Nikhil Rathi's warning that traditional rulemaking cycles cannot match the speed of AI development is not a prediction—it is a statement of fact already reshaping how regulated firms must operate. The question is whether your compliance infrastructure is built for speed or for yesterday's rulebook.
Regulatory Watch  Trovix AuditLegal · Financial Services · Insurance · Accountancy

On 3 July, the FCA's chief executive made a statement that should be pinned above every compliance officer's desk in the City and beyond: the traditional cycle of regulation simply cannot keep pace with agentic AI. Rathi was explicit about the problem. Old-style rulemaking takes time—consultation, impact assessment, parliamentary process, implementation. Meanwhile, AI development operates in months. For mid-market law firms, insurers, financial services firms and accountancy practices, this means the rules you are complying with today may be obsolete by the time you finish implementing them. The FCA's Consumer Duty PS22/9 and the SRA Code remain the framework, but both were written before agentic AI moved from research to production. Rathi called for 'collaborative tools' to close the gap. What he meant, in plain English, is that regulation and the firms it governs must work together in real time, not in five-year cycles.

This is part of a much larger shift that most regulated firms have not yet internalized. The EU AI Act came into force with hard rules about 'prohibited' and 'high-risk' systems. Harvey, one of the most widely adopted legal AI tools, has built its entire compliance story around predefined boundaries. Luminance and others follow the same pattern: design the system to comply with known rules, then deploy. But agentic AI—systems that can operate autonomously within parameters—breaks that model because you cannot predict all the scenarios the system will face. The PRA's SS1/23 guidance on operational resilience and the ISO 42001 standard on AI management systems both assume human oversight and defined decision trees. Agentic systems, by definition, escape both. Rathi's real warning is not about rule-breaking. It is about the inadequacy of compliance-by-design when the thing being designed is moving faster than the rules.

Here is Trovix's view: the firms that will survive this transition intact are not the ones buying off-the-shelf AI solutions and hoping compliance catches up. They are the ones building visibility into what their AI systems actually do. This is not the same as buying an AI tool. Most legal and insurance AI products—even good ones like Luminance or Microsoft Copilot—give you an audit trail. They do not give you real-time governance. Trovix Audit was built specifically for this problem: not to tell you whether your AI is 'compliant' by yesterday's standards, but to show you, continuously, what decisions it is making and where the drift happens. The ICO's UK GDPR guidance now explicitly warns about automation bias and drift. The FRC's ISA UK standards require documentation of control effectiveness. When Rathi speaks of 'collaborative tools,' he means the ability to show regulators—and yourselves—what your AI is actually doing, in real time. Most AI implementation stories focus on productivity gains. The compliance story is about visibility. Without it, you are building on sand.

What should a mid-market firm do on Monday morning? First: audit your existing AI deployments with brutal honesty. If you cannot answer the question 'What decision did this system make and why?' within 48 hours, you have a governance problem, not a technology problem. Second: stop waiting for the rulebook to be finished. The FCA, SRA, PRA and ICO are not going to produce a comprehensive AI compliance manual before agentic systems become essential. Instead, build a compliance infrastructure that is asset-light and speed-focused. This means moving away from static policies and towards continuous monitoring. Lloyd's Blueprint Two and the FCA's market integrity work both point in the same direction: regulators now want to see evidence of adaptive governance, not compliance artifacts. Third: choose your AI tools carefully. Not because they are the most capable, but because they integrate with governance infrastructure. If your AI assistant—whether it is Trovix Aria or another product—cannot feed data into a real-time compliance dashboard, you have chosen wrong.

Source: CNBC

Related Trovix product:

Trovix Audit →Book a demo →