The Red Hat finding is stark: 52% of UK IT leaders cannot see where their data lives. In regulated firms, that is not just sloppy—it is a compliance failure waiting to happen. The FCA Consumer Duty PS22/9, SRA Code, PRA SS1/23 and ICO UK GDPR all demand firms know what data they hold, where it is processed, and who can access it. Three-quarters without strong AI governance plans means three-quarters are betting that their regulators will not ask awkward questions. That bet is closing fast.
What this research really shows is that UK firms have rushed into AI tools without the institutional infrastructure to use them safely. They have bought Copilot licenses, dabbled with Harvey or Luminance, integrated ChatGPT into workflows—and now they are realizing that bolt-on AI does not equal governed AI. The 89% of British respondents who want public policy to enforce open source principles for AI reveals something deeper: firms know that closed-box, proprietary AI systems create data lock-in and governance blind spots. They want regulation to force transparency. But they cannot wait for Brussels or Westminster to act.
Trovix's approach differs fundamentally here. We do not treat AI governance as a layer you add after deployment. We build it into the architecture from day one—which means data lineage, audit trails, and regulatory compliance are baked in, not bolted on. When a law firm uses Trovix Aria or Trovix Sift, the system knows exactly what data enters, how it is processed, and what output is generated. You get the productivity gains of modern AI without the governance debt. Products like Copilot or generic ChatGPT cannot tell you this. They were not built for regulated environments.
If you are a mid-market legal firm, insurer, financial services company or accountancy practice, the practical question is not whether to use AI—it is whether you can answer your regulator when they ask: where is our data, how is it being processed, who owns the output, and can you prove it? Start there. Audit your current AI implementations using Trovix Watch to flag regulatory change and governance gaps. Then, when you add or replace AI tools, make data visibility and auditability non-negotiable criteria. The firms that do this now will not be the ones scrambling to explain three-quarters visibility gaps to the FCA or SRA in 2027.
Source: Computer Weekly