Deterministic work
Rules / BPM / traditional automation
Low flexibility · high predictability
Known conditions, fixed policy, deterministic calculations and workflow routing.
Fees, validations, reconciliations, explicit eligibility rules.
AI / GOVERNANCE
CONSEQUENCE → CONTROL
CONTROL → EVIDENCE
EVIDENCE → RECONSTRUCTABILITY
The objective is not to prove that the institution uses AI responsibly. It is to make every material AI decision understandable, controllable and reconstructable.
Governance becomes useful when it changes what AI is allowed to do, who remains accountable, which controls are required and what evidence must survive the process.
Control intensity should follow consequence, not technology.

By José Ñáñez
Technology Advisor · Board Member
Published April 7, 2026 · Updated August 24, 2026 · 11 min read
THE GOVERNANCE PROBLEM
Regulated institutions do not need more generic statements about responsible AI. They need operating clarity. Which AI systems exist? What are they allowed to influence? Who owns the outcome? Which actions require a person? What happens when the system moves outside its expected behavior? And, months later, can the institution reconstruct what actually happened?
The governance problem becomes harder as AI moves from assistance to recommendation, decision and execution. The same control model should not be applied to a summarization assistant and to an agent that changes a customer record, approves an exception or triggers a financial action.
Good governance therefore starts with consequence. Technology matters, but consequence determines how much accountability, evidence, human authority and intervention capability the institution needs.
Governance is not a committee around AI. It is the operating system that defines authority, consequence and evidence.
START WITH THE WORK
Not every problem needs generative AI, and not every generative AI problem needs an agent. A deterministic rule does not become more valuable because an LLM executes it. When logic can be expressed clearly, traditional software may be cheaper, more predictable and easier to evidence.
Machine learning is useful when patterns and probabilities matter. Generative AI is useful when language, synthesis, ambiguity or unstructured knowledge matter. RAG is useful when enterprise context must be grounded in governed information. Agents become relevant when value depends on completing work across multiple steps, tools or systems.
This is a governance decision as much as an architecture decision: unnecessary autonomy creates unnecessary control cost.
Every step from rules to agents increases flexibility. It can also increase ambiguity, authority and the cost of being wrong.
GOVERNANCE OPERATING MODEL
Select technology according to the structure of the work. Increase governance according to the authority and consequence attached to it.
Flexibility ↑
Autonomy ↑
Consequence ↑
Control requirement ↑
Rules / BPM / traditional automation
Low flexibility · high predictability
Known conditions, fixed policy, deterministic calculations and workflow routing.
Fees, validations, reconciliations, explicit eligibility rules.
Machine learning
Probabilistic output · model risk
Pattern recognition, ranking, propensity, anomaly detection and forecasting.
Fraud scoring, churn, propensity, collections prioritization.
Generative AI
Flexible output · limited execution
Interpret, summarize, draft, classify and transform unstructured information.
Service summaries, document analysis, drafting, knowledge assistance.
GenAI + RAG
Grounded context · source governance
Generate responses grounded in approved internal sources and current enterprise context.
Policies, products, procedures, internal and service knowledge.
ML / GenAI + policy engine
Decision influence · stronger control
Recommend or select actions inside explicit policies, thresholds and exceptions.
Next best action, prioritization, bounded eligibility and exception preparation.
Agentic AI + tools + policy
Execution authority · maximum evidence
Coordinate steps, invoke tools and complete authorized actions across systems.
Originations, service operations, collections and remediation.
CONTROL BY CONSEQUENCE
The correct question is not “Is this GenAI?” The correct question is “What can this system cause?” Materiality, reversibility, customer impact, data sensitivity and execution authority are better governance signals than model family.
Control effort should concentrate where consequence is highest rather than surrounding every AI experiment with the same bureaucracy.
Identity, data handling, approved use, basic logging
User, input/output, model/service, connected sources
Evidence, human decision rights, review criteria
Recommendation, supporting context, human acceptance or override
Policy boundaries, exception handling, materiality thresholds
Decision context, policy, exceptions, final accountable decision
Permissions, action limits, monitoring, intervention, rollback
Tool calls, system changes, authorization, action IDs, overrides, outcome
ACCOUNTABILITY
AI governance often becomes committee-centric. That is a mistake. Committees define the perimeter and resolve material exceptions, but they should not absorb accountability that belongs in the operating business.
