The Cambridge report surveying 600 firms and regulators paints a clear picture of what's coming: agentic AI making financial decisions independently, without real-time human intervention. Today, roughly a quarter of financial services firms are deploying these systems. By 2030, that rises to four in five. The FCA knows this is happening. They don't yet have the supervisory frameworks or technical capacity to oversee it properly. For UK-regulated financial services firms, insurers, and the accountancy practices that advise them, this gap between deployment speed and regulatory readiness is already creating genuine compliance risk—not in three years' time, but right now.
This is part of a much larger shift we're tracking. The industry has moved past 'AI as a tool to help humans work faster' and into 'AI as an agent making decisions on behalf of clients.' Harvey, Luminance and others have built products that can draft, review and even handle matter intake autonomously. But financial services are different. When an agentic AI system decides whether to approve a lending application, execute a trade, or process an insurance claim, the stakes are higher and the regulatory expectation is stricter. The FCA Consumer Duty (PS22/9) now explicitly requires firms to act in customers' best interests. You cannot outsource that duty to an unmonitored algorithm. The EU AI Act, which will influence UK thinking even post-Brexit, already classifies certain financial AI uses as 'high-risk.' We're moving toward a world where agentic AI in finance requires active, auditable governance—and most mid-market firms don't have the infrastructure for it yet.
Here's Trovix's view: agentic AI is valuable, but not without guardrails. Many firms are deploying these systems because they solve a real problem—speed, consistency, scalability. But they're deploying them in the dark. They don't have continuous visibility into whether their AI is behaving as expected, whether it's drifting from approved decision logic, or whether it's creating unintended bias. The difference between Trovix's approach and 'just buy an agentic AI product' is this: we build governance into the operation from the start. Trovix Audit gives regulated firms the real-time monitoring and compliance dashboard they need to understand what their autonomous systems are actually doing, not what they're supposed to do. Without this layer, you're betting your FCA relationship on the assumption that a third-party vendor's system will never fail, never drift, and never create a regulatory incident. That bet will not pay off.
What should a mid-market law firm, insurer or financial services business do now? First, accept that agentic AI is coming to your sector—either you'll build it or a vendor will sell it to you. Second, don't deploy autonomous decision-making systems without documented governance. Third, start mapping your regulatory obligations now. The FCA, PRA, SRA and ICO are all circling AI governance. Your current risk frameworks are not adequate. Use Trovix Watch to track emerging regulatory signals in real time, so you're not caught flat-footed when the FCA publishes new AI oversight expectations. Fourth, if you're already running agentic systems, audit them immediately. If you're planning to deploy them, build in governance from day one. The firms that will thrive in this transition are not the ones that adopt agentic AI fastest. They're the ones that adopt it most responsibly—with eyes open, with oversight in place, and with regulators seeing exactly what they're doing.
Source: CNN