The FCA has admitted it cannot write rules fast enough for AI. That means your firm is now expected to self-regulate, and the regulator will audit your governance framework, not just your compliance checklist. Move first, or move late under pressure.
AI Governance  Trovix ReachLegal · Financial Services · Insurance · Accountancy

When the UK Financial Conduct Authority's CEO publicly warns that traditional regulatory cycles cannot keep pace with AI development, you should listen. Nikhil Rathi's acknowledgment in July 2026 was not a casual observation—it was a statement of regulatory defeat. The FCA, PRA and their European counterparts have admitted they are designing rules for technology that is already obsolete by the time the rules are published. For mid-market law firms, insurers, accountants and financial services businesses, this matters enormously. It means you cannot wait for prescriptive guidance. The regulators have signalled they expect you to move first, demonstrate responsible governance proactively, and prove you have thought through the risks before they finish writing the rulebook. The old compliance model—wait for rules, then comply—is dead.

This story reveals a seismic shift in how regulation will work. The era of detailed prescriptive rules written by committees is ending. What is replacing it is principles-based oversight: the regulator sets the principle (manage AI risk responsibly, protect consumers, maintain market stability), and your firm proves you have done so. We have already seen this in the Consumer Duty (PS22/9), the SRA's approach to technology in law firms, and the FRC's ISA UK framework. The EU AI Act attempts prescription but will fail to keep pace within 24 months of implementation—everyone knows it. Agentic AI (systems that act autonomously on behalf of users) is moving faster than anyone predicted. Products like Harvey and Luminance have already moved beyond simple document review into autonomous decision-making. The regulatory environment is fractionalizing: the FCA's principles, the PRA's SS1/23 on AI governance, the ICO's UK GDPR interpretation, Lloyd's Blueprint Two for insurance—each piece points in the same direction. You will be judged not on compliance with a specific rule you may not have yet, but on whether you have a credible, documented, tested governance framework that a regulator can audit.

Here is Trovix's honest view: most AI implementations in professional services fail not because the technology is bad, but because firms treat AI as a technology problem rather than a governance problem. They deploy Copilot, integrate an API from Luminance or Harvey, spin up a chatbot, and assume compliance follows. It does not. Generic enterprise AI tools (Microsoft Copilot, Claude, standard LLMs) were not designed for regulated professional work. They do not track decisions, explain reasoning in audit-trail format, or give you the evidence you need when a regulator asks why your firm made that recommendation. Principles-based oversight demands visibility. You need to know what your AI did, why it did it, what it got wrong, and whether a human caught the error before it hit a client. Trovix Audit exists precisely because this gap exists—it is a governance and compliance dashboard built for regulated firms, not a general-purpose AI wrapper. If you are using generic AI tools without a governance layer, you are building regulatory debt, not compliance.

What should you do right now? First: accept that you are now in a governance-first posture. Before you add another AI tool, audit what you already have. What is it doing? Who is checking it? Is there a decision log? Can you explain it to the FCA? Second: invest in principles-based documentation. Write down your approach to AI risk: where you use it, why you use it, what could go wrong, how you catch failures, who is accountable. Make it real, not theoretical. Third: implement monitoring. Trovix Watch tracks regulatory change as it happens—not quarterly newsletters, but real-time alerts when the FCA, PRA, ICO or Lloyd's issues new guidance on AI. You cannot wait for the rules to crystallize; you need to move as they move. Fourth: if you are using client-facing AI, ensure it has a human-in-the-loop review before any output reaches a client. Trovix Reach is built with that principle embedded—it assists your people, it does not replace them. Finally: join an industry working group or forum. Peer pressure and shared approaches matter when regulators are watching. The firms that will thrive in this new regime are those that move now, document everything, and can tell a coherent story about how they govern AI. The firms that will struggle are those that wait for rules.

Source: CNBC

Related Trovix product:

Trovix Reach →Book a demo →