The FCA's July 2026 position is unambiguous: it wants expanded regulatory perimeter, tighter oversight of autonomous AI decision-making, and a public-interest AI guidance service. What this means for mid-market financial services, insurance and legal firms is equally clear — the days of deploying a Microsoft Copilot instance or a generic LLM for client advice without documented governance are numbered. The regulator has spotted that British consumers are increasingly asking chatbots for financial guidance, seen the accuracy and liability risks that creates, and decided the current rulebook cannot hold. Consumer Duty PS22/9 already demands firms know what their tools do and why. The FCA's new stance makes it explicit: generic AI is not 'knowing'. It is gambling.
This is part of a wider pattern now visible across UK regulated sectors. The SRA, ICO and FCA are all moving in the same direction — from tolerating AI experimentation to demanding auditable, boundary-aware implementation. The EU AI Act's escalating compliance model is influencing UK thinking even outside its jurisdiction. At the same time, consumer harm is accumulating: people are getting bad financial advice from bots trained on internet data, not regulatory guidance. Firms cannot hide behind 'the AI told them' anymore. When rules tighten, liability flows back to the firm that deployed it. The FCA's signal is that tightening is coming fast.
Here is Trovix's honest take: most of the AI tools in use today by mid-market firms — including popular platforms like Harvey and Legora — are purpose-built for document review and pattern matching. They excel at that. But they are not designed for regulated advice generation or autonomous client-facing decision-making. Deploying them for that use case is not a compliance failure yet. It will be one soon. What you need instead is AI that understands regulatory boundary (what can and cannot be said), knows the specific rulebook your firm operates under, and logs every decision in a way that survives audit. Trovix Reach exists because we started from that problem, not from a general-purpose LLM looking for a use case. It operates inside your regulatory perimeter by design, not retrofitted. And it is auditable because every response is traced to your policies and your training data, not to the internet.
What should you do Monday morning? First, audit what AI you are actually using with clients or for regulated decisions. Second, document the governance around it — FCA oversight is now going to expect this. Third, if that audit reveals generic tools or chatbots generating advice without explicit regulatory controls, treat that as a priority refit, not a nice-to-have. Trovix Audit helps you map what you have and where the gaps are. Finally, use Trovix Watch to track FCA guidance as it hardens from suggestion into requirement. The rules are coming. Firms that move first will be compliant. Firms that wait will be under pressure.
Source: City AM