The FCA has admitted it can't write rules fast enough to contain AI risk. That means your firm can't wait for regulatory guidance—you must implement governance now or face exposure when the rules eventually arrive.
AI Governance  Trovix WatchLegal · Financial Services · Insurance · Accountancy

Nikhil Rathi's admission on 3 July was unusually candid: Europe's regulators know AI is moving faster than their rule books can handle. The FCA, PRA and their counterparts across the EU are watching agentic AI accelerate—systems that can autonomously make decisions, trade, process claims, or draft legal advice—and they're openly acknowledging the gap between innovation velocity and regulatory cycle time. This matters urgently to every mid-market law firm, insurer, financial services outfit and accountancy practice in the UK because it means two things: first, formal AI governance rules are coming, but not soon enough to guide your deployment decisions; second, the regulators are now signalling that firms which wait for rules before implementing controls will find themselves exposed to both operational risk and regulatory sanction when frameworks finally land. The FCA Consumer Duty PS22/9, the SRA Code, the PRA SS1/23 and emerging alignment with the EU AI Act are all moving targets. Waiting is no longer a defensible strategy.

This story is the public version of a private panic. Over the past 18 months, we've watched regulated firms chase every AI trend—ChatGPT for document review, Claude for legal research, Microsoft Copilot integrated into case management, agentic systems like Harvey for matter automation—without asking whether they understood what they were deploying or could trace a decision back to a human accountable for it. The result is a market split in two: large firms with dedicated AI governance teams and budget to absorb mistakes; and mid-market firms running AI pilots with one part-time compliance person and a hope that 'we're being responsible.' Regulators can't move fast enough to stop this, so they're doing something subtler: they're telling firms that the burden of governance now rests with you, not with them. The FCA's warning is less 'we'll write rules soon' and more 'if you don't govern your AI, we'll hold you accountable under existing frameworks.' That's a fundamental shift.

Trovix's view is blunt: the gap between AI capability and AI oversight is not a technology problem that tools will solve. It's a governance problem. Most firms buying AI today focus on feature set—does this system draft a motion, summarise a policy, flag a tax issue?—and assume that because the underlying model (GPT-4, Claude, a fine-tuned variant) works at scale, it's safe to deploy. That's wrong. What matters now is not whether you use Harvey, Luminance, Legora or Microsoft Copilot. What matters is whether you can explain why you're using it, what outputs it produces, who checks those outputs, what happens when it fails, and how you've tested it for bias or market-moving errors. We've seen firms integrate Copilot into their risk systems without documenting the model's training data or performance on edge cases. We've seen law firms use agentic document review without a human review gate. That's not cutting-edge. That's negligence waiting to be discovered. The firms that will survive regulatory tightening are the ones implementing governance first and integrating AI second—not the other way around.

Here's what your firm should do this quarter: audit the AI systems already in use (including shadow AI—the tools people are quietly using without IT approval). For each system, document what it does, what inputs drive it, what outputs matter, who is accountable if it goes wrong, and whether you've tested it against your regulatory obligations under the SRA Code, FCA rules, ICO UK GDPR or ISO 42001. You don't need to stop using these tools. You need to be able to defend them. Trovix Audit is designed exactly for this—it gives mid-market firms a way to document, trace and justify AI deployment without requiring a team of PhDs. Second, activate Trovix Watch to track the FCA's regulatory signals in real time. The guidance is changing monthly now. Third, before you deploy the next AI system—whether it's for intake automation, client communication, or underwriting—run it through a governance frame. Ask: can I explain this decision to the FCA? Can I prove a human was in the loop? Can I show I tested for failure? If the answer to any of these is no, you're not ready. The cost of governance now is a fraction of the cost of remediation later.

Source: CNBC

Related Trovix product:

Trovix Watch →Book a demo →