The Red Hat survey landed in April 2026 and it should have landed like a brick. Eighty-seven per cent of UK business IT decision-makers are running agentic AI systems—the kind that make autonomous decisions, access data, and interact with customers and third parties. Yet only 25% have strong governance frameworks around them. For mid-market law firms, insurance brokers, financial advisers and accountancy practices, this gap is not academic. It is a direct collision with FCA Consumer Duty PS22/9, SRA Code requirements on competence and technology, PRA SS1/23 operational resilience expectations, and FRC ISA UK audit standards. Every regulator now expects firms to know what their AI systems are doing, who trained them, what data they touch, and who is accountable when they fail. Three-quarters of UK IT leaders cannot answer those questions about their own deployments.
This is not the fault of the technology. It is the fault of how most firms have bought and deployed it. The industry pattern is clear: teams run pilots with vendors like Microsoft Copilot, Harvey, Legora or Luminance—good products in their lanes—then roll them out into production because the ROI looks fast and the friction feels low. Governance gets bolted on later, if at all. Nobody asks whether the model has been tested on firm data that contains privilege, confidentiality or third-party secrets. Nobody documents the decision-making logic for audit trails. Nobody agrees accountability lines with the vendor. Nobody maps data flows through ISA UK or ICO UK GDPR lenses. By the time compliance or the audit partner asks the hard questions, the system is entrenched and the shortcuts are baked in. That is the pattern this story reveals: AI adoption has outrun AI stewardship.
Trovix's view is different. We believe regulated firms cannot outsource governance to product features or vendor promises. Agentic AI that touches client data, makes decisions or generates advice must be deployed within a documented control framework from day one—not after. That means: (1) mapping exactly what data flows into the system and under what retention and deletion rules; (2) defining the human sign-off gate for autonomous decisions; (3) creating an audit trail that satisfies FRC ISA UK section 315 expectations; (4) testing the model against edge cases and bias; (5) naming the person accountable if it fails. This is not about being anti-AI. It is about refusing the false choice between speed and safety. Tools like Trovix Watch exist to monitor regulatory change in real time so you know when your governance framework needs to flex. Tools like Trovix Sift help you understand exactly what data you are feeding into agents before you feed it. That is the opposite of how most firms today deploy agentic AI—and it shows in the survey results.
If you are a partner or compliance officer at a mid-market firm and you have deployed agentic AI in the last 18 months without documenting a governance frame, act now. Audit season is coming. FCA thematic reviews on operational resilience and outsourcing are live. The EU AI Act is already shaping expectations even for UK-only firms. Pull a simple map: what agentic AI systems are you running? What data do they touch? Who trained the model? Who signs off its outputs? What happens if it fails? If you cannot answer those questions in the next two weeks, you have a problem. If you can, you need to prove it to your auditors and your regulator. Neither will accept 'the vendor handles it'.
Source: Computer Weekly