Nikhil Rathi is correct: traditional regulatory cycles cannot keep pace with AI that evolves in weeks. But the real problem is not that regulators are slow — it is that most mid-market firms are building AI implementations without the governance spine that regulators will inevitably demand.
AI Governance  Trovix ReachLegal · Financial Services · Insurance · Accountancy

On 3 July, the FCA's CEO told Europe's top bankers something they already know but refuse to act on: the rulebook moves in years, AI moves in months. Agentic AI — systems that can make decisions, execute transactions, and adapt their own logic — accelerates this problem from inconvenient to structural. For UK regulated firms in law, insurance, financial services and accountancy, this is not a theoretical problem. The FCA Consumer Duty (PS22/9), PRA SS1/23, SRA Code requirements around competence, and the emerging standards under ISO 42001 all assume human oversight and traceable decision logic. Agentic systems — like those being deployed by some enterprise vendors — obscure exactly that. When regulators catch up, firms using black-box agentic approaches will have a compliance crisis.

This warning reveals a deeper pattern: the industry has split into two camps. One camp — vendors selling off-the-shelf large language models with minimal guardrails (think generic Microsoft Copilot dropped into practice management systems, or Harvey and Luminance deployed without proper outcome auditing) — is betting that volume and speed will outrun enforcement. The other camp, smaller and quieter, is building AI systems designed from day one for regulatory transparency. They assume regulators will demand explainability, outcome logging, and human decision points. That assumption is now officially correct. The FCA, PRA, SRA, FRC ISA UK, and ICO guidance all trend toward mandatory auditability. The firms that win the next three years are those that implement AI governance before regulation mandates it, not after.

Trovix's position on this is blunt. Any AI system deployed in regulated firms must operate within a documented governance framework from implementation day one — not bolted on retrospectively. This means: recorded decision provenance (why did the system recommend this action?), human sign-off points on material decisions, outcome measurement against actual client outcomes (not just process speed), and change logs when the system's logic evolves. Tools like Harvey excel at document analysis and legal research speed, but if your firm is using Harvey to make recommendations without logging why the system chose option A over option B, you are building a compliance violation. Luminance's anomaly detection is genuinely useful for fraud and risk spotting, but only if your firm's governance framework treats Luminance's flags as input to human decision, not as replacement for it. Trovix Watch monitors regulatory change in real time so you see FCA and SRA guidance shifts as they land, not months later when compliance teams finally cascade it. But watching is useless without Trovix Audit — a governance dashboard that logs what your AI systems are actually doing, why they recommended it, and what the human outcome was. That audit trail becomes your legal defense when regulators (not if, when) ask to see it.

Here is what a mid-market firm should do right now. First: audit every AI system currently in production. Not 'Is it helpful?' but 'Can I explain to an FCA inspector why this system made this decision on this client's matter?' If the answer is no, you have a problem. Second: any new AI implementation must include a governance line item in the budget — typically 15-25% of total project cost. That is not wasted spend. It is insurance. Third: do not wait for FCA guidance to formalize. ISO 42001 and the emerging AI Act standards give you the framework already. Fourth: treat AI governance as continuous, not one-time. Systems drift. Client profiles change. Regulatory expectations shift. Trovix Watch flags the shifts; your governance framework acts on them. Fifth: be suspicious of vendors who sell speed without auditability. Harvey, Luminance, and others are good tools. But a good tool used without governance is a liability waiting for a regulator's discovery request.

Source: CNBC

Related Trovix product:

Trovix Reach →Book a demo →