The FCA's decision to avoid prescriptive AI rules is being celebrated as regulatory pragmatism. It isn't. What the CEO actually said—that the regulator won't issue detailed rules and will instead rely on existing principles like Consumer Duty and operational resilience—is a polite way of saying: compliance is your problem now. For mid-market law firms, insurers, financial advisors and accountancies, this means the FCA will judge your AI use against Consumer Duty PS22/9, SRA Code principles (for law firms), PRA SS1/23 (for insurers), and FRC ISA UK standards (for accountants). You will be expected to demonstrate documented risk assessment, vendor accountability, model performance monitoring, and audit trails. Generic AI products—whether that's Microsoft Copilot, Harvey, Legora, or Luminance—are not compliance frameworks. They are tools. The difference matters enormously.
This regulatory stance reflects a broader industry reality: the AI field is moving faster than any regulator can keep up with, and London wants to compete with San Francisco and Singapore on innovation speed. But the FCA is not, in fact, being light-touch. It is shifting the compliance burden from the regulator to the firm. You cannot simply license an AI product and declare yourself compliant. You must operate that product within a documented governance structure. This is why we are seeing parallel movements: the EU AI Act hardening into prescriptive categories, the ISO 42001 standard gaining traction as firms seek measurable governance frameworks, and the ICO UK GDPR guidance on AI becoming more granular. The UK is choosing the principles route; it is not choosing the light-touch route.
Trovix's view is that principles-based regulation is honest and workable, but only if you build real governance first. This means: documented AI use cases tied to client or regulatory outcomes; vendor risk assessment and contractual accountability; performance benchmarking against human baselines; exception reporting and escalation protocols; and auditable decision logs. Many firms treat AI as a productivity hack and regulation as a compliance checkbox. That approach will fail under scrutiny. Tools like Legora or Harvey can perform specific legal tasks well—contract analysis, due diligence, brief drafting—but they do not themselves provide governance. We built Trovix Audit precisely because mid-market firms need visibility into what AI is actually doing, not just what vendors claim it does. We also built Trovix Watch because regulatory change (including soft guidance from the FCA, PRA, SRA, and ICO) is now continuous, and principles-based frameworks require you to stay ahead of interpretation shifts.
Your immediate action: audit what AI you are already using. If you have rolled out Copilot, ChatGPT, or any LLM-powered document tool without documented governance, stop now and create one. Document the business purpose, map it to a regulatory principle (operational resilience, consumer protection, professional competence), assess vendor risk, define what success looks like, and set up monitoring. Do this before the FCA's next thematic review. Second: engage with your regulator's soft guidance, not just final rules. The FCA's AI guidance is live on its website; so is the ICO's. Read them. Third: choose AI tools with native auditability and governance hooks. Trovix Reach and Trovix Brief were built with regulated firms' governance requirements in mind—they produce traceable decision logs and integrate with compliance workflows, not as an afterthought but as the architecture. If your AI vendor cannot answer 'how will my regulator audit this?' then it is not built for the UK market.
Source: CNBC