A Red Hat survey of 500 UK IT leaders has confirmed what we've observed in dozens of regulated firms: 87% are already using agentic AI systems, yet only 25% have strong governance in place. For mid-market law firms, insurers, financial services providers and accountancy practices, this is not an academic problem. The SRA Code of Conduct for Solicitors, the FCA's Consumer Duty (PS22/9), and the PRA's operational resilience expectations (SS1/23) all require firms to understand and control the tools they deploy. Less than half of respondents have complete visibility of where their data is stored and processed in AI systems. This is not just sloppy. It is a compliance breach waiting to happen.
The pattern is clear: the industry has adopted AI tools faster than it has built the infrastructure to govern them. Generic enterprise AI platforms like Microsoft Copilot, Harvey, and Luminance have made AI accessible and impressive. But accessibility is not the same as control. Firms bought or built agentic systems—automated workflows that make decisions and access data without human review at every step—and assumed governance would follow. It has not. The underlying problem is structural: most off-the-shelf AI solutions are built for deployment speed, not for the audit trail, data lineage, and decision transparency that regulated firms actually need. The gap between 87% adoption and 25% governance is not closing. It is widening.
Here is what Trovix believes: agentic AI in regulated firms must start with governance, not end with it. Governance cannot be bolted on after deployment. It must be built into the system architecture from day one. This means knowing exactly which data the AI touches, being able to audit every decision it makes, understanding its training and fine-tuning data, and proving compliance to regulators on demand. Trovix Audit exists specifically because we saw firms deploying Copilot or Luminance or Harvey without this visibility, and then scrambling to document what those systems actually do. The honest truth is that most agentic AI products assume a low-regulation context. Regulated firms need something different: AI that is built for the compliance perimeter, not fitted into it afterwards.
If your firm uses or is considering agentic AI—whether for contract review, claims triage, client intake, or regulatory monitoring—do this now: map every data input and output, document the training data and model version, establish a review process for high-risk decisions, and assign accountability. If you cannot answer those four questions today, you are operating outside your regulatory obligations. Trovix Watch can help you track where regulatory expectations are shifting (they are shifting fast). Trovix Brief and Trovix Reach are built with governance as a first principle, not an afterthought. But the hard truth is that governance is not a feature you can buy. It is a discipline you must build.
Source: Computer Weekly