Jamie Dimon's newly expanded Alliance for Critical Infrastructure is solving for the wrong problem. Yes, 40+ companies coordinating on AI-related cyber and operational risks sounds sensible. Yes, financial services firms need to talk to government about threat prevention. But here is what the story actually reveals: major institutions are still treating AI risk as a cyber problem when the real risk — for UK regulated firms especially — is governance and control. The FCA Consumer Duty PS22/9 and PRA SS1/23 do not care if you have a fancy alliance. They care whether you can prove that your AI systems are doing what you say they do, that they are not breaching client trust, and that you can explain decisions back to regulators. JPMorgan's coalition addresses infrastructure resilience. It does not address model drift, hallucination, bias, or the audit trail that FCA and SRA will demand the moment something goes wrong.
This story is a symptom of where the industry actually is right now: still in denial about the gap between AI capability and AI accountability. We see it everywhere. Firms buy Harvey or Luminance for document review and assume the risk is managed because the vendor says so. They deploy Microsoft Copilot across practice because it is cheap and fast. They do not ask the hard questions: can we explain this recommendation? What training data was used? What guardrails exist? How do we prove compliance to the regulator? The Alliance announcement is telling because it skips these questions entirely. It is easier to talk about defending against external threats than to admit that most regulated firms have no real governance layer around their own AI systems. That gap — between deployment speed and governance depth — is where liability lives.
Here is Trovix's honest take: this industry alliance is necessary but insufficient. Cyber resilience matters. Cross-sector coordination matters. But it will not protect a mid-market legal firm, insurer, financial services firm or accountancy practice from regulatory action because it does not touch governance. You need three things simultaneously: first, a way to see what AI systems are actually doing in your practice (not marketing claims, actual behavior); second, a way to document and prove that behaviour to auditors and regulators; third, a way to know when something changes — model updates, vendor changes, regulatory changes — that could affect your compliance posture. That is why Trovix Audit exists. It is not a cyber product. It is not an alliance. It is a governance layer that sits between your AI systems and your audit file. Trovix Watch complements it by tracking regulatory changes — FCA rules, SRA guidance, EU AI Act implementation, ICO UK GDPR decisions — so you know when your AI governance assumptions have become obsolete.
If you are running a mid-market firm and you read this JPMorgan story and thought 'good, my vendor is part of that,' you are not thinking about the real risk. Talk to your tech team this week about three specific questions: (1) Can you produce, right now, a complete list of every AI system in use, what data it touches, and what decisions it makes? (2) Do you have an audit trail that proves your AI outputs are consistent with your documented policies? (3) Do you have a process that tells you immediately when regulatory guidance changes and might affect your AI use? If the answer to any of these is no, you have a governance problem that no industry alliance will solve. That is where you need to invest.
Source: Reuters/PYMNTS