From Operator to Observer: Where AI Accountability Goes to Hide


The Senior Managers Regime (SMR) has spent the best part of a decade making accountability personal. Named individuals. Defined responsibilities. Reasonable steps. People, not just firms, answerable when things go wrong. Yet the Mills Review, published by the Financial Conduct Authority (FCA) in July 2026, raises a quietly unsettling question about that achievement: as firms hand more of the work to artificial intelligence, and the human role drifts from doing to overseeing, does the chain of accountability stretch until it snaps?
The Review, led by Sheldon Mills and drawing on 140 written submissions alongside panels and roundtables across industry, academia and regulation, does not predict the end of personal accountability. Its conclusion is more careful, and more useful. The framework is sound; the pressure is real; and the point at which the two collide is now coming into view.
A spectrum, not a switch
The Review's central device is the autonomy spectrum, a framework it draws from Feng and colleagues' 2025 paper on levels of autonomy for AI agents. It describes not what the machine does, but how the human role changes as the machine does more. There are five positions. As an operator, the human uses AI as a tool. As a collaborator, human and AI plan and act together. As a consultant, AI recommends and the human decides. As an approver, AI prepares the action and the human authorises it. As an observer, AI acts continuously within agreed limits while the human merely watches the outcomes.
Same technology, five very different risk profiles. That is the point. At the operator end, the worry is accuracy and over-reliance. At the observer end, the worries are consent, auditability and redress, because the human is no longer making each decision but setting the conditions inside which thousands of decisions are made.
Not every activity will travel the full length of the spectrum, and few corners of financial services will become entirely autonomous. But the direction of travel is not in doubt. Mills notes that more than 20 frontier models were released between late 2025 and the Review's completion, and that firms are moving from systems that recommend actions to systems trained and empowered to take them. One chief executive quoted in the Review joked that the sector might soon need a Turing test of its own.
The regime that still holds
Start with the reassurance, because the Review does. The Senior Managers Regime was built to flex. It allocates responsibility for regulated activity to named individuals, requires them to take reasonable steps to prevent breaches in their designated area, and records those responsibilities in a formal Statement of Responsibilities. None of that depends on the technology a firm happens to use.
Industry wants to keep it. Firms consistently argued that accountability should continue to rest with senior managers in regulated entities, exercised through systems, controls and oversight; notably, no firm asked for the accountability model to change. The Review agrees, and finds the regime robust while AI operates as operator, collaborator or consultant, its levels one to three. Where a human still challenges the output and makes the call, the line of responsibility is easy enough to follow.
That matters beyond compliance. In a technological arms race, the Review observes, personal accountability is one of the few things stopping firms from treating regulatory penalties as a priced cost of a growth-at-all-costs strategy. When individuals are answerable, fines are harder to internalise as a rounding error. Personal accountability is not just a control; it is a brake on recklessness.
Strain begins where delegation deepens
The trouble starts as the human becomes an approver, then an observer. The Review maps its regulatory analysis directly onto the autonomy spectrum, and for the Senior Managers Regime the picture is honest. Levels one to three operate effectively. Level four brings increasing complexity. Level five is marked, in the Review's own words, as a pressure point where meaningful human control is likely to be difficult to evidence.
That phrase, meaningful human control, is doing a great deal of work. The Review borrows it deliberately from the academic literature on machine autonomy. The problem is not that a responsible person disappears; someone will still hold the Statement of Responsibilities. The problem is whether that person can genuinely control a system that updates continuously, draws on inputs the firm did not build, and produces probabilistic rather than deterministic outputs. Accountability, as the Review puts it, remains clear but becomes harder to exercise.
This is where accountability goes to hide. Not in an absence of names, but in the widening gap between the name on the document and what that person can actually see, understand and challenge. The Review points to the risk of responsibility gaps, citing Santoni de Sio and Mecacci's 2021 work on the four such gaps AI creates. Model drift makes it worse. A system that behaved acceptably at deployment can degrade quietly, and periodic review may not catch it. It will not be enough, the Review warns, to say a person remains in the loop. Firms must be able to say what that person is expected to do, what they see, when they can intervene, how challenge is recorded and how escalation works.
