Slow AI approvals usually reveal weak triage, not excessive governance.
When every use case enters the same queue and receives the same evidence demands, risk assessment becomes a roadblock by design.
The 30-second take
AI risk assessment should answer three practical questions: what decision is changing, how serious could the impact be and what evidence is needed before proceeding?
Those answers should determine the review path, decision authority and monitoring.
Fast governance is disciplined governance. Low-impact uses move through a controlled fast lane, while uncertain or high-impact uses receive stronger testing, independent challenge and senior approval.
FCA is testing AI in live business settings
On 21 April 2026, the UK’s Financial Conduct Authority announced the second AI Live Testing cohort. Eight firms, including Barclays, Experian, Lloyds Banking Group’s Scottish Widows and UBS, are testing customer-facing and business-to-business applications.
The use cases cover targeted investment support, credit insights, agentic payments, anti-money-laundering detection and know-your-customer activity. The firms are working with the FCA and technical partner Advai on evaluation, risk management and live monitoring, with an evaluation report planned for the first quarter of 2027.
The lesson is not that every organisation needs a regulatory programme. It is that bounded deployment can produce better evidence than an extended paper review. Clear limits, measurable outcomes, human intervention and stop criteria allow teams to learn while containing exposure.
Controlled experimentation is operating at scale
The FCA’s second Supercharged Sandbox cohort launched on 13 July 2026. It selected 21 organisations from 199 applications to develop and test AI-enabled propositions in a secure environment with infrastructure, datasets and expert support.
Participants are exploring fraud detection, safer agent-led payments, AI governance, support for vulnerable consumers and compliance automation. The FCA expressly says participation is not approval or endorsement. That distinction matters internally too: permission to test is not approval for unrestricted deployment.
A controlled environment, approved data, named decision rights and evidence captured during testing can provide a safer route to value than either uncontrolled experimentation or indefinite delay.
NIST makes proportionality practical
The NIST AI Risk Management Framework Playbook is organised around Govern, Map, Measure and Manage. NIST describes it as voluntary and tailorable, allowing organisations to select practices that fit their context rather than treating every use case identically.
A workable model creates three paths. Low-impact internal productivity tools use approved platforms, prohibited-data rules and accountable human review. Medium-impact uses require a defined evidence pack and conditional approval. High-impact or uncertain uses attract enhanced validation, independent challenge and staged testing.
Cycle time should be measured by stage. Teams often wait because the owner is missing, evidence is requested twice, reviewers work sequentially or a decision forum lacks authority. Fixing those handoffs can reduce delay without weakening the assessment.
Questions to test your AI assessment process
- Can teams determine the likely review path before investing heavily in an AI use case?
- Are impact, uncertainty and reversibility used to set evidence requirements and decision authority?
- Can approved platform, vendor, privacy and security evidence be reused without repeating the same review?
- Does each assessment end with a recorded go, conditional go, pause or stop decision?
- Do cycle time, rework, incidents and post-deployment outcomes feed back into the triage model?
Make governance part of delivery
If risk assessment begins only after a solution has been selected, delay and conflict are predictable. Visit the Innovation of Risk AI Tools to test where your AI assessment process can become faster, clearer and more proportionate.

