On 22 July 2026, the Financial Conduct Authority announced that Anthropic will support the second cohort of its Supercharged Sandbox, the controlled environment in which firms experiment with advanced AI.1 Anthropic provides participants with access to Claude, including Claude Code and Claude Cowork, to accelerate development work.2 Twenty-one organisations join the cohort, among them Scottish Widows, Money Advice Trust and TrueLayer, selected from 199 applications, a 51% increase on the first cohort's 132.3 The cohort launched on 13 July 2026 and runs to 31 December 2026, with a showcase demonstration day on 26 November 2026. The programme builds on the Digital Sandbox infrastructure provided by NayaOne and the accelerated computing and NVIDIA AI Enterprise software made available since the first cohort.4 Alongside the announcement, the FCA launched the Agentic Academy, a ten-week specialist AI programme delivered with the Centre for Finance, Technology and Entrepreneurship.5
“The high level of interest in the Supercharged Sandbox demonstrates the demand for trusted environments where firms can experiment safely and responsibly” — Jessica Rusu, Chief Data, Intelligence and Information Officer, FCA, 22 July 2026
Anthropic joins NayaOne and NVIDIA in supporting the second cohort of the FCA's Supercharged Sandbox, giving 21 selected organisations access to Claude, Claude Code and Claude Cowork through a programme running to 31 December 2026. The legal position is precise: the sandbox is infrastructure, not dispensation. Participation confers no approval, endorsement or authorisation, and every AI system built inside it answers to the existing rulebook, the Consumer Duty and the Senior Managers and Certification Regime foremost, because the FCA will not write new rules for AI.
The machinery: what the sandbox is and is not
The Supercharged Sandbox is a cohort-based experimentation programme. Participants operate in a secure cloud environment with five integrated capabilities: GPU-enabled compute for large-scale workloads; enterprise AI tooling across the full model lifecycle; synthetic and curated datasets reflecting real financial services scenarios; mentorship from experts across financial services, AI and regulation; and the end-of-programme showcase before industry, regulatory and technology stakeholders.6 Participation is free. FCA authorisation is not a condition of entry, and international firms may apply where the solution is relevant to UK financial services. Firms may bring their own data and models, subject to the sandbox terms of use.
What the sandbox is not requires equal precision, and the FCA supplies it in terms: “Participation in the Supercharged Sandbox does not indicate FCA approval, endorsement, or authorisation of a product or service.” This is the sentence every participant's general counsel must internalise. The Supercharged Sandbox is not the regulatory sandbox; it modifies no rule, waives no requirement and moves no perimeter. A regulated participant remains bound by every applicable obligation. An unregulated participant acquires no permission it did not hold before, and a solution that would require authorisation to deploy in live markets still requires it the day the cohort ends. The sandbox supplies compute, data, tooling and proximity to the regulator. It supplies nothing else.
The cohort and its five use-case streams
The second cohort's work falls into five streams: enabling safer agent-led payments and commerce; detecting fraud and economic crime more effectively; strengthening AI governance and accountability; widening access to financial services for vulnerable and underserved consumers; and streamlining compliance and business automation.7 The composition matches the streams: an established life and pensions brand, a debt-advice charity, an open banking infrastructure provider, and a bench of specialist firms spanning fraud analytics, agentic systems, compliance automation and financial wellbeing.3 The first stream is the consequential one. Agent-led payments place an autonomous system inside the payment initiation chain, and a UK regulator is now hosting that experiment on its own infrastructure. The supervisory question it forces is the question of the decade: when an agent moves money, whose mandate authorised it, and which accountable human answers for the boundary. Singapore's MAS published its industry framework for exactly this problem on 3 July; the FCA is running the laboratory version. Agentic finance is now a supervisory programme on two continents in the same month.
