Nikhil Rathi's warning that traditional rulemaking cycles cannot match AI velocity is correct. But it is also incomplete. When the FCA's own CEO admits regulators are behind the curve on agentic AI, what he is really describing is a gap not between rule-makers and technologists, but between how most UK financial services, legal, insurance and accountancy firms are *building* AI and how they will *need to explain* what that AI does. Mid-market firms installing generic large language models like Microsoft Copilot or fine-tuned models without proper governance scaffolding are not ahead of regulators. They are building future compliance problems. The FCA, PRA and ICO are not saying the rules don't exist—they are saying that firms are deploying AI without the transparency, auditability and human oversight that FCA Consumer Duty PS22/9, PRA SS1/23 and the emerging UK AI Bill of Rights already require.
This story is the third major regulatory signal in eighteen months that the game has changed. First came the EU AI Act's classification of financial AI as 'high-risk'. Then came the ICO's guidance on UK GDPR and generative AI (clarifying that you cannot simply consent your way out of data governance). Now Rathi is saying regulators will move from *reactively* fining firms for AI failures to *proactively* defining what 'trustworthy' AI governance looks like. That shift means regulatory frameworks will soon include mandatory AI impact assessments, documented decision logic for agentic systems, and real-time model monitoring—similar to how ISO 42001 already works in other jurisdictions. Firms that wait for final rules before acting will lose years. Firms that treat AI governance as a compliance checkbox will fail even sooner.
Trovix's position is this: the bottleneck is not between regulators and AI speed. It is between the AI tools firms are using and the governance discipline those tools enable. Most general-purpose LLMs and RAG systems sold to professional services have no built-in chain-of-custody for decision-making. They don't track which source document informed which output. They don't maintain the audit trail that PRA SS1/23 demands for model governance. They are fast. They are not defensible. Tools like Harvey, Legora and Luminance have built better transparency into their legal and financial workflows, but they still sit on top of client infrastructure that may not support the kind of continuous monitoring and control the FCA is now expecting. That is why we built Trovix Watch alongside Trovix Aria—not to replace the model, but to wrap governance around it. Watch monitors regulatory change in real time so your AI workflows stay compliant as rules evolve. Aria returns answers from your knowledge base with full source transparency. Together they create something the generic tools do not: an audit trail that a regulator can actually examine and sign off on.
What should your firm do on Monday morning? First, stop treating AI as a productivity hack. Start treating it as a regulated service delivery channel. Second, map which processes in your firm handle client money, confidential data or binding decisions—those are your high-risk AI zones and they need governance before they need speed. Third, identify what you cannot explain about your current AI deployments. If you cannot explain why your system recommended a particular underwriting decision, compliance classification or deal structure, you have a PRA problem. Fourth, talk to your regulator now, not after an enforcement sweep. The FCA has signalled it wants to collaborate with early movers on AI governance frameworks. Being transparent about your approach now builds credibility later. Fifth, invest in regulatory monitoring infrastructure. Rules are coming fast. Compliance is now a continuous function, not an annual audit item.
Source: CNBC