Back to AI

AI / GOVERNANCE

CONSEQUENCE → CONTROL

CONTROL → EVIDENCE

EVIDENCE → RECONSTRUCTABILITY

Governance for AI in regulated environments

The objective is not to prove that the institution uses AI responsibly. It is to make every material AI decision understandable, controllable and reconstructable.

Governance becomes useful when it changes what AI is allowed to do, who remains accountable, which controls are required and what evidence must survive the process.

Control intensity should follow consequence, not technology.
Portrait of José Ñáñez

By José Ñáñez

Technology Advisor · Board Member

Published April 7, 2026 · Updated August 24, 2026 · 11 min read

THE GOVERNANCE PROBLEM

A policy is not an operating model

Regulated institutions do not need more generic statements about responsible AI. They need operating clarity. Which AI systems exist? What are they allowed to influence? Who owns the outcome? Which actions require a person? What happens when the system moves outside its expected behavior? And, months later, can the institution reconstruct what actually happened?

The governance problem becomes harder as AI moves from assistance to recommendation, decision and execution. The same control model should not be applied to a summarization assistant and to an agent that changes a customer record, approves an exception or triggers a financial action.

Good governance therefore starts with consequence. Technology matters, but consequence determines how much accountability, evidence, human authority and intervention capability the institution needs.

Governance is not a committee around AI. It is the operating system that defines authority, consequence and evidence.

START WITH THE WORK

Use the least autonomous technology that solves the problem

Not every problem needs generative AI, and not every generative AI problem needs an agent. A deterministic rule does not become more valuable because an LLM executes it. When logic can be expressed clearly, traditional software may be cheaper, more predictable and easier to evidence.

Machine learning is useful when patterns and probabilities matter. Generative AI is useful when language, synthesis, ambiguity or unstructured knowledge matter. RAG is useful when enterprise context must be grounded in governed information. Agents become relevant when value depends on completing work across multiple steps, tools or systems.

This is a governance decision as much as an architecture decision: unnecessary autonomy creates unnecessary control cost.

Every step from rules to agents increases flexibility. It can also increase ambiguity, authority and the cost of being wrong.

GOVERNANCE OPERATING MODEL

Where AI belongs — and what type fits the work

Select technology according to the structure of the work. Increase governance according to the authority and consequence attached to it.

Flexibility ↑

Autonomy ↑

Consequence ↑

Control requirement ↑

01

Deterministic work

Rules / BPM / traditional automation

Low flexibility · high predictability

Known conditions, fixed policy, deterministic calculations and workflow routing.

Fees, validations, reconciliations, explicit eligibility rules.

02

Prediction

Machine learning

Probabilistic output · model risk

Pattern recognition, ranking, propensity, anomaly detection and forecasting.

Fraud scoring, churn, propensity, collections prioritization.

03

Language & synthesis

Generative AI

Flexible output · limited execution

Interpret, summarize, draft, classify and transform unstructured information.

Service summaries, document analysis, drafting, knowledge assistance.

04

Enterprise knowledge

GenAI + RAG

Grounded context · source governance

Generate responses grounded in approved internal sources and current enterprise context.

Policies, products, procedures, internal and service knowledge.

05

Bounded recommendation / decision

ML / GenAI + policy engine

Decision influence · stronger control

Recommend or select actions inside explicit policies, thresholds and exceptions.

Next best action, prioritization, bounded eligibility and exception preparation.

06

Multi-step execution

Agentic AI + tools + policy

Execution authority · maximum evidence

Coordinate steps, invoke tools and complete authorized actions across systems.

Originations, service operations, collections and remediation.

CONTROL BY CONSEQUENCE

The control model should become stronger as authority increases

The correct question is not “Is this GenAI?” The correct question is “What can this system cause?” Materiality, reversibility, customer impact, data sensitivity and execution authority are better governance signals than model family.

Control effort should concentrate where consequence is highest rather than surrounding every AI experiment with the same bureaucracy.

01

Assist

Identity, data handling, approved use, basic logging

User, input/output, model/service, connected sources

02

Recommend

Evidence, human decision rights, review criteria

Recommendation, supporting context, human acceptance or override

03

Decide

Policy boundaries, exception handling, materiality thresholds

Decision context, policy, exceptions, final accountable decision

04

Execute

Permissions, action limits, monitoring, intervention, rollback

Tool calls, system changes, authorization, action IDs, overrides, outcome

ACCOUNTABILITY

The business owner owns the outcome

AI governance often becomes committee-centric. That is a mistake. Committees define the perimeter and resolve material exceptions, but they should not absorb accountability that belongs in the operating business.

