech use in consumer protection and 67 per cent in capital markets, and those are the only domains where activity crosses the 50 per cent line. The survey also shows a dominance of medium-tech solutions across core functions, a cautious preference for operational reliability over frontier capability. Appetite is almost everywhere. Built, working capability sits in a much smaller set of places.

That distance between intent and deployment is the real work, and it does not get closed by buying a tool. It starts with an honest read of where an authority actually is, then a roadmap it can start executing. This is the kind of work I do with supervisors, policymakers and development banks, and the honest read is usually the hardest part.

Source: IOSCO SupTech report.

Quick links
The FSB consults on 12 sound practices for responsible AI adoption

Published 10 June, the Financial Stability Board’s consultation report sets out a practical menu of 12 sound practices across the full AI lifecycle: organisation-wide governance, risk management through development and deployment and AI-related cyber, ICT and third-party risk. Grounded in real-world case studies and designed for proportionate application, it is aimed squarely at boards and senior management. The core message: understand the opportunities, stay alert to the evolving risks and build the right guardrails. Consultation closes 22 July, final report expected in October. FSB.

The Basel Committee maps ICT risk management practices

Published 2 June and drawing on 16 jurisdictions, the report focuses on non-malicious ICT incidents, the unglamorous outages that disrupt critical operations without any attacker involved. The most frequently reported causes: change control gaps, weaknesses in system design and testing, capacity issues and external dependency failures. A useful benchmark for any operational resilience framework, and a complement to the cyber-focused work covered above. Basel Committee.

The World Economic Forum publishes its AI Playbook for Financial Services

Released 24 June and built on 18 months of roundtables with more than 150 senior leaders across 100+ organisations, the playbook is grounded in global case studies with measurable results across the financial sector. The core observation: leading institutions run a two-speed strategy, capturing quick productivity gains while investing in the governance and data foundations that make scaling possible. World Economic Forum.

Number of the week
11 million

UK adults, a fifth of the adult population, that FCA-commissioned research estimates are likely to use AI that can act autonomously on their finances within pre-set goals. When the agent does the shopping, who exactly is the customer? FCA.

Andres Lehtmets Advisory Newsletter

Weekly briefing on financial innovation and regulation. Join 5,000+ fintech, insurance and regulatory professionals.

Subscribe
Working together

Advisory for regulators, boards and fintech leaders navigating digital finance policy and regulation. See how I can help.

Selectively considering sponsorship for this newsletter. Reach 5,000+ decision-makers in financial innovation and regulation. Enquire.

Andres Lehtmets

Andres Lehtmets

Independent advisor on financial regulation and digital innovation. Former Senior InsurTech Expert at EIOPA. Research Analyst at Cambridge Centre for Alternative Finance. Writing weekly for 4,700+ professionals.

Get the newsletter

Weekly insights on financial innovation and regulation. Join 4,700+ professionals.