Three-quarters of UK IT leaders have no real AI governance framework in place, yet 87% are already running agentic AI systems. For law firms, insurers, financial services firms and accountancies, this isn't a technology problem—it's a regulatory landmine. The FCA Consumer Duty (PS22/9), SRA Code Paragraph 6D, and ICO GDPR enforcement are not theoretical frameworks. They require demonstrable governance of algorithmic decision-making. A governance 'plan' that lives in a spreadsheet or a Slack conversation is not a plan. It is paperwork waiting to be demolished in a regulator's examination.
This survey reveals a pattern that has defined the last 24 months of enterprise AI: vendors sell speed and capability, buyers assume governance will follow, regulators wait for the first breach to clarify the rules. The arrival of agentic AI—systems that make autonomous decisions without human review—has turbocharged this gap. Products like Microsoft Copilot and GPT-4 integration frameworks were built for general enterprise use. They don't understand the concept of FRC audit file retention, PRA stress-testing documentation (SS1/23), or the Lloyd's Blueprint Two attestation model. The gap between deployment velocity and oversight infrastructure has stopped being an inconvenience and started being a liability.
Here's what we believe: AI governance in regulated firms cannot be a function bolted onto IT operations after the fact. It has to be built into the data and process architecture from day one. This is why Trovix's approach is different from retrofitting frameworks around commodity AI tools. You cannot audit what you cannot see. Firms need continuous visibility of where data moves, who accesses it, what decisions are made and on what basis—not quarterly reports. Trovix Watch exists because regulatory change and AI governance move together. You cannot comply with rules you do not know have changed. And you cannot demonstrate compliance with systems you cannot explain. That requires deliberate architecture, not better prompts.
If you are a partner at a mid-market law firm or the chief underwriter at a regional insurer and you have deployed agentic AI in the last 18 months without a documented, auditable governance model, you have approximately 90 days to fix this. Not because Trovix says so, but because the next FCA thematic review, SRA desktop exercise, or ICO investigation will find it. Start by mapping where your data actually sits and what your AI systems do with it. Then build visibility and control around those flows. Use Trovix Sift to establish where sensitive data is embedded in unstructured documents and client communications. Establish a register of AI applications with documented risk assessments. Make it real, not theatrical. The firms that will survive the next regulatory cycle are the ones that treated governance as a hard requirement, not a checkbox.
Source: Computer Weekly