Bank of England AI Consortium: the June 2026 minutes and UK AI rules already in force

In short: the Bank of England AI Consortium published minutes of its fourth quarterly meeting on 5 August 2026, covering the meeting held on 3 June 2026. Four workshops reported on explainability, AI-accelerated contagion, concentration risk and AI edge cases. Under its terms of reference the Consortium has no decision-making capacity, so nothing in the minutes changes a firm’s obligations.
A payment institution or an e-money institution putting a large language model into a customer-facing process this year has no AI rulebook to comply with. What it has instead is a set of obligations written before generative AI existed, which apply to the deployment anyway. The Bank of England and the Financial Conduct Authority run a public-private forum on that problem, and the minutes of its 3 June 2026 meeting, published on 5 August 2026, set out where the industry side of the forum thinks the difficulty sits.
What the AI Consortium is, and what it can do
The Bank of England and the FCA established the Artificial Intelligence Consortium on 2 May 2025 as a platform for public-private engagement on the capabilities, deployment and risks of AI in UK financial services. It meets quarterly. Its terms of reference record that it “has no decision-making capacity”, that neither regulator is under any obligation to act on its discussions or on the outputs of its workshops, and that it does not consider the Bank’s or the FCA’s own use of AI.
Sarah Breeden, the Bank’s Deputy Governor for Financial Stability, and David Geale, the FCA’s Executive Director of Supervision, Policy and Competition, co-chair it. Members serve in a personal capacity and number around thirty. The 3 June 2026 meeting, held at the FCA’s offices, drew members from retail and wholesale banks, building societies, insurers, card schemes, cloud and data providers, a trade association and academia. The Information Commissioner’s Office, HM Treasury and Ofcom attended as observers.
Contributions were made under the Chatham House Rule, so the minutes name no member, and the Bank published them two months after the meeting.
What the four workshops reported in June 2026
Four workshops presented near-complete analysis at the 3 June 2026 meeting: explainability and transparency in generative AI, AI-accelerated contagion, concentration risk, and the evolution of AI edge cases. Each group proposed a framework rather than a rule. The co-chairs confirmed the outputs will be consolidated into a single publication later in 2026, ahead of a second phase.
| Workshop | What the group reported | What the group proposed |
|---|---|---|
| Explainability and transparency in generative AI | System complexity and interconnectivity, limited transparency from third-party providers, and variable and unpredictable outputs make it hard to apply existing model risk frameworks proportionately | Manage model risk at the level of the AI model system rather than the individual model; outcome-based validation; model scorecards; separate approaches for developers and deployers |
| AI-accelerated contagion | Automation, speed and shared technical dependencies create common points of failure; fast contagion can follow a provider outage within minutes, while correlated errors propagate slowly and surface only on cross-firm comparison | A firm-level response taxonomy; keeping agent actions within defined limits; wargaming rather than forecasting; kill switches for higher-risk consumer-facing agents |
| Concentration risk | Concentration arises at the model and compute levels with limited alternatives, and matters most where those services support Important Business Services; software-as-a-service access increases third-party dependency and reduces substitutability | A shared understanding of firms’ relationships with third-party AI providers, building on Cross-Market Operational Resilience Group work; AI upskilling and a domestic talent pipeline beyond London |
| Evolution of AI edge cases | Across six themes of novel AI use, failures resembled one another in how they presented, and traditional risk management controls were not readily applicable | A four-step approach: identify the failure type, detect it through observable signals, establish the minimum evidence needed to diagnose it, and apply pre-defined containment controls; voluntary output reporting across firms |
The wider discussion turned on frontier models, with members citing recent releases including Anthropic’s Mythos model, and on the safe deployment of agentic tools inside firms. Members discussed model harnesses, meaning the software layer that manages a model’s execution and its interaction with other systems, and execution boundaries separating probabilistic reasoning from deterministic system actions. Several observed that human-in-the-loop review is widely relied on but not practical in every context. Members also raised the standardisation of AI incident reporting, and stress-testing of scenarios in which capability advances faster than expected, agentic payments among them.
