The FCA's acknowledgment that AI moves in weeks while rulemaking takes years is not a comforting observation—it is a warning shot. Rathi is telling UK regulated firms that the old model of waiting for guidance, implementing, and staying compliant no longer works. The EU AI Act, the ICO's AI governance expectations, the SRA Code updates: all are moving targets. For mid-market law firms, insurers, financial services houses and accountancies, this means compliance cannot be a checkbox exercise. It has to be a continuous practice. You cannot build an AI system in Q1, get it approved in Q2, and assume it is compliant for 18 months. Regulators will shift their expectations faster than your quarterly reviews.
This story is part of a pattern that defines 2026. The PRA, FCA, SRA, and FRC have all moved from prescribing *which* technologies you can use to asking *how* you govern the ones you choose. The ECB's warning about cybersecurity risk shows the problem is not AI itself—it is unmanaged AI. Firms like Harvey and Legora have built their entire pitch on the idea that large language models can be dropped into legal and insurance workflows with minimal risk. That assumption is increasingly exposed. Generic LLM-based tools do not automatically meet Consumer Duty PS22/9 standards or FRC ISA UK audit governance. Luminance's approach—layering industry-specific guardrails and bias detection—comes closer, but even that only works if firms audit their own implementation regularly. The collaborative regulatory model Rathi describes means you will be expected to show your governance, not just show compliance.
Here is what Trovix believes needs to happen: firms should move away from treating AI as a technology problem and start treating it as a governance problem. That means real-time tracking of regulatory changes (not quarterly policy reviews), documented decision-making about which AI tools fit your risk profile, and continuous audit trails showing how your AI systems performed against your own standards and regulatory expectations. Microsoft Copilot in your practice management system is not inherently risky—but using it without documenting your data classification, your bias testing, or your audit log is. The firms that will win the next five years are those that treat AI governance as a competitive advantage, not a compliance cost. Trovix Watch exists because firms need to stop reactive compliance and start anticipatory governance. Trovix Audit exists because compliance teams cannot audit what they cannot see—and most firms today cannot see inside their own AI deployments.
If you are running a 50–500 person firm, your action list is short but urgent. First: inventory every AI tool you are using or planning to use—not just the obvious ones like document review platforms, but Copilot, ChatGPT in email workflows, generative intake forms. Second: map each against your regulatory obligations. A Trovix Watch scan takes two weeks and will show you which regulatory shifts matter to your AI choices. Third: establish a governance working group that reviews AI risk at least quarterly, and document every decision. The SRA, FCA, and FRC all expect to see this trail. Fourth: pilot bias testing and output validation on your highest-risk use cases before they become enforcement targets. The firms caught out by the next wave of regulatory action will not be those using AI—they will be those using AI without evidence of deliberate governance.
Source: CNBC