Nikhil Rathi and Christine Lagarde are correct, and their warning should alarm every mid-market legal, insurance, and financial services firm in the UK. AI moves in weeks. Regulation moves in years. But there is a third variable firms consistently ignore: governance. The FCA, PRA, SRA, and ICO are not standing idle. They are building enforcement capacity around AI Governance (PRA SS1/23, FCA Handbook Chapter SYSC 12D, the upcoming UK AI Act implementation). When they audit your firm's AI use—and they will—they will not ask whether your large language model is faster than your old system. They will ask whether you can prove what it learned, why it made that decision, whether it breached Consumer Duty or the SRA Code, and whether you logged it. Most firms deploying Harvey, Legora, Luminance, or generic Microsoft Copilot cannot answer these questions. That is not a technology problem. It is an accountability problem.
We are watching the industry repeat the failed pattern from cloud migration, third-party risk, and cybersecurity. Firms adopt the tool first. They worry about governance later. Regulators then prosecute the pioneers. By the time mid-market firms realise they need to build audit trails, data lineage, model cards, and decision records, they have already embedded systems that cannot produce them. The ECB's warning about 'lack of adequate defense mechanisms' is not abstract. It means firms using AI without logged, auditable, explainable workflows will find themselves unable to defend themselves in an FCA thematic review or a client complaint. The EU AI Act implementation will accelerate this pressure across the Channel. Lloyd's Blueprint Two and emerging ISA UK standards (FRC ISA UK) are already embedding AI risk into audit. This is not coming. It is here.
Trovix's position is this: AI without governance is compliance debt. Many vendors—including some who market themselves as 'responsible AI'—sell you speed and capability. They do not sell you the ability to prove you were responsible. That distinction matters enormously. A document AI tool like Trovix Sift is only genuinely useful in regulated environments when it generates auditable extraction records, flags confidence thresholds, logs human overrides, and integrates with a compliance dashboard. Similarly, fee-earner assistants like Trovix Aria only reduce compliance risk when they retain full chat provenance and can be tied to matter records and billing systems. And client-facing tools like Trovix Reach only survive regulatory scrutiny when every interaction is logged, attributed, and reviewable. The honest truth: if your AI vendor cannot show you an audit trail of what happened, why, and who checked it, that vendor is selling you regulatory risk, not productivity.
What you should do right now: Stop treating AI as a tool acquisition project. Start treating it as a governance project. Before implementing any AI system—whether it is an off-the-shelf chatbot, a document automation platform, or a third-party API—map it against PRA SS1/23 (if you are PRA-regulated), SYSC 12D (if you are FCA-regulated), and your firm's own SRA or FRC obligations. Specifically: Can you produce an audit log? Can you explain the model's decisions? Can you demonstrate human review? Can you link it to your existing risk framework and client data classification? If the answer to any of these is no, do not deploy it. Use Trovix Audit or a comparable governance platform to baseline your current AI inventory and build a compliance dashboard before the FCA does thematic work on your sector. The firms that will avoid enforcement action are not the ones with the newest AI. They are the ones with the most rigorous audit trails.
Source: CNBC