Automated decisions in a broker inbox: what changed for UK brokerages in February 2026
On 5 February 2026 the UK replaced Article 22 with Articles 22A to 22D. What a brokerage running AI replies, risk scores and lifecycle triggers must now show.
A governance checklist for broker firms using AI-assisted WhatsApp replies under Consumer Duty: sign-off, escalation, records and SM&CR accountability.
AI that drafts or sends client replies is no longer hypothetical for UK brokerages: it is a feature in ordinary tools, switched on with a toggle. The FCA has been clear that it does not plan an AI rulebook — existing frameworks apply, as set out in its AI update for financial services. That is not a reprieve. It means every AI-assisted message a firm sends to a retail client already sits inside the Consumer Duty, the FCA Handbook's record-keeping rules and, for accountability, the Senior Managers and Certification Regime. The question for a broking firm is not “are we allowed to use AI?” but “can we evidence that we govern it?”
Two Consumer Duty outcomes bite directly on automated or AI-assisted messaging. Consumer understanding makes the firm responsible for communications being clear, fair and likely to be understood — authorship is irrelevant, so a misleading sentence drafted by a model is the firm's misleading sentence. Consumer support requires that clients get effective help; an automated reply that deflects a vulnerable client or buries a complaint is a support failure the firm owns.
The consequence is that AI-assisted replies need the same treatment as a new financial promotion process or a new outsourced function: defined scope, named accountability, controls, monitoring and records. None of that is exotic. It fits on one page — and it should, because a policy nobody can remember is a policy nobody follows.
A workable monitoring pack for a small or mid-size brokerage is four numbers and one sample. The numbers: share of inbound messages answered automatically, share escalated to a human, average time-to-human on escalated messages, and complaints referencing an automated reply. The sample: ten AI-involved conversations a month, read end-to-end by someone who did not handle them. Firms that do this discover quickly where the boundary between “safe to automate” and “needs a person” actually lies in their own book — it is rarely where the vendor's demo suggested.
Be honest in client-facing terms too: nothing in the Duty requires you to pretend a human wrote every message, and clients who discover otherwise trust the firm less. The comparison between an unsupervised chatbot and supervised AI is worth reading if the firm is still deciding which side of that line to build on.
It helps to see the checklist mapped onto a real system. In ORIS, auto-reply is off until a firm enables it, and it runs under rules: a cooldown between automated replies and a maximum number of auto-replies per client. Every incoming message is analysed for sentiment; an automated reply can only be sent when sentiment is positive (or neutral, if the firm allows it). Negative sentiment never gets an automated answer — the AI produces a draft instead, and a handler is notified that a draft reply is ready to review in the shared inbox. The drafting prompt itself forbids promises about price or cover. Messages the system cannot classify safely are flagged for a human. Every message, automated or not, is stored and exportable to CSV, so the audit trail the checklist demands exists by construction rather than by memo.
Whatever tool you use, insist on those same properties: rules you set, a sentiment gate you can see, drafts by default, and records you can export. If a vendor cannot show you where the human enters the loop, that is your answer.
No. There is no authorisation gate specific to AI. The firm remains responsible under existing rules — Consumer Duty, ICOBS, SYSC and SM&CR — for the outcomes its communications produce, however they are generated.
A Senior Management Function holder whose statement of responsibilities plausibly covers client communications or operations. What matters is that one named person approved the scope, reviews the monitoring and can stop the system — not the job title.
It should not answer them autonomously. Premium and cover statements carry advice and misrepresentation risk; route these to a human, with the AI at most preparing a draft from the policy record for the handler to verify.
The message content, timestamps, recipient, whether it was auto-sent or human-approved, and the escalation signals detected. Keep them in the same archive and for the same period as the rest of the client conversation.
Yes. Complaints are a lagging and heavily filtered signal — most poor outcomes never become complaints. Sampling conversations is the only way to see how the system behaves with real clients before the annual Consumer Duty board report asks you to evidence it.
Shared WhatsApp inbox, client records, follow-ups and opportunities for the whole brokerage. 15-minute demo.
On 5 February 2026 the UK replaced Article 22 with Articles 22A to 22D. What a brokerage running AI replies, risk scores and lifecycle triggers must now show.
EIOPA's opinion on AI governance covers intermediaries, not only insurers. What its six areas ask of a brokerage running AI in a shared WhatsApp inbox.
Your brokerage runs AI-assisted replies. What MIPRU 3.2 obliges you to hold, and what the Insurance Act 2015 duty of fair presentation means at renewal.