The FCA is telling you something important: the AI tools you are installing right now may not survive the regulatory scrutiny coming in six months. The issue is not regulation itself — it's that most firms are deploying AI products designed for speed, not for the transparent, auditable risk manageme
AI Governance  Trovix AriaLegal · Financial Services · Insurance · Accountancy

On 3 July, Nikhil Rathi, CEO of the FCA, warned that traditional rulemaking cycles cannot match AI's pace. That sounds like regulators are falling behind. They are not. What Rathi is actually saying is this: firms cannot wait for final rule books before they act. Instead, they must build AI implementations that are transparent, explainable, and continuously monitored — because regulators will inspect them long before any formal AI Rulebook lands. For any mid-market legal, insurance, financial services or accountancy firm running AI in client-facing work, document review, risk assessment or compliance flagging, this is the core message: if you cannot explain what your AI did, why it did it, and how you caught it when it got it wrong, you have a compliance problem now, not when the rules arrive.

This story reflects a fundamental shift in how regulators approach AI governance. The EU AI Act is now live. The FCA has published its AI framework. The PRA's SS1/23 guidance on artificial intelligence governance sits on every prudential bank's desk. Lloyd's of London has embedded AI audit requirements into its Blueprint Two underwriting standards. None of these frameworks waits for perfect knowledge of AI behaviour. Instead, they demand proportionate risk assessment, human-in-the-loop validation, audit trails, and regular testing — all of it now. The pattern is clear: regulators are moving towards a 'governance-first' model where the proof of safe AI lies not in the AI itself, but in how a firm manages, monitors and explains it. Firms still buying off-the-shelf generalist AI tools and hoping regulation will not touch them are gambling.

Here is where most firms go wrong. They buy Harvey for contract review, or Microsoft Copilot for general document work, or a general-purpose RAG system for knowledge retrieval, install it, train their teams, and assume compliance follows naturally. It does not. These tools are designed for productivity, not auditability. They do not log why they made a decision. They do not flag confidence levels in a way compliance teams can act on. They do not separate human input from AI output in a way that satisfies SRA Code requirements or FCA Consumer Duty PS22/9 obligations. They do not create the forensic audit trail that ICO UK GDPR inspections and ISO 42001 internal audits now require. The gap between 'this AI saves our fee-earners time' and 'this AI is compliant with our regulatory obligations' is where most mid-market firms are sitting right now. It is the gap between a productivity choice and a governance choice. Trovix Aria and Trovix Audit are built into this governance model from the start — they log decisions, flag confidence, separate human and AI work, and create the audit trail regulators expect to see. That is not a nice-to-have. After 3 July, it is a baseline.

If your firm has AI in production today, run an audit within the next four weeks. Ask these specific questions: Can your compliance team see every AI decision made on every document or case? Can they see the reasoning — not just the output? Can they measure the error rate and spot patterns in failure? Can they produce a log of that AI's decisions for any client or regulator on demand? If the answer to any of these is 'no', or 'we would have to ask the vendor', you need to change either the tool or how you use it. Mid-market firms do not have the leverage to demand governance APIs from Microsoft or OpenAI. You do have the option to deploy AI products built by firms that understand UK regulated work — firms that understand that 'AI that works' and 'AI that is compliant' are not the same thing. Start with Trovix Sift for document intelligence if you are drowning in data review. Start with Trovix Audit if you already have AI in use and need visibility. But do start. The FCA just told you the window for hoping regulation stays theoretical is closed.

Source: CNBC

Related Trovix product:

Trovix Aria →Book a demo →