The FCA's July announcement that it will not introduce detailed AI-specific rules is a regulatory decision masquerading as restraint. It is neither. The regulator has simply shifted the burden of AI interpretation and compliance from rule-writers to the firms using these tools — and done so at a moment when most mid-market law firms, insurers, accountancy practices and financial services firms are still treating AI as a competitive experiment rather than a governed utility. This matters urgently: under FCA Consumer Duty PS22/9, the SRA Code, and the FRC's ISA UK framework, you are already accountable for the outputs of AI systems you deploy. The FCA's silence does not reduce that accountability. It amplifies it. You must now interpret vague principles — fair outcomes, effective risk management, appropriate human oversight — and apply them to systems that did not exist when those principles were written.
This regulatory approach reflects a pattern across UK financial services and the professions: watchdogs are banking on 'responsible innovation' without providing the scaffolding that would make it real. The EU AI Act offers prescriptive rules; the UK chose principles. The ICO's UK GDPR guidance on automated decision-making is helpful but shallow. Lloyd's Blueprint Two talks about AI governance but stops short of mandating specific controls. Meanwhile, the market is flooded with AI tools positioned as solutions — Harvey and Legora in legal, Luminance in document review, Microsoft Copilot everywhere — each with different training data, hallucination rates, audit trails and risk profiles. None of them came with a principles-based compliance reading. Firms are left scrambling to retrofit governance onto systems already in production. That is not innovation. That is drift.
Trovix's view is simple: principles-based regulation only works if firms have the means to operationalise those principles quickly and with evidence. Generic AI products like Copilot are blunt instruments for regulated work. They were not trained on your data. They have no memory of your workflows. They cannot tell you why they made a specific decision about a client matter. Legal discovery, underwriting decisions, audit conclusions, tax advice — these demand explainability and traceability that off-the-shelf generative AI cannot provide. You need AI built for regulated work, with governance baked in from day one, not bolted on after deployment. That is why Trovix Audit exists: to give you the governance dashboard the FCA assumes you already have. It is also why Trovix Sift and Trovix Aria are built on retrieval-augmented generation and your own document stores, not public foundation models. You control the training data. You can explain the decision. You own the compliance record.
Do this now: audit every AI system currently in use in your firm — including that Copilot instance your finance team installed last month. Document what it does, what it accesses, what it outputs, and who is responsible for checking it. Map that against FCA rules, SRA outcomes, and your own PRA SS1/23 expectations (if applicable). Then build a governance framework that treats AI as a regulated process, not a productivity hack. If you cannot explain why your AI made a decision, you cannot defend it to a regulator. If you cannot trace what data it used, you cannot demonstrate compliance with UK GDPR. The FCA's refusal to write detailed rules means your compliance team must. Start today.
Source: CNBC