The regulatory phase most agencies have been operating in just ended.
For the better part of two years, the FCA’s message to the finance sector was rhetorical: speeches, consultations, statements of concern. We’re watching. We’re concerned. We’ll be consulting.
In the last two weeks, that message changed.
On July 30, the FCA set a trial date for an individual charged with promoting FX CFDs on social media without authorisation. On August 7, it sent information requests to roughly 900 firms and said it would scrutinise their registrations “closely” — adding that applications “should expect to take longer.” Underneath both sits the FCA’s newly explicit position on AI: “Accountability for regulated activities and outcomes must remain clear.”
The FCA isn’t warning anymore. It’s collecting data, scrutinising registrations, and prosecuting people.
If you run PPC for forex, crypto, iGaming, prop firms, or any other regulated client, here’s the only question that matters now: when the FCA traces a promotion back to your agency, can you prove what happened — who touched it, when, and under what sign-off — in 90 seconds?
The Enforcement Escalation: Three Signals in a Fortnight
None of these events is subtle. Stacked together, they’re a pattern.
Signal 1 — July 30: a trial date for illegal financial promotions. The FCA announced a trial date for an individual charged with promoting FX CFDs on social media without FCA authorisation, contrary to sections 21 and 25 of the Financial Services and Markets Act 2000. This isn’t a consultation paper or a speech. It’s a crown court prosecution for the exact activity finance agencies do every day: running financial promotions on social media.
Signal 2 — August 7: information requests to ~900 firms. The FCA published a statement on Annex 1 firms — unregulated lenders, safe custody providers, money brokers, and financial leasing companies that must register with the FCA for anti-money-laundering purposes but aren’t FCA-authorised. The FCA’s concern is blunt: “the potential for them to facilitate financial crime.” It has watched firms “rely too heavily on the financial crime controls of their parent company.” And its response is operational, not rhetorical: it is “closely scrutinising applications to register,” registration applications “should expect to take longer,” and it has sent an information request to around 900 Annex 1 firms. Combined with work done with 300 firms in late 2025, that is every registered Annex 1 firm in the UK — contacted.
Signal 3 — the accountability mandate. On June 24, FCA Chief Executive Nikhil Rathi told a techUK audience that “legislation will never keep up” with AI and that 80%+ of financial services firms are already adopting it. His conclusion: “Accountability for regulated activities and outcomes must remain clear.” The speech predates July and August, but it’s the lens through which everything since makes sense. The FCA can’t write AI rules fast enough, so it’s enforcing the rules that already exist — and demanding that firms prove they followed them.
This Isn’t Three Events. It’s One Apparatus.
Read separately, these look like three different stories: a prosecution, an AML registration crackdown, and a speech about AI. Read together, they’re one thing.
The FCA has industrialised enforcement. The sequence is visible: warn, collect data, scrutinise, prosecute.
The Rathi speech was the warning. The ~900 information requests are the data collection. The Annex 1 registration scrutiny is the tightening. The trial date is the endpoint.
And the common denominator across all four stages is the same demand: proof. The FCA isn’t asking firms what they intended to do. It’s asking them to demonstrate — with records, timestamps, and attributable decisions — what actually happened.
For a PPC agency, that’s a specific and uncomfortable question. When the FCA looks at a financial promotion your agency ran, it doesn’t ask how the campaign performed. It asks who created it, who approved it, when it went live, when it changed, and what disclaimers ran alongside it. Then it asks you to prove all of it.
The ~900 information requests are the template. The FCA asked Annex 1 firms about their activities, their business models, and their risks. When it comes for a promotion — or for the agency that ran it — the questions follow the same shape. What did you do? Who authorised it? Can you show me?
Why Generic Platforms Can’t Produce Any of It
Here’s the uncomfortable reality of the current PPC tool landscape: almost nothing agencies use today was built to answer that question.
Data connectors (Windsor.ai’s Claude-connector blitz is the cleanest example) are built to move data from a source to an AI assistant. They can tell Claude what your campaign spent. They cannot tell a regulator who changed the campaign, when, with what approval, or under which jurisdiction’s rules. A Claude chat log is not compliance evidence.
