The UK government has just handed £100 million to domestic AI startups to compete for public sector contracts in NHS, defence, compute and security. On the surface, this is the right move—building sovereign AI capability and reducing dependency on OpenAI, Anthropic and Meta. But read between the lines and you see something more revealing: the government is finally acknowledging that regulated firms need British solutions. The problem is not where the AI comes from. The problem is that most law firms, insurers, accountancies and financial services practices have no idea how to implement AI safely under SRA Code, FCA Consumer Duty PS22/9, PRA SS1/23, or ICO UK GDPR. They have bought tools—Harvey, Legora, Luminance, Microsoft Copilot—without the governance layer to use them.
This procurement scheme is part of a broader pattern. The public sector is racing ahead while the regulated private sector is stuck. NHS trusts, defence bodies and government agencies have regulatory cover and procurement frameworks that force them to think about explainability, bias testing, audit trails and human oversight from day one. They will demand compliance dashboards. They will require documented sign-off. They will want to know who is responsible when the AI fails. The private sector—where actual client money, legal privilege, underwriting decisions and audit judgments are at stake—has mostly ignored this. We have seen firms deploy document AI without testing for hallucination. We have seen insurance firms use models that cannot explain their recommendations to claimants. We have seen accountancies use agents without audit trails. The government's £100M scheme will force change, but only because it creates a two-tier market: government-ready AI (with governance built in) and everything else.
Trovix's view is blunt: the tool is not the problem. The governance framework is. A homegrown AI model from a UK startup is not safer than Claude or GPT-4 if you deploy it without controls. Conversely, any model—domestic or imported—can be used responsibly if you have the right processes. This is why firms should not be waiting for the government to hand them a solution. Instead, they should be building governance now. That means: documenting what each AI system is allowed to do, testing outputs against your professional obligations, logging decisions, and auditing outcomes against your regulatory responsibilities. Tools like Trovix Audit exist precisely because compliance frameworks—not model choice—separate safe deployment from reckless risk. The firms winning the next three years will not be those with the fanciest model. They will be those with the best governance dashboard.
What should you actually do? First, audit where AI is already running in your practice. You may find it embedded in document assembly, client intake, billing or compliance checking—often added by vendors without your explicit sign-off. Second, map that usage against your regulator's expectations: SRA Code Standard 5 for legal practices, FCA's rules on outsourcing and algorithmic decision-making for financial firms, FRC ISA UK requirements for auditors, ICO guidance on AI and GDPR for all firms handling personal data. Third, decide which AI tools genuinely add value versus which are just fashion. Finally, implement a lightweight governance layer—decision logs, output sampling, human sign-off gates—before deploying anything new. The £100M scheme will produce excellent homegrown models. But they will fail in your practice unless you treat AI governance as non-negotiable. Start now, not after the regulator calls.
Source: The Register