The Regulator Is Arriving Before the Ambulance

Regulation once followed a familiar script. Something went wrong, customers suffered, investigators arrived, penalties followed and lessons were published. In fast-moving digital markets, however, waiting for the wreckage is increasingly untenable. AI-driven failures can scale in minutes, cyber incidents can cascade across interconnected firms and financial crime can race through networks. Regulators are therefore shifting from enforcement towards anticipation, prevention and resilience. The Financial Conduct Authority (FCA), for example, is integrating AI into regulatory workflows to detect harm more effectively, while EU supervisors are deploying supervisory technology (SupTech) to identify financial-crime risks earlier. Enforcement remains vital, but increasingly the regulatory ambition is simply to find the smoke before the fire.

Can Regulators Spot Trouble Before It Becomes a Crisis?

Traditional supervision often resembles driving through the rear-view mirror with regulators examining what has already happened. Increasingly, however, they are building radar. The Prudential Regulation Authority (PRA) describes its banking supervision as forward-looking and risk-focused, combining regulatory returns, management information and scenario analysis to identify emerging vulnerabilities and intervene early. Its 2026 Future Banking Data paper also highlights peer benchmarking, which can expose outliers and concentration risks before they become crises.

The FCA is travelling in the same direction. In 2025/26, its intelligence and analytics identified 30 suspected unregistered crypto brokers and a payments institution linked to around £30 million of potentially unregistered crypto-related payment flows, prompting supervisory and enforcement action.

For firms, this creates the prospect of the “pre-breach conversation”. Tomorrow’s supervisor may be less interested in asking, “Which rule did you break?” than “Your indicators suggest trouble is developing. What are you doing about it?” Complaints, staff turnover, control overrides, cyber incidents, transaction anomalies and that boards should identify, monitor and challenge these signals before supervisors do.

When Continuous Supervision Replaces the Annual Check-Up

RegTech helps firms comply. SupTech turns the telescope around, giving regulators technology to analyse firms and emerging risks. Across the EU, this is moving beyond experimentation. A European Banking Authority (EBA) study published in August 2025 found that 47% of identified anti-money laundering/ combatting financial terrorism (AML/CFT) SupTech tools and projects were already in production, with another 38% under development. Reported benefits included efficient risk identification and improved data quality.

The UK is pushing further towards what might become “always-on supervision”. The FCA’s 2026/27 programme includes integrating AI into regulatory workflows, using generative AI to review firms’ documents and testing automated data feeds between participating firms and the regulator. Such feeds could eventually reveal changing risk patterns between conventional reporting cycles rather than months afterwards.

Yet faster supervision creates a new problem. More data is not necessarily better intelligence. Inaccurate, inconsistent or poorly governed information could simply help regulators reach the wrong conclusion faster. Firms therefore need data lineage, ownership and quality controls, not impressive dashboards. The uncomfortable test for boards is simple….. if your regulator could inspect your risk data tomorrow morning, would it tell the same story as your board papers?

Should Regulators Help Build the Solutions They Police?

The traditional dividing line between regulator and innovator is becoming increasingly blurred. The FCA’s Supercharged Sandbox shows how far this shift has travelled. Its first cohort selected 22 firms to test AI-enabled propositions in a controlled environment, including tools for financial inclusion, vulnerable-customer support and agentic systems designed to combat financial crime.

The logic is compelling. Sandbox participation creates a cycle of experimentation, evidence and, potentially, safer market adoption. Regulators see how emerging technologies behave in practice, while firms can uncover regulatory and consumer-protection problems before committing to a full-scale launch. Earlier FCA evidence also suggested that sandbox testing can reduce time and cost to market.

Yet an awkward question remains: when does the referee become part of the coaching team? Close collaboration can create perceptions of endorsement, favour firms with better access to regulators, blur responsibility and increase the danger of regulatory capture. The FCA itself stresses that sandbox participation is not regulatory exemption and firms remain responsible for compliance.

For innovators, the lesson is clear. Regulatory engagement should become part of product development, not a last-minute hurdle before launch.

Regulating the Network, Not Just the Firm

A well-governed bank can still stumble if the technology ecosystem beneath it fails. That reality is pushing regulators beyond individual firms towards the networks on which whole markets depend. Under the EU’s DORA (Digital Operational Resilience Act) framework, the European Supervisory Authorities now oversee designated critical ICT third-party providers, assessing factors including systemic impact, interconnectedness and limited substitutability.

The UK is moving in the same direction. The PRA’s 2026/27 programme confirms continued work with the FCA on the Critical Third Parties regime. More strikingly, SIMEX26 will test the consequences of an extended outage at a major third-party technology provider. This is prevention at network level where firms, suppliers, platforms, concentration points and systemic consequences must be understood as one connected picture.

The principle extends beyond technology. Financial crime also travels through networks of customers, intermediaries, jurisdictions and transactions, making firm-by-firm visibility increasingly inadequate.

For businesses, the practical response is to build dependency maps, not merely supplier lists. Boards should identify which providers support critical services, where concentration exists, what realistic substitutes are available and how disruption could spread. In an interconnected economy, an external weakness can quickly become your internal crisis.

When Prevention Becomes Intervention

The preventive regulator faces an uncomfortable dilemma. Intervene too late and consumers or markets may suffer. Intervene too early and supervision can drift into management, discouraging legitimate risk-taking and innovation.

The FCA’s supervisory approach illustrates the balance. It is forward-looking, seeking to pre-empt poor conduct before harm materialises, but also proportionate and evidence-led. Under the Consumer Duty, firms must avoid foreseeable harm, while the FCA says its response should be proportionate to the risk involved.

A zero-failure culture could encourage firms to play safe, while intensive regulatory involvement creates moral hazard. If supervisors have scrutinised a strategy for months, management may assume that silence amounts to approval — or later argue that the regulator “knew what we were doing”.

Prevention should therefore identify dangerous trajectories and demand credible corrective action, not turn supervisors into shadow executives. The PRA reinforces this boundary: boards and management are expected to run regulated firms prudently.

For boards, the rule is simple. Welcome regulatory challenge, but never outsource judgement. The regulator can challenge the decision. Management still owns it.

The Best Regulatory Intervention May Be the One Nobody Notices

Enforcement is not disappearing, but the regulatory toolkit is widening. Punishment is being joined by prediction, periodic reporting by continuous intelligence, firm supervision by ecosystem oversight, and post-failure investigation by earlier intervention. The FCA, for example, explicitly aims to identify potential harm and act before it materialises. Yet prevention creates a curious measurement problem. Fines and prosecutions are visible; disasters avoided are not. How do regulators prove the value of a crisis that never happened? For businesses, the answer is demonstrating resilience before regulators have to demand it.

And what about you…?

  • Do you believe greater use of real-time data, SupTech and predictive analytics will improve regulatory supervision, or could it lead to excessive regulatory intervention?
  • Does your organisation understand its wider network of dependencies well enough to identify how failures involving suppliers, cloud providers, platforms or other third parties could affect critical services?