Nikhil Rathi's admission that traditional rulemaking cannot match the pace of AI change is not a regulatory apology—it is a warning that the compliance rulebook mid-market firms rely on is already incomplete. The FCA Consumer Duty PS22/9, PRA SS1/23, and SRA Code will not be rewritten in time to address the specific risks your firm faces when deploying agentic systems, RAG-based assistants, or document automation tools. Christine Lagarde's point is sharper: the means of defense have not yet been found. This is not hyperbole. It describes the exact situation facing a law firm deciding whether to use Harvey or Legora for legal research, an insurer evaluating claims AI systems, or an accountancy practice implementing document extraction. Regulatory uncertainty is not temporary. It is the new operating environment.
This admission reveals a structural problem in how AI governance happens. Regulators move through consultation, impact assessment, and implementation—months or years of work. AI products move through dev, beta, and production—weeks. The EU AI Act creates a framework, but it still classifies risk by hazard category, not by deployment context. The ICO's GDPR guidance on AI is sensible but does not tell you whether your specific implementation of Luminance or Microsoft Copilot creates acceptable model drift or hallucination risk in your particular workflow. ISO 42001 compliance helps, but it is a control standard, not a risk standard. The gap between what regulators can certify and what firms must decide sits precisely where mid-market firms are making deployment choices today.
Here is what Trovix believes this actually means. First: any firm telling you that using a general-purpose AI tool (whether ChatGPT-based, Claude-based, or built on open models) in a regulated role is 'safe because regulators haven't banned it' is wrong. Absence of prohibition is not permission. Second: the firms winning this period are not those waiting for rules to clarify. They are those implementing AI with explicit audit trails, documented decision-making about model choice and data handling, and regular reassessment of outputs against actual outcomes. This is not about finding the 'best' AI product. It is about building accountability into how you use any product. Third: tools like Trovix Watch that monitor regulatory change matter more now, not because regulation will catch up, but because your firm needs to know the moment new guidance lands—and you need documentation that you acted on it. The firms deploying Trovix Sift or Trovix Aria with clear data governance and output validation are building defensible positions. The firms deploying the same AI tools without that discipline are building liability.
If your practice is mid-market—50 to 300 fee-earners—you are in the highest-pressure group right now. You have revenue need pushing you toward AI adoption. You do not have in-house AI governance teams or legal counsel dedicated to AI risk. You cannot wait for the FCA or ICO to tell you how to proceed. What you should do immediately: audit every AI tool already in use (including the free ChatGPT instances your team members are using) and document what data it touches and what decisions it affects. For new tools, require a written specification of how you will validate outputs before they reach client work or regulatory reporting. Trovix Brief for intake, Trovix Sift for document work, and Trovix Aria for knowledge work are built with that validation principle embedded. They are not 'safer' because they have more guardrails than competitors—they are designed so that you, not the vendor, remain the decision-maker about risk. That is what accountability means when regulators have admitted they cannot govern at the speed of the technology.
Source: CNBC