When Nikhil Rathi, the FCA's CEO, tells the world that traditional rulemaking cycles don't work anymore, he is saying something UK regulated firms need to hear clearly: you cannot wait for rules to stabilise before moving on AI. The FCA's own Consumer Duty PS22/9 framework, the PRA's SS1/23 guidance on operational resilience, and the SRA Code all assume a predictable timeline for change. They do not account for agentic AI systems that can make autonomous decisions at speeds regulators cannot match. This is not a hypothetical problem. It is a statement of structural failure in how UK financial services, legal services and insurance firms are supposed to stay compliant whilst innovation accelerates.
What regulators are really saying is that the gap between what AI can do and what the rules permit has become unmeasurable. Every major financial centre is facing the same problem: the EU's AI Act creates mandatory risk classifications that do not map to how financial services firms actually deploy models; frameworks like ISO 42001 and Lloyd's Blueprint Two describe governance processes that assume humans review outputs; compliance teams are still built for document review, not for monitoring agentic systems that learn and adapt. The honest truth is that AI products like Harvey and Luminance solved document intelligence well because documents are static. But agentic AI—systems that make decisions without human intervention—breaks the entire assumption that governance means oversight. Most firms are still buying point solutions (document extraction, chatbots, research assistants) and pretending they have an AI strategy. They do not.
Here is Trovix's view: regulatory uncertainty is not an excuse to do nothing. It is a reason to do something deliberately. The firms that will survive the next regulatory correction are not those waiting for the FCA to publish definitive guidance. They are the ones building auditability and explainability into their AI systems now—before regulators mandate it. That means choosing AI tools that are built for regulated environments, not adapted to them afterwards. Trovix Watch tracks regulatory change in real time so you know when new guidance lands. Trovix Aria and Trovix Sift are built from the start to generate audit trails and explanations of how they reached conclusions—not as an afterthought. This is different from products that prioritise speed or cost-saving over provenance. When the FCA or the SRA eventually publishes rules on agentic AI in financial services or legal services, firms that have been running explainable systems will have evidence of compliance. Firms with black-box tools will have a problem.
For a mid-market law firm, insurance broker, financial adviser or accountancy practice, the practical step is this: audit what AI you have deployed right now. Not the strategy document—the actual systems your people are using. Can you explain to a regulator how that ChatGPT instance knows which client data to access? Can you trace how your document AI system classified that underwriting case? If the answer is no, you have a governance gap that no amount of waiting for new rules will fix. Start with Trovix Brief on intake automation—it is a contained use case where explainability is built in, and it will teach you what good AI governance looks like before you scale to more complex systems. Then expand using tools designed for audit and traceability, not speed and cost-cutting. The firms that move fastest now will move safest later.
Source: CNBC