European regulators are finally admitting that traditional compliance frameworks cannot track AI development. For mid-market UK firms, this means your AI governance model is already wrong—and your regulator knows it.
AI Governance  Trovix SiftLegal · Financial Services · Insurance · Accountancy

Nikhil Rathi's warning in July is not new rhetoric. The FCA CEO stated what every regulated firm already suspects: traditional rulemaking cycles measured in years cannot track AI development measured in weeks. This is not a theoretical problem. It is an immediate operational risk for every law firm, accountancy practice, insurance broker and financial services firm running generative AI tools—whether bespoke implementations or off-the-shelf products from vendors like OpenAI, Anthropic or Claude. The Consumer Duty (PS22/9), SRA Code, PRA SS1/23 and FRC ISA UK all contain AI-adjacent obligations around governance, due diligence and outcomes. But they were written before agentic AI. Your compliance framework was not.

This story is part of a larger pattern: regulators are admitting that command-and-control regulation has failed to keep pace. The EU AI Act attempted to prescribe rules at design time. It is already outdated. The outcome is that regulators are signalling a shift toward collaborative, principles-based, real-time approaches. Lloyd's Blueprint Two, the ICO's emerging AI guidance, and informal FCA engagement with major firms all point toward a world where firms that can demonstrate live, observable AI governance will survive the next enforcement cycle, and those that cannot will not. This is not a compliance checkbox exercise. It is existential.

Here is Trovix's honest position: most AI tools deployed in UK regulated firms today are not designed for this world. They solve point problems—document review (Luminance, Harvey), knowledge retrieval (Microsoft Copilot)—but they do not solve governance. They do not show regulators what happened inside the AI system, why it made that decision, or how it failed. This is why we built Trovix Audit. It is not an AI tool that does work. It is an AI tool that watches other AI tools doing work. It logs decisions, traces reasoning, flags drift, and surfaces what happened to your regulator in plain language. When the FCA or ICO calls, you do not scramble to reconstruct what your Copilot or Harvey instance did three months ago. You hand them a dashboard.

What should a mid-market firm do right now? Stop treating AI governance as a compliance team problem. It is a technology problem. Audit every generative AI system in use—including free versions, internal pilots, and vendor-supplied integrations. Map which systems touch regulated outputs (advice, client decisions, underwriting, audit conclusions). For those systems, implement real-time observability. If you cannot see what the AI is doing and prove it to a regulator, do not use it on regulated work. This means integrating Trovix Audit into your technology stack before you scale agentic AI deployment. It also means treating Trovix Sift and Trovix Aria as governance-first tools, not speed-first tools. The firms that survive the next two years will be those that can honestly tell their regulator: we moved fast, and we showed our work.

Source: CNBC

Related Trovix product:

Trovix Sift →Book a demo →