Keynote speech given by Kate Jones, CEO, Digital Regulation Cooperation Forum at the Lewis Silkin AI Agenda 2026 event, 23 September 2026, London.
Good morning and thank you to Bryony and the Lewis Silkin team for inviting me to open today.
I don’t know about you, but I find that governance is a bit like plumbing. Rather technical and uninteresting until it bursts, and then it’s all anyone can talk about. It feels as though during the last fortnight the pendulum has swung from a huge race towards AI adoption to sudden collective consciousness about risks and side effects.
But my aim today isn’t to give a political speech about AI frontiers and geopolitics, fun as that would be, nor is it to sweat us all into the fevers of the day.
On the contrary, my aim is to bolster you, as governance leaders, in your aim of having AI governance embraced as an important dimension of strategic leadership and to encourage you in the measured, thoughtful approach you are no doubt already taking.
At non-frontier level too, when AI governance goes wrong, it’s noticed. Whether the High Court urging senior lawyers to avoid hallucinated citations in high-stakes litigation,[1] or the West Midlands police chief’s resignation over faulty AI intelligence about football fans from a minority community,[2] it’s embarrassing and it’s big news.
So the fundamental question for us as a community of GRC professionals is: as AI becomes part of business as usual, what do organisations need to get right?
I’m not going to comment on the HR dimensions – that’s for others.
And I am not going to suggest that good governance is easy when technology is moving so quickly. I don’t have a tick box exercise or off the shelf playbook to give you. But it certainly can be done, and done well.
My central argument this morning is simple: the organisations that benefit most will not be those that move fastest, but those that embed good governance in their strategic leadership. Innovation and trustworthiness have to go hand in hand for your business to thrive.
Agentic AI
Before I get to regulation, let me start with an example of agentic AI: its transition from being a tool we use to a system that acts, and the governance questions it raises.
Just this month, Meta announced the launch of Muse, a so-called ‘digital companion’ and Meta’s first foray into agentic AI. And I am sure there are other, similarly ‘amusing’, agents on the market.
Let’s say you, as consumer, ask Muse or similar to book your next holiday – it could book your annual leave, research the web for the best holiday for you, scan for the cheapest flights, barter for the best possible villa deal, organise payment and sort out travel insurance - and then, most alarmingly, adjust your gym schedule to get you a ‘beach-ready’ body whether you wanted one or not.
In organising this trip, the agent has saved you hours of admin time. But it has also processed your personal data, searched across online services, recommended products, purchased financial services, taken payment and affected competition between providers.
To illustrate the governance implications, consider first the consumer perspective. The user may no longer experience each step as a separate decision. We call this action bundling. [3] It makes some of the usual governance tools, like consent, transparency and availability of redress, harder to apply in ways that consumers can understand.
And then consider the experience inside the agentic business. The Mills Review on the Future of AI and Retail Financial Services – which I highly recommend on the future of AI deployment and regulation - describes operational changes as autonomy grows. It describes people moving through roles: first being a traditional operator of a service, towards being a collaborator with AI, then consultant, then approver of the AI’s actions and finally the observer of the AI operating the service. With each step, the human’s role becomes less direct: from doing the transaction to, eventually, being an observer who grants permissions and monitors outcomes.[4]
You might envisage this as AI no longer arriving in organisations as a new piece of software. It's arriving more like a new member of staff. At first it behaves like an apprentice: you give it tightly defined tasks, you check everything, and mistakes are expected. Then it becomes a colleague, helping with meaningful work. And increasingly, with agentic systems, it starts to look more like an employee operating independently within a defined remit.
The governance challenge is obvious. We would never hire thousands of new employees, give them access to customers, data and purchasing authority, and then worry about supervision, accountability and training afterwards. Governance is the discipline that ensures we recruit, supervise and manage our digital workforce as carefully as we do our human one.
What regulators are seeing
I’ll come back to what that means for you as governance professionals. First, let me talk about regulation.
The DRCF regulators, the CMA, FCA, ICO and Ofcom, have remits embracing competition and consumer protection, financial services, data protection, communications and online safety.[5] From our perspective as DRCF, this one agentic example has engaged the remits of all four members. This is why the DRCF is so important: technology converges, whereas regulation historically specialised. AI does not arrive in neat regulatory boxes.
Zooming out from the example to the general, from a cross-regulatory vantage point, we regulators are seeing three key changes this year.
