About a-team Marketing Services
The knowledge platform for the financial technology industry

A-Team Insight Blogs

Insights from the Mills Review for Wholesale Surveillance

Subscribe to our newsletter

“Tweak the contract” triggered the surveillance control. But the surrounding exchange concerned a kitchen renovation. Alex de Lucena, Director of Product and Governance Strategy at Shield shared this example in a recent discussion with RegTech Insight following the publication of the FCA Board-sponsored Mills Review in July 2026.

In late 2025, the FCA Board asked Executive Director, Consumers & Competition, Sheldon Mills to examine how advances in artificial intelligence could transform retail financial services by 2030 and beyond.

The review examines four connected areas:

  • How AI technology might evolve, particularly towards more powerful, autonomous and agentic systems.
  • How those developments could affect firms and markets, including competition, market structure and UK competitiveness.
  • How AI could affect consumers, including outcomes, risks, behaviour and demand for financial services.
  • How financial regulators might need to evolve to ensure retail financial markets continued to work well.

The resulting Mills Review, although focused on retail financial services, offers several insights relevant to capital markets and wholesale treasury.

Agents as Process-Actors

Mills describes five roles for the human along a spectrum of increasing AI autonomy: operator, collaborator, consultant, approver and observer. Read as a process model, the framework can also help firms identify who acts at each stage: a human, an agent or both. At observer level, the AI system acts continuously within preset limits while the human monitors outcomes. As the Review puts it: “Control shifts towards setting permissions and boundaries.”

Different positions on the spectrum may coexist within a single surveillance workflow. One agent might assemble the context surrounding an alert, another assess the suspected risk and a third challenges that assessment. Closing an alert gives an agent more authority than summarising one, even when both tasks use the same model. Controls should therefore cover each process-actor’s task, authority and decisions, as well as the underlying technology.

Mills notes that “Some harms only become discernible when viewed across the market.” Its proposed Agentic Supervisory Model could include tools that analyse transaction and order-book data across markets to identify potential market abuse more quickly.

Near-continuous supervision would depend on comparable data, agreed semantics and rules governing what an FCA agent could request or infer. It could also generate noise at regulatory scale. A signal connected across firms is not automatically evidence of misconduct, and a supervisory agent’s conclusion would require the same provenance and challenge expected of firms.

Shield’s de Lucena reads Mills as a “permission structure” for firms that have tested AI but remain wary of putting it into production. He sees the five roles framework helping firms describe increasing autonomy and where existing accountability arrangements may come under strain as agentic solutions move into production. “At scale, we have to be much more deliberate in how we build agents; we have to govern them,” he says.

A narrowly drawn agent has a stated job, known inputs and outputs that can be examined. In the kitchen example, the agent records why the surrounding conversation changes the meaning of the flagged phrase.

Shield has an agent that can make that distinction and close the case. “It closes it as if there was a reviewer and it provides a reason for why it closed it,” says de Lucena. The alert stays in the system. A reviewer can reopen it, spot-check the decision or draw a random sample. See: Compliance risk is connected. Your AI should be too.

Agents can also give firms a way to test for false negatives. Traditional surveillance assurance has focused largely on the alerts a system produced: whether analysts reviewed them promptly, whether cases were handled consistently and how many proved irrelevant. But what about the messages that never entered the queue?

After a message triggers an alert for one type of conduct risk, Shield’s agents examine the wider context and check the same message for other risks the client has chosen to monitor. “We have agents specifically looking for anything we might have missed,” said de Lucena.

The arrangement provides a basis for a recorded false-negative test that firms can sample, compare with human review and track after a model or policy change. It cannot establish complete coverage, but it offers more evidence than a broad claim about alert quality.

Subscribe to our newsletter

Related content

WEBINAR

Upcoming Webinar: Generative and Agentic AI in Financial Markets: What the Data Really Shows

Date: 15 October 2026 Time: 10:00am ET / 3:00pm London / 4:00pm CET Duration: 50 minutes Artificial intelligence is reshaping financial markets – but the reality on the ground is more nuanced, more uneven, and more instructive than the headlines suggest. A new A-Team Insight research programme, drawing on responses from senior AI decision-makers at...

BLOG

Model Context Protocol Opens Agentic AI for RegTech Platforms

As 2025 was the year GenAI took hold in RegTech solutions, 2026 is seeing the rise of AI agent adoption raising the upside for compliance automation and creating new risk surfaces. Early GenAI solutions enabled unstructured communications, policies and case files to combine with structured transaction and customer data. Early use-cases focused on productivity enhancements...

EVENT

Eagle Alpha Alternative Data Conference, Spring, New York, hosted by A-Team Group

Now in its 9th year, the Eagle Alpha Alternative Data Conference managed by A-Team Group, is the premier content forum and networking event for investment firms and hedge funds.

GUIDE

AI in Capital Markets Handbook 2026

AI adoption in capital markets has moved into a more disciplined phase. The priority is now controlled deployment: where AI can be used safely, where it can deliver measurable value, and how outputs can be governed, monitored and evidenced. The 2026 edition of the AI in Capital Markets Handbook examines how AI is being applied...