Regulators have stopped waiting for AI to slow down. They expect you to govern it instead. That means building frameworks now—not after the next scandal.
AI Governance  Trovix BriefLegal · Insurance · Financial Services · Accountancy

Nikhil Rathi is correct. The FCA CEO's July statement that traditional rulemaking moves too slowly for AI—particularly agentic AI systems—identifies a real problem for UK regulated firms. Rules take 18 to 36 months. Useful AI models iterate in weeks. But Rathi's acknowledgement of regulatory lag is not an invitation to move without guardrails. It is a warning that firms can no longer wait for prescriptive rules before deploying AI. The FCA, PRA, and SRA expect you to build governance frameworks first and deploy second. That is the actual message. Firms that treat regulatory flexibility as permission to experiment without consequence will face enforcement action under existing principles-based rules—especially the FCA Consumer Duty (PS22/9) and the SRA Code of Conduct for firms. The question is not whether you can use agentic AI. It is whether you have documented, tested, and governed its use before it touches client work.

This story reflects a wider shift in how regulators approach fast-moving technology. The EU AI Act (in force since January 2026) and the FRC's recent ISA UK guidance both push responsibility back to boards and senior management, not to regulators to pre-approve each use case. The Lloyd's Blueprint Two framework for insurance AI does the same—it sets principles, not prescriptions. Regulators are tired of chasing technology and are instead installing governance requirements upstream. This is sensible. It is also demanding. It means firms that rely on watching competitors to learn what is safe will lag. The regulatory space is moving from 'wait for rules' to 'show your work'. Firms without documented AI assurance processes, vendor due diligence, and audit trails will find themselves in the difficult position of defending decisions they have not properly recorded.

Trovix's approach reflects this reality. Systems like Harvey, Legora, and Luminance promise to reduce workload and speed up review. They are genuinely useful for document-heavy work—but they work best inside a governance structure, not as substitutes for one. We do not sell AI that talks first and asks permission later. Trovix Brief and Trovix Sift embed governance checkpoints into intake and extraction workflows. They produce audit trails by design. Trovix Aria is a RAG assistant—it retrieves from your own knowledge, not the public internet—which means you control what it can say and you can explain why. And Trovix Watch monitors regulatory change as it happens, so you are not two years behind the FCA. The difference is not that we move slowly. It is that we move with documentation. That is what regulators actually want.

For a mid-market law firm, insurer, financial services house, or accountancy practice, the implication is clear: do not wait for the next FCA Dear CEO letter on AI before building your AI assurance framework. You have three months to document how AI is being used in your firm, what controls exist, who owns the risk, and how you test for drift in model performance. Start with your highest-risk workflows—client intake, underwriting, investment advice, tax planning. Do not deploy an agentic system until you have run it in shadow mode with human review. Do not assume that because a vendor's AI works in their demo, it will work on your data. And do not confuse regulatory flexibility with regulatory indifference. The FCA is clear: you must govern this yourself, now. Firms that treat that as optional will not survive the next wave of enforcement.

Source: CNBC

Related Trovix product:

Trovix Brief →Book a demo →