On 3 July, Europe's bankers and regulators publicly admitted what most of us already knew: the traditional regulatory cycle is broken. The FCA's CEO has stated plainly that rulemaking timelines — typically 18 to 24 months — cannot keep pace with AI development, particularly as agentic AI (systems that act autonomously on user instruction) accelerates. For mid-market legal, insurance, financial services and accountancy firms in the UK, this is not a theoretical problem. It means the rules you expect to guide your AI deployment will arrive late, possibly after you've already built systems that regulators later decide pose unacceptable risk. You are being asked to implement AI in a regulatory grey zone that gets narrower every quarter.
This is part of a larger pattern: regulators are shifting from prescriptive rule-setting to principles-based governance and real-time oversight. The EU AI Act, already law, took this approach. The FCA's proposed Algorithmic Management Framework reflects it. Lloyd's of London's Blueprint Two demands documented AI governance. The PRA's supervisory expectations (SS1/23) increasingly focus on what firms can prove about their AI systems, not just what rules they followed. What this reveals is that compliance through rulebook-reading is ending. Instead, regulators want evidence of continuous monitoring, documented controls, and the ability to switch off or limit faulty AI quickly — the circuit-breaker concept mentioned in this story. Mid-market firms cannot outsource their way through this with off-the-shelf products that promise 'AI compliance in a box'.
Here is Trovix's honest assessment: many AI products currently deployed in professional services — including Harvey, Legora, Luminance and mainstream Copilot implementations — were built to solve document processing and legal research problems. They are not built to satisfy the governance demands that regulators are now signalling will be non-negotiable. They excel at speed and pattern-matching but often lack the auditability, control boundaries and real-time monitoring that a regulator inspecting your firm will demand to see. Generic tools do not solve the problem that a faulty agentic AI model must be stoppable mid-transaction. A tool that cannot explain why it produced a specific recommendation is now a liability, not an asset. Trovix Watch and Trovix Audit were built specifically to address this gap — they monitor regulatory change as it happens and provide documented evidence of how your AI systems are controlled and what they output. You need governance tools, not just AI tools.
What should you do today? First, do not wait for the FCA to publish detailed guidance on agentic AI or circuit breakers. Second, audit every AI system currently in use in your firm against the principles in the FCA Consumer Duty (PS22/9) and the PRA's SS1/23 framework — particularly around model explainability, bias testing and kill-switch capability. Third, document who approved each AI deployment, what risk it was meant to address, and what controls constrain it. Fourth, assume that 'it was vendor-supplied so it must be compliant' will not satisfy a regulator. Fifth, implement monitoring and governance dashboards now, before new rules make them mandatory. Firms that treat this as a 2027 problem will find themselves explaining to regulators in 2026 why they were not prepared.
Source: CNBC