No Get Out of Jail Free Card: Five Data Leaders on AI in Regulated Industries

5 Aug 2026 · 25 min · 10 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

AI in UK financial services and other regulated industries, focusing on “responsible AI” adoption—no “get out of jail free” for using AI. The FCA role is to enable safe innovation via tools like Digital Sandbox/AI Lab, AI sprints (e.g., agentic/chatbots/vulnerable customers), and “AI live testing” with live market deployments and governance evidence (data selection/lineage, model choice, testing, guardrails, responsiveness).

Guests (backgrounds)

  • Jessica Russo, FCA Chief Data, Information and Intelligence Officer.
  • Edmund Towers, FCA Head of Advanced Analytics and Data Science Unit.
  • Luke Pierce, Santander UK (data/AI leader).
  • Sarah Self, AI Director at Aviva (insurance).
  • Kevin Cassar, Chief Data and AI Officer at Tok Tok; previously built an AI triage system in health insurance.

Key claims + examples

  • Compliance and innovation are the same agenda; responsible AI is end-to-end (including operational resiliency and accountability), not a tick-box.
  • FCA uses Consumer Duty (fair value, needs, complaints/vulnerable customers, inclusion).
  • Examples: Aviva claim summarization cut handler hold times 50%+; Aviva medical underwriting achieved ~99% accuracy; health-insurance triage to route scarce clinician resources; FCA synthetic transaction dataset (with Turing Institute) for AML/scam/fraud detection and reduced false positives.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

The Role of AI in Financial Services

2:07 to 3:21

Explore the significance of AI technology in the financial sector.

“I'd love to kick us off maybe with the second part first, which is around, you know, AI in the external world in the industry.”

FCA's Approach to AI and Regulation

3:21 to 5:34

Understand the FCA's role in promoting safe AI practices.

“And then AI is the technology innovation of the next decade, at least.”

The Ongoing Journey of Responsible AI

5:34 to 7:45

Discover the continuous process of ensuring responsible AI usage.

“So these could be large banks that maybe they want to deploy a chatbot.”

Challenges and Accountability in AI Adoption

7:45 to 10:10

Learn about the challenges firms face when integrating AI responsibly.

“We're using air responsibly and we feel good about it.”

C-Suite Support and Innovation

10:10 to 12:54

Discuss the importance of C-suite support in driving AI innovation.

“If it's your firm, you have to understand how it works and you have to understand the impact on customers all of the time.”

Improving Customer Experience with AI

12:54 to 15:01

Examine how AI can enhance customer interactions in financial services.

“I think in the last couple of years are probably as a result of that support that the C-suite has given us.”

AI in Medical Underwriting

15:01 to 17:47

Discover how AI supports accurate and efficient medical underwriting.

“Other ones that I love are things like our medical underwriting, which we're industry leading, very pleased to say around that.”

Triage Solutions in Healthcare

17:47 to 19:54

Explore the role of AI in triaging healthcare claims for better outcomes.

“In this case, it was the chief operating officer in conjunction with the CDO that sponsored it, because obviously there's a data and there's operation aspect.”

Addressing Financial Crime with AI

19:54 to 21:40

Understand the significance of AI in combating financial crime and fraud.

“Could you walk us through one initiative you delivered in the past?”

Enhancing Consumer Financial Services

21:40 to 23:15

Learn how data analysis can improve financial services and consumer experiences.

“But really, it's absolutely fundamental that we we use technology in ways that can help fight some of these really serious issues.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:08Welcome to Data and AI Mastery, the podcast where we sit down with the data and AI leaders shaping the future of business. I'm your host, Raoul Gabriel-Urma. Today, we're doing something a little different. One of the things I love about hosting this show is what happens when you step back from the individual conversations and look at the bigger picture. Patterns start to emerge. Themes that keep coming back across different industries and different companies, no matter what stage of the AI journey they find themselves on. This episode is built around one of those themes. Today, we're going into the sectors where the stakes are highest.

