Nikhil Rathi and Europe's banking regulators have finally said what mid-market UK firms already know: traditional compliance cycles move at glacial speed compared to AI evolution. When tools like ChatGPT, Claude and specialized platforms like Luminance or Harvey can change their capabilities or outputs in weeks, but your firm's AI governance policy takes six months to draft, you are already behind. The FCA's acknowledgment matters because it signals that regulators will not wait for perfect rules before they start asking questions. If your firm has deployed AI without documented governance frameworks aligned to FCA Consumer Duty PS22/9, SRA Code requirements, or equivalent PRA SS1/23 expectations, you are now exposed.
This story reveals a deeper truth about where the industry actually is: most mid-market regulated firms have implemented AI tools in isolation, reacting to productivity pressure rather than risk. A law firm adds Harvey to speed up contract review. An insurance firm deploys document AI to extract claims data faster. A financial advisory practice uses Copilot for client communication. None of these decisions are bad on their own. But they are being made without the governance infrastructure that regulators increasingly expect. The EU AI Act is now live. The ICO has updated UK GDPR guidance on AI. Lloyd's Blueprint Two now requires underwriting firms to demonstrate AI oversight. Regulators are not saying AI is bad. They are saying the gap between how fast you are deploying AI and how carefully you are managing it has become a systemic risk.
Here is Trovix's honest view: the mistake most firms make is treating AI governance as a compliance box to tick after implementation. They buy a tool, measure its accuracy on a test set, write a risk register entry, and call it done. This does not work because AI risk in regulated settings is not about the tool's raw accuracy—it is about whether you can prove the tool is doing what you said it would do, when it is doing it, and why it failed when it failed. That requires continuous, documented oversight. Tools like Luminance and Harvey are good at what they do, but they are domain-specific solutions. They do not solve the governance problem. This is precisely why Trovix Audit exists: not to replace your AI tools, but to create the governance layer that sits above them. It gives you the audit trail, the performance metrics, the drift detection, and the compliance dashboard that regulators are now asking about. You also need a trusted knowledge layer—Trovix Aria handles that by making your AI outputs traceable to source, so when a regulator asks 'where did that recommendation come from?', you have an answer.
What should you do this week? First: audit what AI you actually have in production. Not pilots. Not experiments. What is live and making decisions or generating outputs that clients or stakeholders rely on. Second: document the governance you have for each tool. Be honest about gaps. Third: identify which of those tools is mission-critical or high-risk under FCA/SRA/PRA standards. For those, implement oversight that actually works—not a spreadsheet, but a system that continuously monitors performance, catches drift, and logs decisions. If you have not already done this, you are now in the position of every firm that deployed AI without thinking about the Prudent Persons test or the accountability principle in UK GDPR. Regulators are moving from warnings to actual supervision. The lag between deployment and governance is closing fast.
Source: CNBC