The Red Hat survey is a mirror held up to a problem that has been obvious for eighteen months: UK firms are deploying agentic AI systems at scale without the governance infrastructure to control them. Eighty-seven per cent of IT decision-makers use these systems. Only 25% have strong governance in place. For regulated firms — law practices, insurers, asset managers, accountants — this is not a capability problem. It is a compliance problem. Under the FCA Consumer Duty PS22/9, the SRA Code of Conduct, PRA SS1/23, and the ICO's UK GDPR enforcement stance, firms have a duty to know where client data goes, how it is processed, and who can access it. The survey reveals that less than half of respondents have complete visibility of their data. That is not a gap. That is exposure.
What this story really reflects is the speed-adoption trap. The market pushed agentic tools — Microsoft Copilot, Harvey, Legora, Luminance and others — into production faster than governance frameworks could follow. These are powerful products. Harvey has genuine traction in legal research. Luminance's document intelligence works. Copilot's integration is seamless. But deployment without governance is like giving a powerful tool to someone who has not been trained in how to use it safely. Firms see productivity gains and move fast. Regulators move slowly. The gap between those two speeds is where the risk lives. The EU AI Act, already in force, and Lloyd's Blueprint Two's emerging guidance on algorithmic risk, are tightening what 'acceptable' looks like. UK firms are building the guardrails after the building is already occupied.
Here is what Trovix believes should happen differently. Governance has to precede or run parallel to deployment, not follow it. It cannot be a compliance checkbox added later. It has to be integrated into how AI is chosen, tested, and monitored from day one. That means real visibility — not just knowing that agentic AI exists in your firm, but knowing which data feeds it, who trained it, what decisions it influences, and how you would detect if it failed. Most firms today have that visibility nowhere. They have scattered tools, spreadsheets, and hope. Trovix Audit exists specifically because that gap exists. It gives regulated firms a single place to see what AI is running, where data flows, compliance status, and audit trail. Compared to the approach of 'deploy first, govern second', or the approach of 'use a general-purpose AI governance tool designed for tech companies', the regulatory-first design matters. Your regulator will ask you questions in an enforcement interview. You need to answer them clearly, in real time, with evidence.
If you run a mid-market law firm, insurance broker, wealth management operation or accountancy practice, the action is clear. First: audit what AI systems are actually in use right now — not what you think is in use. Second: map your data flows into those systems. Third: establish what governance you actually have versus what you need under your specific regulator's expectations. Fourth: do not wait for a regulatory letter to do this. The firms that move now will have data and controls. The firms that wait will be explaining gaps during enforcement. Trovix Audit is one way to do this systematically. A spreadsheet and good intentions is not.
Source: Computer Weekly