87% of UK firms have deployed agentic AI systems. Only 25% have governance in place. Trovix argues this is a regulatory time bomb waiting for the FCA, SRA and ICO to investigate.
AI Governance  Trovix AriaLegal · Insurance · Financial Services · Accountancy

The Red Hat survey published last month revealed a chasm that should alarm every compliance officer in the UK regulated sector: 87% of IT decision-makers are running agentic AI systems, yet only 25% have strong governance in place. Worse, fewer than half can account for where their data lives or how it moves through these systems. For mid-market law firms, insurers, financial services businesses and accountancy practices, this is not an abstract problem. The FCA's approach to AI governance (outlined in its expectations on model risk and data use), the SRA's requirement for supervision under their Code of Conduct, and the ICO's tightening stance on GDPR compliance mean that 'we didn't know what our AI was doing' will not satisfy a regulator. The survey shows the industry is sleepwalking into enforcement action.

This governance gap reflects a systemic failure in how UK enterprise AI is being adopted. Most firms treated agentic AI as a productivity tool, not a system that processes client data, handles sensitive transactions, or makes decisions that carry legal liability. Products like Microsoft Copilot, Harvey and Luminance were rolled out because they promised speed and cost reduction. Few of those deployments included proper data classification, audit trails, or control frameworks before go-live. The pattern is now clear: technology adoption is outpacing control mechanisms by a factor of three or four. Regulators have noticed. The FRC's expectations on AI governance in audit (ISA UK framework), Lloyd's Blueprint Two requirements on underwriting AI, and the emerging PRA SS1/23 expectations on model governance all point to the same direction: if you cannot explain what your AI system is doing and why it reached that conclusion, you will struggle to justify it to a regulator.

Trovix's view is that agentic AI governance requires a fundamentally different architecture than most enterprise deployments currently use. The problem with deploying general-purpose AI assistants (even good ones) is that they inherit the organization's existing data visibility problem—they cannot govern what they cannot see. The answer is not to buy more AI tools; it is to build a governance foundation first. That means mapping data flows, establishing what should and should not be exposed to AI systems, and creating an audit trail that tracks what an AI system accessed, how it processed that data, and what it did with the result. Trovix Audit is built on this principle: governance and compliance visibility must come before or alongside capability deployment, not after. This is a different philosophy from layering a dashboard on top of an already-deployed system of black boxes.

For a mid-market legal firm, insurance broker or financial services practice, the immediate step is not to stop using AI—that horse has bolted. The step is to commission an honest audit of what AI systems you are already running, what data they can access, and what controls are in place. If that audit reveals what the Red Hat survey suggests (fragmented deployments, limited visibility, no formal governance), you need a structured remediation plan. That plan should include data classification, approved use cases (not 'any use case'), and a mechanism to log and review AI-driven decisions in sensitive areas like underwriting, case assessment or client advice. The FCA Consumer Duty (PS22/9) requires you to understand how tools you deploy affect your clients. Using AI without visibility into its behaviour makes that requirement impossible to meet. Act on this now, not when the regulator knocks.

Source: Computer Weekly

Related Trovix product:

Trovix Aria →Book a demo →