The FCA admits regulation cannot keep pace with AI. That is not permission to move recklessly. Mid-market UK firms need a different strategy: documented, auditable, defensible AI — not the fastest AI.
AI Governance  Trovix SiftLegal · Insurance · Financial Services · Accountancy

Nikhil Rathi's warning in early July was not subtle: traditional rulemaking cycles cannot keep pace with AI development, especially as agentic AI systems become more autonomous and harder to predict. For mid-market legal, insurance, financial services and accountancy firms in the UK, this admission from the FCA's top regulator should land like a wake-up call. You cannot treat AI governance as a box-ticking exercise against existing frameworks. The FCA Consumer Duty (PS22/9), SRA Code of Conduct for Solicitors, PRA SS1/23 on operational resilience, and the emerging UK implementation of the EU AI Act all assume humans remain in control of material decisions. Agentic AI — systems that can initiate actions, negotiate, and execute tasks with minimal human supervision — breaks that assumption. Waiting for definitive regulatory guidance before deploying AI is now a competitive disadvantage, not a compliance virtue.

What Rathi articulated is the gap between the speed of innovation and the speed of rule-making. The pattern is already visible: firms using general-purpose foundation models with minimal guardrails are moving fastest. Those building bespoke, documented, auditable AI workflows are moving slower but sleeping better. The real problem is that neither approach has a clear regulatory home yet. The EU AI Act will apply to UK firms trading with EU clients, but its classification of financial services and legal AI as high-risk still leaves operational ambiguity. Meanwhile, regulators are asking for 'collaboration' and 'new tools' — code for: we don't have the framework yet, please help us build it. That leaves mid-market firms in a vacuum. The big players (Magic Circle firms using Harvey, tier-one insurers piloting Luminance, Goldman Sachs deploying custom agents) can afford regulatory ambiguity because they have compliance teams and legal budget to absorb the risk. Mid-market firms cannot.

Trovix's position is this: do not wait for perfect regulation, but do not deploy imperfect AI either. The difference between betting on generic LLMs wrapped in Copilot interfaces and building documented, domain-specific AI systems is not academic — it is the difference between a compliance liability and a compliance asset. When the FCA or ICO comes asking questions (and they will), you need to show: what data went in, what rules governed the model, how decisions were logged, who audited the output, where the human remained in control. Tools like Trovix Sift for document intelligence are inherently auditable because they extract structured data from defined sources and make decisions against documented business rules. That is not flashy. It is not agentic. But it is defensible. Compare that to a Copilot instance told to 'summarise this client file' — you have no idea what the model hallucinated, what it trained on, or whether it met your Data Protection Impact Assessment. One approach makes regulators nod. The other makes them investigate.

Here is what you should do in August 2026: First, map your current AI use cases. Which ones are genuinely agentic (making autonomous decisions that affect client advice, claims decisions, or financial counsel)? Which are augmentative (helping humans work faster on defined tasks)? Second, for augmentative use cases, document your framework now — data sources, decision rules, audit trail, human sign-off. This is not burdensome; it is your insurance policy. Tools like Trovix Watch can track emerging regulatory signals so you spot changes before they become enforcement actions. Third, for any genuinely agentic AI you are considering, pause. Work with your regulator informally (the FCA has sector chairs for this). Do not assume that because Lloyds of London is running agents, or because the EU AI Act has a 'sandbox' provision, you can deploy first and adjust later. You cannot. Mid-market firms have less margin for error. The firms that win in this regulatory gap are not the ones moving fastest with off-the-shelf models. They are the ones being deliberate about what AI does, why it does it, and who remains accountable.

Source: CNBC

Related Trovix product:

Trovix Sift →Book a demo →