Nikhil Rathi's warning last month was not subtle: European regulators cannot write rules at the speed AI moves. The FCA's acknowledgement that 'traditional rulemaking cycles don't work when technologies move in weeks or months' is not a problem statement — it is an admission that mid-market UK law firms, insurers, financial services businesses and accountancy practices are now operating in a compliance vacuum. You are using AI tools today (Harvey for legal drafting, Luminance for contract review, standard LLM-powered assistants for client intake) without clear regulatory guardrails beyond vague principles. The FCA Consumer Duty PS22/9, SRA Code and PRA SS1/23 do not address synthetic reasoning, retrieval-augmented generation or agentic workflows. You are compliant on paper and legally exposed in practice.
This gap reveals a structural problem in how regulated industries approach AI adoption. Large firms with dedicated AI governance teams and six-figure budgets for compliance pilots are building proprietary systems with audit trails and human-in-the-loop safeguards. Mid-market firms are buying off-the-shelf products and hoping they are good enough. Regulators are warning that 'collaborative approaches with markets' will replace prescriptive rules — which is regulator-speak for: you will be expected to demonstrate responsible AI governance even though the rules do not yet exist. The EU AI Act, now live, sets classification tiers for AI risk. The ICO's UK GDPR guidance on AI is fragmentary. Lloyd's Blueprint Two and ISO 42001 exist but are voluntary. Every day without a clear governance baseline, you are creating compliance debt.
Here is what Trovix believes: AI tools themselves are not the problem. Luminance's document clustering, Harvey's legal research synthesis, even Microsoft Copilot in your Microsoft 365 estate — these work. The problem is deployment without visibility and control. Most mid-market firms use AI in pockets: one team runs document review on Luminance, another uses Copilot for research, a third implements OCR on intake forms. Nobody has a complete picture of what AI is doing, where it is making decisions that affect clients, or whether outputs are being checked. This is not a technology failure. It is a governance failure. Trovix Watch exists because regulators now expect firms to monitor the regulatory environment in real time — not wait for the next FCA update bulletin. The same logic applies to AI: you need continuous visibility of what your AI systems are doing, not annual audit cycles.
Start here. First, audit what AI you are actually using — not what you think you are using. Second, document the decision points: where is AI influencing client advice, casework outcomes, or risk assessment? Third, design a simple governance loop that shows regulators you have thought about accuracy, bias, data lineage and human override. This does not require perfect rules. It requires demonstrating that you know where AI operates in your firm and that you have chosen to use it deliberately. Trovix Sift helps you understand what data AI systems are processing. Trovix Aria is built with audit trails and source attribution precisely because regulators will ask you to prove your AI is not hallucinating advice. The firms that will survive the inevitable AI enforcement wave are not the ones waiting for final rules. They are the ones building the compliance habits now.
Source: CNBC