The Red Hat survey confirming three-quarters of UK IT leaders lack strong AI governance is not a wake-up call—it's evidence the industry is deploying AI on borrowed time. For regulated professional services firms, this gap between deployment speed and control maturity is not a technology problem. It
AI Governance  Trovix AriaLegal · Insurance · Financial Services · Accountancy

A Red Hat survey published in April 2026 found that 87% of UK business IT decision-makers are running agentic AI systems, yet only 26% have strong governance frameworks in place. Worse, fewer than half have visibility of where their data is being stored, processed and accessed. For law firms, insurers, financial advisors and accountants, this is not merely an operational inefficiency—it is a direct breach waiting to happen. The FCA Consumer Duty (PS22/9), SRA Code, ICO UK GDPR guidance and PRA SS1/23 all require documented, demonstrable control over data processing, model behaviour and algorithmic risk. Running a chatbot or document-processing agent without knowing where client data lands is not agile. It is negligent.

What this survey reveals is a pattern now endemic in UK professional services: AI adoption has outpaced governance maturity by years. Firms have rushed to deploy large language models, retrieval-augmented generation (RAG) systems and agentic AI because competitors are doing the same. They have bought Harvey, Legora, Luminance, or bolted Microsoft Copilot onto their document stores. Few have then asked: where does the prompt go? Where is the response cached? Who has access to the training data? What happens when the model hallucinates or breaches privilege? The Red Hat data suggests this is not the concern of outliers—it is the norm. The industry has normalized deployment without control.

Trovix's view is straightforward: agentic AI in regulated firms must be built from governance backwards, not bolted on afterwards. That means knowing exactly what data enters the system, how it is processed, what outputs are logged, and how non-compliance is detected in real time. This is not about restricting AI—it is about making it trustworthy enough to use at scale. Systems like Trovix Audit exist precisely because the market has failed to embed governance into mainstream AI products. Most platforms—Harvey, Legora, Luminance included—are built for speed and capability. None of them are built primarily for a UK law firm that must satisfy the SRA, a regulated insurer answering to Lloyd's Blueprint Two and the FCA, or a financial advisor under ICO scrutiny. They require bolt-on governance. That is expensive, slow and creates gaps.

If you are a mid-market law firm, insurance broker, financial services firm or accountancy practice, the practical step is this: audit your current AI systems today against the ICO's AI and data protection guidance and your regulator's requirements. Document what data flows into each system. Establish where outputs are stored. Build a written AI governance policy—even a basic one—because having nothing is indefensible. Then, if you are deploying new agentic AI, insist on transparency about data handling and audit trails from day one. The firms that moved fast without this in 2025 and 2026 will spend 2027 retrofitting controls or facing enforcement action. The firms that insist on governance from the start will have competitive advantage, not penalty.

Source: Computer Weekly

Related Trovix product:

Trovix Aria →Book a demo →