A statistic everyone repeats, that nobody can find

Blog

September 2026

Tall grasses and seed heads silhouetted against an ember and rose dusk sky

We were building a piece about automated decisions in regulated industries, and we wanted one particular fact in it. The claim is everywhere: that a financial regulator reviewed AI-driven lending refusals and found that in more than half of cases, the firm could not give a human-understandable reason for the decision.

It is a good fact. Vivid, specific, and it supports an argument we happen to agree with.

We could not find it. We now think it does not exist.

What the trail actually looks like

  1. The closest real source says something weaker. The Financial Conduct Authority speech that surfaces is Sheldon Mills, 28 January 2026, on AI in retail financial services. It contains a genuine line: that it can be hard to explain to a consumer, or to the regulator itself, why a particular decision was made where models rely on complex data and proxies. That is a qualitative observation in a speech. It is not a review and it carries no statistic.
  2. A second version was invented in transit. A search result told us confidently that a US consumer regulator had found over 60% of AI credit decisions lacked explainable reasoning, and attributed it to a named vendor page. We opened the page. The claim is not on it. The only figure there is a survey of what institutions say they are worried about.
  3. A third number is real, but has had its meaning changed. A vendor survey of 230 US banking professionals found 72% named either model kill-switches or regulatory reporting of AI failures as the area their bank was least prepared in. That is a self-assessment of relative preparedness. It now circulates as a finding that 72% of banks lack kill switches, which is a different and much stronger claim.
  4. The regulator's actual evidence is not published yet. The FCA's AI Live Testing programme began its second cohort in April 2026, and its evaluation report is due in the first quarter of 2027. Guidance on audit trails and explainability is expected at the end of 2026.

So the position is this. A finding that everybody believes already exists is scheduled to be produced about a year from now.

Two hands lightly clasped, close, against a soft warm background

Why compliance content is unusually exposed to this

Compliance writing has a structural weakness: almost nobody in the audience can check anything.

The reader has a deadline, not a research question

They are a provider with a registration date, not an analyst. The claim sounds plausible, it is attributed to a regulator, and checking it means locating the primary instrument and reading it. Nobody does that at 9pm.

Every repetition looks like more evidence

The tenth blog to carry a number looks better sourced than the first, because by then it appears everywhere. Volume reads as verification. It is the opposite.

And the incentives all point the same way

A vivid statistic makes a stronger post than an honest gap. Nothing in the market rewards the person who checks and finds nothing.

That is the disease this whole discipline is meant to treat, and the sector's own content is a carrier.

The ladder we use instead

Every fact we publish carries a grade, and the grade is printed rather than implied.

  • V, verified. Checked against the instrument itself or the regulator's own page, with the date it was checked. A clause number, a commencement date, a published report.
  • C, corroborated. Two or more genuinely independent sources. Solid enough to build on, not solid enough to lead on.
  • T, single secondary source. A lead. It tells you where to go looking. It is not yet a fact.

Two rules make the ladder work.

Primary beats secondary, always. A consultant's summary can alert us and can corroborate. Only the instrument or the regulator can verify.

A fact can climb down as well as up. When a compilation moves clause numbers, every affected V reverts to T until somebody re-checks it. A grade is a claim about when it was last looked at, not a permanent badge.

The rule that does the most work is the least comfortable one. Ten consultants saying the same thing is still C. Repetition is not evidence. It is one claim, arriving more times.

An aerial view of long ridgelines receding to a pale dawn horizon
Two people talking at home, one using a wheelchair, seen from behind

What we did with the piece

We ran it without the statistic. The argument did not need it: the EU deferred its high-risk AI rules to December 2027, Colorado repealed and replaced its AI Act, and Australia shelved its mandatory guardrails. All verifiable, all dated, and considerably more interesting than one contested percentage.

The missing fact turned out to be the better story. A sector that cannot check its own claims is a sector where a number can be born inside a search summary, attributed to a page that does not contain it, and repeated until it becomes common knowledge.

If you take one thing from this section, take the habit rather than the facts. When you read a compliance claim with a number in it, go and find the instrument. It takes about four minutes, and roughly one time in five it will not be there.

Sources. FCA, "The FCA's long term review into AI and retail financial services", Sheldon Mills, 28 January 2026 (`V`, and it contains no such statistic). FCA AI Live Testing, feedback statement FS25/5, second cohort from April 2026, evaluation due Q1 2027 (`V`). Wolters Kluwer US Banking AI Risk and Governance Index H1 2026, n=230 (`V` as to the figure, and note the widespread misstatement of it). The vendor page carrying the attributed "60%" claim was opened and does not contain it (`V`, negative finding).

Otherblogs

We’ll show you a certification done in ten hours.

You decide whether it holds up.

Rise © 2026