A Red Hat survey of 500 UK IT leaders reveals that 87% have deployed agentic AI systems, but only 25% have implemented strong governance controls. Worse: less than half of UK respondents can account for where their data is stored or processed. For regulated firms in law, insurance, financial services and accountancy, this is not an interesting data point. It is a regulatory emergency. The FCA's Consumer Duty PS22/9 demands that firms understand and manage AI risks. The SRA Code requires solicitors to act with integrity and in accordance with the law. The ICO's UK GDPR guidance is explicit: deploying AI without visibility of data processing is a breach. Yet three-quarters of IT leaders lack strong plans to close this gap. Your firm is almost certainly among them.
This pattern reflects a fundamental imbalance in how the market has developed. Generalist AI products—Copilot, ChatGPT, Claude—solved an immediate problem: generating text faster. They were easy to deploy, required little integration work, and felt transformative. So firms bolted them onto their workflows. Agentic AI systems went further: autonomous document review, automated reasoning, unsupervised data processing. These products are genuinely powerful. Harvey's legal brief summaries, Luminance's contract analysis, even Legora's intake automation—they work. But power without control is liability. The survey data shows what happens when deployment speed exceeds governance speed. Firms built the car before they fitted the brakes.
Trovix's perspective on this is direct: AI governance cannot be an afterthought or a compliance checkbox. It has to be baked into how you choose, deploy and monitor AI systems from day one. That means three things. First: data visibility. You must know, with certainty, where client data and proprietary information flows when an AI system processes it. Generic SaaS tools like Copilot fail this test immediately—your documents go to Microsoft's cloud infrastructure, and your visibility ends. Second: audit and control. You need continuous monitoring of what the AI is actually doing, not just what it claims to do. A system that passes its validation test in month one may drift in month six. Third: segregation by risk. Not all AI use cases carry the same regulatory weight. A knowledge assistant for internal fee-earner research (like Trovix Aria) is lower risk than an autonomous system making decisions about client funds or insurance claims. This tiering has to drive your governance architecture. Trovix Audit was built on this principle: governance as a live, repeatable process, not a static document.
Here is what a mid-market firm should do immediately. First: audit what you're currently running. Not what you think you're running—what you're actually running. Include shadow AI: the ChatGPT instance a partner uses, the Claude subscription bought on a corporate card, the generic automation tools embedded in your case management system. Second: map your data flows. Where does client information go when it touches an AI system? Third: prioritise. Not all AI use is equal. Routine document extraction poses different risks to autonomous decision-making. Focus your governance resources where the regulatory and reputational exposure is highest. Fourth: choose tools that were built with governance in mind, not bolted on afterwards. If a vendor cannot give you data residency guarantees, audit trails, and compliance documentation aligned to FCA, SRA and ICO standards, it is not fit for regulated use. The cost of implementing proper governance now is a fraction of the cost of an ICO enforcement action, an SRA disciplinary hearing, or an FCA fine for failure to manage AI risk.
Source: Computer Weekly