The business owner remains accountable for purpose, customer and economic outcome. Technology operates the system. Risk, compliance, security and data challenge the control design. Audit verifies whether controls and evidence operate as described.

The committee governs the perimeter. The business owner owns the outcome. Technology operates the system. Risk challenges the control. Audit verifies the evidence.
01Board / executive leadershipRisk appetite, material exceptions, portfolio visibility
02Business accountable ownerPurpose, outcomes, process design, decision rights
03AI / technologyArchitecture, release, permissions, reliability, AgentOps
04Risk / compliance / security / dataClassification, challenge, controls, escalation
05OperationsHuman intervention, exceptions, service continuity
06Internal auditIndependent verification of governance effectiveness and evidence

LEARN FROM THE FRONTIER

Provider governance is inherited control — not institutional governance

The largest AI providers are developing useful governance patterns, but those patterns operate at different layers. OpenAI combines enterprise controls with a separate frontier governance framework. Anthropic makes proportional safeguards explicit through its Responsible Scaling Policy. Open-weight ecosystems push more deployment responsibility toward the institution using the model.

These examples reveal a common direction: capability, access and deployment context change the safeguards required. But a bank cannot outsource accountability for why it used AI, which data it exposed, what decisions it delegated or what happened to the customer.

Governance responsibility shifts with deployment model

Managed AI service

More provider controls can be inherited

Enterprise integration

Shared responsibility becomes explicit

Self-hosted / open-weight

More operating responsibility moves to the institution

Identity & access

Data controls

Model evaluation

Safety layers

Observability

Patching

Incident response

GOVERNANCE EVIDENCE

In the end, governance is evidence

Saying “we use AI responsibly” has almost no operational value. Saying that a material decision was produced by a specific system version, using a defined context, under an approved policy, within explicit permissions, and that a named person or system accepted, changed or executed the result is governance.

Evidence is what converts policy into control. If the institution cannot reconstruct what happened, the control environment is weak even if policies, committees and model inventories exist.

The output of governance is therefore not approval. It is reconstructability: the ability to explain the intent, identity, context, authority, decision, action, intervention and outcome of a material AI process.

Governance without evidence is policy. Evidence turns policy into control.
01IntentWhy was AI used and what objective was authorized?
02IdentityWhich model, agent, service and person participated?
03ContextWhat data, knowledge and state were available at the time?
04AuthorityWhat was the system allowed to recommend, decide or execute?
05DecisionWhat did it recommend or decide, under which policy?
06ActionWhat actually changed in the enterprise or customer process?
07InterventionWho approved, overrode, stopped, reversed or escalated it?
08OutcomeWhat happened to the customer, process, risk and business result?

VERSION

TIME

POLICY

OWNER

TRACE

EVIDENCE BY CONSEQUENCE

Evidence intensity should follow consequence too

The institution does not need the same evidence depth for every AI use. But every increase in authority should add evidence, not replace it.

01

Assist

User + model/service + input/output + data handling
02

Recommend

+ evidence used + recommendation + human decision
03

Decide

+ applicable policy + decision context + exceptions + accountability
04

Execute

+ permissions + tool calls + system change + transaction/action ID + rollback state

REGULATED OPERATING MODEL

Keep a common governance core and localize obligations

A regional institution should not recreate its entire AI governance model country by country. The common operating core should define inventory, accountability, risk classification, lifecycle, evidence, AgentOps, intervention and incident response.

Local rule packs should add jurisdiction-specific privacy, consumer protection, explainability, sector regulation, record retention, outsourcing, data-location and supervisory requirements.

This keeps governance scalable without pretending that one global policy resolves every local obligation.

Shared governance core + provider controls + country / regulatory overlay

THESIS

The objective of AI governance is not to prove that the institution uses AI responsibly. It is to make every material AI decision understandable, controllable and reconstructable.

Choose the least autonomous technology that solves the problem. Increase control with consequence. Preserve evidence until the institution can explain what happened without relying on memory or trust.

José Ñáñez