Rathi and Lagarde are right. The gap between AI speed and regulatory capacity is real. But that gap is not an excuse for weak governance—it is a warning that firms without documented controls will be enforcement targets in 2026 and 2027.
AI Governance  Trovix ReachLegal · Financial Services · Insurance · Accountancy

Nikhil Rathi and Christine Lagarde have stated something UK regulated firms need to hear: AI moves at velocity, rulemaking does not, and the gap is now a supervisory crisis. The FCA is not warning about AI itself—it is warning about uncontrolled deployment. For mid-market law firms, insurers, financial advisers and accountancy practices, this is not an abstract problem. The FCA Consumer Duty (PS22/9), SRA Code of Conduct, and PRA SS1/23 all demand that firms govern their tools. If you have deployed ChatGPT, Harvey, Legora or Luminance without documented risk assessment, governance framework, and audit trail, you are already exposed. The regulators know it. They are watching.

The pattern is clear: firms rushed into AI adoption through 2024 and 2025 without building the governance infrastructure first. Some bought point solutions (document review AI, intake automation, research assistants) and bolted them onto legacy systems. Others handed employees access to consumer LLMs and called it innovation. Meanwhile, regulators have moved from curiosity to active concern. The EU AI Act took effect. The FRC published ISA UK guidance. The ICO clarified UK GDPR compliance for AI systems. Lagarde's point about 'inadequate defence funding' is especially sharp—she means firms are not investing in detection, monitoring and response. They are investing in the tool. Not the guard rails.

Trovix's view is direct: AI governance cannot be bought as an afterthought. It must be designed in. That means before you deploy an AI system—whether it is a large language model, a document classifier, or an agentic system—you need three things: first, a written risk assessment tied to your specific firm's regulatory obligations; second, a compliance dashboard that monitors outputs and user behaviour in real time; third, an audit trail that survives a regulatory visit. Tools like Luminance and Harvey are powerful. They work. But they only reduce risk if you own the governance layer above them. Too many firms treat the AI tool as the risk mitigation. It is not. The tool is the exposure. Trovix Audit exists because firms need to see what their AI systems are actually doing, not what the vendor says they do. Trovix Watch exists because regulatory change in AI governance is now happening monthly, not annually, and you cannot outpace it alone.

What should a mid-market practice do right now? First, pause new AI deployments until you have documented governance. This sounds defensive. It is not—it is the fastest path to genuine competitive advantage. Second, audit what you have already running. If you cannot explain to the FCA or SRA how your AI system makes decisions, what data it sees, how you tested it for bias, and how you monitor it, you have a compliance gap. Third, build a governance framework before you scale. The firms that moved fastest in 2025 are now retrofitting controls. The firms that move deliberately now will have clean deployments in 2027. Fourth, stop thinking of AI as a cost-saving measure and start thinking of it as a controlled operational capability—like any other regulated activity. When a law firm deploys document AI under the SRA Code, it is not optional governance. When an insurer deploys claims triage under the Consumer Duty, the output audit trail is mandatory. Rathi and Lagarde are telling you that regulators will enforce this.

Source: CNBC

Related Trovix product:

Trovix Reach →Book a demo →