The governing law: the rulebook that already exists
The legal frame for everything built in the sandbox is settled, and the FCA has published it. Its approach to AI is principles-based and outcomes-focused, and the position on new rules is categorical: the FCA does not plan to introduce extra regulations for AI and will rely on existing frameworks.8 The commitment is repeated at the level of government relations in the FCA's letter to the Prime Minister on supporting growth.9 The 2024 AI Update is the interpretive key, and it names the two load-bearing frameworks. The Consumer Duty requires products and services that meet the needs of their target customers, communications that meet customers' information needs, and support that meets customers' needs; an AI system that generates a communication, a decision or a support interaction is measured against those outcomes without any AI-specific gloss.10 The Senior Managers and Certification Regime supplies the accountability: a named senior manager owns each area of a firm's business, and the deployment of an AI system within that area is that individual's responsibility.11
The doctrine's consequence is that technology-neutral means liability-neutral. There is no AI defence and no AI discount. A hallucinated disclosure is a misleading communication. A discriminatory model output is a failure to deliver good outcomes for a customer cohort. An agent that exceeds its payment mandate is a failure of systems and controls, and the senior manager who owns payments answers for it under the same standard that governs a human employee exceeding authority. The absence of AI-specific rules does not thin the law; it routes AI conduct through rules with a decade of enforcement architecture behind them. Firms that read “no new regulations” as regulatory lightness have misread the doctrine. It is the opposite: immediate, full application of the existing rulebook, with no transition period, because nothing new needs to commence.
The sandbox is also an intelligence instrument, and participants should price that in. The FCA states that the programme generates insights that inform future regulatory thinking. Every use case tested, every failure mode observed and every governance pattern demonstrated inside the sandbox becomes supervisory knowledge. That is a fair exchange, and firms should make it with open eyes: the sandbox terms of use govern data, models and confidentiality, and they are the contract that matters. Counsel should review them with the same rigour applied to any technology agreement under which a counterparty, here the regulator's platform, hosts the firm's intellectual property and observes its performance.
Assessment
First, the UK has chosen supervision-by-participation over legislation. Where the European Union codified AI obligations in horizontal legislation, the FCA embeds itself in the development process: it provides the environment, watches the experiments and reserves the rulebook it already has. The regulator learns inside the sandbox what others learn through rulemaking consultations, and it learns it earlier, on real systems. The 51% application increase demonstrates that the market has accepted the bargain.
Second, the existing-frameworks doctrine concentrates AI risk on individuals. SM&CR converts every AI deployment into a named person's accountability, and the Consumer Duty converts every model output touching a retail customer into an outcomes obligation. The two frameworks were built for human misconduct and organisational failure; they now govern machine behaviour without amendment. The practical bar for AI governance in UK financial services is therefore set by the statement of responsibilities and the outcomes evidence file, not by any future AI statute.
Third, the vendor layer has become supervisory infrastructure. NayaOne provides the platform, NVIDIA the compute, and Anthropic the frontier models through which the cohort builds. A regulator selecting and integrating commercial AI capability into its own innovation apparatus is itself a regulatory signal: the FCA is not evaluating AI from the outside; it is provisioning it. Firms selecting model providers for regulated use cases will read the composition of the sandbox's support bench accordingly, and should still apply their own outsourcing and operational resilience analysis to any provider, because the sandbox endorses nothing.
What firms should do
Firms in the cohort should treat the programme as a supervised dress rehearsal: build the governance file alongside the prototype, because the evidence that persuades at the showcase on 26 November is the evidence that survives an SM&CR conversation later. Firms outside the cohort should note the cadence, two cohorts inside thirteen months, and prepare for the third: the published assessment criteria reward a defined use case, a realistic testing plan and a credible pathway to deployment. Every firm deploying AI in UK financial services, sandbox or not, should map each AI system to its accountable senior manager, test its outputs against the Consumer Duty's outcomes, and document both, because the FCA's doctrine makes that file the entire compliance position. Digital asset firms should watch the agent-led payments stream specifically: the mandate-and-accountability patterns proven there will set the supervisory expectations for agent-operated wallets and settlement flows under the incoming cryptoasset regime.
