Agentic AI Governance & Model Risk
21 pieces from Duczer East's practitioners on governing AI agents in regulated enterprises: how they get identity, what they are permitted to do, where those limits are enforced, and what evidence a risk committee or examiner will accept.
What this topic is about
An AI agent is a non-human identity that can take real action inside your systems. Most regulated enterprises are about to have more of them than they have employees, and the security and model-risk frameworks those institutions run were written for neither. Model-risk guidance assumes a model produces a number a human reviews. Identity and access frameworks assume the principal behind a credential is a person or a fixed service. Agents break both assumptions at once.
The work in this collection starts from a position that is no longer controversial among practitioners: a system prompt is not a control. Governance that holds up has to live where it can be enforced and evidenced — in identity, in the permission model, in the control plane between an agent and the systems it touches, and in the audit trail that records what the agent knew when it acted. The pieces here work through each of those layers, the vendor claims made about them, and the economics of building them properly.
For banks the question sharpened in April 2026, when SR 26-2 replaced fifteen years of model-risk guidance and deliberately placed generative and agentic AI outside its scope. The duty to govern did not move. The template for doing it disappeared. Three pieces below take that situation apart from the perspectives of the architect, the chief compliance officer and the CFO.
Start here
Four pieces that set out the argument the rest of this hub assumes.
-
Why Agent Governance That Passes Pilots Fails Audit
Where governance actually has to live once the system prompt is ruled out.
9 min read -
Design the Decision Before the System
The control-surface decisions architecture teams are making by default, and how to make them deliberately.
9 min read -
The Kill Switch Is Not the Story
Why a vendor control tower is not the same as an enterprise answer for agent management.
8 min read -
Every Prompt-Based Control Is a Future Postmortem
A prompt instruction is a suggestion. Enforceable controls sit somewhere else.
8 min read
SR 26-2 and the model-risk gap
In April 2026 the banking regulators rewrote model-risk guidance and placed generative and agentic AI outside it. These three read the consequences.
-
SR 26-2 Carved Out Agentic AI. The Liability Didn't Move.
The short version: outside the guidance is not outside the risk perimeter.
3 min read -
After SR 26-2, Agentic AI Governance Has to Be Load-Bearing
The standard a bank writes to fill the gap is worth what its architecture can enforce and prove.
8 min read -
The CCO and CFO Inherit SR 26-2
The guidance did not say who owns the cost of governing agentic AI. That silence lands on two desks.
7 min read
Identity, permissions and control planes
The mechanics: how an agent gets credentials, what it is allowed to touch, and where the boundary between observing and acting is enforced.
-
Workload Identity Federation Stops at the Agent
Eliminating long-lived credentials is the easy part. Holding the pattern at a hundred projects is not.
8 min read -
MCP Is a Context Protocol. Most Enterprises Are Letting It Become an Authorization Model.
The API-versus-MCP debate sits one layer above the decision that matters.
8 min read -
Onboarding Friction Is Either Vendor Policy or Your Policy
If an agent needs a human to click Approve for credentials, every workflow inherits that step.
6 min read -
Scalable Capital Publishes Its Agent Permission Model
A European bank published which doors it locked for AI assistants. The locked list is the useful one.
3 min read -
Single-Agent Governance Is Buildable. Enterprise Scale Is Where the Work Lives.
Constraining one agent is a solved pattern. Constraining a fleet consistently is the open problem.
3 min read -
The Agent Did Exactly What the Attacker Told It To
A prompt-injection incident walked end to end, and what the permission model should have prevented.
7 min read -
Conditionally Approved: Where AI Projects Go to Stall
The governance gate between pilot and production, and why most portfolios cannot clear it on schedule.
4 min read
The economics of governing agents
For the sponsor and the CFO: what agent governance costs, what to ask before approving it, and why the requests are arriving one platform at a time.
-
The CFO Question on Agent Governance Spend
Each capital request is defensible alone. The exposure is in the gaps between them.
4 min read -
What Your Agent Platform Sponsor Should Tell You
A diligence standard for agent control planes that is different from the one that worked for SaaS.
4 min read -
The Line Item Every CFO Is About to Add to the AI Budget
The cost structure of AI moving from experiment to operation is not what the first business cases assumed.
4 min read -
Governance Is Now the Gating Factor for AI Scale
The constraint has shifted from what AI can do to what the enterprise can govern.
4 min read
Notes from the field
Shorter reads on developments worth knowing about.
-
Your AI Agents Have Credentials. Do You Know Which Ones?
On the Okta threat research showing agents leaking tokens under ordinary enterprise conditions.
3 min read -
The Agent Wars Aren't About Agents
Who owns the audit and policy plane is the decision underneath the platform announcements.
3 min read -
AI Protections Are Failing as Powerful Systems Spread Online
What a CISO can and cannot assume about the safety barriers in a frontier model.
3 min read
Governance that clears model-risk review, not just the pilot
Duczer East designs and builds the identity, permission and control-plane architecture that lets agents operate inside a regulated institution — and produces the evidence a risk committee needs to approve it.