THE AI MINDSET

Good morning, AI leaders.

Most of what you read about AI regulation this month was either wrong or already out of date. So this week, three things that are actually true, and actually yours to deal with.

The EU AI Act was widely reported as delayed. The part that governs your chatbots and your marketing content was not, and it applies from 2 August.

Closer to home, the FCA has just published its most significant AI review to date, and confirmed it will not be writing AI-specific rules, which means the accountability sits exactly where it already sat: with you. And quietly, in the background, AI agents are being handed more authority than the governance around them was built for.

None of this needs a data science team to understand. It needs someone to own it. Let's get into it.

In today’s AI Mindset

  • The AI Act Deadline That Didn't Move

  • The FCA Just Said It Won't Regulate AI. Here's What That Actually Means

  • Your AI Agents Have More Authority Than Your Governance Does

LATEST DEVELOPMENTS

AI REGULATION
🌎 The AI Act Deadline That Didn't Move

Most coverage said the EU delayed the AI Act. The part that governs your chatbots and your marketing content did not move, and it applies from 2 August.

Category: AI Regulation | Reading time: 9 minutes:

What changed: May's Digital Omnibus deferred the high-risk obligations to 2027 and 2028, and that delay became the headline everywhere. But Article 50, the transparency rules, was left exactly where it was. On 20 July, thirteen days before the deadline, the Commission published its final guidelines, superseding the May drafts most commentary still quotes.

How it affects you: Article 50 catches far more organisations than the high-risk rules, because it applies whether or not your system is high-risk. Chatbots must identify themselves. AI-generated content needs machine-readable marks. Deepfakes and some public-interest text must be labelled. It is extraterritorial, so a UK firm serving EU customers is in scope, with fines up to €15 million or 3% of global turnover. The hard part is not the labelling technology. It is deciding who holds each duty, because provider and deployer obligations fall on different parties, and the guidelines place the deployer duty on the contracting party. That makes this a contracts problem, not an engineering one.

What to do: Before 2 August, list every AI system that talks to a customer or generates published content, and name who holds the disclosure duty for each. Where the contract is silent, that is your gap.

Key takeaway: The systems in scope usually sit with marketing or customer service, not IT. If your AI governance conversation is happening only in the technical team, the people who hold these duties are not in the room.

Most organisations cannot say which of their AI systems would trigger the rules above. The SAFE™ AI Readiness Assessment shows you, across ten governance domains, in under ten minutes.

AI REGULATION
The FCA Just Said It Won't Regulate AI (For Now). Here's What That Actually Means.

The FCA has published its biggest AI statement yet, and firms that stalled projects waiting for an AI rulebook now have their answer. There isn't going to be one. The accountability was always yours, and the regulator has just confirmed it is staying that way.

Category: AI Regulation | Reading time: 8 minutes

What changed: On 6 July the FCA published the Mills Review, a 147-page report led by Sheldon Mills and the first of its kind from any financial regulator globally. Firms had stalled AI projects for eighteen months waiting for an AI rulebook. The review's answer: there won't be one. It concludes the existing framework is fit for purpose and recommends no new AI-specific rules.

How it affects you: "No new rules" is harder than it sounds, not easier. There is no box to tick. Accountability does not move as AI takes over more work. SM&CR still applies, and your firm remains answerable for AI-driven outcomes. Because supervision is outcomes-based, your defence is not that you followed a rule. It is evidence that the outcome was fair and that a named person is accountable for it. Two developments are worth watching: a review of the regulatory perimeter within three to six months, the FCA's first concrete position on general-purpose AI, and a shift toward continuous monitoring replacing point-in-time sign-off.

What to do: Check that every AI-influenced customer outcome in your firm has a named senior manager who could answer for it. If the honest answer is "the system did it," that is the gap to close first.

Key takeaway: The FCA has not stepped back. It confirmed the accountability regime you already operate under was built to hold, and it intends to supervise AI through that regime rather than a new one. The question it will ask is unchanged: can you show the outcome was fair, and name who is accountable?

The FCA will judge you on outcomes and evidence, not on a rulebook. The SAFE™ AI Assessment shows you where your governance is defensible and where it is exposed, before someone else asks.

PRACTICAL AI GOVERNANCE

Your AI Agents Have More Authority Than Your Governance Does

AI agents act, they do not just advise. And they are being handed authority faster than anyone is building the controls to govern them.

What changed: Gartner forecasts 40% of enterprise applications will embed task-specific AI agents by the end of 2026, up from under 5% a year earlier. That is an eightfold jump in a single year. These are not chatbots. They decide and act across systems, often without a human seeing the individual decision. Meanwhile only 21% of organisations have a mature governance model for them.

How it affects you: The danger is rarely a dramatic error. It is authority creep. An agent is deployed as cautious decision-support, performs well, and has its limits relaxed step by step until a system with high-risk authority is still governed as the pilot it once was. The endpoint is a state where no one made a bad decision, because no one made the decision at all. Under SM&CR that is not a defence, it is an admission. Traditional access controls do not help, because agents get treated as generic service accounts, over-permissioned and untracked.

What to do: Answer three questions this week. Can you list every agent that can take an action, not just chat? Does each one have a named human owner? Does the authority it holds now still match what you originally approved?

Key takeaway: Those three questions produce a register, a named owner, and a review record. That is unglamorous, but it is exactly the evidence an accountability regime asks for, and far more than most organisations deploying agents currently hold.

Still reading? Then you already suspect there are gaps worth finding. The SAFE™ AI Assessment gives you a plain-English read on your ten governance domains, and the one most likely to catch you out. Free, under ten minutes.

Until next week