Runtime governance of agentic AI
Banks want to scale agentic AI. The control question is not whether the agent may act. It is whether the institution authorized the meaning the agent is acting on. That layer is the reasoning layer. My capstone framework, published this spring, governs it: Summary on https://t.co/ofjEMrnWYc
The Agentic AI Governance Playbook is now live.
A runtime governance architecture for determining whether an autonomous system’s Operational Interpretation remains institutionally authorized before execution.
https://t.co/Agot9UqKiq
#AgenticAI#AIGovernance
Maureen Doyle-Spare submitted April 2026 to the Financial Stability Board on Agentic Workflow Drift, Agentic Workflow Subversion and the Semantic Deviation Index as cross-border propagation risk.
https://t.co/okN5njijWt
Frontier AI has moved squarely into the Financial Stability Board‘s financial-stability agenda. In a letter dated 28 August and published on 31 August, FSB Chair Andrew Bailey warned that frontier AI models are developing increasingly sophisticated autonomy, problem-solving abilities and threat capabilities.
https://t.co/wg1JC5LcuK
Maureen Doyle-Spare submitted April 2026 to the Reserve Bank of India on Agentic Workflow Drift, the Semantic Deviation Index and the Deterministic Gate for the FREE-AI implementation phase.
https://t.co/dnILWgIa9u
India is preparing UPI for delegated machine payments. Once an agent can turn a standing instruction into a transaction, payment authorization starts before the payment rail.
https://t.co/F61Az4ad4M
Agentic AI is changing cybersecurity from individual automated actions to coordinated operational workflows.
Taiwan's latest disclosure is an important signal. As agents carry state across tools and systems, the trajectory itself becomes a governance problem.
https://t.co/O5Me9avwaQ
I unpack the governance gap here, including Operational Interpretation, the Reasoning Layer, pre-execution assurance, and why model governance alone does not close it:
https://t.co/x7BDJ6Rmej
Fannie Mae’s new AI governance requirements are now in effect for covered mortgage sellers and servicers.
That moves AI governance from principle into operating obligation.
As agentic AI moves deeper into origination and servicing, the harder control question sits at runtime: what meaning was the system authorized to act on?
Thank you @FinancialBrand for publishing my latest article.
As organizations adopt agentic AI, governance has to extend beyond models to the reasoning layer where operational meaning is resolved at runtime.
https://t.co/l6FQc5a50W
Agentic Workflow Drift: The Next Control Failure in Banking Will Not Break a Rule. It will execute cleanly and look like success.
I name it Agentic Workflow Drift: a meaning resolved in the reasoning layer that no one authorized.
New in @towards_AI https://t.co/Cc8bn7odb3
Thank you SSRN. Agentic AI introduces a new governance surface: the reasoning layer, where meaning is resolved before any action is taken. The Agentic 3 C’s Framework sets the foundation for governing it. Context. Control. Coordination.
https://t.co/18QBdtpxQc
SR 26-2 did not create a governance vacuum for agentic AI. It created a governance obligation.
Banks must now decide how to control the layer where an agent determines what institutional inputs mean before it acts.
That is not conventional model risk. It is reasoning-layer governance.
My piece for @CogWorldHub
SR 26-2 placed generative and agentic AI outside model-risk scope and left each bank to govern it.
That did not remove the control risk. It relocated it to the reasoning layer, where the agent decides what its inputs mean before it acts.
New piece in @CogWorldHub
https://t.co/5tQwWYHNxZ
The hard part with agentic AI: the failure reads green everywhere. No output is wrong, so model risk misses it. No process breaks, so ops risk misses it. No person acted, so conduct risk misses it. The drift lives in the reasoning layer none of them owns.
The hard part: the failure reads green everywhere. No output is wrong, so model risk does not see it. No process breaks, so operational risk does not see it. No person acted, so conduct risk does not see it. The drift lives in the layer none of them owns.
The full runtime reference architecture behind this piece, covering the Reasoning Layer, the Semantic Control Plane, the Semantic Deviation Index, and the Deterministic Gate, is in my capstone paper:
https://t.co/kSgcYnC879
New on @DDInvestorHQ: From Model Risk to Reasoning Risk. A validated model can still act on an unauthorized meaning. Agentic AI moves the governance exposure from the model to the interpretation it acts on at runtime.
https://t.co/kjehrN4LTa
Runtime governance of agentic AI
Banks want to scale agentic AI. The control question is not whether the agent may act. It is whether the institution authorized the meaning the agent is acting on. That layer is the reasoning layer. My capstone framework, published this spring, governs it: Summary on https://t.co/ofjEMrnWYc
SR 26-2 tells banks to govern agentic AI. It does not say how to govern the reasoning layer, where the agent resolves what a regulated term means before it acts. That is the unsolved gap. Five papers mapping it. Research library: Research Library: https://t.co/ESKeGlS8SS
Banks are deploying agentic AI with controls built for a different object.
Input validation checks inputs. Model risk checks models. Nothing checks the interpretation an agent resolves before it acts.
I spent the last year building the runtime architecture that governs that layer. @towards_AI just published it:
https://t.co/GsUAsY1hLY