Governance Isn’t a Framework You Wait For. It’s an Architecture You Build.

August 28, 2026
August 28, 2026 Srikanth Robbi

Governance Isn’t a Framework You Wait For. It’s an Architecture You Build.

A governance gap is opening up in financial services: 62% of firms have deployed AI agents, 93% of those firms gave the agents real autonomy before building the visibility to fully see what that autonomy was doing, and regulators just wrote generative and agentic AI out of the first meaningful rewrite of model risk guidance in over a decade. The fastest-growing risk category in the building is now the one with no dedicated supervisory framework attached to it.

We agree with that diagnosis, laid out recently by Gunjan Doshi. This piece is about the part that comes next: what do you actually build while the framework catches up.

The gap isn’t a policy problem. It’s a design problem.

It’s tempting to treat “no dedicated regulatory framework yet” as a governance program to write — a policy document, a review committee, a set of approval gates layered on top of AI initiatives already in flight. That instinct isn’t wrong, exactly. It’s just late. By the time governance shows up as a policy document, the agents it’s meant to govern are usually already in production, already making decisions, and already generating an audit trail — or failing to — based on however they happened to be built.

That’s the pattern we see most often when we’re brought in after the fact: an organization with a genuinely well-intentioned governance initiative underway, and an agent architecture underneath it that was never designed to produce the evidence the governance initiative now needs. The two were built on different timelines by different teams answering different questions. Reconciling them after the fact is expensive, slow, and rarely complete.

What “built in” actually means

The distinction we work from with clients is simple to state and harder to execute: governance has to be a property of how the system is architected, not a layer applied to it afterward. Concretely, that means three things are true from the first line of code, not retrofitted once an examiner asks:

Every agent’s authority is explicit and scoped. Not “the agent has access to the customer database,” but a specific, enumerable list of what it can read, what it can write, what it can escalate, and what it cannot do under any circumstance without a human in the loop. If you can’t produce that list today for every agent currently in production, that’s the first gap to close — before adding a single new one.

Every consequential action produces an evidentiary trail by default, not by configuration. The difference between “we could probably reconstruct what happened” and “here is the record” is the difference between a governance program that survives an exam and one that doesn’t. That trail has to be a structural feature of the system, generated automatically as a side effect of the agent doing its work, not a logging feature someone has to remember to turn on.

Authority can be revoked at the speed the risk moves, not the speed the org chart moves. A kill switch that requires a change-management ticket isn’t a kill switch. If an agent’s authority can’t be paused or narrowed in minutes by the person accountable for it, the governance model is aspirational rather than operational.

None of this is exotic. It’s the same operating discipline that’s shown up, independently, in how the major payment networks are approaching agent-to-agent commerce this year, and in how the more mature banking AI deployments are structuring credit and underwriting agents. The organizations converging on this pattern didn’t coordinate with each other. They arrived at the same architecture because it’s the only one that scales past a handful of pilots without accumulating risk faster than anyone can track it.

Why this is where we start

This is the premise our AI-DLC delivery model is built around: the cadence at which AI-native teams can build has changed by an order of magnitude, and the governance wrapped around that build has to change with it — designed in from the first Bolt, not bolted on once the pilot succeeds and the board asks what happens next. An operating model that treats authority, audit trail, and revocability as first-class requirements doesn’t need to wait for the RFI to resolve into a rule. It’s already built to whatever the strictest plausible version of that rule turns out to be.

The regulatory vacuum Gunjan described won’t last. What gets built into your agents while it’s open will.

Read Gunjan Doshi’s original piece, The Governance Gap Nobody’s Racing to Close, for the full picture of what the data is telling the industry right now.

Let's Work Together

InRhythm drives AI-driven digital transformation and platform modernization for Fortune 500 companies in wealth & asset management, payments, and enterprise retail sectors. Our expert team delivers innovative solutions to accelerate technology adoption and improve time to market.

© 2025 InRhythm all rights reserved.

195 Broadway
Suite 2400, Floor 24
New York, NY 10007

ge*@******hm.com

1 800 683 7813

© 2024 InRhythm all rights reserved.

contact-section
InRhythm
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.