Salesforce's research landed at exactly the right moment. Agentic AI — software that acts autonomously on behalf of users — is now in the top three sales techniques adopted by UK firms. That is real adoption, not hype. But here is the uncomfortable truth: the same research found that 81% of executives know their AI initiatives will fail without process visibility, and 85% want to become 'agentic enterprises' within three years. This is the UK regulated sector's governance crisis in one data point. For law firms bound by SRA Code obligations, insurers accountable to the PRA, financial services firms under FCA Consumer Duty PS22/9, and accountancy practices subject to FRC ISA UK standards, this is not abstract. When agentic systems make decisions — whether flagging high-risk cases, underwriting policies, or advising on regulatory interpretation — you own the outcome. That ownership demands you know exactly what the AI did, why it did it, and whether it stayed within the guardrails you set. Most firms deploying agentic AI today cannot answer those questions.
This is not new friction between technology and regulation. It is the predictable consequence of how vendors sell AI and how firms buy it. The market has spent three years selling speed: deploy Copilot, add an LLM wrapper, automate the thing. Vendors like Harvey, Legora and Luminance have built impressive tools for legal research and document review, but even they cannot solve what is fundamentally a governance problem. You cannot outsource compliance to a product. The pattern repeating across regulated industries is always the same: adopt first, govern later. It works until it does not. The EU AI Act is already forcing a reckoning. The ICO's guidance on UK GDPR and generative AI tightens the screw further. And now — finally — firms are asking the hard question: what happens when an agentic system makes a decision we cannot explain to a regulator?
Here is Trovix's honest take. Agentic AI works beautifully inside bounded, well-documented processes. It fails spectacularly in the vague, interpretation-heavy work that defines regulated professions. A law firm can deploy agentic intake automation because matter intake is a process: capture data, run rules, route work. That has guardrails. But you cannot safely automate legal advice to a client using agentic tools without knowing exactly what training data the model saw, how it reasones, and how you will audit its outputs. The same applies to insurance underwriting decisions and financial advice. Most agentic tools today are black boxes pretending to be transparency. If you are relying on a vendor's 'explainability' dashboard to satisfy regulatory requirements, you are already exposed. The firms that will thrive are those building agentic systems on top of process visibility from day one — not adding it afterward. Trovix Sift and Trovix Brief exist precisely because we built them on this principle: you cannot deploy AI safely in regulated work without first knowing what data you have, what the process actually does, and what happens when the AI makes a judgment call.
If you are a mid-market law firm, insurer, accountancy practice or financial services firm, here is what to do immediately: audit the agentic or autonomous AI systems you have deployed in the past 18 months. For each one, document: (1) what data it uses, (2) how decisions are logged and retrievable, (3) who owns the outcome if something goes wrong, (4) how you would explain it to your regulator, and (5) whether you have tested its failure modes. If you cannot answer all five, you have a governance gap. Second, if you are planning agentic deployments, make process visibility your first requirement, not your last. Map the process, document the rules, identify where human judgment is still needed, then—and only then—introduce the agent. Third, use Trovix Watch to stay ahead of regulatory changes in your sector. Governance requirements around AI are moving fast. FCA Handbook updates, SRA guidance, PRA SS1/23 expectations—they are all tightening. You need to know what is changing before it affects your AI strategy. The firms that will lead are not the fastest to adopt agentic AI. They are the ones who adopt it slowly enough to keep governance ahead of the curve.
Source: Computer Weekly