The Red Hat survey should terrify every partner, compliance officer and general counsel in regulated UK firms. Deploying agentic AI without governance frameworks is not innovation—it is negligence dressed as ambition.
AI Governance  Trovix SiftLegal · Insurance · Financial Services · Accountancy

A Red Hat survey published in April 2026 reveals that 87% of UK IT decision-makers have rolled out agentic AI systems, yet only 25% have built strong governance to control them. Worse: fewer than half can say where their data lives. For regulated firms—law practices bound by the SRA Code, insurers under the FCA's Consumer Duty PS22/9, financial services firms subject to PRA SS1/23, and accountancies answerable to the FRC—this is not a statistic. It is an indictment. Every AI system touching client data, premium data, investment data or audit data must be auditable, explainable and reversible. If you cannot say where your data is processed, you cannot comply with the ICO UK GDPR. If you cannot audit your AI decisions, you cannot defend them to a regulator. The gap between deployment speed and control governance has become dangerous.

This survey captures a wider pattern: the industry has fallen in love with AI capability while pretending governance is a thing you bolt on later. It is not. Tools like Microsoft Copilot and Harvey have made it easy to drop a large language model into a workflow. But ease of deployment is not the same as safety in a regulated context. Generalist LLMs were built to be flexible, not compliant. Agentic systems—those that make decisions and take actions without human review—amplify this risk exponentially. The EU AI Act classification of high-risk systems is coming. The Lloyd's Blueprint Two is already here. ISO 42001 certification will soon become table stakes. Yet most UK regulated firms are still treating AI governance as a security team problem, not a business and compliance problem.

Trovix's view is this: if you cannot see it, you cannot control it, and if you cannot control it, you should not deploy it. The governance crisis revealed by this survey stems from a false choice: either you move fast and break compliance, or you move slow and lose market share. That is a choice only bad organisations face. The right approach starts with visibility and auditability before agents touch live data. Trovix Audit exists precisely because we saw firms deploying agentic systems and then asking us—after the fact—where their data was going. That should never happen. Unlike point solutions that bolt governance onto existing systems, Trovix Audit is built to map what your AI agents are actually doing: which documents they touch, which data they retrieve, which decisions they influence, and whether those decisions are explainable to a regulator. This is not afterthought compliance. It is engineering from first principles.

If you are a partner or general counsel in a mid-market regulated firm, here is what you should do this month: conduct a data audit of every AI system currently in production or pilot. Find out which systems have access to client data, customer data or proprietary data. Ask your IT team to map the data flows. If they cannot answer in two weeks, you already have a problem. Then establish a decision: will you deploy only AI systems you can explain to your regulator, or will you keep rolling the dice? If the former, you need governance infrastructure in place before you expand use. If the latter, document that risk decision and reserve money for remediation. The 25% of firms with strong governance will not be penalised by regulators. The 75% without it will be.

Source: Computer Weekly

Related Trovix product:

Trovix Sift →Book a demo →