Nikhil Rathi's admission in July cuts to the heart of a problem that will define the next three years for every mid-market regulated firm in the UK. The FCA's CEO stated plainly that traditional rulemaking cycles cannot match the speed of AI development—particularly with agentic AI systems now moving into live deployment. This is not a theoretical concern dressed up in regulatory language. It means the compliance frameworks that kept your firm safe under PRA SS1/23, FCA Consumer Duty PS22/9, and the SRA Code are now running on outdated assumptions about what AI systems can do and how they behave. By the time the EU AI Act fully lands, by the time the FRC's guidance on algorithmic risk hardens into expectation, your firm will have already made critical decisions about which AI tools to deploy and how. Those decisions cannot wait for permission slips from regulators.
This admission reveals a structural failure in how the financial services and professional sectors have approached AI adoption. For three years, firms have watched regulators triangulate between innovation and safety, publishing principles-based guidance while the technology accelerated past the pace of consultation. The result is a vacuum that is being filled not by regulation but by market pressure and vendor claims. Products like Harvey, Legora, and Luminance have gained traction because they promised to solve specific problems—contract review, legal research, claims triage—but their deployment has often outrun the governance infrastructure needed to justify their use under existing regulatory frameworks. Firms have treated these tools as point solutions to productivity problems rather than as systems that generate new regulatory exposures. The regulators' warning is really an acknowledgement that this pattern cannot continue.
Trovix's position on this is straightforward: the gap between AI capability and regulatory clarity does not excuse firms from building rigorous governance. It demands the opposite. The firms that will survive regulatory scrutiny in 2027 and 2028 are those that treat AI governance as a live compliance problem today, not as something to bolt on when the rules finally arrive. This means moving beyond vendor assurances and deploying AI systems only where you can answer three hard questions: What decision or task is this system performing? What data is it trained on or drawing from? What happens when it fails, and who is responsible? Generic LLM-based assistants like Microsoft Copilot fail this test in regulated environments because they cannot guarantee either data lineage or system behaviour. Trovix products like Trovix Aria and Trovix Sift are designed from the ground up to answer these questions—they maintain audit trails, constrain outputs to known data sets, and document exactly what the system is doing at each step. That is not a feature. It is the baseline for deployment in any regulated firm.
What should a mid-market law firm, insurer, financial services firm, or accountancy practice do on Monday morning? First, stop treating AI as a productivity play and start treating it as a governance problem. Audit which AI systems are currently in use—formal and informal. Map them to regulatory obligations under the SRA Code, FCA rules, PRA expectations, and ICO UK GDPR. Use Trovix Watch or equivalent regulatory monitoring to track how AI governance guidance is evolving month by month. Second, build a decision framework for new AI deployments that requires sign-off from compliance and risk before implementation, not after. If a tool cannot produce an audit trail, cannot explain its outputs, or relies on vendor 'trust us' assurances, it does not go live in your firm. Third, begin implementing governance-first AI tools that are designed for regulated environments. Trovix Brief for intake, Trovix Sift for document review, and Trovix Aria for knowledge work—these are designed to work within the constraints that regulation will eventually impose. The firms that move now will have compliance evidence and operational capability in place by the time regulators stop warning and start enforcing.
Source: CNBC