Nikhil Rathi's warning that traditional rulemaking can't keep pace with AI development is correct. But the answer isn't weaker rules or waiting: it's embedding compliance logic into AI systems from the ground up, not bolting it on afterwards.
AI Governance  Trovix SiftFinancial Services · Legal · Insurance · Accountancy

On 3 July, the FCA's chief acknowledged what many practitioners have felt for two years: the gap between how fast AI moves and how fast regulators can write rules is now a real problem. In financial services, this gap is dangerous. Money laundering detection, sanctions screening, transaction monitoring and fraud prevention cannot wait for the next supervisory update cycle. Yet firms using generic large language models—the kind that power ChatGPT or Microsoft Copilot in its standard form—have no way to explain their AI's decisions to the FCA, let alone prove those decisions comply with SR22-17 (Transaction Monitoring) or the financial crime provisions of the Senior Managers and Certification Regime. When the FCA's supervision becomes more real-time and outcome-focused (which Rathi signalled it will), firms using opaque AI tools will fail first.

This story is part of a bigger shift. The EU AI Act came into force this January. The FRC's plans for ISA (UK) 320 and 330 now explicitly require auditors to document how they use AI and what they trust it to do. The SRA's update to the Code of Conduct for solicitors now treats AI decisions in client matters as lawyer decisions—ownership cannot be delegated to a tool. Meanwhile, agentic AI—systems that can act without human instruction—is moving from research labs into financial products. The regulatory picture is becoming clearer: rules are moving from 'use AI carefully' to 'prove what your AI does, why it does it, and that it doesn't break the law.' Generic tools were never built for that burden.

Trovix's position is straightforward: financial crime AI and compliance AI cannot be the same product as general-purpose AI. A tool built to answer email questions works nothing like a tool built to flag a suspicious wire transfer. Systems like Harvey and Luminance are designed around explainability—they show their reasoning—but they were built for legal review and due diligence, not for transaction monitoring. In financial crime specifically, firms need AI that is transparent by design, audit-ready by default, and built to handle the regulated decision-making that the FCA and PRA now expect. That means systems where every flag can be traced back to a rule, where confidence scores are real and defensible, and where human judgment stays in control. Trovix Watch exists partly because we learned early that compliance teams cannot use generic AI to track regulatory change—you need systems built to understand the binding force of FCA Handbook rules, not just pattern-match keywords.

What should a mid-market insurer, law firm or financial services outfit do now? First, audit what you're using. If you've deployed ChatGPT, Copilot or an in-house RAG system built on a general LLM without documented compliance controls, you have a regulatory vulnerability. Second, don't wait for the FCA to publish new rules; assume Rathi's next supervisory letter will ask for explainability and auditability. Third, bring your compliance and operations teams into AI decisions early—not after procurement. And fourth, when you do select tools for financial crime, transaction monitoring or client onboarding, choose systems built for those specific functions, not borrowed from consumer AI. The firms that will thrive over the next two years are those that treat AI as a compliance tool first and an efficiency tool second.

Source: CNBC

Related Trovix product:

Trovix Sift →Book a demo →