The Red Hat survey is damning but unsurprising: three-quarters of UK IT leaders have no real AI governance framework, even as they race to deploy agentic systems. For legal, insurance, financial services and accountancy firms, this is not a technology problem—it is a compliance crisis.
AI Governance  Trovix WatchLegal · Insurance · Financial Services · Accountancy

The numbers from Red Hat are stark. Eighty-seven per cent of UK IT decision-makers now run agentic AI systems—tools that make autonomous decisions, retrieve data, and execute tasks with minimal human intervention. Yet only one in four has strong governance in place. Worse, less than half have complete visibility of where their data is stored and processed. For a regulated firm in financial services, insurance, law or accountancy, this is not a performance metric. It is evidence of a breach. The FCA Consumer Duty (PS22/9) requires firms to understand their material harms. The SRA Code demands competence and supervision over technology. The PRA's SS1/23 explicitly covers AI risk in banking. You cannot comply with any of these if you do not know where your data goes or what your AI system decides to do with it. This survey reveals not innovation; it reveals wholesale non-compliance masquerading as transformation.

What the Red Hat data exposes is a fundamental mismatch in the industry. Commercial AI vendors—from Microsoft Copilot to specialized legal AI platforms like Harvey and Luminance—have made it trivially easy to deploy agentic systems. The barrier to adoption has collapsed. The barrier to understanding what you have deployed has not fallen at all. Most firms treat AI governance as a post-deployment box-tick: write a policy, tick the audit box, move on. The regulatory environment has moved in the opposite direction. The EU AI Act is in force. The ICO's framework on UK GDPR and generative AI tightens by the month. Lloyd's Blueprint Two now requires underwriters to evidence algorithmic accountability. ISO 42001 (AI management systems) is becoming a market expectation, not a nice-to-have. The gap between how fast firms are deploying AI and how slowly they are governing it has become a canyon. This survey is not reporting a trend; it is documenting the eve of enforcement.

Trovix's view is straightforward: agentic AI in regulated firms needs to be governed before it is deployed, not after. That means three things. First, complete visibility of data flows—not 'nearly half' visibility. You need to know what data your agentic AI can access, where it retrieves it from, what it does with it, and where the output goes. Systems like Luminance offer document intelligence, but they are designed for human-in-the-loop review within a firm's own document set. They do not solve the governance problem of systems that autonomously query external databases, call APIs, or route decisions to third parties. Second, real-time governance, not batch compliance. A policy written in 2025 that you audit in 2026 is not governance; it is archaeology. You need continuous monitoring of how your agentic AI behaves—what decisions it makes, what data it accesses, whether its outputs drift from its training intent. Third, explicit human accountability. Harvey and other specialist legal AI tools have built-in provenance and explainability, which is good. But most generic agentic AI deployments simply do not. They optimize for speed, not auditability. A regulated firm cannot afford that trade-off. Trovix Watch exists precisely because the industry has failed to solve this. You need something that monitors regulatory change, yes—but you also need something that enforces what you have decided to monitor, that flags drift, that surfaces where agentic AI systems are operating outside their governance envelope.

What should a mid-market law firm, insurer, financial services firm or accountancy practice do right now? Stop treating agentic AI adoption and governance as separate workstreams. They are not. Before you deploy another agent—whether it is retrieval-augmented generation for case research, autonomous document classification, or decision automation in claims or underwriting—audit where your current deployments actually are. Not where your procurement team says they are. Actually audit. Map data flows. Establish what 'authorized' behaviour looks like for each agent. Build a roll-back plan. Then, and only then, deploy the next one. The firms that will thrive through the next two years of regulatory tightening will not be the ones with the most AI. They will be the ones with the most AI that they can actually explain to a regulator on 48 hours' notice. The Red Hat survey is a warning. Act on it before the ICO, FCA, SRA or PRA do.

Source: Computer Weekly

Related Trovix product:

Trovix Watch →Book a demo →