The FCA's Mills Review, published in July 2026, is not a speculative exercise. It describes four systemic shifts already underway — operations, customer journeys, competition, and fraud detection — and signals that regulators will now sharpen their focus on governance as firms move from pilots to production. For mid-market legal, insurance, and financial services firms, this means the FCA has moved past permissiveness. The Consumer Duty (PS22/9) already requires firms to put customer outcomes at the centre of their decision-making. Deploying AI at scale without rigorous governance structures around model selection, data lineage, bias testing, and explainability will no longer be treated as a failure of execution — it will be treated as a conduct breach.
This shift reflects a pattern now visible across UK regulation. The PRA's SS1/23 on operational resilience, the ICO's guidance on AI and UK GDPR, and the emerging FRC standards around audit and AI all point to the same conclusion: regulators have stopped asking whether firms should use AI and started asking how firms will be accountable when they do. The EU AI Act is pushing the same logic from Brussels. Mid-market firms that delayed AI adoption because they lacked confidence are now caught between two pressures: their competitors are already embedding AI into workflows, and their regulators are about to demand they prove it is governed properly. There is no graceful middle ground.
Here is where Trovix's approach differs from the pattern we see in most AI products. Tools like Harvey (legal document analysis), Luminance (contract intelligence), and Legora (regulatory research) solve specific, high-value tasks — and they do that work well. But they do not solve the governance problem. A mid-market law firm using Harvey on due diligence without a documented model card, bias testing protocol, or audit trail is not safer than it was before. It is just faster at being exposed. The same applies to Copilot and similar general-purpose assistants: they accelerate work but create compliance risk if they sit outside your governance framework. Trovix Audit was built specifically to close that gap — it sits across your AI deployments (whether they are specialist tools or internal systems) and creates the governance artefacts regulators will now demand: audit trails, data provenance, bias testing records, and explainability documentation. It is not a nice-to-have. Under the Mills Review's logic, it is table stakes.
What should a mid-market firm do in the next 90 days? First, audit what AI is already in use — including shadow AI that business units have deployed without central IT knowing. Second, document the governance structure around each deployment: Who approved this model? What data does it use? How is accuracy monitored? What happens when it fails? Third, identify the gaps. Most firms will find they have tools but no governance layer. That is the problem the Mills Review was written to surface. Trovix Watch will also flag the FCA consultation responses and the emerging enforcement guidance as it lands. But the real work is immediate: build a governance framework that a regulator can audit, or prepare to explain why you deployed AI without one. The FCA is no longer asking permission. It is asking for evidence.
Source: Deloitte UK