Reasonable steps buckles first
Reasonable steps is the hinge on which the whole regime turns, and it is exactly the concept AI puts under load. What counts as reasonable when a senior manager oversees a model they cannot fully interrogate, supplied by a third party they did not choose, changing in ways they did not sanction?
The Review does not pretend this is settled, but it is constructive. It sets out two developments that could ease the strain. First, future model architectures may become less opaque and less probabilistic than today's, making oversight more tractable. Second, and more immediately, a maturing market in assurance tools, pre-deployment checks and ongoing monitoring could give senior managers a credible way to demonstrate reasonable steps, including over third-party models running upstream. The answer to accountability under automation is not less automation; it is better evidence.
This is why the Review's third priority recommendation matters. It calls on the FCA to monitor the transition to autonomous models and adapt regulatory frameworks accordingly, and it names clearer guidance on the reasonable steps expected of senior managers as the specific thing industry is asking for. Firms told the Review that such clarity would give them the confidence to adopt more delegated AI, and that broader adoption could in turn support growth and competitiveness. Guidance here is not a brake on innovation; it is the permission slip.
The hardest problem is upstream
The most difficult version of the problem is not inside the firm at all. It is in the supply chain. As AI moves closer to execution, firms lean more heavily on model providers, infrastructure and specialist vendors. The Review is emphatic on the principle: firms remain responsible for outcomes even where systems rely on external models or infrastructure. Saying it is easy; evidencing it is not.
When a single model is shared across many firms, the sector inherits a risk that no one accountable individual can see. Correlated behaviour, herding, common points of failure, opacity; these propagate across firms faster than any firm-level control can respond. That is why the Review reaches past the Senior Managers Regime towards system-level answers, including its proposed Agentic Supervisory Model, an AI-enabled supervisory capability designed to spot the cross-firm patterns no individual firm can. Personal accountability answers who is responsible inside a firm. It has no answer for what happens when every firm leans on the same handful of providers.
Governance becomes the advantage, not the cost
Here is the reframe firms should take from the Review: governance is becoming a source of competitive advantage, not a cost of doing business. Firms that can demonstrate auditability, explainability where it is needed, robust testing, clear permissions and effective escalation will deploy AI with confidence. Those that cannot will move slowly or expose themselves and their customers to risk. Trust, the Review notes, is already the main barrier to consumer adoption of AI in finance, so a reputation for well-governed AI will win business, not merely avoid censure.
The near-term work is unglamorous and entirely achievable. Extend model risk management, of the kind already familiar to dual-regulated firms under the FCA's PS6/23, from a point-of-deployment check towards live monitoring for drift and degradation. Write down, for every material AI use case, what human oversight actually involves. And treat reasonable steps not as a compliance formality but as a design principle, built into systems before they ever reach an approver or observer level of autonomy.
Conclusion: Accountability does not disappear, it hides
The Mills Review does not conclude that AI breaks accountability. It concludes something more demanding. The regime holds, but only where firms do the work to keep the human meaningfully in control as that human moves further from the decision. Accountability will not vanish of its own accord. It hides only when firms let the distance between the name on the form and the decision on the screen grow unwatched. That distance is now theirs to close.
Do you know exactly what your senior managers are expected to see, challenge and escalate when an AI system acts on the firm's behalf, or only that a name sits on the form?
At OpusDatum, we help firms turn accountability principles into controls that hold as automation advances, from mapping AI and third-party dependencies to evidencing meaningful human control under the Senior Managers Regime. As systems move from recommending to acting, defensible governance is what separates confident adoption from quiet exposure.
If you would like to discuss how to keep accountability meaningful as your firm moves along the autonomy spectrum, contact us.
%20-%20C.png)


