Nikhil Rathi and Christine Lagarde have identified a real problem, but they have named it backwards. The issue is not that regulators cannot move fast enough. The issue is that most regulated firms are deploying AI tools that were never designed for regulated environments. When the FCA Consumer Duty PS22/9 requires firms to understand AI model behaviour, or when the SRA Code demands that lawyers remain in control of advice, generic large language models like ChatGPT and Copilot create liability, not efficiency. Mid-market legal practices, insurers and accountancy firms are copying each other in adopting off-the-shelf solutions. They are creating a compliance debt that will become a regulatory event within 18 months.
This story reflects a deeper truth: the AI industry has split into two. One track—the headline track—builds consumer-facing products and chases scale. The other, quieter track builds AI for regulated work: Harvey for legal, Luminance for due diligence, Legora for insurance claims. The second track is slower and more expensive because it has to work backwards from compliance rules, not forwards from raw capability. The firms buying generic AI are competing on cost and novelty. The firms building compliant AI are competing on risk avoidance. Regulators cannot close the gap between them by writing faster rules. They can only close it by making non-compliance expensive. That day is coming.
Trovix's view is that this regulatory warning is an invitation to move first. Firms that embed compliance into AI implementation today—not as an afterthought, but as the design constraint—will have a three-year competitive advantage over those that do not. Trovix Audit exists precisely because we believe the future of regulated AI is not 'how fast can the model work?' but 'can you prove the model worked compliantly and auditably?' The FCA's existing toolkit—ISA UK requirements, PRA SS1/23 on operational resilience—already requires this. Firms using Trovix Aria for knowledge retrieval and Trovix Sift for document processing report that they can answer every compliance question a regulator asks within days, not weeks. Firms using ChatGPT cannot.
If you lead a mid-market law firm, insurance broker, financial services firm or accountancy practice, the practical step is to stop asking 'which AI tool is cheapest?' and start asking 'which AI tool is most defensible under FCA, PRA, ICO UK GDPR and SRA scrutiny?' Audit your current AI use today. If you cannot explain the model's output to a regulator, you are already in breach. That does not mean you need to rip out existing tools tomorrow. It means you need an implementation roadmap that treats compliance governance as a first-class citizen. The FCA and ECB warning is real. But it is not permission to wait. It is permission to act decisively on the firms that move first.
Source: CNBC