Regulators have admitted they cannot write rules fast enough to keep pace with AI. For UK regulated firms, that means you must build governance now—waiting for new rules is no longer a strategy.
AI Governance  Trovix AuditFinancial Services · Legal · Insurance · Accountancy

Nikhil Rathi and Europe's banking regulators have just admitted something critical: they cannot keep up. Technology moves in weeks or months, the FCA CEO told CNBC, while traditional rulemaking cycles take years. This is not a theoretical concern for mid-market UK law firms, insurers, banks and accountancies. It is an immediate instruction. The FCA Consumer Duty PS22/9 framework, PRA SS1/23, and the UK's approach to the EU AI Act all assume regulators can set the rules and firms follow them. That assumption has broken. Agentic AI—systems that can act autonomously, delegate tasks, and make decisions without human intervention—is moving too fast. The regulatory gap is real, and it is widening.

This story is part of a larger, uncomfortable truth the financial services sector is learning. The 2024–2026 wave of foundation model integration has created a layer of operational complexity that existing supervisory frameworks simply do not contemplate. Firms deployed ChatGPT-style tools, Harvey for legal, Luminance for document review, and various Microsoft Copilot implementations with the assumption that regulators would tell them what "safe" looked like. They did not. Instead, regulators are now admitting they need new collaborative tools to monitor AI risks in real time. The SRA Code and FRC ISA UK standards assume humans make the final call. Agentic AI breaks that model. The ISO 42001 framework gives structure, but it is a governance standard, not a safety guarantee. Regulators are running diagnostics on the industry to understand what is already deployed. That diagnostic is just beginning.

Here is Trovix's direct view: the firms that will survive this regulatory transition intact are those that build AI governance first and features second. The industry split is already visible. Some vendors—tools like Legora for due diligence or certain Copilot deployments—prioritize speed and user experience. They are right that adoption matters. But they have treated governance as a post-implementation concern. That approach will not work for regulated firms anymore. Trovix's position is that AI governance and compliance must be embedded from day one, not bolted on afterwards. Trovix Audit exists precisely because the FCA, PRA, and SRA now expect firms to hold real-time visibility of what their AI is doing, how it is being governed, and where the risks live. A mid-market firm cannot wait for new rules to land; it must already know its AI drift, its decision audit trail, and its model performance variance. That is the only way to answer a regulator's question honestly when they ask, as they now will: "Explain your AI decision here."

What should a regulated firm do right now? Three things. First, take an honest inventory of every AI tool in use—including shadow AI, including tools deployed by individuals—and map it to your SRA Code, FCA Handbook, or PRA framework. You will find gaps. Second, implement a supervised AI governance framework that tracks outcomes, not just inputs. You need to know if your AI is drifting, biasing, or making decisions that contradict your duty of care. Third, select AI tools that were designed with regulatory compliance in mind from the start, not adapted for it later. Trovix Reach and Trovix Aria were built to operate inside that kind of governed environment. They log decisions, they flag exceptions, they work with your auditors, not against them. The firms that do this in August 2026 will be the ones that meet the FCA's new supervisory approaches without panic in September.

Source: CNBC

Related Trovix product:

Trovix Audit →Book a demo →