The government has announced a £100 million procurement scheme to develop AI solutions for NHS productivity, defence, computing efficiency and AI agent security. This is part of Sovereign AI, a broader push to build UK-controlled AI capacity rather than depending on US platforms. It sounds strategic. It is. But there is a sharp misalignment between what government procurement will deliver and what mid-market law firms, insurers, accountancies and financial services firms actually need. The scheme prioritises innovation and supply-side problems. Regulated firms face a different constraint entirely: how to deploy AI without breaching the SRA Code, FCA Consumer Duty PS22/9, PRA SS1/23, ICO UK GDPR, or the incoming requirements of the EU AI Act and UK AI Bill. That is not a procurement problem. That is a governance problem.
This story sits within a wider pattern we have watched develop over the past two years. AI product vendors — from generalist tools like Microsoft Copilot and OpenAI's API, to legal specialists like Harvey and Luminance — have raced to build capability and market access. They have succeeded. Capability is no longer scarce in 2026. What is scarce is the ability to deploy these tools in a way that satisfies a regulator, survives an audit, and protects the firm from liability when the model hallucinates, discriminates, or leaks client data. The government's procurement programme will likely produce excellent technology. But unless those tools ship with auditable decision trails, impact assessments aligned to UK regulatory frameworks, and clear documentation of where human review must remain mandatory, regulated firms will still face the same implementation cliff that stops them today.
Here is our honest assessment: most AI projects in professional services fail not because the technology is bad, but because the firm tried to bolt compliance on top of deployment rather than building it in from the start. Harvey produces strong legal research capability, but firms using it still need to answer to the SRA: who is accountable when advice changes between queries? Luminance finds anomalies in documents, but where is the human sign-off matrix? Copilot is productive, but which of your datasets should never be seen by US cloud infrastructure? These are not technology questions. They are governance questions. We built Trovix Audit specifically because we saw firms choosing between productivity and compliance, when they should be choosing neither. The scheme's focus on agent security is welcome, but agents without accountability frameworks are just faster paths to regulatory breach.
If you are running a mid-market regulated firm and you see this news, do not wait for government procurement to deliver your AI solution. Instead, audit your current AI use — whether informal (spreadsheets with ChatGPT, junior staff using Copilot) or formal (contract analysis tools, underwriting automation). Document what you are actually doing. Map it against your regulatory obligations. Then decide: which AI use cases are compliant-ready, which need governance investment, and which are not worth the risk. Use Trovix Watch to track how AI regulatory requirements are tightening — because they are. The firms that will succeed are those that treat AI as a compliance implementation problem first, and a productivity gain second.
Source: The Register