Home/ Insights/ Agentic AI Governance
Research topic

Agentic AI Governance & Model Risk

21 pieces from Duczer East's practitioners on governing AI agents in regulated enterprises: how they get identity, what they are permitted to do, where those limits are enforced, and what evidence a risk committee or examiner will accept.

What this topic is about

An AI agent is a non-human identity that can take real action inside your systems. Most regulated enterprises are about to have more of them than they have employees, and the security and model-risk frameworks those institutions run were written for neither. Model-risk guidance assumes a model produces a number a human reviews. Identity and access frameworks assume the principal behind a credential is a person or a fixed service. Agents break both assumptions at once.

The work in this collection starts from a position that is no longer controversial among practitioners: a system prompt is not a control. Governance that holds up has to live where it can be enforced and evidenced — in identity, in the permission model, in the control plane between an agent and the systems it touches, and in the audit trail that records what the agent knew when it acted. The pieces here work through each of those layers, the vendor claims made about them, and the economics of building them properly.

For banks the question sharpened in April 2026, when SR 26-2 replaced fifteen years of model-risk guidance and deliberately placed generative and agentic AI outside its scope. The duty to govern did not move. The template for doing it disappeared. Three pieces below take that situation apart from the perspectives of the architect, the chief compliance officer and the CFO.

From research to delivery

Governance that clears model-risk review, not just the pilot

Duczer East designs and builds the identity, permission and control-plane architecture that lets agents operate inside a regulated institution — and produces the evidence a risk committee needs to approve it.