On 3 July, FCA CEO Nikhil Rathi told European regulators what they did not want to hear: traditional rulemaking cycles cannot keep pace with AI developments that unfold in weeks or months. He was not wrong. The EU AI Act took years to finalise. The UK's AI Bill is still in consultation. Meanwhile, agentic AI systems—those that act independently on behalf of users—are already embedded in underwriting workflows, legal due diligence, and financial crime detection across UK firms. Mid-market regulated practices in law, insurance, financial services and accountancy face a real problem: they cannot wait for the FCA, SRA, PRA, or ICO to clarify the rules because the rules will not arrive in time to guide deployment decisions happening right now.
This is not new anxiety dressed up as news. It reflects a deeper structural shift. The old model was simple: regulator writes rule, firm implements, regulator audits compliance. The new model is messier: firms deploy AI to solve real operational problems, regulators scramble to understand what has been deployed, and guidance arrives months or years later—usually after something has gone wrong. The Financial Conduct Authority's Consumer Duty PS22/9 and PRA's SS1/23 on outsourcing both tried to address third-party risk and algorithmic bias, but they were written before agentic AI became mainstream. The FCA is now signalling that it wants 'collaborative approaches' with industry. Translation: we will figure this out together, which means your firm needs to act as though it is already responsible for the governance framework, because it is.
Here is where many firms get it wrong. They deploy a large language model like Microsoft Copilot or a specialised legal AI like Harvey or a document intelligence tool like Luminance, treat it as a black box that produces answers, and assume that compliance happens because the vendor is reputable. It does not work that way. The SRA Code of Conduct for Solicitors and the ICO's UK GDPR guidance are clear: you own the output. If an AI system makes a negligent recommendation, recommends discriminatory action, or mishandles personal data, your firm is liable. Trovix's approach is different. Trovix Watch monitors regulatory developments so you know what compliance obligations are emerging before they become hard law. Trovix Aria and Trovix Sift are built with explainability at the core—you can see why the system recommended something, trace the data it used, and demonstrate proportionate governance to a regulator. That is not a feature; it is a requirement.
So what do you do on Monday morning? First, stop asking 'Will the FCA allow this?' Start asking 'Can we explain and defend this?' Second, audit the AI systems you have already deployed or are deploying—particularly in client intake (Trovix Brief helps here), document handling, and underwriting decisions. Map them against Consumer Duty PS22/9, your sector-specific ICO guidance, and ISO 42001 (AI management systems). Third, build an AI governance framework now that assumes regulators will want to inspect it within 12 months. Fourth, choose AI vendors and integrators who can help you do that—not vendors who promise AI magic and leave compliance to you. The FCA's acknowledgement of regulatory lag is permission to act, not an excuse to move recklessly. Firms that build robust, auditable AI governance now will move faster and face less friction when guidance hardens into rule. Firms that do not will look negligent when they do.
Source: CNBC