The FCA has decided it will not write a rulebook for AI in financial services. That does not mean AI is unregulated—it means your firm is now responsible for proving it is safe. Trovix believes that responsibility demands real visibility, not hope.
AI Governance  Trovix AuditLegal · Financial Services · Insurance · Accountancy

The FCA's July statement that it will not issue 'lots of new, detailed rules on AI' is not a green light to experiment. It is a reallocation of responsibility. The UK regulator is signalling that it will hold firms accountable under existing principles—Consumer Duty PS22/9, the SRA Code, PRA SS1/23—rather than create a prescriptive rulebook. That sounds lighter-touch. It is not. It means your firm must design, document and defend your own AI governance framework. The FCA will judge you against outcomes, not compliance checklists. For mid-market law firms, insurers, financial advisers and accountancy practices, this is harder, not easier.

This decision reflects a wider shift in how UK regulators view AI. The ICO's UK GDPR enforcement (Clearview AI, British Airways) has already shown that principles-based accountability is not theoretical—it has teeth. The EU AI Act's tiered risk approach is influence UK thinking, even as the UK charts its own course. Meanwhile, the gap between what regulated firms actually need (concrete guidance) and what regulators will provide (trust us, you'll know when you've gone wrong) is widening. Firms that have spent the last eighteen months waiting for detailed AI rules are discovering they should have been building governance all along. The firms that started early—those using tools like Luminance or Harvey with clear audit trails—are now ahead precisely because they did not wait for a regulator to tell them what good looks like.

At Trovix, we hold a specific view: principles-based regulation works only if you can prove your principles are working. That requires real-time visibility into how AI is being used, by whom, on what data, with what outcomes. Many AI products in the legal and financial services space—including some well-funded platforms—lack this. They are good at generating output (summaries, contract reviews, risk scoring) but poor at generating evidence of safe deployment. Generic tools like Microsoft Copilot in legal contexts create particular risk because they were not built for regulated environments and generate no audit trail that satisfies FCA or SRA scrutiny. Trovix Audit was built for this specific challenge: it gives you a compliance dashboard, not a denial of deployment. That is the difference between 'we hope this is okay' and 'we know this is okay'.

Your immediate action is not to buy AI tools faster. It is to inventory what you are already running—which models, which versions, which data, which users—and document the risk. Then build governance that the FCA can audit. That means: clear use cases, human sign-off on outcomes that matter (legal advice, financial recommendations, underwriting decisions), data provenance tracking, and bias testing on your own firm's client base, not generic benchmarks. If your AI tool cannot tell you why it reached a specific conclusion in a specific case, it is too risky in a regulated environment. The firms that will thrive under principles-based regulation are those that treat AI as a business decision, not a technology decision—and build the paper trail to prove it.

Source: CNBC

Related Trovix product:

Trovix Audit →Book a demo →