The Red Hat survey published by Computer Weekly in April 2026 exposed a chasm between AI adoption and AI control in UK business. Eighty-seven per cent of UK IT leaders have deployed agentic AI systems—autonomous agents that make decisions, retrieve data, and execute tasks with minimal human intervention—yet only 25 per cent have strong governance in place. For regulated firms in legal, insurance, financial services and accountancy, this is not a headline about tech trends. It is a regulatory breach in slow motion. The FCA Consumer Duty PS22/9, the SRA Code of Conduct, PRA SS1/23 on operational resilience, and the ICO's UK GDPR enforcement all demand that firms know what their systems do, where data goes, and who is accountable when things fail. Three-quarters of UK IT leaders cannot say they meet that standard.
This story is not an outlier. It is the pattern. Since 2023, the industry has raced to deploy large language models, retrieval-augmented generation systems, and agentic AI without first building the scaffolding that regulated firms need: data lineage tracking, decision audit trails, model performance monitoring, and clear ownership chains. Chat-based assistants like Microsoft Copilot have become default tools because they are cheap and easy. Luminance and Harvey built their reputations on document intelligence and legal reasoning, but neither solved the governance problem for firms deploying multiple AI vendors across multiple workflows. The EU AI Act is coming. Lloyd's Blueprint Two will tighten AI standards in insurance. The FRC's ISA UK framework is demanding more. Firms without governance today will face remediation costs, regulator friction, and client trust damage tomorrow.
Trovix's view is this: agentic AI without governance is uninsurable for regulated firms. The problem is not that AI is being used. The problem is that most deployments treat governance as an afterthought—a compliance checkbox added after systems go live. That is backwards. Governance must be built into the deployment from day one. Firms need continuous visibility of where data is stored, who (or what) accessed it, what decisions were made, and whether those decisions passed regulatory logic checks. This is not about blocking AI. It is about controlling it. A mid-market law firm cannot tell the SRA how its AI intake system makes eligibility decisions if it has not built an audit trail. An insurance firm cannot defend a claims-handling AI to the FCA if it cannot trace why a payout was rejected. Trovix Audit exists because this gap is real and because existing tools—dashboards that report on usage metrics, or vendors who only cover their own products—leave the hard questions unanswered.
If you lead a regulated firm, here is what to do now, before your next regulatory request or audit: First, inventory every AI system in use, including shadow AI (the Copilot instances, the ChatGPT logins, the browser extensions that teams have adopted without approval). Second, map data flow: where does input data come from, where is it processed, who owns the output, and is any of it retained or retrained into another model? Third, establish accountability: for each system, who is the named owner if the regulator calls? Fourth, build an audit capability before you need it. Trovix Audit is designed to close exactly this gap—showing you what your AI systems are doing, where your data is going, and whether you can defend it to your regulator. Fifth, use Trovix Watch to track regulatory changes in real time so you are not caught flat-footed when the next guidance lands. Do this in the next 90 days, not next year. The 75 per cent who lack governance are about to discover that regulators notice.
Source: Computer Weekly