Skip to content
Open to board advisory and board seats: 2H 2026, then CY 2027-2028.
See details →
Topic

AI Governance & Regulation

Essays on AI governance in regulated finance: NIST AI RMF and ISO 42001 mapping, fair lending, shadow AI, and controls that survive an audit.

AI governance from the practitioner's side: mapping to NIST AI RMF and ISO 42001, fair lending as the real governance problem in consumer credit, shadow AI, and why a policy PDF your agents can't read isn't a control. Written by Michael York, who stood up AI governance for a regulated fintech platform. These essays treat governance as an engineering discipline, not a document.

27 posts, newest first

Aug 26, 2026 10 min

Your AI Contract Covers a Third of the Traffic

Every enterprise AI control binds to an account. Two thirds of AI users on corporate devices use personal logins, so your contract governs a minority of use.

AIAI GovernanceIdentityShadow ITFintech
Aug 25, 2026 10 min

The Model Was Bad Is Not a Root Cause

A model defect, a provider stall, a bad route, and a broken check are four separate findings. If your AI failure log has one bucket, none can be acted on.

AIAI GovernanceObservabilityModel RiskFintech
Aug 19, 2026 10 min

Four Verbs, and None of Them Is Delete

A memory store's tool manifest is its real retention control. When the verbs read capture, search, list, count, you built a system of record with no eraser.

AIAI GovernanceData ProtectionGRCFintech
Aug 17, 2026 10 min

Open Weights Are Not a Residency Plan

I caveated self-hosted open weights on capability, not infrastructure. Near-frontier weights need a rack, and downloading them makes you the model provider.

AIAI GovernanceAI InfrastructureModel RiskVendor Risk
Aug 11, 2026 10 min

Your Agent Decides Which Record Wins

Reconstructing a customer across six systems means deciding which record wins. Hand it to an agent and unwritten precedence becomes code nobody approved.

AIAI GovernanceAI AgentsRisk ManagementFintech
Aug 7, 2026 10 min

Sanitized Is Not Authorized

"PII redaction before egress" is filed as the data-handling control. It answers whether identifiers remain, not whether this content may go to this destination.

AIAI GovernanceData ProtectionGRCFintech
Aug 3, 2026 10 min

Country of Origin Is Not a Control

Risk committees ask whether to allow Chinese models as if nationality were a control. Your regulator defines foreign by where the work happens, not the flag.

AIAI GovernanceVendor RiskModel RiskFintech
Jul 29, 2026 10 min

Your Tool Catalog Is Standing Access

A resident tool definition is a standing grant with no request, no approver, and no expiry. We scoped the MCP servers and never scoped the catalog.

AIAI AgentsAI SecurityNon-Human IdentityAI Governance
Jul 22, 2026 8 min

Fair Lending: The Real AI Governance Problem

Mapping models to AI frameworks isn't governance for credit. The binding constraint is fair-lending law: ECOA/Reg B, FCRA adverse action, SR 11-7 model risk.

AIAI GovernanceFair LendingModel RiskFintech
Jul 21, 2026 9 min

'We Don't Train on Your Data' Is Not Enough

An agent told to open no files obeyed, while the product uploaded the whole repo, canary included. "We don't train on your data" answers the wrong question.

AIAI SecurityAI GovernanceFintech
Jul 18, 2026 8 min

Your Prompt Is the Approval. That's the Gap.

An MCP connector executes writes with no approval screen: your prompt becomes the one boundary nobody governed. That missing gate is a control-plane gap.

AIAI AgentsAI SecurityAI GovernanceNon-Human IdentityFintech
Jul 15, 2026 10 min

Your AI Policy Is a PDF. Agents Can't Read It

A model given thousands of extra words wrote better prose, and failed the delivery contract two runs in three. Rules agents can ignore fail audits.

AIAI GovernanceGRCAuditPolicy-as-Code
Jul 9, 2026 9 min

Shadow AI: Your "Personal Tool" Is Production

A coding agent stands up a data-touching tool in an afternoon. The moment it needs a login or gets shared, it's a production system nobody reviewed.