Notes
1. FCA press release, Anthropic to support FCA's Supercharged Sandbox, 22 July 2026. The Supercharged Sandbox, announced in 2025, is a cohort-based programme for firms in the discovery and experimentation phase of AI: a secure cloud environment for developing and testing AI use cases. It is distinct from the FCA's regulatory sandbox, which permits live-market testing with real consumers under regulatory controls; the Supercharged Sandbox involves no live market activity and no regulatory modification.
2. Anthropic is the AI safety company behind the Claude family of models. Claude Code is its agentic coding tool, permitting developers to delegate software engineering tasks; Claude Cowork is its agentic knowledge-work application. Access to frontier models and agentic tooling addresses the sandbox's development-velocity constraint: cohort periods run under six months, and build speed determines what can be evidenced by the showcase.
3. The full second cohort: Aegis Trace; Blackdot Solutions; CareLayer; calQrisk; Condukt; Deepflow; FSCom; GAI Labs; IntelXview Ltd; Kaption; Merx Digital Solutions Ltd (SmartDrops); Money Advice Trust; Relace; RMI Agentic; Sardine AI Corp; Scottish Widows; TrueLayer; Trustie Labs; Ubyx, partnering with Amazon; Welleness; Zquas. Applications ran 5 May to 1 June 2026; outcomes were notified on 26 June 2026. The 199 applications compare with 132 for the first cohort (September 2025 to January 2026, 22 firms selected).
4. The Supercharged Sandbox runs on the Digital Sandbox infrastructure provided by NayaOne, a technology platform supplying the secure environment, synthetic datasets and tooling. NVIDIA's collaboration gives participants accelerated computing infrastructure and NVIDIA AI Enterprise software, continued for the second cohort. The support bench is therefore three-layered: platform (NayaOne), compute (NVIDIA), models and agentic tooling (Anthropic).
5. The Agentic Academy is a ten-week specialist AI programme for selected firms, delivered by the FCA with the Centre for Finance, Technology and Entrepreneurship (CFTE), a financial education institution. Its subject matter, agentic AI, confirms that the FCA treats autonomous-agent deployment as a distinct supervisory competence requiring dedicated capability building on both sides of the regulatory relationship.
6. The five assessment criteria for entry are published: relevance and strategic fit to UK financial services; degree of innovation, with AI playing a substantive role; feasibility and readiness within the cohort timeframe; potential impact for consumers, firms or markets with a credible pathway to deployment; and demonstrated need for the sandbox environment rather than general innovation support.
7. The first cohort's use cases anticipated the second's: personalised financial guidance to close the advice gap, identification and support of consumers in vulnerable circumstances, financial inclusion, and machine learning and agentic systems against financial crime. The persistence of the vulnerability and inclusion streams across both cohorts marks them as standing FCA priorities, not cohort themes.
8. FCA, AI and the FCA: our approach: “We do not plan to introduce extra regulations for AI. Instead, we'll rely on existing frameworks, which mitigate many of the risks associated with AI.” The approach is principles-based and outcomes-focused, giving firms flexibility to adapt to technological change rather than detailed prescriptive rules.
9. FCA letter on a new approach to ensure regulators and regulation support growth (2025), the FCA's response to the Prime Minister's growth correspondence, committing among other measures to avoid additional AI regulation by relying on existing frameworks. The sandbox is expressly framed as delivery of the growth commitment: Ms Rusu's statement ties the programme to “maintaining the UK's position at the forefront of responsible AI adoption and innovation.”
10. The Consumer Duty (PRIN 12 and PRIN 2A of the FCA Handbook) requires firms to act to deliver good outcomes for retail customers across four outcomes: products and services, price and value, consumer understanding and consumer support. Applied to AI, the Duty attaches to the output, not the mechanism: the firm answers for what the system delivered to the customer.
11. The Senior Managers and Certification Regime allocates every area of a firm's regulated business to a named senior management function holder through statements of responsibilities, with a statutory duty of responsibility: where a firm breaches a requirement in a senior manager's area, the manager is accountable unless they took reasonable steps to prevent it. An AI system operating in an SMF's area is, for accountability purposes, part of that area.