0:47Financial services, insurance, and regulated environments more broadly. If you work in one of those worlds, you'll know the AI conversation sounds a little different. The opportunity is just as real, but so is the scrutiny. And the consequences of getting it wrong aren't abstract. They land on real customers at real moments that really matter. You're going to hear from several guests, in particular, two from the Financial Conduct Authority, Jessica Russo, the FCA Chief Data Information and Intelligence Officer, as well as Edmund Towers, head of the FCA's Advanced Analytics and Data Science Unit, who, between them, give you the clearest picture I've heard of what responsible AI adoption looks like from both the regulatory and technical side.

1:33You'll also hear from Luke Pierce at Santander UK, from Sarah Self, AI Director at Aviva, and from Kevin Cassar, Chief Data and AI Officer at Tok Tok, drawing on his experience building AI trial system in health insurance. What comes true across every one of these conversations is that the organizations doing this well are not treating compliance and innovation as opposing forces. They are treating them as the same agenda. Let's get into it.

2:07I'd love to kick us off maybe with the second part first, which is around, you know, AI in the external world in the industry. How do you think about the role of the FCA in the world of AI? So financial services contributes a massive amount to the UK economy, about 10 % of GDP, which is roughly between like£200 and£300 billion a year. It employs over a million people. And technology and AI is absolutely at the heart of financial services. whether you're talking about a high street bank or, you know, a big multinational wholesale firm, many of whom consider themselves technology firms first these days, the UK is kind of a, is already kind of a world leader in the use of technology in finance or what's often called fintech, whether that be a small startup firm who's looking to attract investment into the UK and into their business, or whether it's a big incumbent firm, like an institutional firm, using technology to deliver better products and better services to their consumers.

3:20So that's the kind of context, right? And then AI is the technology innovation of the next decade, at least. We are already seeing the massive potential of that. And there's a huge opportunity there for the UK to lead the way in the use of safe and responsible AI in financial services. So as a regulator, that's what it all comes back to. We have to create the right regulatory environment that supports that, that helps firms innovate, that helps firms deliver new products that can better serve those consumers. And we want those firms to build their AI here in the UK, right, and then to export it to the rest of the world.

4:10Externally, what we see is that firm needs when it comes to AI delivery come in different shapes and sizes. So we have tried to be as flexible as possible to meet whatever those needs are. So it's not all fintechs. I described already the AI lab services that we have. So we've built on top of our digital sandbox this AI lab that gives AI spotlight opportunities for firms to showcase types of AI tech that are working well and what they're solving for. We have specific sprints focused on different types of AI, for example, agentic use cases or chatbots or vulnerable customers. So we have developed all of these offerings where firms can come and essentially use our tech or use our services.

5:05But not all firms necessarily need to engage with the FCA, and they don't necessarily have to come into the sandbox. But what we decided to offer was this concept called AI live testing. What that means is our teams are going along as an innovator and from a supervisory standpoint to work side by side with firms as they are doing live product testing in the market. So these could be large banks that maybe they want to deploy a chatbot. Maybe they want to give consumer advice. Maybe they want to use some tool internally or externally. And they don't need to come in the sandbox, but they do want to showcase how they are thinking about AI governance.

5:58And so the typical questions that you might expect, you know, how have you selected data for this model? Why did you choose the model that you chose? What sort of testing have you done to make sure that, you know, as consumers are going to interact with this, you know, what guardrails have you put around that service or that product? So we sort of ask all of the questions that you would expect to see. But again, from a guidance and a best practice sharing standpoint, not as a here's a tick box approach to deploying AI, because we know that every application is unique. And we know that technology is moving so quickly that what might have been a good model six weeks ago might not be a good model six weeks from now.

6:52So it's really about how robust has the firm considered this product delivery? What guardrails do they have around it? And how able are they to respond to that? So that's the AI live testing initiative. And we have just announced the second cohort of firms that will be kind of going through that experience. Yeah, amazing. so it sounds like you know spending a good amount of time thinking about the assumption the lineage the guardrails around the output how's that used and be able to evidence it i do wonder is there like a uh a moment where all right we've done a good job here you know it's responsible or is that a an ongoing journey you know as as model gets better and better that you know companies you still going through?

7:43Like when can we answer the question? We're using air responsibly and we feel good about it. So from a policy perspective, we continue to leverage the consumer duty. The consumer duty essentially says you have to offer fair value to consumers. You have to make sure that the products and services they receive meet their needs, that they have flexibility and choice. We look at things like complaints volumes and vulnerable customers as well. How are they being treated and do consumers have access? We call it sometimes consumer financial inclusion. So are there certain groups of customers that are somehow being excluded from financial services?

8:27So all of those things mean that by saying that the rules haven't changed, we feel that that is actually a stronger starting point rather than a weaker starting point. So in some places, we've had some feedback, oh, you should make some rules for what responsible AI looks like. And as I said, as a data scientist, I could give you my opinion as to what I think responsible data science looks like. But it's more than just the data or the tech. It's an end-to-end application that will be integrated into the financial institution. It could be back office. It could be operational. It could be front office facing.

9:10It could be consumer facing. So there is no one-size-fits-all definition of what responsible AI looks like. But if you think about some extreme examples, they're already covered by legislation and policy. So let's say, for example, a firm decides that they just want to cut out an entire department and replace it with some agentic workforce. They could do that. But have they thought through the operational resiliency, you know, responsibilities? What would happen under the senior manager's regime? Who's accountable if all of that agentic workforce were not able to show up for work one day because there was an outage or a systems issue?

9:56So as they think about deploying technology wherever they deploy it, the same rules of the game apply, meaning there's no get-out-of-jail-free card just because you use AI. You cannot say, oh, it was a black box and it was too complicated. If it's your firm, you have to understand how it works and you have to understand the impact on customers all of the time. And so we actually feel that that's a more responsible AI place to be versus having some sort of, OK, if you do these 10 things, then you've ticked the box.

10:37It's a really interesting point because I do think that you can be stifled a lot in the data space. by people thinking that data is there, you have to get it under control. And particularly in the finance industry, there's a lot of regulatory scrutiny. And have you got your data? Is it trusted? Do you have controls on it? And you end up in a very governance-focused environment. And I think that's probably the bit that, like I say, stifles creativity, and it really ensures that you're not getting the best value out of the data. And probably, I would say, lots of the banks have been through that journey over the last few years because we've all had risk models we've all had i mean bcbs um 239 you know we've got ss123 now in there and so the regulation is coming in saying you need to have your data and you need to have control of your data um what's been really nice in santander is is we've actually then started to see right from the ceo um all the way through the the Exco is a real, almost an invite to, can you make the data do more?

11:40Can you show us the value and how can we support you in that journey? And I think that's a really important for any organization. If you have that sponsorship at the C-suite level, it becomes a lot easier to open the door to lots of those new opportunities. And I think the bit for me, when we started to look at generative AI, because obviously generative AI became one of the buzzwords, everyone wanted to to understand it, what it could be used for. But having that support means that you start going from probably an environment where people are very risk averse to doing anything new because they want to know that the, you know, the regulator is going to be supportive, that we're going to have like controls.

12:16And can we do these things, which, you know, are really quite new and innovative for the organization, you know, without having that, that worry to actually let's, let's start to push ahead with this agenda. Let's start to see how we can make it work both for our colleagues and our customers. and it opens up a lot of doors. And in a different way, you have people in second line and third line actually trying to find ways through and trying to manage these new environments where you need to probably identify new controls. You need to do new ways of looking at things, how you manage your risk portfolio.