First, as I’ve mentioned, AI is moving into operational workflows. The Mills Review reports firms piloting or deploying AI across customer support, fraud detection, software development, compliance and operations.[6]
Second, consumer use is developing too. Ofcom’s research has found that over half of UK adults now use AI tools, and over three-quarters of 16-24 year olds. And there’s evidence that a significant number of AI users are comfortable with AI acting autonomously. The Mills Review’s survey of over 5,000 UK adults found that 20% would consider AI that acts autonomously within pre-set goals, rising to 28 per cent among existing AI users.[7]
Third, trust is becoming decisive. Despite increasing use, concerns about data misuse, protection when things go wrong and concentration of power remain high.[8] A recent DRCF discussion on maximising consumer interests in AI found broad agreement that trust is fundamental to successful adoption, and that compliance, fairness, safety and transparency need to be built in from the outset.[9]
What regulators are doing
That brings me to the UK’s approach: that smart regulation helps innovation. Innovation and regulation do not sit on opposite sides of a balance sheet.
The UK’s pragmatic, pro-innovation approach is bearing fruit. We see that in UK businesses: developing self-driving technology,[10] applying AI to cybersecurity[11] and using AI and automation in fulfilment centres.
It doesn’t mean that we’ve put the brakes on regulation. Good regulation provides clarity about outcomes. And regulators are moving together with industry on the innovation and adoption journey, and providing support in real time.
Through the DRCF we are anticipating future developments, including through our foresight work on agentic AI and horizon scanning into consumer robotics.
We have also supported innovation more directly. The DRCF AI and Digital Hub piloted a joined-up advisory service for innovators. Now we have the DRCF Thematic Innovation Hub, starting with agentic AI and now taking authentication and trust, to engage businesses earlier on cross-regulatory questions.[12]
We are testing a regulator-owned prototype DRCF Digital Regulatory Library intended to make it easier for businesses to access guidance from all four regulators.[13]
And we are currently researching consumer attitudes, to better understand what’s needed for public trust as generative and agentic AI become more capable. [14
Our member regulators are innovating in their own remits as well. The FCA’s Supercharged Sandbox gives firms a controlled environment, compute, datasets and expert support to test advanced AI.[15] The CMA has published practical guidance,[16] the ICO is exploring data protection questions in its Tech Futures work, and Ofcom’s 2026/27 strategy applies outcomes-based principles to enable safe and secure adoption.[17]
In these ways, regulators are on a shared journey with business.
Effective governance: the three things to get right
Turning to you as GRC professionals, the key point is that AI autonomy does not remove organisational responsibility. DRCF regulators are clear that existing obligations around transparency, fairness, safety, consumer protection and competition continue to apply.[18]
So, what should you get right in your governance now? I would suggest that in every boardroom conversation about AI, there are three questions leaders should ask:
One: Who is accountable?
Two: Why should people trust it?
Three: Do have we have capability to oversee and challenge it?
So first, for accountability, implement holistic governance. End the internal silos just as we regulators have done via the DRCF. AI decisions cannot sit with Legal, Technology, Risk, HR or Compliance alone. You need practical shared ownership: clear decision rights, mapped accountability, risk-based thresholds and evidence that controls work in practice. Your governance needs to be as holistic as the technology you are adopting.[19] You need to be strategy enablers for your boards.
Second, enable customer trust. To do that, ensure organisational clarity about when AI is acting, what it is authorised to do, what data it collects and how that’s used, how the AI is monitored, what controls are in place, where a human will intervene and how outcomes can be challenged.[20] Overall, do you have the capability to let consumers give meaningful consent, to monitor AI agents in real-time, and to offer accountability when something goes wrong?
Third, ensure human capability. Don’t simply assume that someone who has done a task themselves is equipped to monitor AI doing it. Train your staff so they are clear what information they need to see, what they need to understand about the AI’s workings, when they should intervene and how they can challenge.[21] If necessary, train them to use AI to assist in their monitoring and intervention.
Overall, your leadership should be asking not only what AI can do, but whether the organisation can govern it at speed and scale with the trust and accountability that customers demand.
Conclusion
In concluding, this may be one of the few moments when governance choices in the next year or two could shape organisational behaviour for decades. The decisions you make and organisational culture you establish now, at this moment of transition to AI, may influence your businesses and your industry for decades to come.
The organisations that benefit most will not be those that move fastest. They will be those that ask not only what the technology can do, but also how to govern it so as to build and maintain customer trust.
We often speak as though the AI revolution is a race. But the organisations that prosper will not simply be those that accelerate fastest. They will be those that learn to steer. In the end, governance is not the handbrake on innovation. It's the steering wheel.
Thank you.