The UK rules that already apply to AI deployment
No UK statute regulates AI in financial services as such. Four frameworks already in force apply instead, and which of them binds a firm depends on its permissions. The FCA confirmed in June 2026 that it is making no new AI rules, an approach set out in our note on the FCA AI approach and the AI Lab.
| Framework | Firms it applies to | What it requires |
|---|---|---|
| SS1/23, model risk management (current version effective 23 April 2026) | UK-incorporated banks, building societies and PRA-designated investment firms holding internal model approval for credit risk, market risk or counterparty credit risk | Five principles covering model identification and risk classification, governance, development and use, independent validation and risk mitigants, applied to in-house and vendor models alike |
| SYSC 15A, operational resilience | Enhanced scope SMCR firms, banks, designated investment firms, building societies, Solvency II firms, UK recognised investment exchanges, electronic money institutions, payment institutions, registered account information service providers and consolidated tape providers (SYSC 15A.1.1) | Identify important business services, set impact tolerances for each and remain within them (SYSC 15A.2.1) |
| Critical third parties, section 312L Financial Services and Markets Act 2000 | Persons designated by HM Treasury who supply authorised persons, e-money institutions, payment institutions, registered account information service providers or financial market infrastructure entities | Direct oversight by the FCA, the PRA and the Bank of England, on designation by the Treasury where failure could threaten the stability of, or confidence in, the UK financial system |
| Consumer Duty and the Senior Managers and Certification Regime | FCA-authorised firms serving retail customers, and their senior managers | Accountability for outcomes stays with the firm and the responsible senior manager as autonomy moves to the model |
HM Treasury made the first four designations on 13 July 2026, covering Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited, under the Critical Third Parties (Designation) Regulations 2026. The regime and its comparison with the EU Digital Operational Resilience Act are set out in our note on the critical third parties regime, and the accountability position in our note on the Mills Review, AI, autonomy and accountability.
Three mismatches between the workshop analysis and the rules in force
The first mismatch is one of scope. Workshop 1 worked on how generative AI systems are classified under SS1/23 and how the framework can be applied to them proportionately. SS1/23 applies only to UK-incorporated banks, building societies and PRA-designated investment firms with internal model approval. A payment institution authorised under the Payment Services Regulations 2017, or an e-money institution authorised under the Electronic Money Regulations 2011, has no model risk supervisory statement to apply at all. Its operative framework is SYSC 15A, whose obligations concern important business services and impact tolerances rather than model quality or validation.
The second concerns the layer at which concentration is regulated. Workshop 3 located concentration at the model and compute levels, with limited alternatives, and observed that access through software-as-a-service increases dependency and reduces substitutability. The designation power in section 312L is not confined to cloud infrastructure: it covers any person supplying services to authorised persons, e-money institutions, payment institutions, registered account information service providers or financial market infrastructure entities, where the Treasury considers that failure or disruption could threaten the stability of, or confidence in, the UK financial system. All four designations made so far are cloud infrastructure providers. What is absent is a designation covering a model or compute provider, not a power to make one.
The third is the unit of governance. All four workshops moved from governing a model to governing an AI system, taking in the harness, the prompts, the retrieval layer and the execution boundaries. SS1/23 is drafted around models and SYSC 15A around business services, so a firm adopting the system-level approach the workshops describe documents the mapping itself, in its own model inventory, third-party register and impact tolerance analysis. Members raised standardised AI incident reporting and voluntary output reporting for the same reason: neither exists as a UK requirement.
The firms most exposed sit outside the prudential model risk perimeter and inside the operational resilience one: payment service providers, e-money institutions, and the payments and data infrastructure they depend on. The practical starting point for them is the mapping between an AI deployment and the important business services it supports, which is where our AI and data governance advice page and our payments regulation practice both begin. There is a further layer for agentic deployments, covered in our note on HM Treasury’s agentic payments consultation.
Frequently asked questions
Does the Bank of England AI Consortium make rules?
No. The Consortium’s terms of reference state that it has no decision-making capacity, and that neither the Bank of England nor the FCA is under any obligation to act on its discussions or on the outputs of its workshops. Its activities and outputs are not an indication of future policy by either regulator.
Which firms does SS1/23 apply to?
SS1/23 applies to UK-incorporated banks, building societies and PRA-designated investment firms that hold internal model approval to calculate regulatory capital for credit risk, market risk or counterparty credit risk. Payment institutions, e-money institutions and firms without internal model approval are outside its scope. The current version took effect on 23 April 2026.
Does the critical third parties regime apply to AI model providers?
It can. Under section 312L of the Financial Services and Markets Act 2000, HM Treasury may designate any person supplying services to authorised persons, e-money institutions, payment institutions, registered account information service providers or financial market infrastructure entities, where failure could threaten the stability of, or confidence in, the UK financial system. The four designations made on 13 July 2026 are all cloud infrastructure providers.
What did the concentration risk workshop find?
The workshop reported that concentration arises from the underlying characteristics of AI provision, particularly at the model and compute levels, where alternatives are limited. It flagged services supporting Important Business Services as the sharpest case, identified talent concentration as a second systemic issue, and found from its own member survey that reliance runs more heavily on software-as-a-service access than on in-house hosting.
For advice on which UK framework applies to an AI deployment in a payments, e-money or data business, and on the operational resilience mapping that follows, contact Rob Bratby at Bratby Law.
