Quick Summary
- FCA, ICO, and SRA compliance obligations around AI are already in effect under existing frameworks. No new rules are required for liability to exist.
- Regulators need two things: evidence that controls exist, and evidence that those controls actually fired.
- Enterprise AI governance platforms are built for organisations developing their own AI models, not for controlling how employees use external tools like ChatGPT.
- Deployment speed is a compliance variable. A tool that takes months to roll out cannot address a regulatory inquiry due next quarter.
The Scenario
Here is a scenario that comes up in regulated firms more often than most IT Directors would like. A fee earner pastes a client portfolio summary into ChatGPT to help draft a report. There is no policy covering it. Nobody flagged it as a problem. And personal data has now left the organisation without a lawful basis, without a Data Protection Impact Assessment, and without a log entry anywhere in the firm's systems.
That is not a theoretical risk. In the recent case, Munir v Secretary of State for the Home Department, the Upper Tribunal addressed exactly this situation, finding that uploading confidential documents into an open-source AI tool such as ChatGPT places that information in the public domain, breaches client confidentiality, and may warrant referral to both the relevant regulatory body and the Information Commissioner's Office. It was the first time an English court directly linked the use of public AI platforms with the loss of legal privilege. addressed exactly this situation, finding that uploading confidential documents into an open-source AI tool such as ChatGPT places that information in the public domain, breaches client confidentiality, and may warrant referral to both the relevant regulatory body and the Information Commissioner's Office. It was the first time an English court directly linked the use of public AI platforms with the loss of legal privilege.
For IT Directors at FCA-regulated firms, law firms, and other UK regulated organisations, the practical question is which category of tool addresses this problem. This article works through that.
What UK Regulators Currently Require
A common assumption is that AI-specific regulation has not yet arrived, so compliance obligations are limited. In practice, existing frameworks already create real obligations and regulators are actively applying them.
The FCA
The FCA does not yet have AI-specific rules, but applies its existing principles-based framework to AI adoption. Firms are expected to demonstrate operational resilience, governance over third-party dependencies, and evidence of ongoing oversight where employees use external AI tools. The FCA's guidance on third-party and service provider oversight creates practical documentation requirements even where no formal outsourcing arrangement exists.
In January 2026, the FCA launched the Mills Review, a long-term examination of how AI will reshape retail financial services, with recommendations due to the FCA Board in summer 2026. Separately, the House of Commons Treasury Committee has recommended that the FCA publish comprehensive AI guidance covering the application of consumer protection rules and the accountability expected from senior managers under the SM&CR by the end of 2026. Firms that document their AI governance now will be better positioned when that guidance arrives.
The ICO
ICO obligations under UK GDPR are more immediate. Any AI system that processes personal data requires a lawful basis, a DPIA where processing is high-risk, and documentation demonstrating accountability under Article 5(2). The ICO's AI and data protection guidance sets out specific expectations around transparency logs, information governance records, and audit trails that demonstrate how personal data flows through AI systems.
Under the ICO's governance and accountability guidance, organisations are expected to maintain comprehensive audit trails that log and monitor access to datasets used in AI systems. An aggregate dashboard showing how many employees used AI tools last month does not satisfy this requirement.
The SRA
For SRA-regulated law firms, the obligation layer is deeper. Under Paragraph 6.3 of the SRA Code of Conduct, solicitors must keep client affairs confidential unless disclosure is required by law or the client consents. The SRA has confirmed that solicitors remain personally responsible for confidentiality even when using third-party technology, and that the duty to assess data breach risks and conduct due diligence on service providers applies in full.
The Munir judgment made the practical consequence explicit. The tribunal referred practitioners to the SRA and the ICO. Law firms waiting for explicit SRA AI guidance before acting are taking a material regulatory risk.
What Compliance Actually Requires in Practice
Across all three regulators, the documentation requirements converge on two things: evidence that controls exist, and evidence that those controls were enforced.
A regulatory-grade audit trail means timestamped activity logs, per-user policy enforcement records, and data exportable enough to respond to a regulatory inquiry. It does not mean a dashboard showing aggregate AI tool usage across the organisation.
When the ICO or FCA asks for evidence of governance, they expect specific policy enforcement events, not summary statistics.
This distinction is worth pressing during any vendor evaluation. Ask to see a sample audit log export. If a vendor cannot produce one during a trial period, they will not produce one when the request is real.
How Different Tool Categories Measure Up
Enterprise AI Governance Platforms
A category of platforms has developed around centralised AI governance for large organisations: model registries, risk dashboards, lifecycle documentation workflows, and regulatory alignment reporting. These tools are designed for organisations building and deploying their own AI models, where the compliance question centres on how a proprietary model was developed, tested, and governed over time.
For most UK regulated mid-market firms, this addresses a different problem. A financial advisory firm with 80 staff does not typically need a model governance suite. It needs to prevent a financial adviser from pasting client data into a free AI tool and to produce evidence that controls are in place if a regulator asks. Enterprise governance platforms address the model development pipeline. They are not architected for real-time browser-level enforcement.
Implementation timelines are also a practical constraint for firms under near-term regulatory pressure. Deployment timescales of months, combined with requirements for technical resource to configure and maintain the system, can create a gap between when a firm needs compliance evidence and when the platform is operational.
Network-Level DLP
Traditional network-level data loss prevention intercepts traffic at the perimeter and applies policy rules. The architectural limitation for browser-based AI tool usage is that network-level approaches can struggle to distinguish between an employee reading a webpage and pasting confidential data into a ChatGPT prompt. Without additional instrumentation, per-user per-event enforcement logging may not be granular enough to satisfy ICO accountability requirements.
Browser-Level DLP
Browser-level data loss prevention operates at the point of data entry, intercepting paste events and file uploads before data moves outside the organisation's controlled environment. This approach is designed specifically for the problem of employees using external AI tools, because enforcement happens at the exact moment the data transfer attempt occurs.
For FCA-regulated firms and SRA solicitors, browser-level enforcement has a practical advantage: it can produce a per-user per-event audit trail that records precisely which policy fired, when, and for which user. That is the format of evidence regulators expect to see.
Where Fendr Fits
Fendr is a browser-level AI security tool built for UK regulated mid-market firms. It deploys as a browser extension and governs how employees interact with external AI tools in real time: blocking sensitive data uploads, enforcing per-tool policies, redirecting staff to approved platforms, and generating a full audit trail of every policy event.
Deployment takes under five minutes via Mobile Device Management with no infrastructure changes required. For IT Directors managing lean security teams, that means compliance evidence from day one rather than after a lengthy rollout.
Fendr has deployed with UK wealth management clients and can provide redacted case study documentation on request. The most reliable way to evaluate fit is a structured 14-day audit against your own environment.
Book a free 14-day audit at fendrsecurity.com/contact. We will show you exactly what your employees are doing with AI tools, and what a regulator would see if they asked.