The FCA is warning that AI moves faster than rulemaking. Most UK regulated firms are still implementing AI like it's software. Both assumptions are now broken.
AI Governance  Trovix WatchLegal · Financial Services · Insurance · Accountancy

Nikhil Rathi, the FCA's CEO, is right. Traditional compliance cycles — where you implement a rule and then wait two years until the next update — are now obsolete for AI. When large language models improve measurably every quarter, and when a tool like Harvey or Luminance can redefine due diligence workflows in weeks, a rulebook published in July 2024 is already stale. The FCA has signalled clearly that the era of fixed compliance checkboxes is ending. What's coming instead is continuous, collaborative engagement between regulators and firms. For mid-market legal practices, insurers, wealth managers and accountancy firms, this is not an optional refinement. It is a structural change in how you must think about AI governance. The Consumer Duty PS22/9 and the incoming PRA SS1/23 have already hinted at this. The FCA's latest warning makes it explicit: you need to be in permanent dialogue with regulators about AI risk, not just annual sign-off ceremonies.

This story is the third act of a three-year play. Act One was the hype cycle: AI will solve everything, move fast, break things. Act Two was the hangover: firms deployed Harvey, Microsoft Copilot, Luminance and others, saw genuine productivity gains, then discovered that 'it works' is not the same as 'it complies' and that hallucination, bias and transparency gaps are not edge cases. Now Act Three: regulators realising that they cannot write their way out of this problem. The EU AI Act, the ICO's AI principles, and now the FCA's implicit call for adaptive regulation all point in the same direction. The firms that survive the next two years will be those that stop asking 'Is this AI tool compliant?' and start asking 'Do I have the governance infrastructure to manage this tool continuously and explain it to the regulator?' Most UK mid-market firms have neither the systems nor the discipline for that yet.

Here is Trovix's honest view: most AI products being sold to regulated firms are point solutions. They are good at what they do — document review, contract analysis, intake triage — but they are sold with an implicit lie: 'Implement this, configure it, and you're done.' Harvey does brilliant legal work. Luminance's anomaly detection is genuinely useful. Microsoft Copilot integrates seamlessly into workflows. None of them, however, can tell you in real time whether their outputs are drifting from regulatory expectations or whether they are amplifying bias in underwriting or lending decisions. They do not flag when a regulatory shift requires retraining. They do not connect to your broader risk governance. This is not a flaw in those products. It is a flaw in treating AI as IT rather than as a first-order business risk. The FCA's warning is saying: you need continuous regulatory monitoring, continuous model evaluation, and continuous dialogue with your regulator. You need Trovix Watch not just to track what the FCA publishes, but to detect when new guidance applies to your specific AI deployments. And you need Trovix Audit — an AI governance and compliance dashboard — to show auditors, the FCA, and your board what your AI systems are actually doing, not what the vendor claims they do.

What should a mid-market law firm, insurer or accountancy practice do on Monday morning? Three things. First, inventory your AI. Write down every tool you have deployed in the last two years — every instance of Copilot, every contract automation platform, every underwriting model. Second, ask your AI vendors a hard question: 'What happens when the FCA issues new guidance on AI bias, or transparency, or model decay? What is your process for notifying us and what support do you provide for re-evaluation?' If they say 'We'll send an email,' they do not understand the new regulatory reality. Third, begin thinking of AI governance not as a compliance box but as a continuous business function. That means someone on your leadership team owns it. It means you have quarterly reviews of AI model performance against regulatory expectations. It means you document decisions about AI trade-offs — productivity versus explainability, speed versus audit trail — and you file those decisions where regulators can see them. The firms that treat this as 'IT security plus regulatory filing' will fail. The firms that treat it as 'chief risk officer priority plus board-level visibility' will thrive.

Source: CNBC

Related Trovix product:

Trovix Watch →Book a demo →