Skip to content
Open to board advisory and board seats — 2H 2026, then CY 2027–2028.
See details →
Topic

AI Governance & Regulation

Essays on AI governance in regulated finance: NIST AI RMF and ISO 42001 mapping, fair lending, shadow AI, and controls that survive an audit.

AI governance from the practitioner's side: mapping to NIST AI RMF and ISO 42001, fair lending as the real governance problem in consumer credit, shadow AI, and why a policy PDF your agents can't read isn't a control. Written by Michael York, who stood up AI governance for a regulated fintech platform — these essays treat governance as an engineering discipline, not a document.

19 posts, newest first

Jul 22, 2026 9 min

Fair Lending: The Real AI Governance Problem

Mapping models to AI frameworks isn't governance for credit. The binding constraint is fair-lending law — ECOA/Reg B, FCRA adverse action, SR 11-7 model risk.

AIAI GovernanceFair LendingModel RiskFintech
Jul 21, 2026 9 min

'We Don't Train on Your Data' Is Not Enough

An agent told to open no files obeyed — while the product uploaded the whole repo, canary included. "We don't train on your data" answers the wrong question.

AIAI SecurityAI GovernanceFintech
Jul 18, 2026 8 min

Your Prompt Is the Approval. That's the Gap.

An MCP connector executes writes with no approval screen — your prompt becomes the one boundary nobody governed. That missing gate is a control-plane gap.

AIAI AgentsAI SecurityAI GovernanceNon-Human IdentityFintech
Jul 15, 2026 9 min

Your AI Policy Is a PDF. Agents Can't Read It

A model given thousands of extra words wrote better prose — and failed the delivery contract two runs in three. Rules agents can ignore fail audits.

AIAI GovernanceGRCAuditPolicy-as-Code
Jul 9, 2026 10 min

Shadow AI: Your "Personal Tool" Is Production

A coding agent stands up a data-touching tool in an afternoon. The moment it needs a login or gets shared, it's a production system nobody reviewed.

AIAI GovernanceAI AgentsSecurityGRC
Jul 6, 2026 8 min

Stop Gating the $40 Question

Two hours and $40 did what a top engineer says he couldn't — and no routing table would have assigned it. Gating frontier access defunds your own sensing.

AIAI GovernanceOrg DesignFinOpsBoard Reporting
Jul 3, 2026 9 min

The Second Agent Cheap, the Fiftieth Boring

Build cost was never the constraint in a regulated shop — agent #50 hits the same security review as agent #1. Make identity and action gates reusable.

AIAI AgentsPlatform EngineeringAI GovernanceDevOps
Jul 1, 2026 9 min

Context Custody Is a Concentration Risk

Intelligence went cheap, yet enterprise buyers expect to pay more for Claude. You're not paying for the brain — you're paying for where your context lives.

AIAI GovernanceBoard ReportingRisk ManagementFintech
Jun 28, 2026 13 min

Why We Built AgentOS

One model scored 78% in one agent harness and 42% in another. In regulated fintech the harness is where governance lives, so we built our own: AgentOS.

AIAI AgentsAI GovernanceSecurityFintech
Jun 27, 2026 7 min

Bake Audit Evidence Into Your AI Pipeline

Audit-defensibility isn't a document you write after the fact — it's a property you engineer into the AI pipeline so its operation emits evidence as exhaust.

AIAI ComplianceAuditNIST AI RMF
Jun 25, 2026 7 min

The 2026 AI Regulatory Map on One Page

Everyone read 'EU AI Act deferred to 2027' and exhaled — but the part fining 3% of global revenue turns on in August. The four 2026 rules with teeth.

AIAI GovernanceComplianceNIST AI RMF
May 26, 2026 6 min

Your Agent Dashboard Is Green and Lying

Uptime tiles tell you the service answered — nothing about whether the answer was right. That gap is where a model-risk review will eat you alive.

AI GovernanceObservabilityRisk ManagementFintech
May 22, 2026 5 min

The Boundary Layer Is the Actual AI Control

Every AI governance framework describes the same controls. The one that matters is a design decision: does this output get acted on, or interpreted first?

AI GovernanceNIST AI RMFISO 42001CCPA
May 12, 2026 6 min

Three Token Counts, Zero You Can Attest To

Codex says one number, Claude another, your gateway a third. That isn't a metering problem — it's an attestation problem regulated industries can't afford.

AI GovernanceFintechDevOpsCloud Security
Apr 21, 2026 6 min

Concentration Risk in the Three-Lab AI Stack

Most of the AI on your roadmap traces to three labs on the same chips, supply chain, and balance sheets. That's a concentration risk your board hasn't priced.

AI GovernanceVendor RiskBoard StrategyResilience
Apr 7, 2026 6 min

Dark Code Is a Control Failure, Not Tech Debt

AI is filling repos with code nobody can explain. We call it tech debt; it's a control failure — and it should fail CI like a missing approver does.

AI GovernanceDevOpsSoftware Supply ChainFintech
Mar 17, 2026 7 min

Shadow-Agent Discovery for Regulated FIs

Unsanctioned AI agents already run in your environment with your credentials. Find, classify, and gate them before they touch member data or an exam does.

AI SecurityAI GovernanceFintechRisk Management
Mar 5, 2026 6 min

An AI Agent Dropped Prod: The Change Playbook

Coding agents are committing real change to real systems. The question isn't whether to let them — it's how to give them speed without a SOC 2-fatal mistake.

AI GovernanceDevOpsComplianceFintech
Feb 24, 2026 6 min

Agent Memory Is a Data-Residency Problem

Give every agent a durable, MCP-connected brain and you've stood up a new data lake of PII and PCI scope nobody classified, encrypted, or can purge.

AI GovernanceData ProtectionFintechDevOps