The FCA is not writing a rulebook for AI. That is good news for innovation and bad news for firms hoping compliance means ticking boxes. Mid-market regulated firms now face a harder question: do you actually understand what responsible AI looks like in your business?
AI Governance  Trovix WatchLegal · Financial Services · Insurance · Accountancy

On 2 July, the FCA CEO confirmed what many suspected: detailed AI rulebooks are not coming. Instead, the regulator will hold firms accountable against existing principles—fair outcomes for customers, governance, transparency, risk management—without prescribing exactly how to get there. For a mid-market law firm, insurance broker, asset manager or accountancy practice, this is simultaneously a relief and a warning. Relief because you are not about to face a compliance checklist as long as PRA SS1/23. Warning because you cannot hide behind 'the FCA didn't tell us to do it.' Under the Consumer Duty (PS22/9) and the SRA Code, principles-based regulation has always been the reality for regulated firms. AI just makes the stakes more visible.

This approach reflects a broader pattern in UK financial regulation: the days of granular, sector-specific rule books are ending. The FCA learned from the EU AI Act that exhaustive prescriptive frameworks tend to ossify before implementation even begins. Meanwhile, firms are already deploying AI—Harvey for contract review, Luminance for anomaly detection, Microsoft Copilot for research—with wildly inconsistent governance behind them. The regulator is effectively saying: we will judge the outcome (did your AI cause customer harm, break fair lending, leak data?) not the specification of your model. That puts the burden of proof firmly on your shoulders.

Here is Trovix's honest view. A principles-based approach only works if you actually have principles. Too many mid-market firms treat AI deployment like software procurement: buy the tool, run it, measure results. That fails under principles-based regulation because you have not documented your risk appetite, tested fairness across protected characteristics (which tools like Luminance can highlight but cannot ensure), or created an audit trail showing you understood what the model does and does not do. The FCA and SRA will not accept 'the vendor told us it was safe.' You need to own the governance. That is why Trovix Audit matters—not as a tick-box exercise, but as the mechanism to prove that you have applied judgment and oversight to every AI decision in your firm. Compare that to approaches that offer 'compliance-ready' AI: those products typically bundle one interpretation of the rules into the system itself. When principles shift (and they will), those systems calcify. You need governance that separates the principle from the tool.

What should you do now? First, stop waiting for FCA guidance on AI. It will be sparse and principle-level. Second, audit what AI you already have deployed—research tools, document review systems, intake automation, analytics—and map it against your existing governance framework. You likely already have obligations under the Consumer Duty, SRA Code, ICO UK GDPR and FRC ISA UK that apply to AI. Third, establish a simple but documented process: before deploying any AI tool (Harvey, Legora, Copilot or anything else), ask three questions: what decision or task is it making, what could go wrong, and how will we know? Document the answers. Use Trovix Watch to track FCA and SRA signals on AI so you are not caught flat-footed when principles do clarify. The regulator is saying it trusts your judgment. Prove them right by actually exercising it.

Source: CNBC

Related Trovix product:

Trovix Watch →Book a demo →