When Nikhil Rathi tells the world that traditional regulatory cycles cannot keep pace with AI development, he is not offering reassurance. He is admitting defeat. The FCA, PRA and ICO have no playbook for agentic AI systems that operate with minimal human oversight, learn from their interactions, and make decisions that affect market integrity in real time. For mid-market law firms, insurers, financial services firms and accountancies, this admission has a sharp implication: regulators will not write rules fast enough to guide your AI deployment. You will be the ones making judgment calls about what is safe, compliant and defensible. The FCA is signalling, in effect, that if your firm uses AI and something goes wrong, the regulator will ask first what governance framework you had in place — not whether you violated a rule that did not exist yet.
This story is part of a larger pattern we are seeing across UK financial regulation. The FCA Consumer Duty PS22/9, the SRA's Code of Conduct for solicitors, the PRA's SS1/23 guidance on model risk, the FRC's ISA UK standards for auditors, and the ICO's interpretation of UK GDPR have all shifted from prescriptive rule-making to principles-based accountability. The EU AI Act is coming. Lloyd's Blueprint Two expects insurers to manage third-party AI risk. ISO 42001 certification is becoming table-stakes. But none of these frameworks tell you exactly how to deploy a RAG system, govern a generative AI copilot, or audit an agentic workflow. They tell you that you must be able to explain and justify it. That is a fundamentally different burden than compliance. It means your firm needs genuine, documented governance — not just a vendor's white paper and a signed DPA.
Here is where we are direct about what this means: most AI products on the market today are built to solve a single problem fast. Harvey generates legal briefs. Luminance runs contract review. Microsoft Copilot surfaces search results. Legora does case law retrieval. They are all useful, but they are not built around the governance framework your regulator is now demanding. They give you capability without visibility. You get speed, but you do not get the audit trail, the change control, the impact assessment, or the documented decision-making that the FCA, SRA and PRA will ask for in twelve months. Trovix Audit exists precisely because this gap exists. It sits between your AI tools and your compliance function, making the reasoning visible, the decisions traceable, and the risks quantifiable. That is not sexy. It is not the AI that wins pitches. But it is what keeps you out of an FCA enforcement case.
What should your firm do now? Three things. First, do not wait for the FCA to publish detailed AI governance rules. They will not, and regulators have said so explicitly. Start building your AI governance framework today, using principles-based reasoning: Why this tool? What could go wrong? How will you know if it does? What will you do about it? Second, audit the AI tools you already have in place against that framework. If you cannot explain to a regulator why you chose that vendor, what data feeds it, how you monitor its outputs, or how you would pull the plug if it failed, you are exposed. Third, build governance into your AI stack from the start, not bolted on afterwards. Trovix Aria and Trovix Sift are designed to work within that governance model — giving your fee-earners and analysts the AI capability they need while keeping the firm in control of what the system knows, what it is allowed to do, and how it is audited.
Source: CNBC