The Red Hat findings published in April 2026 expose a structural problem: 75% of UK IT leaders lack strong AI governance plans, and only 48% have complete visibility of where AI data is stored and processed. For law firms, insurers, financial services firms and accountancy practices, this is not an abstract technology problem—it is a regulatory time bomb. The FCA's Consumer Duty (PS22/9), the SRA's Code of Conduct, and the ICO's GDPR enforcement have set a clear standard: you must know what your systems do, where your data goes, and why. When an AI system makes a decision that affects a client or a regulated outcome, you cannot answer 'we don't know where the data is processed' without risking enforcement action, fines, and reputational damage. The story arrived too late: by September 2026, the question is no longer whether firms need AI governance. They need it now.
This data reflects a wider pattern in the UK regulated sector. Firms have been seduced by the promise of AI tools—Harvey for legal document review, Luminance for contract analysis, Microsoft Copilot integrated into M365, Legora for insurance workflows. Many of these products are genuinely useful. But adoption has outpaced infrastructure. Firms bought the tools without building the governance layer underneath. They did not ask: where does this model train? What happens to my client data? Who owns the output? Can I audit the decision? The EU AI Act, now influencing UK practice, has made these questions formal requirements. UK firms in regulated sectors now face a cascade of obligations—ISA UK audit standards, PRA SS1/23 on third-party risk, Lloyd's Blueprint Two for insurance governance—that all demand the same thing: documented, auditable, visible AI systems. The 89% of UK respondents demanding open source AI principles is telling: firms are desperate for transparency because proprietary black boxes no longer feel safe.
Trovix's view is this: governance must come before deployment, not after. Too many firms are trying to retrofit governance onto systems already in production. They use point tools—document AI for extraction here, a knowledge assistant there—without connecting them to a coherent data and compliance architecture. The result is fragmentation: different systems, different data retention policies, different audit trails, impossible to defend to a regulator. The answer is not to ban AI or to move slower. It is to start with visibility. You need to know: what data enters your AI system? Who trained the model? Where is it hosted? What is the audit trail? Can you explain the output to a client or a regulator? Only then do you deploy at scale. Trovix Watch exists precisely because firms need continuous visibility into regulatory change and how it applies to their AI stack. Trovix Sift and Trovix Aria are built with governance first: they process your data, they show you what they did, you control the output. That is the difference between a tool and a system you can defend.
What should a mid-market regulated firm do on Tuesday morning? First: audit what AI systems are already running in your practice. Document them. Second: map your data flows. Where does client information go when it enters a generative AI system? Third: connect those flows to your governance framework—your FCA, SRA, or ICO obligations. Fourth: do not wait for a directive. The firms that will survive the next round of regulatory scrutiny are those that can show they knew what they were doing. Governance is not a compliance checkbox. It is competitive advantage. The firms getting this right now will be the ones with the fastest, safest, most defensible AI deployments in 2027.
Source: Computer Weekly