The FCA’s Mills Review, published on 6 July 2026, set out four ways artificial intelligence is expected to reshape retail financial services: firm operations, consumer journeys, market competition, and fraud and cyber risk. It described a rapid move from human-led to AI-enabled services, noted that millions of consumers already use AI for personal finance decisions, and warned that the regulator needs greater powers to keep pace.
Pay.UK operates the UK’s retail interbank payment systems and is leading the work on their next generation. The Fintech Times put six written questions on the review to David Crawford, its chief strategy and

transformation officer, who joined from NatWest, where he led payments for the retail bank. His answers pick out fraud as the shift moving fastest, describe what agentic commerce will ask of payment rails, and set out the oversight he thinks the regulator should have.
Of the four shifts, Crawford has no hesitation about which is moving fastest. “Fraud and cyber risk are moving fastest and are among the most immediate challenges facing the sector.” Firms’ operations are evolving quickly through internal AI tools, he says, but AI-enabled fraud affects consumers, payment service providers, infrastructure operators and regulators alike.
“AI is a double-edged sword. It can be used to strengthen fraud detection, pattern recognition and response across complex payment ecosystems, but it is also making it easier for criminals to create more convincing scams through social engineering campaigns, synthetic identities, mule-account activity and automated attack patterns.”
With criminals adopting AI faster than legitimate institutions can respond, he says the priority for payment infrastructure is safety and resilience across the whole ecosystem: shared fraud intelligence, stronger data governance and near-real-time monitoring. He cites Pay.UK’s Enhanced Data Exchange, “which builds on Confirmation of Payee tools by sharing critical data points such as account tenure and holder age. This helps the network to detect suspicious patterns earlier, while leaving customer interventions with front-line firms.”
From transaction processing to intelligent networks
Asked what the move from human-led to AI-enabled services means for the interbank systems and for the next-generation infrastructure Pay.UK is championing, Crawford starts from the customer’s expectation. “Payments are expected to be instant and secure. The challenge is that AI is increasing the speed at which decisions are made, customer journeys are completed and fraud attempts can occur.” The rules, standards and physical rails of the current core systems remain highly resilient, he says, and can accommodate early-stage AI integration.
The longer-term change is in kind rather than speed. Interbank systems “will need to evolve from simple transaction processing towards being more in the way of intelligent networks that provide real-time visibility but without eroding consumer trust.” As automated tools take a larger role in financial decisions, resilience depends on the quality of the data behind them. “High-speed services need trusted data provenance and explainable AI outputs, so automated choices remain auditable and subject to meaningful human oversight.”
Next-generation infrastructure, in his description, should let participants innovate without creating unmanaged risk. In practice that means pairing modern rails with adaptable governance and stronger data capabilities, “and moving away from static, document-heavy rulebooks towards more dynamic, data-driven oversight where obligations, controls, and risk signals are clearly connected across the payment value chain.”
Preparing for agentic commerce
Millions of consumers already use AI to budget, compare products, manage bills and make financial decisions. Crawford says the sector has to prepare for the growth of agentic commerce. “More of our payments will be initiated or influenced by digital agents rather than a person acting alone. This is likely to influence what we ask of payment systems in the future.”
Speed and convenience will still matter, but infrastructure will also need clear consent models, reliable identity and account signals, and stronger protections against manipulation or error. “If an AI recommendation shapes a transaction, both consumers and institutions need confidence that the payment was properly authorised and backed by accurate data.” He sees an opportunity to enable that innovation while keeping trust in account-to-account payments: by setting standards for richer payment data and actionable fraud warnings, the ecosystem can support agent-driven experiences without undermining consumer protection or system integrity.
What oversight should look like
The Mills Review’s warning that the regulator needs greater powers prompted the question of what that oversight should look like from an infrastructure operator’s seat. “From our perspective, regulatory oversight should be risk-based, proportionate and focused on outcomes. Regulation should support innovation in payment services while making sure AI is governed with the same rigour as operational resilience or cyber risk management.”
That means regulators having clear visibility of where AI is used, the risks it creates, how they are managed and where accountability sits across the ecosystem. Crawford places this alongside wider policy shifts: the proposed merger of the Payment Systems Regulator into the FCA under the Enhancing Financial Services Bill, potential rewrites of the Payment Services Regulations 2017, and the Cyber Security and Resilience Bill.
Because AI tools rely on external technology providers, he calls third-party risk management “absolutely critical”. An effective model should reinforce transparency and explainability while preserving human oversight. “Oversight also needs to be built into the technology lifecycle rather than added on after deployment.” Turning responsible AI principles into measurable controls, he says, requires formal stage-gates, model validation and ongoing monitoring, so that every high-risk use case proves its safety, accuracy and value before it goes live.
Collective value, not just firm controls
On the balance between AI’s fraud-fighting potential and the new fraud risks it creates, Crawford frames the technology as both tool and threat. It can shift fraud management from reactive investigation to proactive prevention, “but only if the governance controls match the sophistication of the technology itself.”
Getting the balance right, he argues, means pointing AI at collective value rather than only at individual firm controls. “No single institution sees the full threat landscape, so industry-wide collaboration through shared fraud typologies, richer data standards, and federated data models is essential.” Connecting insights without centralising sensitive data can support faster analytics while maintaining strict data stewardship.
“Crucially, innovation cannot be allowed to run ahead of safeguards.” Deploying AI effectively, in his account, means privacy by design, continuous testing for model bias and drift, explainable outputs, and clear human accountability for any automated decision that affects consumers or payment outcomes.
The next two years
Asked for Pay.UK’s priorities over the next two years, Crawford returns to the same pairing. “Our priority is to enable innovation while safeguarding system resilience and public trust. Modernising payment infrastructure is central to that.” As AI makes fraud more sophisticated, the rails must deliver richer data and real-time intelligence sharing so that next-generation services remain secure and interoperable.
He also wants responsible AI governance embedded inside Pay.UK and across industry participants, with a close watch on legislative reform, naming stablecoin framework changes and tokenisation initiatives. Automated services, he says, need structured stage-gate approvals and active oversight rather than controls added as an afterthought, so that adoption stays safe, transparent and aligned with the public interest.
The last word goes to people rather than systems. “Ultimately, success depends on workforce capability. AI may change how decisions are made and how risks are managed, but accountability and judgement must remain firmly with people.”
The reforms Crawford points to, the Payment Systems Regulator’s proposed absorption into the FCA and the rewrite of the Payment Services Regulations 2017, are the next fixed points on that calendar.
The post Pay.UK’s David Crawford: AI fraud Is The Fastest-Moving Shift appeared first on The Fintech Times.