12:49It's all of those things come together and actually the outcome is quite amazing. So some of the things that we've managed to do, I think in the last couple of years are probably as a result of that support that the C-suite has given us.

13:04we started very much with a view of we wanted to drive customer value and benefit so we wanted to look for solutions that we believed would improve the customer experience improve the customer journey and so that again it drills you into an area quite quite easily if you like if you know that that's the outcome you're trying to get to then you look for areas where you say where is that potentially less efficient for a customer than it could be? Where is that slower? Or what is the problem that we want to solve? And that led us to some of our early successes. So one of the first things that we put into production and we scaled and then we shared out across multiple products and markets, very proud of that, was a claim summarization solution.

13:47And just very simply, you know, our claims handlers that talk directly to customers do an amazing job. But the first thing they have to do when a customer comes on the line is they have to get themselves familiar with that case. So who is this customer? Why are they calling in? What's the case history? What's happened already on this claim? And invariably the way that they do that is they say, hello, Mr. Self, you know, nice, nice, nice to see you. Just bear with me one moment whilst I get myself familiar with what's gone on. And they put the customer on hold and they read. and the customer sits there on hold.

14:24So actually one of the first things we did was we used summarization capability to provide those claims handlers a really succinct but accurate view of the case history all in one place, really easily digestible that they could take accurately and very quickly pick up to the customer. So it reduced those hold times by over 50%. So customer gets a far better experience. The claim handler loves it because actually they don't want to put a customer on hold. It was easier for them. It was better for the customer. Sounds really simple, but it's a great use of AI. Other ones that I love are things like our medical underwriting, which we're industry leading, very pleased to say around that.

15:07And again, this was supporting our medical underwriters. So we have a really inclusive medical underwriting policy at Aviva. And that means that sometimes you are underwriting really complicated personal medical histories. And the way in which you do that and understand that is you look at a huge amount of data. So again, we delivered capability that meant that we were accelerating how the underwriters could go through that process with 99 % accuracy, you know, brilliant kind of service. And actually, we can therefore get back to customers more quickly, we can go through the process more quickly, we can be confident with the outcomes.

15:46And their problems that you were relatively they're well fitted for AI capability so you've matched them together really nicely but they had a really clear purpose and intent that was aligned to customer value and benefit and you could measure that you can measure how long a process takes you.

16:07So when I was at AXA it's a health insurance company so the aspect is to give people access to halt private health sector. So that's what was one of the mandates of the insurance sector. Like data scientists, there are good data scientists and there are average data scientists the same way with every practice in there. So the mandate that we had, one of the mandate was to triage the number of claims that come to us to identify where can we give help, more help to other people that need it most. So some cases are not the same as others. And in In some instances, some cases would need better support from inside doctors or physiotherapists, etc.

16:47Which, as you can imagine, you don't have enough resources to give all this additional support to tailor the treatment to everyone. So you need to have a triage problem. So the business case that we had in there is how can we build up AI solution to help us triage between the cases, which are the cases that will require more support than others. And then how can we help those individuals? And the why do we care for this reason is twofold. So we can give customers better outcomes. So people could get better tailored procedures or medical care in order to get healthier quicker. But equally, well, that's on the outside.

17:28On the inside is how can we make the best allocation for the very scarce and expensive resources as well. So it's a win-win situation. and when you present it from that aspect we can give better customer satisfaction help us to achieve our mandate that we need to give better health to outcome to customers but equally would help us to improve our operational efficiency and manage the cost which ultimately can lead to lower our prices and better competition so that's the pitch why do we care and then it comes to can we trust the data so that's when we build models and there's different methods and techniques how you profile the data make sure the data coming in and out of the models that you build is what it is there's methods you know better than i do um how the models you can make a model explainability interpretability model performance metrics and what have you and let's then present that information digestible manner to whether c suite colleagues to give them comfort that we can trust the data that is coming out of our algorithms or models that we build that's a great uh example So in such a project, who would be the sponsor and what level of update would you need to give throughout the delivery of this initiative?

18:39Yeah, absolutely. In this case, it was the chief operating officer in conjunction with the CDO that sponsored it, because obviously there's a data and there's operation aspect. So it was two people that co-sponsored that piece of work. And this brings in to your second question, how do we ensure that the business comes along the journey with us? And we tailored, when I set up this project, I tailored at the time the concept of having multidisciplinary squads, not just from a data perspective, but including also the business colleagues, the risk colleagues, as well as obviously data scientists, platform engineers, data engineers, and what have you.

19:14and business spoke really highly about bringing them at the end of each sprint we worked in an agile methodology so at the end of each sprint we did a sprint demo where we presented what we set out to do in this initial sprint what we achieved at the end of the sprint and if there was a demo of the products that we delivered we we shared it with business you know when you pitch an initiative you have to think about why it matters so that's kind of like tapping to the pain the problem what we can get out of it. So why does it matter in practice? I guess that's the ROI, the solution that, you know, one could believe in.

19:50And then are we actually going to believe it? You know, is it going to be a possible outcome? Could you walk us through one initiative you delivered in the past?

20:03Innovation growth is about how we help firms, you know, safely adopt AI, how we help uk firms be a leader in that that global uh market right and ensure that uh we are kind of able to adopt here and and kind of hopefully export to the rest of the world so that's kind of one element the financial crime i guess is some of those use cases we talked about i mean most firms are using some form of analytics pretty much every firm is using analytics or ml or in some situations like you know on some of these problems like uh fraud scams uh money laundering detection so you know we are also doing that internally ourselves we do our own work proactively trying to identify fraudulent financial promotions using web scraping and then take action against those via the isp but at the same time we're also doing this work where you know we know that uh there are sort of more complex ai driven approaches to money laundering that potentially can reduce the improved detection rates and reduce false detection rates, you know, that also cost firms on it.

21:14And these are real problems. I mean, you know, I think sometimes when you talk in the abstract, well, like these things sound a bit dry, especially for people who aren't there. Right. But money laundering is about, you know, that's the money that finances terrorism. It's the money that finances, you know, human trafficking, that finances the global drug These are serious, like these are really high impact personal issues. Right. And it can be easy to then abstract this up to sort of, you know, AML. Right. And there's three letter acronym. But really, it's absolutely fundamental that we we use technology in ways that can help fight some of these really serious issues.

21:50It's the same for scams. I mean, you know, you I think all of us either know someone personally who's been subject to some kind of scam or have read about it in the newspapers. Right. These are these are real impacting issues. So the more that we can do to help identify these kind of things, take action on it, fraud, you know, as well, like push payment fraud, it's really fundamental. And technology has a massive role to play in that. The industry is already using it. We are using it, but we're kind of committed to kind of pushing and working with firms to help them move further, which is why, you know, one of the things we've done is generate this synthetic transaction data set using data from one of the major firms in the UK and then working very closely with the Turing Institute, actually, and to develop this new day set that we're looking to make available to firms who want.

22:43You know, the helping consumers point is, you know, we all as consumers want to make the most use of our money. Financial services is a really important way for people to achieve their life goals, right? So whether that is, you know, buying your first house or saving for retirement or being able to afford that home improvement or that kind of thing, you know, having access to financial services that can help you achieve those life goals and do it in a way that is safe and trustworthy and usable is really actually fundamental to how most of us, you know, achieve our life goals. So using data analysis in that area to understand different consumers, how they move through these journeys, what products they have access to, are there any gaps, are there ways in which consumers could be better utilizing those kind of things, are there ways and for you know are there any areas we want firms to be kind of uh improving how they operate like these are really again really really important kind of topics now that's a wrap on today's episode across every one of these conversations the same idea keeps surfacing getting the compliance right and getting the innovation right aren't two separate jobs they are the same job and the ones making real progress started by asking not just what ai could do but what responsible progress actually looks like for the people they serve.

24:02If what you've heard today has sparked further reflection, these were just the highlights. The full conversations go much deeper. Links to every episode featured are in the show notes and are well worth your time. If you found this useful, please do subscribe. It means you'll never miss a future conversation with the leaders driving data and AI forward. And if you're enjoying the show, a review on Spotify or Apple Podcasts goes a long way. And if you're a data and AI leader looking to build genuine capability across the organization, whether that's executive education, large-scale upskilling, or something more tailored, Cambridge Spark can help.

24:40Find out more at cambridgespark.com or connect with us on LinkedIn. Until next time, stay ahead, stay inspired, and stay masterful.

From the publisher

👉 Discover how Cambridge Spark helps organisations build the data and AI capabilities needed to turn strategy into measurable impact: cambridgespark.com

What does it actually take to ship machine learning inside one of the UK's largest insurers? Jeremy Bradley sits down with Alberto Romero, director of AI engineering at Aviva, to trace his path from InsurTech founder to enterprise AI leader.

Alberto explains why prototypes are so often mistaken for finished products and what production readiness really demands once edge cases, drift and adversarial behaviour enter the picture. The conversation covers how to get genuine explainability out of large language models rather than plausible-sounding justification, when fine-tuning earns its place in a regulated stack, and why Aviva built its own internal platform to govern AI use cases at scale.

Alberto also shares his take on fraud detection as an adversarial ML problem and the one failure mode he sees engineering teams repeat most often.

Follow Data & AI Mastery so you never miss an episode, and share it with a colleague working through similar production challenges.

If you enjoyed this conversation, you might also like this episode featuring Sarah Self. She joined us on Data and AI Mastery to explore what most organisations get wrong when deploying AI.

Apple: https://podcasts.apple.com/gb/podcast/from-cybersecurity-to-ai-director-sarah-self-on-leading/id1779783413?i=1000764247007

Spotify: https://open.spotify.com/episode/0BpSq5X1ZP8ctIYTxWVAJT?si=1264586e79f3446f

YouTube: https://www.youtube.com/watch?v=2jgM095SYG0

Glossary Terms

RAG: Retrieval-Augmented Generation is an AI methodology that enhances Large Language Models by pulling factual context from external knowledge bases.

GAN: Generative Adversarial Network is a deep learning architecture in which two neural networks compete against each other to create highly realistic synthetic data from a training dataset

Non-deterministic: describes a process, algorithm, or system whose outcome is inherently unpredictable and cannot be guaranteed to repeat exactly, even when it starts from the exact same initial conditions

ReAct (Reasoning + Acting) approach: a prompting technique that enables AI models to solve complex problems by alternating between thinking and taking action

Chapter Markers

(00:00) - Cold open: why prototypes get mistaken for production

(02:53) - Avoiding common AI adoption pitfalls in regulated sectors

(05:44) - Real explainability versus post-hoc justification in LLMs

(09:18) - From startup founder to enterprise: the mindset shift

(11:38) - Managing AI across 70+ use cases at Aviva

(13:31) - Standards first, technology second

(17:19) - Where fine-tuning earns its place

(20:33) - Building Aviva's own governed AI platform

(23:51) - Fraud detection as an adversarial ML problem

(28:34) - Quick fire: the most common AI failure mode

(29:37) - What deserves more attention as AI scales

Useful Links

Connect with Alberto Romero on LinkedIn: https://uk.linkedin.com/in/albertoromero-uk

For more AI insights follow Jeremy on LinkedIn: https://uk.linkedin.com/in/jeremy-bradley

Explore Cambridge Spark’s AI upskilling programmes at https://www.cambridgespark.com

More from Data & AI Mastery

All 33 episodes
No Get Out of Jail Free Card: Five Data Leaders on AI in Regulated IndustriesData & AI Mastery · 25 min
Listen in VO