The Red Hat survey confirms what we see in the market: UK regulated firms are racing to deploy agentic AI systems without the governance infrastructure to control them. That's not innovation. That's regulatory exposure dressed as competitive advantage.
AI Governance  Trovix AuditLegal · Insurance · Financial Services · Accountancy

The Red Hat data is stark. Eighty-seven per cent of UK IT leaders have already deployed agentic AI systems. Only 25 per cent have strong governance in place. For regulated firms—law practices, insurers, financial services, accountancy—this is not an academic problem. The FCA's Consumer Duty (PS22/9), the SRA's Code of Conduct, and the PRA's operational resilience rules (SS1/23) all demand that firms maintain complete visibility of where client data lives, who processes it, and under what terms. Less than half the firms surveyed know where their data is actually stored or processed. That is a breach waiting to happen. It is also a business continuity failure. When your agentic AI vendor goes down—or changes terms, or gets acquired—you won't know the blast radius.

This story fits a broader pattern we have watched for two years. The market split into two tribes early: firms that bought point solutions (Harvey for legal, Luminance for document review, Microsoft Copilot for general tasks) and tried to bolt governance on afterwards, and firms that started with governance architecture and then fitted AI into it. The first group is now discovering that point solutions are hard to audit, that vendor lock-in makes compliance audits painful, and that data lineage is opaque. The second group—still a minority—sleeps better. The EU AI Act is coming. The Lloyd's Blueprint Two governance framework is tightening. Regulators are moving from 'tell us what you are doing with AI' to 'prove you control it'. The window for retrofitting governance is closing.

Here is our honest assessment. Most agentic AI tools—whether enterprise-grade or consumer-grade—prioritise capability over auditability. They are not designed for compliance-first environments. That is not the vendors' fault; their markets are broader than regulated services. But it is the reason why a law firm deploying Harvey or Legora without a governance layer underneath is taking unnecessary risk. You need three things running in parallel: first, a real-time inventory of where AI systems are deployed and what data flows through them (Trovix Audit does this); second, continuous monitoring of your regulatory obligations as they change (Trovix Watch runs this); and third, the ability to audit and explain every AI decision after the fact. None of this is negotiable under FRC ISA UK auditing standards or ICO UK GDPR enforcement. Most firms are doing none of it.

If you are a mid-market legal, insurance, financial services or accountancy firm and you have deployed agentic AI in the last eighteen months without documenting your governance model, act now. Pull a list of every AI tool in use across your business. For each one, document: the vendor, the data it touches, where that data is processed, your data processing agreement, and your incident response plan if the vendor fails. If you cannot complete that grid within two weeks, you have a control gap. Second, establish a single source of truth for AI governance—a dashboard that your compliance and IT teams can both see, that shows what is running, what is approved, and what needs review. Third, implement vendor management controls that make AI relationships as visible as your critical infrastructure contracts. The compliance regulator will ask for this. Your insurer already expects it.

Source: Computer Weekly

Related Trovix product:

Trovix Audit →Book a demo →