Nikhil Rathi's warning that traditional rulemaking cannot keep pace with AI development is not new — but the FCA's admission that it cannot is. What matters to mid-market legal, insurance, financial services and accountancy firms is this: regulators are telling you they will not have new rules ready when you need them. The EU AI Act's implementation is already fragmenting compliance expectations. PRA SS1/23 expectations on model risk exist, but they predate agentic AI systems that can act autonomously on client accounts, market positions and underwriting decisions. The FCA Consumer Duty PS22/9 requires you to act in consumers' interests, but no regulator has yet defined what that means when an AI agent makes a decision on your behalf. This gap is not closing soon. It is widening.
This is what regulatory lag looks like in real time. Firms adopting AI are choosing between three bad options: move fast and assume regulators will accept it retrospectively (foolish), move slowly and lose competitive ground to less-scrupulous competitors (painful), or build internal governance frameworks that exceed current rules in anticipation of stricter ones ahead (expensive but wise). The pattern is clear: agentic AI — systems that can initiate actions, not just suggest them — has moved from laboratory to production faster than any technology the financial services sector has seen. Harvey and Luminance have proven that large language models can work on real legal and compliance tasks. But proving something works is not the same as proving it is safe, fair or auditable under ICO UK GDPR or SRA Code standards. Europe's regulators know this. That is why they sound alarmed.
Here is what Trovix believes: firms that wait for regulators to write the rules will be left explaining to their own boards why they were slow to implement solutions that better competitors deployed months earlier — and they will have poor documentation to show they tried to do it safely. The solution is not to deploy unaccountable AI tools and hope. It is to deploy AI with human-centred governance from day one. That means documented decision-making at each point where AI has autonomy. It means audit trails that can explain not just what the AI did but why it was allowed to do it. It means knowing, every week, what regulatory changes are coming — not after they land. Trovix Watch exists because this weekly monitoring is the only rational response to the speed differential Rathi described. Trovix Audit exists because a dashboard that shows you which AI systems are working as intended, which ones are drifting, and which ones are creating unquantified risk is no longer optional — it is the only credible defense when regulators eventually move from warning to enforcement.
What should a mid-market firm do right now? First, stop waiting. Second, map which AI tools are already in use — generative chat, document analysis, intake automation, case prediction. You likely have more than you think. Third, run a governance gap analysis: for each AI deployment, can you articulate why it is fair under the Consumer Duty, auditable under the FCA's model risk framework, and defensible under the ICO's standards for automated decision-making? Fourth, where you cannot articulate that, pause deployment or redesign it. Fifth, establish a weekly regulatory watch function — not monthly, weekly — because the EU AI Act, the Online Safety Bill amendments, and emerging PRA guidance on AI concentration risk will change your operating environment faster than your quarterly compliance cycle can absorb. For mid-market firms without dedicated AI governance teams, this is the case for embedding regulatory monitoring and AI compliance dashboards into your infrastructure before the rules force you to do it at much greater cost.
Source: CNBC