The business owner remains accountable for purpose, customer and economic outcome. Technology operates the system. Risk, compliance, security and data challenge the control design. Audit verifies whether controls and evidence operate as described.
The committee governs the perimeter. The business owner owns the outcome. Technology operates the system. Risk challenges the control. Audit verifies the evidence.
LEARN FROM THE FRONTIER
The largest AI providers are developing useful governance patterns, but those patterns operate at different layers. OpenAI combines enterprise controls with a separate frontier governance framework. Anthropic makes proportional safeguards explicit through its Responsible Scaling Policy. Open-weight ecosystems push more deployment responsibility toward the institution using the model.
These examples reveal a common direction: capability, access and deployment context change the safeguards required. But a bank cannot outsource accountability for why it used AI, which data it exposed, what decisions it delegated or what happened to the customer.
OpenAI / ChatGPT Enterprise
Managed enterprise controls + provider-level frontier governance
SSO, access controls, retention, audit/compliance capabilities; separate frontier risk framework.
Institution still owns purpose, data use, integration, decision rights and outcome.
Anthropic / Claude Enterprise
Managed enterprise controls + proportional capability safeguards
SSO, role-based permissions, audit logs, SCIM, retention; Responsible Scaling Policy and risk reporting.
Institution still owns deployment context, workflow controls, human authority and customer consequence.
Open-weight models / Llama ecosystem
More deployment control → more institutional responsibility
Model cards, use policies and system safeguards exist, but developers tailor policies, testing and deployment protections.
Institution increasingly owns hosting, patching, safety layers, monitoring, integration and incident response.
Governance responsibility shifts with deployment model
Managed AI service
More provider controls can be inherited
Enterprise integration
Shared responsibility becomes explicit
Self-hosted / open-weight
More operating responsibility moves to the institution
Identity & access
Data controls
Model evaluation
Safety layers
Observability
Patching
Incident response
GOVERNANCE EVIDENCE
Saying “we use AI responsibly” has almost no operational value. Saying that a material decision was produced by a specific system version, using a defined context, under an approved policy, within explicit permissions, and that a named person or system accepted, changed or executed the result is governance.
Evidence is what converts policy into control. If the institution cannot reconstruct what happened, the control environment is weak even if policies, committees and model inventories exist.
The output of governance is therefore not approval. It is reconstructability: the ability to explain the intent, identity, context, authority, decision, action, intervention and outcome of a material AI process.
Governance without evidence is policy. Evidence turns policy into control.
VERSION
TIME
POLICY
OWNER
TRACE
EVIDENCE BY CONSEQUENCE
The institution does not need the same evidence depth for every AI use. But every increase in authority should add evidence, not replace it.
User + model/service + input/output + data handling+ evidence used + recommendation + human decision+ applicable policy + decision context + exceptions + accountability+ permissions + tool calls + system change + transaction/action ID + rollback stateREGULATED OPERATING MODEL
A regional institution should not recreate its entire AI governance model country by country. The common operating core should define inventory, accountability, risk classification, lifecycle, evidence, AgentOps, intervention and incident response.
Local rule packs should add jurisdiction-specific privacy, consumer protection, explainability, sector regulation, record retention, outsourcing, data-location and supervisory requirements.
This keeps governance scalable without pretending that one global policy resolves every local obligation.
Shared governance core + provider controls + country / regulatory overlay
RESEARCH CONTEXT
These sources illustrate governance patterns. Product capabilities and policies evolve, so institutions should validate current controls before regulated deployment.
THESIS
The objective of AI governance is not to prove that the institution uses AI responsibly. It is to make every material AI decision understandable, controllable and reconstructable.
Choose the least autonomous technology that solves the problem. Increase control with consequence. Preserve evidence until the institution can explain what happened without relying on memory or trust.
José Ñáñez