The University of Cambridge's new report is a mirror held up to the industry's delusion: we are deploying autonomous AI agents at scale while our supervisory frameworks are still learning what questions to ask. For UK-regulated firms, this gap is not academic—it is a compliance cliff.
Agentic AI  Trovix ReachFinancial Services · Legal · Accountancy

The numbers are stark. Agentic AI adoption in financial services is expected to surge from 24% today to 81% by 2030—a tripling in four years. Yet the same Cambridge report that projects this explosion also documents something far more alarming: regulatory frameworks and technical oversight capacity have not kept pace. For UK firms already operating under FCA Consumer Duty PS22/9, PRA SS1/23, and the incoming EU AI Act requirements, this is not a future problem. It is a present one. Mid-market financial services firms, insurers, and accountancy practices are caught between competitive pressure to deploy autonomous agents and genuine uncertainty about what 'responsible deployment' means in their context. The FCA has issued guidance on AI governance (CCPG 2023/4), but that guidance predates widespread agentic deployment. Regulators are playing catch-up, and firms deploying agents without governance frameworks are the ones who will face enforcement.

What this story reveals is a fundamental mismatch in the industry's thinking. Agentic AI is being treated like a feature set to bolt onto existing systems—something you license from OpenAI, Google, or the growing suite of financial-sector-specific providers and then run. That mentality is the problem. Autonomous agents make decisions, escalate matters, execute transactions, and interact with clients and counterparties without human intervention in the moment. They are not document processors or pattern-matchers like the earlier generation of GenAI tools. They operate in a different regulatory and operational category entirely. Yet many firms are adopting agents with the same governance light-touch they use for Copilot deployments. The gap between what regulators can oversee and what firms are building is widening because adoption is outrunning governance, not the other way around.

Here is Trovix's direct view: agentic AI in regulated industries requires governance first, deployment second. Not in sequence—in parallel. You cannot retrofit compliance into an autonomous system that is already live. Firms using Harvey, Legora, or even best-in-class proprietary agent builds without a contemporaneous governance framework are taking a regulatory bet they do not realize they are taking. The difference between an AI assistant that suggests a decision (and requires a human to approve it) and an AI agent that makes and executes the decision is profound. It moves the liability, the accountability, and the regulatory exposure closer to your firm. Trovix Audit exists precisely because this gap exists—to map what your agents are actually doing, how they are deciding, what data they are acting on, and where human oversight has actually occurred. It is the governance layer that the Cambridge report says is missing. Trovix Watch matters here too, because regulatory interpretation of agent oversight is moving faster than most firms' change management teams. You need to know what is changing in FCA expectations, ICO guidance on AI and data, and SRA Code implications for law firms deploying agents before you are reading about it in an enforcement case.

If you are a mid-market regulated firm, your action plan for the next 90 days is straightforward. First: audit what agentic systems, if any, you have deployed or are planning to deploy. Understand what decisions they make autonomously versus what decisions they surface for human approval. Second: map those decisions and actions against your regulatory obligations—not generic AI governance frameworks, but your specific PRA requirements, FCA Handbook chapters, SRA Code provisions, or AML/CTFR obligations. Third: implement real-time monitoring and logging of agent decisions and actions. This is not optional—it is the evidence that you are in control. Fourth: engage your compliance and risk teams in a genuine governance design before you scale agent deployment further. The firms that will win the next three years are not the ones that deploy agents fastest. They are the ones that deploy agents with demonstrable governance in place. The regulatory cost of catching up will be far higher than the competitive cost of moving slightly slower with proper oversight.

Source: CNN

Related Trovix product:

Trovix Reach →Book a demo →