MICKAI®ArticlesMPs Press the FCA on AI: Why Audi…
Article · 30 July 2026

MPs Press the FCA on AI: Why Audit Trails Belong on Your Own Hardware

The Treasury Select Committee has told UK regulators to accelerate AI oversight, and firms that record every AI action on their own hardware will be ready before the guidance lands.

Author
Micky Irons
Published
30 July 2026
Follow Micky Irons
LinkedInX
fcaai-audit-trailsfinancial-servicestreasury-select-committeesovereign-ai
MPs Press the FCA on AI: Why Audit Trails Belong on Your Own Hardware

Regulated UK firms should now plan for formal supervisory expectations on AI audit trails and human oversight, because Parliament has asked for them and regulators have signalled they are coming. On 20 January 2026 the Treasury Select Committee published its report on artificial intelligence in financial services, urging the FCA, the Bank of England and HM Treasury to accelerate their oversight of AI. The regulators responded in April 2026, with the FCA signalling that guidance on audit trails and human-in-the-loop protocols is likely. Below we set out what that means for firms deploying AI over regulated data, and why the audit trail belongs on the firm's own hardware.

What did the Treasury Select Committee ask the FCA and the Bank of England to do?

The Committee urged the FCA, the Bank of England and HM Treasury to accelerate their oversight of artificial intelligence in financial services, reflecting concern that AI adoption in banks, insurers and payment firms is outpacing the supervisory framework. None of this is yet a rulebook, and we will not pretend otherwise. It is, however, the clearest signal to date of what UK supervisors intend to ask of firms that let AI touch material decisions, customer outcomes or the movement of money.

For a compliance officer, the practical question is not whether these expectations arrive but what shape the evidence must take when they do. A policy stating that a human reviews AI outputs is an assertion. A record showing which human reviewed which output, at what time, with what authority, is evidence. The gap between those two is where most AI governance programmes fall short.

Why do audit trails keep coming up in AI supervision?

Audit trails recur because they are the only mechanism that lets a supervisor reconstruct what an AI system actually did, rather than what a firm believes it did. Explainability after the fact depends entirely on records made at the time. If a model influenced a lending decision, flagged a transaction or drafted customer communications, the firm needs to show the inputs, the outputs and the human decision that followed, and that the record has not been altered since. Financial services has lived with trade reconstruction, call recording and record-keeping duties for years. AI simply extends the same principle to a new class of actor inside the firm.

A credible AI audit trail must capture at least the following, recorded as each action happens:

  • The instruction the system received and the data it was permitted to touch
  • The output each model produced, including where specialist models disagreed
  • The identity and authority of the human who approved any sensitive action
  • The exact time of every step, in an ordering that cannot be quietly rewritten
  • Cryptographic proof that the record is complete and has not been tampered with
  • The ability to verify all of the above offline, without depending on any vendor

The last two points are the most often missing. A log a vendor can edit, or that can only be checked by calling that vendor's service, is not evidence. It is a favour.

What does human-in-the-loop mean when it has to survive an audit?

Human-in-the-loop only means something if the loop is enforced by the system rather than described in a policy. In our operating system, sensitive actions cannot execute on a model's initiative. Our cooperative multi-model consensus substrate requires specialist models to agree before a sensitive action is even proposed, and the action then waits for voice-biometric human confirmation before it runs. Each step, the consensus, the confirmation and the execution, is signed into the Open Audit Record. When the FCA's expected guidance arrives, a firm running this way will not need to redesign its controls. It will need to print its records.

A regulator does not want to hear that a human was in the loop. It wants to see the loop, signed, timestamped and impossible to rewrite.

Mickai

Why should the audit trail live inside the firm's own perimeter?

Because evidence held by a third party is evidence you have to ask for, and the moment you need it most may be the moment you cannot get it. Mickai is a Sovereign Intelligence Operating System that runs entirely on the customer's own hardware, on premise and air-gapped where the risk demands it. The Open Audit Record is cryptographically signed with post-quantum algorithms, tamper-evident, and verifiable offline, anchored to a hardware-held root of trust in the firm's estate. If a cloud region fails, a supplier is compromised or a commercial relationship ends, the firm's account of what its AI did remains intact and provable, because it never left the building.

This also answers the operational resilience question. A firm whose AI capability and whose evidence of AI behaviour both depend on a remote provider has concentrated two risks in one place. Keeping the models, the data and the audit trail on infrastructure the firm controls removes that concentration and keeps regulated customer data inside the firm's own perimeter.

How do we build for this at Mickai?

We build one operating system carrying 87 studios, ten of them production ready and there at launch, with 77 more in development. Every studio runs on the same substrate: our own sovereign models running fully offline on the customer's hardware, the consensus layer in front of sensitive actions, voice-biometric gating on the steps that matter, and every action signed into the Open Audit Record. The architecture is protected by 104 filed UK patent applications across 2,340 claims held by Mickai LTD, a moat rather than the point. The point is that when a supervisor asks a firm to show its working, the working is already there, verifiable without having to trust us or anyone else.

The Treasury Select Committee has told UK regulators to move faster on AI. Firms that wait for final wording will end up reconstructing evidence under pressure. Firms that deploy AI which records and gates itself by design will already have the answer written down, signed, on their own hardware.

Frequently asked questions

What did the Treasury Select Committee say about AI in financial services?

The report, published on 20 January 2026, urged the FCA, the Bank of England and HM Treasury to accelerate their oversight of AI in financial services. Regulators responded in April 2026, with the FCA signalling likely guidance on audit trails and human-in-the-loop protocols.

When will the FCA publish guidance on AI audit trails?

No date has been confirmed. The FCA signalled in its April 2026 response that guidance on audit trails and human-in-the-loop protocols is likely, so firms should build recording and enforced human oversight into AI deployments now rather than waiting for final wording.

What should an AI audit trail record?

An AI audit trail should record the instruction the system received, the output it produced, the data it touched, the human who authorised any sensitive action and the time of each step, protected so the record cannot be altered and can be verified independently of any vendor.

Can human-in-the-loop be enforced rather than just documented?

Yes. In our operating system, sensitive actions require agreement between specialist models and then voice-biometric human confirmation before they execute, with every step signed into the Open Audit Record. The human step is a technical precondition, not a policy promise.

What is MICKAI?

MICKAI is a Sovereign Intelligence Operating System, a SIOS, that runs on the customer's own hardware, on premise and fully air-gapped. Every action is signed into its post-quantum secure Open Audit Record, which is tamper-evident and verifiable offline. It carries 87 studios on one operating system, with ten production ready at launch and 77 in development, and its architecture is covered by 104 filed UK patent applications across 2,340 claims, filed rather than granted.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/treasury-committee-ai-financial-services-audit-trails. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles