Britain Regulated Four Clouds. Not the Models Inside.

HM Treasury designated AWS, Google Cloud, Microsoft and Oracle as critical third parties on 13 July 2026 — and no foundation-model provider. Four weeks later Moody's called bank dependence on model vendors systemic. The FCA's March 2027 register is where that gap gets closed or hidden.

By Rajesh Beri·August 10, 2026·11 min read
Share:
A printed supplier register lying open on a polished bank boardroom table under a desk lamp, four rows marked through with a highlighter and the fifth row left blank, a pen resting beside it.

Illustration generated using AI

If your bank runs a foundation model in production, the UK now supervises the building it sits in and nothing that happens inside it. On 13 July 2026 four cloud providers came under the direct oversight of the Bank of England, the PRA and the FCA. Not one AI model provider did. The dependency your board is most worried about is the one with no regulator attached to it — and no line of its own on your third-party register.

That gap has a deadline now. From 18 March 2027 every large UK bank, insurer and enhanced-regime firm has to file a register of its material third-party arrangements with the FCA. Whether the model layer appears on that register as its own entry, with its own impact tolerance and its own exit plan, or stays folded inside the cloud contract it was procured under, is a decision your team makes in the next few months. Most registers today make it by default.


What Britain Actually Designated on 13 July

The designation covers four legal entities, not four technologies. The Critical Third Parties (Designation) Regulations 2026 — made 8 July, in force 13 July — name Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited, each designated under section 312L(1) of the Financial Services and Markets Act 2000. It is one of the few times non-financial firms have been pulled inside the UK supervisory perimeter, and the regulators announced three days earlier that supervision would start that Monday.

A critical third party is a supplier whose failure could threaten UK financial stability, designated by HM Treasury on the regulators' advice. The obligations bite on a narrower thing: a systemic third-party service, which Sullivan & Cromwell's reading of the regime defines as a service whose disruption "could threaten the stability of, or confidence in, the UK financial system." Five of the six Fundamental Rules apply only to those services; the sixth — deal with regulators openly — applies across the board, per KPMG's summary of the final rules. Designated firms owe an interim self-assessment within three months, and an initial resource map plus a first incident-management playbook exercise within twelve, as techUK's explainer of the regime sets out.

Read the FCA's statement and you will not find the word "artificial intelligence" anywhere in it. The regulators describe cloud resilience. That is what they designated.

The Model Layer Was Bought Under Someone Else's Contract

Foundation models reach a UK bank through two doors, and the designation only stands next to one of them. The first door is the hyperscaler: Claude and GPT-class models arrive through Amazon Bedrock, Azure AI Foundry and Google Vertex AI, on paper as a cloud service from a now-designated entity. The second door is direct. In June 2026 OpenAI opened GPT-5.5 Cyber to Lloyds Banking Group, HSBC and Nationwide, with NatWest and Santander UK already using it under separate arrangements. Nobody in that sentence is a critical third party.

The first door is not the safe one either. A cloud provider's resilience obligations run to the services it provides. They do not make the model behind the endpoint substitutable, and they do not stop the provider retiring the AI service you built on — AWS put Q Business, Kendra and the original Bedrock Agents into maintenance mode, ending feature development and locking out new customers 30 days later, which no cloud uptime commitment covered. The infrastructure stayed up. The dependency moved anyway.

Three of the banks involved already behave as though they know this. HSBC, Lloyds and NatWest signed memoranda on 3 July to co-design Lumen Sovereign with the British startup Cosine, a model that will run without relying on US cloud infrastructure or AI providers. That hedge is aimed at both layers at once — and only one of them now has a supervisor attached to it.

Moody's Put a Name on It Four Weeks Later

The rating agency had already called the exposure systemic. Moody's Bank of the Future analysis, reported by the Guardian on 9 August, found that "the reliance of most financial firms on a relatively small set of foundation AI model and cloud computing providers risks creating a systemic dependency," because "a model outage at one major provider could potentially spread quickly across customers and sectors." Note the construction: foundation AI model and cloud computing providers, listed as two things. The designation covers one of them.

The second finding is commercial rather than operational. Moody's flagged vendor dependence — the prospect that dominant model and infrastructure suppliers come to set what AI services cost — with pressure building as loss-making generative AI companies, OpenAI and Anthropic among them, are pushed to return something to investors. Moody's expects supervisors to sharpen their focus on operational resilience and on how concentrated the AI stack has become, and puts a one-in-five chance on AI handling the work of a capable mid-level employee by 2030.

Britain's own financial-stability body got there a month earlier. The Financial Policy Committee's July 2026 Financial Stability Report, published 7 July, found that rapid advances in frontier AI capabilities "have increased financial stability risks related to cyber and operational resilience." Six days later the designations took effect without an AI provider on them.


Parliament Asked for This Explicitly. It Did Not Get It.

The gap is not an oversight; it is a sequencing decision that has been argued about in public since January. The House of Commons Treasury Committee's report on AI in financial services, published 20 January 2026, recommended in terms that "by the end of 2026, HMT must designate the major AI and cloud providers as critical third parties". July delivered the cloud half. On the day the regime went live, the Committee's chair, Dame Meg Hillier, welcomed the move and added that "as the use of AI in financial services expands, I believe there may come a time when the government needs to consider designating specific AI firms under the Critical Third Parties Regime". May come a time is not a designation.

One day after the regime took effect, HM Treasury published its Financial Services AI Adoption Plan on 14 July. Recommendation 4, rated high priority, asks government and regulators to "assess critical AI and cloud providers under the Critical Third Parties (CTP) regime, and where appropriate government should designate CTPs, to ensure systemic risks are identified, monitored, and mitigated as adoption scales." The same document warns that "dependence on a highly concentrated cluster of global tech providers (e.g. cloud and model hosts) introduces significant long-term concerns about operational resilience, data security, and concentration risk." Recommendation 6, rated medium, proposes a voluntary industry-led AI third-party assurance framework so that "regulators may accept these assurance certificates as evidence of baseline due diligence."

Read that as a schedule, not a gap. Assessment first, designation later, assurance certificates in between — and every month of that sequence is a month in which the model dependency is yours alone to document.

Europe is not ahead. The European Supervisory Authorities designated 19 critical ICT third-party providers under DORA on 18 November 2025, using criteria that include substitutability and concentration of reliance. The list is cloud, data centres, network and financial-market technology. Same perimeter, larger.

Your Register Is Where This Actually Gets Decided

The most consequential document here is not a designation notice — it is the spreadsheet your third-party risk team files next year. FCA PS26/2 and PRA PS7/26, both published 18 March 2026, come into force 18 March 2027. Firms must notify the regulator of every new material third-party arrangement and every significant change to one, and maintain a register submitted annually.

Two details in that regime decide whether the model layer is visible.

Subcontractors are in scope. A material third-party arrangement covers "any service or product provided to a firm (including intra-group and subcontracted services)". A model consumed through a hyperscaler is a subcontracted dependency, and nothing in the rules lets you stop describing your supply chain at the invoice.

The register asks for the fields that force the argument. Per TLT's breakdown, it captures provider name and LEI, service type, notice periods and governing law, impact tolerances, data locations, annual contract value, and due-diligence and governance outcomes. You cannot fill in a notice period for "the model" if the model is an implementation detail of a cloud line item. That is the test — and if the answer is that no one can name the notice period, the exposure was never assessed.

The taxonomy fights you. DORA's register of information offers 19 types of ICT service in Annex III — from ICT development and data analysis through the three cloud tiers. None of them is AI, machine learning or model provision. A European bank registering a frontier-model API today files it as data analysis or SaaS. The instrument regulators use to see concentration has no field for the concentration everyone is warning about.

The Case for Leaving It Alone

The strongest counter-argument is that models are the most substitutable thing in the stack, and treating them as a critical dependency inverts the risk. Satya Nadella has made this case directly: the durable assets are data, workflow and distribution, and the model is a commodity you swap. Moody's partly agrees — banks retain leverage through proprietary data, long experience negotiating down technology contracts and the option of open-weight models. If a prompt and an eval suite move between vendors in a fortnight, a formal exit plan for a model provider is compliance theatre.

