Nikhil Rathi's warning is blunt: traditional rulemaking is broken for AI. But waiting for new rules is not a strategy. Regulated firms need to build compliance into their AI stack today, not tomorrow.
AI Governance  Trovix SiftLegal · Insurance · Financial Services · Accountancy

The FCA's chief has admitted what many in regulated practice already know: the regulatory cycle cannot match the pace of agentic AI development. Rules that take 18 months to write are obsolete before they land. This creates a dangerous vacuum—not because regulators are asleep, but because the gap between innovation and prescription is now measured in months, not years. For mid-market law firms, insurers, financial services and accountancy practices, this is not a theoretical problem. It means the compliance frameworks you rely on are already incomplete. The FCA Consumer Duty PS22/9, the SRA Code, the PRA SS1/23—these are all solid foundations. But they do not address how to deploy agentic AI safely in document review, underwriting, risk assessment or tax computation. You cannot wait for guidance that may not arrive until the risk has already crystallised.

What Nikhil Rathi is really describing is a shift from prescriptive to principles-based regulation in real time. This is not new in UK financial services—principles-based frameworks have worked well for decades. But they have always assumed human judgment and institutional memory as the backstop. Agentic AI removes that guarantee. A language model can make decisions at scale, in milliseconds, across thousands of cases, with no human in the loop and no audit trail that a human could reasonably review. The EU AI Act anticipates this with its risk-based framework. ISO 42001 certification, now emerging as a market differentiator, is another attempt to codify governance. But both assume firms are building their own AI governance from first principles. Most are not. They are buying off-the-shelf generative AI tools—Harvey for legal work, Luminance for document discovery, Microsoft Copilot for general productivity—and hoping the vendor has thought about compliance. It has not. Vendors build for capability and speed. Compliance is your responsibility.

This is where Trovix's approach differs fundamentally from the broader market. Most AI products sold into regulated firms are trained on general knowledge and general risk profiles. They are then deployed into highly specific contexts—financial crime detection, solicitor client privilege assessment, insurance claims triage—where generic AI fails silently. A language model trained on web data does not understand the nuances of PRA guidance or Lloyd's Blueprint Two. It does not know that an insurance broker's AML procedures differ materially from a bank's. It cannot distinguish between a genuine regulatory change and a consultative proposal. This is why Trovix Watch exists: because principles-based regulation requires real-time intelligence about what is actually being regulated. And this is why Trovix Sift uses domain-specific extraction models rather than general language models for document intelligence—because an algorithm that performs at 95% accuracy on random internet text will fail at 60% accuracy on your client files, your underwriting submissions, or your engagement letters. In a principles-based environment where you cannot hide behind prescriptive rules, that gap is liability.

The practical move is immediate. First: audit every AI tool currently in use—whether it is ChatGPT, Copilot, or a specialist application—and map exactly what it does, what it decides, and who is accountable for its output. The FCA will expect this in real-time collaboration, and you cannot collaborate if you do not have visibility. Second: separate your AI stack into three tiers: commodity tools for genuinely generic tasks (formatting, summarisation), vetted applications for specialist functions (document review, underwriting), and human-led processes for regulatory decisions and client advice. Do not try to automate away judgment; automate away busywork. Third: establish a governance structure that allows you to respond to regulatory signals within weeks, not months. This means regular contact with your regulator on specific AI use cases, not annual compliance meetings. Fourth: choose vendors and products that transparently show how they handle domain specificity and regulatory change. A vendor that cannot explain why their model works differently in financial services than in healthcare is a vendor that has not thought about your risks.

Source: CNBC

Related Trovix product:

Trovix Sift →Book a demo →