The FCA's Regulatory Lag: Releasing Oversight Playbooks While Lenders Ship Six-Minute Loan Decisions
Regulators draft frameworks to control AI in finance while the industry has already moved three moves ahead.
The FCA just dropped a fresh review into how AI will reshape retail financial services by 2030. Stricter oversight. Tighter controls. Better guardrails. Very sensible. Very thorough. Very much arriving at the table after everyone has already eaten.
Here's the thing: Atlantic Federal cut loan origination from two days to six minutes using MANTL. That's not a pilot. That's production. That's real people getting credit decisions faster than a human can read the application. And while the FCA's review was still in draft, fintech shops across the EU were already shipping AI underwriting tools into the market.
This is the core of the regulatory trap. Every guidance memo, every consultation period, every "calls for" statement assumes the industry is moving at the speed of compliance cycles. It isn't. The industry is moving at the speed of GPU releases and model weights. By the time a regulator publishes oversight architecture for Model X, the market has already deployed Model X+1, and nobody knows what X+1 can actually do.
The FCA's new work highlights real risks—discrimination, bias, consumer harm, systemic fragility. Those are legitimate. But the review's timeline assumes a world where lenders pause and wait for a regulatory green light before scaling. That world doesn't exist. A startup with a good model, a growth mandate, and venture capital doesn't wait six months for clarity. It ships, learns, and either scales or gets shut down. The math is ruthless.
Meanwhile, the FCA calls for stricter AI oversight. Absolutely correct instinct. But "stricter" only works if enforcement can actually keep pace with deployment. And it can't. How do you audit a model that changes weekly? How do you stress-test a system running live in production, making credit decisions in real time? How do you even understand the risk surface if the tools vendors sell you are optimized for speed, not transparency?
The honest version of this story is that regulators and the regulated have entered a permanent state of mutual incomprehension. The FCA publishes a comprehensive review of AI's impact through 2030, laying out governance expectations and risk frameworks. Noble work. But the moment it goes live, lenders are already using techniques and models that the review never contemplated. Not because lenders are reckless, but because that's how frontier technology actually moves.
I've spent 25 years in mortgage and fintech. I've lived through every regulatory catch-up cycle: Basel III, Dodd-Frank, GDPR, Open Banking. Every single one was announced while the market was already three steps past it. The pattern never changes. Regulators react. Markets lead. The lag compounds.
So what does "stricter oversight" actually mean when the thing you're trying to oversee is accelerating faster than your ability to measure it? You get theater. You get checklists that lenders tick off because they're smart enough to know the regulator needs to see process, even if the process can't possibly keep up with the speed of change. You get risk managed through compliance theater instead of genuine architectural controls.
That's not the FCA's fault. It's the structure of the game. Regulators move on 18-month cycles. Frontier AI moves on 6-month cycles. Do the math.
The only way out is honesty: regulators need to abandon the pretense that they can write prescriptive guidance for AI in lending and instead focus on outcome-based accountability and real-time instrumentation. Tell lenders what you care about—no discrimination, no fraud, no hidden systemic risk—and mandate that they instrument their systems to prove it, continuously, to human auditors who can actually follow the logic. Stop trying to review and approve AI systems. Start demanding that lenders own the drift and disclose it.
Instead, we get new reviews. Stricter oversight calls. And meanwhile, somewhere in London or Berlin, a fintech team just deployed a new version that makes credit decisions faster, with less documentation, and zero visibility into how it actually works. The regulatory trap isn't malicious. It's just inevitable.
From my toolbox — something I actually ship, not just write about:
@vasperacapital/vasperamesh-agent — VasperaMesh agent runtime — run MCP-compatible agents inside your mesh with AMP protocol support.