For three years, the UK held a statutory power it did not use. The Financial Services and Markets Act 2023 gave the Bank of England, the PRA and the FCA authority to oversee critical third parties to the financial system. The rules were finalised in November 2024. And then nothing happened. No entity was designated. The Treasury Committee noted the gap in its January report on AI in financial services with some irritation: a regime set up for more than a year, with nobody named under it.
That gap closed on 10 July. HM Treasury designated Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited as the first Critical Third Parties, with oversight beginning on 13 July. Four named legal entities. One fixed effective date. A designation instrument, the Critical Third Parties (Designation) Regulations 2026, sitting on the statute book where anyone can read it.
Most coverage treated this as a cloud concentration story. It is that. It is also something more useful to a board: a demonstration, at the level of an entire regulatory regime, of the evidentiary architecture that separates governance from the appearance of governance.
A power on paper is not accountability
Consider what the regime looked like on 9 July. The powers existed. The rulebooks were written. The supervisory statement had been published for eighteen months. If asked whether the UK had a framework for overseeing critical technology providers, the honest answer was yes. Frameworks existed in abundance.
And yet nothing was actually governed. No entity was subject to the rules, because no entity had been named. The regime was, in the precise sense, a charter without a record: a documented capability with no dated decision attached to it.
That is the condition most corporate AI governance is in right now. The policy exists. The committee has terms of reference. The framework has been approved. Ask who is accountable for a specific live deployment, and on what date that person reviewed the specific obligations attaching to it, and the paper trail thins out.
The CTP regime crossed the line the moment the designation was made. Not when the powers were legislated. Not when the rules were finalised. When four specific entities were named, in a dated statutory instrument, with an effective date fixed by something outside any firm's control. Everything before 13 July is capability. Everything from 13 July is accountability. The difference is a name and a date.
The reconciliation problem this creates for regulated firms
For a UK financial services board, the designation is not only a story about four technology companies. It adds a third layer to an accountability map that already has two, and the layers now have to agree.
Layer one: the Senior Managers and Certification Regime. A named senior manager, identified in a Statement of Responsibilities the regulator already holds, is personally accountable for the firm's operational resilience and, increasingly, its AI deployments. The FCA is expected to publish guidance later this year on precisely what assurance it expects from senior managers for harm caused through AI, following the Mills Review and the Treasury Committee's recommendations.
Layer two: the EU AI Act. The Article 50 deployer obligations have been live since 2 August. A firm deploying AI that interacts with the public, or generating synthetic content, carries disclosure duties now, whatever the state of the provider watermarking obligation deferred to December.
Layer three, new since 13 July: the firm's critical suppliers are themselves inside the regulatory perimeter, subject to resilience rules, with an incident and third-party reporting regime arriving on 18 March 2027.
Here is the question those three layers pose together. If the named senior manager's Statement of Responsibilities covers operational resilience, does it reflect that the firm's cloud dependency is now a designated CTP? Is there a dated record showing the senior manager reviewed what the designation changes for the firm's own obligations, created since 13 July, or will that record be assembled when someone asks? Firms remain responsible for their own third-party risk under the existing outsourcing rules. Designation of the supplier did not transfer the accountability. It sharpened the question of who holds it inside the firm.
The next designation wave is the one to prepare for
The Treasury Committee's January report recommended that Treasury designate the major AI and cloud providers by the end of 2026. The July designations answered the cloud half. The Committee chair's response on the day made the direction explicit: as AI use in financial services expands, specific AI firms may need designating under the same regime. The government's Financial Services AI Adoption Plan, published on 14 July and accepted in full, calls for accelerated implementation of the CTP regime including assessment of key AI providers.
Which means a board should assume the AI providers its firm depends on will, within a defined horizon, become named entities under a dated designation. When that happens, the reconciliation exercise runs again: the model provider named in the designation instrument, the senior manager named in the Statement of Responsibilities, and the dated record connecting the two. Firms that treat the July designations as someone else's regulatory event will run that exercise under time pressure. Firms that treat them as a template will already hold the records.
The regime itself has now shown how the standard works. Three years of capability produced no accountability. One instrument, four names and a date produced all of it. Boards asking whether their own AI governance would survive examination can apply the same test the regime just passed: not whether the framework exists, but whether the names and the dates do.
(Regulatory references: FSMA 2023; Critical Third Parties (Designation) Regulations 2026 (SI 2026/777); SS6/24; FCA SM&CR; EU AI Act Article 50; Treasury Committee First Report, January 2026; Financial Services AI Adoption Plan, 14 July 2026.)
The Roche-Review is the weekly publication of Dr Ivan Roche FRSSy FRSA MInstP, Founder of Otopoetic Limited. Subscribe at roche-review.com.


