Nikhil Rathi and Christine Lagarde are right about one thing: traditional rulemaking moves in years, AI moves in weeks. But they are wrong about something more important — they are implying that firms should wait for the rules to catch up before building proper governance. UK regulated firms in law, insurance, financial services and accountancy cannot afford that paralysis. The FCA Consumer Duty PS22/9, SRA Code of Conduct, ICO UK GDPR guidance, and the emerging AI Act expectations are already in place. The gap between regulation and AI capability is not an excuse for inaction; it is a mandate for it. Firms that treat this as a 'wait and see' problem will face enforcement action long before comprehensive rulebooks arrive.
This story reflects a deeper truth the industry has been ignoring: regulation has always lagged technology, but the gap has never been this wide or this consequential. When Excel became the standard risk tool, compliance took two years to catch up. When cloud computing arrived, it took four. AI is moving so fast that regulators are publicly admitting they cannot keep pace — and that admission itself is a regulatory signal. The PRA SS1/23 supervisory statement on AI governance, the Lloyd's Blueprint Two framework for insurance, and early ISO 42001 adoption are all attempts to fill the void with principles-based expectations. These are not nice-to-haves. They are the floor. Firms building proprietary ChatGPT wrappers or buying off-the-shelf tools like Microsoft Copilot without governance layer underneath are building on sand.
The honest truth about AI tools in professional services is this: most products solve implementation problems, not governance problems. Harvey, Legora and Luminance are powerful at what they do — document analysis, contract review, due diligence automation. But they are not designed to solve the question every regulated firm must answer: how do I know this system is doing what I think it is doing, and how do I prove it to my regulator? That requires a different architecture entirely. Trovix Audit exists precisely because firms realized that buying AI capability without visibility into its decisions, biases, and failure modes is the regulatory equivalent of signing off financial statements without an audit trail. You need continuous monitoring of how the system performs, not just at launch but in real use. You need documented decisions about when to use AI and when not to. You need evidence that the thing is actually working as intended across different case types, client demographics, and market conditions.
Here is what to do on Tuesday morning: commission an AI governance audit. Map every AI tool in use — including the ones shadow IT has deployed, the ones you bought on contract but forgot about, and the ones your staff downloaded free. Document the business case for each: where does this reduce costs, where does this create liability, where does this improve client outcomes? Use Trovix Watch to monitor FCA guidance updates, ECB supervisory statements and AI Act implementation timelines so you do not miss the moment when 'guidance' becomes 'expectation' becomes 'enforcement.' Then build the governance layer: who is accountable, how do we test for drift, what is our bias mitigation process, when do we escalate to a human? Use Trovix Audit to document this continuously, because your regulator will not accept 'we did a one-time review in 2026.' They will ask for evidence of ongoing oversight. The firms that move now will have built real governance. The firms that wait for the rules to be written will be six months behind trying to retrofit it.
Source: CNBC