AIAI GovernanceAI AgentsSecurityGRC
Jul 6, 2026 9 min

Stop Gating the $40 Question

Two hours and $40 did what a top engineer says he couldn't, and no routing table would have assigned it. Gating frontier access defunds your own sensing.

AIAI GovernanceOrg DesignFinOpsBoard Reporting
Jul 3, 2026 8 min

The Second Agent Cheap, the Fiftieth Boring

Build cost was never the constraint in a regulated shop: agent #50 hits the same security review as agent #1. Make identity and action gates reusable.

AIAI AgentsPlatform EngineeringAI GovernanceDevOps
Jul 1, 2026 9 min

Context Custody Is a Concentration Risk

Intelligence went cheap, yet enterprise buyers expect to pay more for Claude. You're not paying for the brain. You're paying for where your context lives.

AIAI GovernanceBoard ReportingRisk ManagementFintech
Jun 28, 2026 12 min

Why We Built AgentOS

One model scored 78% in one agent harness and 42% in another. In regulated fintech the harness is where governance lives, so we built our own: AgentOS.

AIAI AgentsAI GovernanceSecurityFintech
Jun 27, 2026 6 min

Bake Audit Evidence Into Your AI Pipeline

Audit-defensibility isn't a document you write after the fact. It's a property you engineer into the AI pipeline so its operation emits evidence as exhaust.

AIAI ComplianceAuditNIST AI RMF
Jun 25, 2026 5 min

The 2026 AI Regulatory Map on One Page

Everyone read 'EU AI Act deferred to 2027' and exhaled, but the part fining 3% of global revenue turns on in August. The four 2026 rules with teeth.

AIAI GovernanceComplianceNIST AI RMF
May 26, 2026 5 min

Your Agent Dashboard Is Green and Lying

Uptime tiles tell you the service answered, nothing about whether the answer was right. That gap is where a model-risk review will eat you alive.

AI GovernanceObservabilityRisk ManagementFintech
May 22, 2026 3 min

The Boundary Layer Is the Actual AI Control

Every AI governance framework describes the same controls. The one that matters is a design decision: does this output get acted on, or interpreted first?

AI GovernanceNIST AI RMFISO 42001CCPA
May 12, 2026 5 min

Three Token Counts, Zero You Can Attest To

Codex says one number, Claude another, your gateway a third. That isn't a metering problem. It's an attestation problem regulated industries can't afford.

AI GovernanceFintechDevOpsCloud Security
Apr 21, 2026 5 min

Concentration Risk in the Three-Lab AI Stack

Most of the AI on your roadmap traces to three labs on the same chips, supply chain, and balance sheets. That's a concentration risk your board hasn't priced.

AI GovernanceVendor RiskBoard StrategyResilience
Apr 7, 2026 5 min

Dark Code Is a Control Failure, Not Tech Debt

AI is filling repos with code nobody can explain. We call it tech debt; it's a control failure, and it should fail CI like a missing approver does.

AI GovernanceDevOpsSoftware Supply ChainFintech
Mar 17, 2026 6 min

Shadow-Agent Discovery for Regulated FIs

Unsanctioned AI agents already run in your environment with your credentials. Find, classify, and gate them before they touch member data or an exam does.

AI SecurityAI GovernanceFintechRisk Management
Mar 5, 2026 5 min

An AI Agent Dropped Prod: The Change Playbook

Coding agents are committing real change to real systems. The question isn't whether to let them. It's how to give them speed without a SOC 2-fatal mistake.

AI GovernanceDevOpsComplianceFintech
Feb 24, 2026 5 min

Agent Memory Is a Data-Residency Problem

Give every agent a durable, MCP-connected brain and you've stood up a new data lake of PII and PCI scope nobody classified, encrypted, or can purge.

AI GovernanceData ProtectionFintechDevOps