Last issue, I promised a closer look at the regulatory moves I'd caught up on after being away. Since then, a third thread has come into view. Read together, they point to one practical thing worth checking in your own organisation before anyone else asks you to: does anyone actually know who's accountable when an AI decision goes wrong, at every level it could go wrong at?
Here's the gist of it.
Three regulators, three levels
The FCA (Mills Review, 6 July) is asking who's accountable closest to the customer. Its framework is an "autonomy spectrum," five stages describing how far a human steps back as AI takes on more: operator (AI as a tool), collaborator (human and AI act together), consultant (AI recommends, human decides), approver (AI prepares actions, human authorises), and observer (AI acts within agreed limits, human just monitors). The report's own finding: the further a firm moves along that spectrum, the harder accountability is to trace, because the human stops making each decision and starts setting the conditions AI operates within.
The FSB (10 June) is asking it at the level of the institution. Its framework groups twelve sound practices into three areas: organisation-wide governance, management of the AI lifecycle, and cyber and third-party risk. Its most direct position is on oversight itself: once agentic systems multiply, having a person review every individual AI decision in real time simply isn't possible. Its answer is "human-in-command": people set the boundaries, AI increasingly monitors AI within them, but the accountability stays with the institution regardless. Worth noting this is still a consultation report, not a finished framework; comments closed in July, and the final version is due in October, so there's a live window in which this is still being shaped.
The Bank of England is asking it at the level of the whole market. Deputy Governor Sarah Breeden's concern isn't a single AI agent misbehaving; it's many agents responding the same way to the same prompts or triggers, a shared price move, a piece of news, a signal several institutions' systems are all watching at once. If enough agents react in the same direction at the same moment, especially if their objectives have started to drift from what they were originally built to do, that correlation itself becomes the risk. The Bank is running joint simulations with the Bundesbank and the BIS, a research collaboration called Project Logos, to study what kind of agent design produces that herding.
Same underlying question. Three different levels: the customer, the institution, the market.
Why that convergence matters
This isn't three regulators independently discovering AI risk. It's disclosure outpacing governance. Banks are increasingly disclosing AI ROI figures to investors, and that earns them something concrete: a stronger investor story, analyst confidence, a competitive signal against peers who haven't disclosed yet. Building the accountability structure underneath that value- the governance, the sign-off chains, the audit trails- doesn't come with an equivalent visible reward. Nobody's share price moves because a bank can prove its AI governance is sound. So there's a strong incentive to show value and a much weaker one to show the accountability underneath it. Three regulators, from three different seats, are now trying to close that gap before it becomes a live incident rather than a design question.
There's one more piece worth knowing, because it changes the stakes of getting this right. The Mills Review doesn't treat governance as just a brake on risk. It argues governance is becoming the thing that lets firms move faster with confidence, not slower. Firms that can show clear permissions, real monitoring, and genuine auditability will be able to deploy AI more confidently. Firms that can't will either move slower or carry more risk than they realise. The accountability question isn't a compliance box. It's becoming a speed advantage.
If you do one thing before the next issue
Pull one AI use case you have visibility into and ask who owns the outcome if it goes wrong, at the customer level, the institutional level, and the market level.
That's a wrap.
- Gaziza
P.S. Thanks for reading. If this one landed for you, sharing it with someone who'd find it useful means a lot.

