Eighty-seven percent of UK firms are running agentic AI with no meaningful oversight. For regulated firms handling client data, this is not a gap — it is a choice to break the rules.
AI Governance  Trovix ReachLegal · Financial Services · Insurance · Accountancy

The Red Hat survey is a wakeup call that arrived too late. Eighty-seven percent of UK IT leaders have deployed agentic AI systems, but only 25% have strong governance frameworks in place. Worse: 48% cannot even see where their data is stored or how it is processed. For legal, insurance, financial services and accountancy firms, this is not a competitive disadvantage — it is a regulatory violation. The FCA's Consumer Duty (PS22/9), the SRA's Code, the PRA's SS1/23 framework and the ICO's GDPR enforcement all demand visibility and control over how client data moves through systems. An unmonitored AI agent processing client instructions, premium calculations or tax advice is not innovation. It is exposed.

This gap between deployment and governance reveals a pattern the industry has repeated since the beginning: we buy tools before we understand what they do. Agentic AI — systems that autonomously plan and execute tasks across multiple steps — operates in a different layer of abstraction than the AI chatbots and document classifiers firms rushed to adopt in 2024 and 2025. When Harvey, Luminance or Legora field an AI assistant for legal research or contract analysis, the model still operates within a bounded scope. An agent is different. It can make decisions, call external APIs, modify data and potentially escape the initial guardrails. The absence of governance in 48% of organisations means nobody is watching what those agents do after deployment. That is the gap that regulators are about to target.

Trovix's view is straightforward: agentic AI adoption without concurrent audit capability is malpractice in a regulated firm. The temptation is to assume that the AI vendor — OpenAI, Anthropic, or the enterprise platforms layering agents on top of those models — bears responsibility. They do not. When your agentic system processes a client's legal matter, that firm's licence is at risk, not the vendor's. You need continuous visibility into what the agent is doing, why it made each decision and what data it touched. This is why Trovix Audit was built specifically for this problem: not to slow down deployment, but to make it safe. Without an audit trail that satisfies the FRC's ISA UK 240 standards and the emerging requirements under the EU AI Act's high-risk classification, you cannot claim due diligence. Microsoft Copilot for Microsoft 365 and the enterprise AI platforms offer logging, but they log what happened — not why it happened or whether it was correct. That distinction matters when the SRA or ICO come asking.

Here is what a mid-market firm should do immediately. First, audit your AI deployments right now using a framework like ISO 42001 as a starting point. Know which systems are already live and what decisions they make. Second, do not deploy any new agentic system without a governance layer in place first. Third, if you are using Trovix Reach or any client-facing AI, tie it to Trovix Audit so that every interaction leaves an explainable record. Fourth, establish a quarterly review process — this is not one-time work. The regulatory environment is shifting faster than most firms realise, and the AI Act's classification of agentic systems as high-risk will change what 'compliance' means by 2027. The firms that wait for guidance will be the ones paying fines.

Source: Computer Weekly

Related Trovix product:

Trovix Reach →Book a demo →