Nikhil Rathi's warning about AI outpacing regulation is not a future problem—it's happening now. UK regulated firms sitting on generic off-the-shelf AI tools are already operating in a compliance blind spot.
AI Governance|Regulatory Watch|Compliance  Trovix AuditLegal · Financial Services · Insurance · Accountancy

When the FCA's own CEO admits that traditional rulemaking cycles cannot keep pace with agentic AI development, regulated firms should stop waiting for the next rule book to be written. Rathi is correct: the old approach—draft rule, consult, implement, enforce—takes years. Agentic systems that can make autonomous decisions, trigger transactions, or recommend actions to clients move in months. This is not hyperbole. The gap between AI capability and regulatory clarity is widening, not closing. For mid-market law firms, insurers, financial services companies and accountancy practices operating under FCA Consumer Duty PS22/9, SRA Code of Conduct, PRA SS1/23, and FRC ISA UK standards, this creates an immediate problem: what governance framework do you actually deploy when the rulebook is incomplete?

What Rathi's comment reveals is a deeper shift in how regulation works. The era of command-and-control rulemaking—detailed prescriptions handed down from above—is ending for AI. Instead, we are moving toward collaborative, iterative approaches where firms, regulators, and vendors must work together in real time to identify and manage emerging risks. The EU AI Act, UK GDPR amendments under the ICO guidance, and emerging frameworks like the Lloyd's Blueprint Two all point in the same direction: regulators will increasingly expect firms to demonstrate robust governance, transparency, and human oversight rather than tick boxes on a compliance checklist. This is harder. It requires judgment. It requires systems that allow you to see what is actually happening inside your AI, not just what it outputs.

This is where many firms are making a critical mistake. Products like Harvey, Legora, Luminance, and general-purpose tools like Microsoft Copilot excel at generating documents, summarizing case law, or extracting data. What they do not do is give you real-time visibility into how the AI is reasoning, what data it is using, and whether it is drifting from its intended purpose. When regulators begin asking—and they will—'how do you know this AI is not systematically discriminating against a protected group?' or 'can you prove this system did not hallucinate a case reference your fee-earner relied on?', generic AI tools leave you exposed. Trovix's approach is different. Trovix Audit is built specifically to create the transparency and governance trail that collaborative regulation demands. It is not about being compliant yesterday. It is about being auditable today. Similarly, Trovix Aria is designed to ensure that RAG-based knowledge systems stay grounded in your firm's actual knowledge base, not the internet's version of truth. These are not marketing claims—they are answers to the specific questions regulators are beginning to ask.

What should a mid-market firm do right now? Three things. First, stop assuming that 'best-practice' AI implementation means using the same tools as a large tech company or Big Four firm. It does not. You need systems that allow you to see and explain what your AI is doing, because regulators will ask. Second, map your AI usage against the specific conduct rules in your sector—not just for accuracy or bias, but for who made the decision, when, and why. FCA Consumer Duty PS22/9 is not abstract. It means you must be able to show a customer what role AI played in their service. Third, start building a collaborative relationship with your regulator now, not when you receive a probe. Bring them into your thinking about governance and risk. Rathi is signaling that this is now expected behavior.

Source: CNBC

Related Trovix product:

Trovix Audit →Book a demo →