The FCA admits regulators cannot keep pace with AI development. UK firms interpreting this as a timing problem are wrong—it is a governance problem, and your compliance strategy needs to change now.
AI Governance  Trovix BriefLegal · Financial Services · Insurance · Accountancy

Nikhil Rathi's warning in early July was not new—but it was candid. The FCA CEO admitted that traditional rulemaking cycles cannot match the speed of AI development, especially agentic systems that make autonomous decisions in financial crime detection, underwriting and claims. For mid-market UK regulated firms, this translates into a single uncomfortable truth: your compliance obligations are being written in real time, and regulators themselves don't yet know what they will be. The FCA Consumer Duty PS22/9, the PRA's SS1/23 on operational resilience, and emerging expectations around AI governance are all being interpreted differently across firms. You are being judged against a moving target.

This is not a temporary regulatory lag. It is the permanent condition of AI in regulated sectors. The EU AI Act, ISO 42001 and the ICO's UK GDPR guidance are all attempting to build frameworks for technologies that change faster than compliance can accommodate. What Rathi and his peers are really saying is that they are abandoning the old model—pre-approval, then market deployment—in favour of collaborative, continuous monitoring. This shift terrifies mid-market firms because it means compliance is now an operational function, not a box-ticking exercise. You cannot buy an AI system, implement it, and assume you are compliant for three years. You have to defend your deployment decisions against criteria that don't yet exist.

This is why the market's current approach to AI in regulated firms is flawed. Tools like Harvey and Luminance sell themselves on capability—document review speed, legal research depth, pattern recognition. They are good at those things. But they were not built with regulatory uncertainty in mind. They assume stable rules and stable use cases. Firms using them are often retrofitting compliance—running internal audits after deployment, discovering gaps, and scrambling to justify risk decisions. Trovix's approach is different. We assume the rules will change. That is why Trovix Watch exists—not to tick a compliance box, but to flag the moments when your current implementation needs defending or rethinking. Tools like Trovix Sift and Trovix Aria are built with explainability and audit trails built in, not bolted on. When a regulator asks you to justify an AI decision, you can show them exactly how it was made.

What you do now matters. First, audit your existing AI systems—not for compliance against rules you know, but for readiness against rules you don't. Second, stop treating AI as a technology problem and start treating it as a governance problem. You need someone accountable for AI risk, not just AI performance. Third, build monitoring into your AI operations. You need to know when your deployment assumptions break, before regulators tell you they have. The firms that will survive the next three years of regulatory churn are not those with the cleverest AI. They are those with the most defensible decisions and the best audit trails. Rathi was telling you that. Listen.

Source: CNBC

Related Trovix product:

Trovix Brief →Book a demo →