Nikhil Rathi's warning in July was not a cry for help—it was a confession. The FCA, PRA and their European counterparts have admitted that traditional rulemaking cannot keep pace with agentic AI deployment. This matters to every mid-market law firm, insurer, financial services house and accountancy practice in the UK because it means regulation will no longer arrive neatly packaged in a Handbook update. Instead, firms will face a rolling series of thematic reviews, ad-hoc enforcement actions, and real-time guidance. The Consumer Duty (PS22/9), already demanding transparency and outcome focus, will be the template—not the exception. You cannot afford to treat AI adoption as a compliance problem to solve after launch. It has to be operational strategy decided before.
This story is part of a larger pattern: the gap between AI capability and governance maturity has stopped widening and started becoming dangerous. Products like Harvey and Luminance have already moved from proof-of-concept into fee-earning workflows across major firms. Agentic AI—systems that can plan, execute, and iterate autonomously on legal research, underwriting, or tax analysis—is no longer theoretical. The EU AI Act, now in force, has already exposed how fragile current compliance frameworks are. Meanwhile, smaller and mid-market firms have watched the regulatory landscape and chosen inaction, assuming that regulation would arrive first. It won't. Rathi's statement is the FCA finally saying out loud what regulated firms should have grasped months ago: you're on your own to set the standard until we catch up.
Our view at Trovix is simple: waiting for perfect rules is a strategy for falling behind your competitors and eventually failing a regulator's stress test. But equally, deploying AI without a coherent governance layer is a strategy for regulatory sanction. The difference between firms that will survive this transition and those that won't isn't technical sophistication—Harvey and Legora are good tools. It's institutional discipline. You need three things now: first, an auditable AI operating model that can show regulators (and your own board) exactly which decisions are AI-assisted, how they're being monitored, and what human oversight exists. Second, real-time visibility into how your AI systems are performing against bias, hallucination, and data protection standards—not annual reviews, not samples. Third, documentation that proves your AI choices are traceable to your risk appetite and your Consumer Duty obligations. That's not something a clever AI assistant does for you. That's governance infrastructure that sits above the tools. Trovix Audit exists precisely because firms told us they had Harvey, or Copilot, or a custom RAG system running in production but no way to answer the question: is this system safe and fair for our clients?
Here's what you should do this week. First, map where AI is already running in your firm—document intelligence, due diligence, underwriting, tax research, client comms. Be honest. Second, audit what you can prove about each system: what data it's trained on, how often it's reviewed, what it's allowed to decide alone versus with human sign-off, whether it's creating an audit trail. Third, if you can't prove it, either fix it or stop using it. Fourth, talk to your regulator—the FCA and SRA have both made clear they reward transparency in AI deployment. A controlled conversation about your AI governance is far cheaper than an enforcement review that finds you've been running undocumented systems at scale. And finally, accept that your AI implementation will evolve. Regulatory guidance will change. But if you build on a solid governance foundation now—one that's auditable, transparent, and risk-conscious—you'll be adaptable. Firms building on ad-hoc tool stacking won't be.
Source: CNBC