The UK government's £100 million procurement scheme is a genuine market signal: public sector bodies will spend real money on domestic AI. For mid-market legal, insurance, financial services and accountancy firms, this matters because those public sector buyers—the NHS, Defence, GCHQ—will demand the same audit trails, explainability and governance standards they will eventually force on private sector suppliers. The problem is that most British AI startups winning these contracts will have built their products for speed, not scrutiny. And when those contracts land, regulated firms in professional services will be asked to integrate systems that were never designed for SRA Code compliance, FCA Consumer Duty PS22/9, PRA SS1/23 or ICO UK GDPR audit requirements.
This procurement scheme is part of a larger UK pattern: subsidise the technology layer, worry about the governance layer later. We saw it with algorithmic decision-making in banking; we're seeing it again with AI agents. The Register story mentions 'security of AI agents' as a procurement focus—which is code for 'we want to know what it's doing'—but security and governance are not the same thing. An AI agent can be technically secure and still make unexplainable decisions that breach the FRC ISA UK standards your audit partner requires, or that expose you to Lloyd's Blueprint Two underwriting scrutiny. The vendors winning public sector contracts will do what vendors always do: they will ship the fastest, flashiest version first and retrofit compliance later. Your firm cannot afford that luxury.
Here is our honest view: the AI products that will win most of these public sector contracts—including some serious players like Harvey, Legora and Luminance in legal, plus the various Copilot-wrapped tools—are strong on retrieval, classification and pattern-matching, but weak on decision provenance. They can tell you what a document says; they struggle to tell a regulator why your firm trusted that output in a client matter. That is not a technical failure. It is a governance failure. The firms that will actually profit from this £100M scheme are not the ones building the shiniest AI; they are the ones building the explainability layer on top of it. Trovix Sift and Trovix Aria are built on that principle—not to replace your judgment, but to create an auditable record of why you made it. That is what the public sector will demand, and it is what the FCA, SRA and PRA will eventually require you to prove.
What should you do right now? Do not wait for the 'compliance version' of the next trendy AI tool. If your firm is thinking about AI integration in the next 12 months—whether you are bidding for public sector work or not—build governance into the procurement brief. Ask vendors how their output can be interrogated by an external auditor. Ask them how they will handle the ICO's position on AI and data rights. Ask them whether they can produce a contemporaneous record of which training data informed which decision. If they cannot answer those questions clearly, they are not ready for regulated practice, however good they are at the base task. Trovix Watch tracks the FCA, PRA and SRA guidance on AI as it lands, because the rules are tightening monthly. Use that to pressure-test your vendor conversations now, not after you have signed a three-year contract.
Source: The Register