When Nikhil Rathi tells CNBC that traditional rulemaking cycles don't work anymore, he is describing a real structural problem — but not the one most UK regulated firms think they have. The FCA is right: regulation lags innovation. But your firm's response probably mirrors the industry mistake — you have deployed AI tools (Harvey for contract review, Luminance for due diligence, Copilot for general work) and then bolted on governance afterwards, usually a compliance checklist against PRA SS1/23 or the EU AI Act requirements. That is backwards. What Rathi is actually saying is that regulators now expect firms to *design* governance *into* AI deployment from inception, not retrofit it. For mid-market legal, insurance, financial services and accountancy practices, this means your current AI implementation is likely compliant on paper but inadequate in structure.
This story signals a fundamental shift in regulatory philosophy — from 'what rules apply to this AI system' to 'what governance capability does this firm need to *stay* compliant as AI evolves'. The FCA's Consumer Duty PS22/9 and the SRA Code already require this thinking for legal firms; the ICO's UK GDPR guidance does the same for data. What is new is that regulators are now saying they cannot write the detailed rules fast enough, so they are delegating the design work back to firms. Firms that wait for prescriptive rules — or copy competitor implementations — will be behind. Firms that build adaptive governance frameworks now will find that competitive advantage persists because regulators will eventually codify what *works* in practice, not what sounded safe theoretically.
Trovix's position is this: most AI products are designed for the tasks they automate — contract analysis, document classification, matter intake — not for the governance context in which they operate. Products like Harvey and Luminance are technically sophisticated but leave governance ownership entirely with the user. That is appropriate for their design. But it means your firm owns the governance risk. The alternative is to build governance infrastructure *alongside* AI deployment, not after. This requires three things: first, real-time monitoring of how AI systems are being used (not compliance audits six months later); second, proactive regulatory change detection so you adapt before rules change; third, a compliance dashboard that connects AI system behaviour to regulatory requirements, not just to policy documents. Trovix Watch and Trovix Audit exist precisely because firms told us the market had no way to do this at speed.
What should your firm do now? First, audit your current AI deployments — not just which tools you use, but how they are *governed*. If you can answer 'what changed in FCA thinking about AI last month' in under two minutes, you have a monitoring problem. If you cannot show how your AI system decisions map to a specific regulatory requirement, you have a governance design problem. Second, stop treating AI governance as a compliance burden. Rathi's point is that regulators will give firms credit for doing this well, because they have no alternative. Third, build or buy capability that monitors regulatory change in your sector continuously — the days of annual compliance updates are ending. Your competitors are already doing this.
Source: CNBC