Dashboards and reporting tools (AgencyAnalytics and the rest) produce beautiful client-facing reports. They show performance. They don’t show attribution, approval chains, or immutable change history. A PDF of yesterday’s ROAS is not evidence of who authorised last month’s ad copy.
Compliance-adjacent platforms (Synter’s 222 blog posts, zero finance content; Whatagraph’s “AI agents — coming soon”) are closer in ambition but structurally identical in outcome: they track what happened to campaigns, not who made it happen, when, with what authorisation, and under which regulatory framework.
That distinction — outcomes versus accountability — is the entire regulated vertical. And it’s why the FCA’s enforcement escalation lands so hard. When the FCA asks “prove it,” a platform that tracks performance is answering a question nobody asked.
The 90-Second Answer
Ott was built the other way around. The compliance infrastructure isn’t a feature bolted onto a reporting tool — it’s the architecture everything else sits on. Here’s what that means when the FCA comes asking.
Activity Logging — the immutable record. Every change to every campaign is logged with the actor who made it, the exact timestamp, and the before/after values. The log can’t be edited or deleted. That’s the difference between a change log and an audit trail: a change log records what happened; an audit trail is admissible as evidence. When the FCA asks who changed the targeting on an FX CFD campaign in March, you have the answer — attributed, timestamped, unalterable.
Agency Hierarchy — jurisdiction-aware accountability. Your clients, brands, and ad accounts are organised in a three-level structure with jurisdiction tags (FCA, MiCA, ESMA, Alberta). Every log entry inherits that jurisdiction context. When the FCA asks about UK promotions specifically, you filter by jurisdiction instead of hand-sorting a year of spreadsheets. Accountability is mapped to the regulatory framework, not to a folder structure.
Campaign Triage — catching the problem before the FCA does. Triage sweeps every brand every morning and flags anomalies — no-spend, CPM spikes, CTR drops, changes that shouldn’t have gone live. The worst time to discover a missing risk disclaimer is when the FCA is already holding it up in an investigation. Triage finds it while it’s still a Monday-morning fix.
Operations MCP — compliance context, not just ad data. Twenty-six compliance-aware tools that answer questions generalist MCPs can’t: “show me every promotion modified in the last 48 hours targeting UK audiences with FX CFD copy and no risk disclaimer.” A data connector can read your ad spend. Only a compliance-aware operations layer can read your regulatory exposure.
The export itself. FCA requests documentation for every FX CFD promotion your agency ran between January and July. You open Activity Logging, filter by jurisdiction, client vertical, and date range, and export. A timestamped, actor-attributed, jurisdiction-tagged record of everything — typically in 60 to 90 seconds. Included in flat pricing ($29–$199/mo). No per-audit fee. No credit consumption. No “compliance add-on” you forgot to buy.
The alternative — the way most agencies would answer that request today — is a two-day fire drill through Meta Ads Manager screenshots, Slack approvals, Google Drive spreadsheets, and email chains. It produces evidence no regulator would accept as immutable, and it takes two days instead of 90 seconds.
Can You Answer These Three Questions?
Forget platform features for a second. Here’s the self-assessment — three questions to ask the tool you’re running regulated campaigns through right now:
- Can it produce an immutable, timestamped, actor-attributed record of every change to every financial promotion you’ve ever run?
- Can it organise that record by jurisdiction — FCA, MiCA, ESMA, or whichever regulator comes calling?
- Can it export that record, regulator-ready, in under two minutes?
If the answer to any of these is no, you’re running the FCA’s enforcement escalation on a platform that was never built to answer it.
The warning phase is over. The FCA is collecting data from ~900 firms, scrutinising registrations, and prosecuting people who promoted financial products illegally. Every one of those enforcement threads ends in the same place: someone being asked to prove what happened.
The only question that matters for your agency is whether you can — in 90 seconds.
See how Ott’s audit trail works → or Start your free trial →