The FCA's refusal to write detailed AI rulebooks is sensible. But it leaves mid-market regulated firms in a dangerous vacuum where guesswork replaces governance.
Regulatory Watch  Trovix BriefLegal Services · Financial Services · Insurance · Accountancy

In early July, the FCA CEO signalled that the regulator will not be cranking out prescriptive rules on AI use in financial services. Instead, the FCA is betting on principles-based regulation — firms must meet overarching standards like Consumer Duty (PS22/9) and conduct risk management, but they decide how. This is good news on the surface. Detailed rulebooks move slowly, stifle innovation, and often become obsolete before they are published. The EU's AI Act, for all its ambition, is already creating friction in financial services precisely because it defines 'high-risk' systems in ways that do not map cleanly to how real firms deploy generative AI. The UK's approach gives firms breathing room. But breathing room is not the same as clarity.

This news sits within a broader, messy reality: the entire financial services and professional services sector is in a regulatory transition zone. The SRA is watching law firms. The PRA has issued guidance on AI governance (SS1/23). The FCA has its Consumer Duty. The ICO is applying GDPR and the Data Protection Act 2018 to AI training and RAG systems. And all of this sits under the emerging shadow of the UK AI Bill, which may or may not introduce statutory duties on AI developers and deployers. Meanwhile, firms like Harvey (focused on legal AI) and Luminance (document AI in audit and law) have been selling into this grey space with confidence, claiming compliance without always proving it. The regulator's refusal to add new rules is not a green light — it is an acknowledgement that principles-based oversight is all the regulator can manage right now.

Here is Trovix's honest take: principles-based regulation only works if firms have the infrastructure to interpret what 'principles' mean in their specific context. A mid-market law firm cannot simply deploy a generic AI assistant like Microsoft Copilot on client matters and call it compliant with SRA Code of Conduct outcomes just because the FCA is not writing rulebooks. You still have to prove duty of care, information governance, and audit trails. You still have to validate that the AI does not hallucinate legal references. You still have to know what data you are feeding into RAG systems, and whether that breaches client confidentiality. Product vendors like Legora and Harvey have built their pitch around 'purpose-built legal AI', which is code for 'we have baked in some compliance thinking'. But purpose-built does not mean auditable. It does not mean your firm knows what is happening inside the black box. The FCA's light-touch approach actually makes this worse, not better, because it forces each firm to become its own regulator. That is why principles-based regulation demands better governance infrastructure, not less.

If you are running a legal practice, insurance broker, IFA, or accountancy firm right now, the FCA's stance means you should be doing three things immediately. First, map your AI use cases against Consumer Duty outcomes and conduct risk — do not wait for new rules to define risk for you. Second, implement document intelligence and data governance tools that give you visibility into what data is being processed, by which AI, for which client matter — this is not optional compliance theatre, it is the ground truth the regulator will ask for if something goes wrong. Third, monitor regulatory signals across the FCA, SRA, PRA, ICO, and emerging AI Bill consultations. The FCA's refusal to write new rules does not mean regulation is frozen. It means regulation is fragmenting. You need Trovix Watch or equivalent — a way to catch the signal before it becomes a surprise.

Source: CNBC

Related Trovix product:

Trovix Brief →Book a demo →