When Nikhil Rathi says traditional rulemaking cycles cannot keep pace with AI development, he is describing a real problem that will hit mid-market regulated firms hard. The FCA, PRA and SRA do not move slowly because they enjoy paperwork. They move cautiously because the consequences of getting AI governance wrong in a law firm, insurance broker, investment manager or accounting practice are material — breach of SRA Code, FCA Consumer Duty PS22/9 violations, PRA SS1/23 operational resilience failures, and ultimately client harm and regulatory sanction. What Rathi is really saying is this: the gap between what your firm can buy off-the-shelf and what your compliance framework can actually justify is widening fast. Most mid-market firms are deploying AI tools — Harvey for legal work, Luminance for due diligence, Microsoft Copilot for general tasks — without the audit trail, control architecture or explainability layer that regulators now expect. That is not innovation. That is exposure.
This story is part of a much larger pattern. The EU AI Act is live. The ICO's guidance on UK GDPR and AI has hardened. Lloyd's of London's Blueprint Two now ties AI governance to underwriting standards. The ISO 42001 framework is becoming the baseline expectation for any firm claiming to manage AI responsibly. What regulators are saying, quietly but clearly, is that they will no longer accept 'the vendor told us it was safe' as a control. They want evidence: bias testing, model cards, third-party audit, human-in-the-loop verification, and documented decision-making for high-risk use cases. Firms that deployed generic AI without this architecture in 2024 and 2025 are now scrambling to retrofit governance. Firms that wait another year will face enforcement action.
Here is what Trovix has learned from working with regulated firms across legal, insurance and financial services: speed and governance are not opposites — bad governance simply makes speed more expensive later. The firms that move fastest and safest are those that build compliance into the implementation from day one, not as an afterthought. This means moving beyond point-solution AI tools. Tools like Harvey or Copilot excel at specific tasks, but they do not tell you what they have done, why they did it, or whether they breached a regulatory boundary. You need three things: first, a knowledge assistant that works within your firm's actual knowledge base and regulatory constraints (Trovix Aria does this); second, AI governance and audit visibility so you can evidence control to regulators (Trovix Audit does this); third, document intelligence that extracts data reliably and explains its reasoning, not a black box that produces answers (Trovix Sift does this). The mistake most firms make is treating AI as a technology problem. It is a governance problem with a technology component.
Here is what you should do this quarter. First, audit every AI tool your firm has deployed in the last eighteen months. Document what it does, what data it touches, what decisions it influences, and what your control is. Second, map that against PRA SS1/23, SRA Code, FCA Consumer Duty, or your sector's equivalent. Third, identify the gaps. Fourth, do not rip out working tools — instead, add governance and audit capability around them so you can evidence control. If that sounds expensive, compare it to the cost of an FCA fine or SRA disciplinary action. Mid-market firms that act now will be compliant by the time enforcement tightens. Firms that wait will be explaining remediation plans to regulators.
Source: CNBC