The Computer Weekly survey published in April 2026 confirms what we already knew: 87% of UK IT leaders are running agentic AI systems, but only 25% have meaningful governance in place. For mid-market law firms, insurers, asset managers and accountancy practices, this is not an interesting statistic — it is a compliance time bomb. The FCA's Consumer Duty PS22/9 requires firms to act in the best interests of consumers. The SRA Code requires solicitors to maintain independence and proper supervision of outsourced legal work. The PRA's SS1/23 covers AI governance in banking. If your firm is deploying Harvey for legal research, Luminance for document review, or Microsoft Copilot for matter intake without documented ownership, audit trails, and data residency controls, you are violating these frameworks whether you know it or not. The 89% of UK respondents who say they want public regulation to enforce open-source principles are, in effect, asking for what should already exist: transparent AI supply chains and vendor lock-in prevention. We should not be waiting for regulation to force good practice.
This gap between deployment and governance reflects a deeper problem: the AI vendor ecosystem has conditioned mid-market firms to think about AI as a point solution to be bolted on, not as a controlled service subject to the same due diligence as any third-party processor. Harvey, Legora and other generalist legal AI platforms have been marketed as 'plug and play' — but there is nothing plug-and-play about handling solicitor-client privilege, client data, or insurance claim handling. The industry has confused speed of adoption with soundness of implementation. Regulatory bodies are now beginning to notice. The EU AI Act, which applies to firms with UK operations or EU clients, explicitly requires documentation of high-risk AI systems. The ICO's guidance on UK GDPR and AI makes clear that firms remain liable for data processing even when delegation occurs. Lloyd's Blueprint Two sets out explicit AI governance expectations for the insurance market. What this survey is really telling us is that most firms are operating on assumption and hope rather than architecture and accountability.
Trovix's view is straightforward: agentic AI in regulated sectors demands governance-first implementation, not governance-after-deployment. This means three things. First: you need continuous visibility of what AI systems are running, what data they touch, and how vendors are controlling it. That is why we built Trovix Watch — to track regulatory change in real time, but also to give you a baseline against which to audit your AI deployments. Second: you need AI systems built on retrieval-augmented generation (RAG) with documented data lineage, not black-box systems that learn from your confidential work. When we designed Trovix Aria, we made data residency and audit trails non-negotiable, not optional. Third: governance cannot be a separate function bolted on to AI. It has to be embedded in the tool itself. This is where many vendors fail: they build for capability first and compliance second. We inverted that.
Here is what to do on Monday morning. First, audit every AI tool in use — including Copilot instances, consumer ChatGPT, and generalist legal AI platforms. Document what data each one touches and where that data lives. Second, map that audit against your compliance obligations: FCA Consumer Duty, SRA Code, PRA SS1/23, ICO UK GDPR, and relevant ISO 42001 expectations if you are aiming for certification. Third, replace or sandbox any system that cannot give you clear answers about data ownership, processing location and audit trails. Fourth, when you evaluate new AI tools, make governance a non-negotiable RFP requirement — not a 'nice to have' appendix. Your legal, compliance and data protection teams should jointly sign off on any new deployment. The regulator will expect it. Your clients will demand it. And frankly, your firm's reputation depends on it. The 75% of firms without strong governance are about to discover that regulatory pressure moves faster than vendor roadmaps.
Source: Computer Weekly