Eighty-seven percent of UK regulated firms have deployed agentic AI without governance in place. That is not agility—it is regulatory exposure. The firms that close this gap now will thrive; those that wait will explain themselves to regulators.
AI Governance  Trovix AuditLegal · Insurance · Financial Services · Accountancy

The Red Hat survey is not surprising, but it should terrify regulated firms. Eighty-seven percent of UK IT leaders have deployed agentic AI systems, yet only a quarter have established governance frameworks to control them. Worse: less than half know where their data actually lives once it enters an AI system. For legal practices, insurers, financial services firms and accountancies, this is not a technology problem—it is a regulatory breach waiting to happen. The FCA Consumer Duty (PS22/9), SRA Code of Conduct, PRA SS1/23, and ICO UK GDPR all require demonstrable control over data and decision-making systems. Operating agentic AI without visibility is operating blind. And regulators know you are doing it.

This gap reflects a wider industry pattern: speed without structure. Firms saw the productivity gains from ChatGPT, Claude and Copilot. They saw competitors moving fast. They deployed. They did not ask themselves whether they could explain what the system was doing, where client data was being processed, who had access to it, or whether output decisions could be audited. The vendors—whether consumer-grade tools or enterprise platforms like Harvey, Legora and Luminance—rarely walk firms through the governance question during a demo. Vendors sell capability, not compliance. And most mid-market firms lack the in-house AI risk expertise to retrofit governance after deployment. By September 2026, this pattern is calcifying: large regulated firms have built centres of excellence and control frameworks; smaller and mid-market firms have drifted into shadow AI deployment, leaving themselves exposed.

Trovix's position is clear: agentic AI is not the problem. Ungovernled agentic AI is. The firms in that Red Hat survey deploying Harvey or Copilot without a documented AI audit trail, data processing map, or approved use policy are not being innovative—they are being negligent. Real governance means knowing which AI system is making which decision, why it was chosen, where client or customer data flows, who approved it, what happens when it fails, and whether output can be explained to a regulator. That takes discipline. It takes tools—specifically Trovix Audit, which maps AI governance posture and compliance readiness—and it takes honesty about which AI tasks actually need human oversight (most of them) versus which can safely run autonomous (fewer than most firms think). The comparison is instructive: a firm using Copilot to draft an email is different from using it to approve a loan decision. One is productivity. The other is delegation without control.

If you are a mid-market law firm, insurance broker, financial services firm or accountancy practice, act now. Run an audit of every AI system in use—whether officially approved or not. Map where data goes. Identify which decisions are autonomous and which are human-in-the-loop. Document your AI governance framework and present it to your compliance team and, if required, your regulator. If you do not have a framework, build one using ISO 42001 as your starting point. Then measure yourself against it quarterly. The firms that did this in 2025 are now compliant and confident. The firms that did this in August 2026 are playing catch-up. The firms doing it now are ahead. The firms doing nothing are facing FCA intervention, SRA censure, or worse.

Source: Computer Weekly

Related Trovix product:

Trovix Audit →Book a demo →