It holds right up to the point where you test it. Swapping frontier models is cheap on a chat endpoint and expensive on an agentic workflow with tuned prompts, tool schemas, cached context and a validated eval baseline — the switching cost lives in the scaffolding, not the weights. And the substitutability argument is an argument about your firm. Systemic risk is about correlation: every UK bank hedging to the same second vendor is not diversification. That is the point of a supervisory perimeter, and the reason a firm-level "we could switch" answer does not close the question a regulator is asking.

There is also a nearer-term case. Availability is not the only failure mode. A vendor can raise prices — the reason DeepSeek's coming increase resets the ceiling for everyone — or change a model under a stable endpoint, or withdraw a service. None of those is an outage, none triggers a resilience clause written for infrastructure, and all of them break a production workflow.

What to Do Before the March 2027 Register

This Week: Pull your third-party register and answer one question — does any foundation-model dependency appear as its own row? Not the cloud account it is billed through. If not, list every production workflow that calls a model, name the provider behind each endpoint, and mark whether the contract is direct or via a hyperscaler. That list is the whole diagnosis, and it usually takes an afternoon.

This Month: Assign each model dependency an impact tolerance in the same units your operational resilience work already uses — maximum tolerable outage for the important business service it supports. Then get a written answer from procurement on the two fields the 2027 register will demand: notice period and change-of-terms rights on the model, not the platform. Where the model came through a cloud contract, ask the account team in writing whether the model provider is named as a subcontractor and what notice you get if that changes. Regulated firms in other sectors are discovering the same hole — fewer than half of health systems have a sandbox to test vendor AI before it touches patients.

Before Renewal: Run one substitution rehearsal on a real workflow, not a demo — swap the primary model, re-run the eval suite, and record elapsed time and failure count. That number is your actual exit plan; everything else is an assertion. Score the resulting concentration the way you would any other supplier (a repeatable rubric beats a debate), and price the hedge honestly — the 19-day vendor blackout that hit enterprise AI users in June is the scenario your tolerance has to survive.

The Bottom Line

Perimeters always lag the thing they are meant to contain. Cloud took roughly fifteen years to move from outsourcing guidance to direct supervision; the model layer is three years old and already carries the correlation that made cloud worth designating. HM Treasury's own adoption plan says the assessment is coming and the Treasury Committee has asked for it by December. Between now and then, the only entity that can register your model dependency as a critical service is you.

The four names on the designation list are the ones the state has decided to watch. The name on your model contract is the one you have to watch yourself — and right now, on most registers, it isn't written down anywhere.

Continue Reading

Share:

Frequently Asked Questions

Which companies did the UK designate as critical third parties in July 2026?

The Critical Third Parties (Designation) Regulations 2026 designated four entities with effect from 13 July 2026: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited. They are now under the direct oversight of the Bank of England, the PRA and the FCA. No AI or foundation-model provider was designated.

Are OpenAI and Anthropic regulated as critical third parties in the UK?

No. Neither is designated. The Treasury Committee recommended in January 2026 that HM Treasury designate the major AI and cloud providers by the end of 2026, and HM Treasury's Financial Services AI Adoption Plan of 14 July 2026 asks regulators to assess critical AI and cloud providers under the regime. Assessment is not designation, and no AI provider is currently in scope.

Does my cloud provider's critical third party designation cover the AI models I run on it?

Not directly. The obligations attach to the systemic services the designated entity provides. They do not make the underlying model substitutable, do not stop the provider retiring an AI service, and do not cover a model bought direct from its developer. Treat the model layer as a separate dependency.

When does the UK material third party arrangements register take effect?

FCA PS26/2 and PRA PS7/26 were published on 18 March 2026 and come into force on 18 March 2027. In-scope firms must notify the regulator of new material third party arrangements and significant changes, and maintain a register submitted annually. The definition covers intra-group and subcontracted services, so a model consumed through a hyperscaler is in scope.

How should a bank record a foundation model in its DORA register of information?

There is no clean answer. Annex III of the DORA implementing regulation lists 19 types of ICT service — including ICT development, data analysis and the three cloud tiers — and none of them is AI, machine learning or model provision. Firms currently file frontier-model APIs under data analysis or SaaS, which is why model concentration is hard to see in the aggregate data.

Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe