AI Governance: From Theoretical to Operational

Read Time: 5 minutes
Authored by: Vera Shulgina
Innovation & Tech
All Segments

Summary

Just as AI goes from experimentation to production, governance goes from theoretical to operational. Investment firms can extend familiar data governance concepts into a new layer of reasoning governance, but human-in-the-loop review remains essential.

The pilot-to-production trigger

As agentic AI moves from pilot to production in investment management, the governance stakes change completely. If an LLM writes an awkward email to a colleague, the stakes are low. If an agent miscalculates NAV or drops assets from a portfolio, the consequences affect careers and firm reputations. Data governance gives firms a foundation to build from, but it doesn’t cover everything that agentic AI puts at risk.

Use of agentic AI is a risk to be managed at the same level as regulatory or operational risk. Our clients have begun to view AI risk as a board-level concern, but many boards find themselves taking only initial steps in discussing it.

Part of the challenge arises because regulatory risk is familiar to boards and the C-suite. If an AI agent does something that violates the ’40 Act, boards can wrap their heads around what happened. But if an AI agent accesses and uses biometric data to determine which investment products a client can access, most jurisdictions don’t have any explicit regulation for this scenario, possibly with the exception of the EU Artificial Intelligence Act.i The more capable AI becomes, the harder it is for regulation to keep up.

Familiar and unfamiliar parts

But there are parallels to data governance alongside the differences. Most firms already have a data governance foundation in place. And that’s the first place to start building from. Absent explicit and unambiguously codified AI regulation, firms can make safe moves by starting with “reasoning governance.”

“The Agentic 3 C’s Framework … [are] the operating principles required at the reasoning-layer to enable safe, trusted agentic AI at scale in financial services. The framework establishes Context, Control, and Coordination as the three conditions under which an agentic system’s reasoning can be considered governable.” — Maureen Doyle-Spareii

The Agentic 3 C’s Framework establishes the conditions for governable reasoning. The table below maps this into practice by extending familiar data governance principles into their reasoning layer equivalents:

Data Governance PrincipleReasoning Principle
IntegrityDoes the chain of reasoning completely reflect the behavior of your asset classes and processes?
TransparencyCan a human understand the logic and actions of your agents, and is it fully exposed to them?
AuditabilityCan others review well-documented agent behavior independently?
AccountabilityDo people have clear ownership of agents and outputs?
StewardshipWho is responsible for managing and protecting the behavior of agents being used in your live environment?
Checks and BalancesWhat oversight exists for the individuals designing and building your agents?
StandardizationDo you have a standard model and platform for the building of agents?
Change ManagementDo you regularly adapt your agents to fit changes to your business model and the broader financial ecosystem?

Table 1: Data governance rules sourced from The Data Governance Institute,iii Reasoning governance analysis by Arcesium

Data sovereignty means knowing whether your platform vendor can guarantee that a reasoning trace containing your portfolio logic never touches their other clients’ environments. In multi-tenant architectures, this guarantee is structurally difficult to make: models, compute, and data layers are shared by design. Single-tenant deployments eliminate that ambiguity, but they come with higher cost and operational overhead. Firms need to weigh that tradeoff explicitly rather than inheriting a default.

Human-in-the-loop isn’t optional

Human review isn’t optional for any action that touches the street, but humans should be assisted by tools and platforms that allow them to complete those parts of the job. An agent builder platform, for example, can help standardize and prevent egregious issues. In investment operations, the operations role remains essential. It’s easy to imagine an AI agent creating a market selloff without careful review.

But aside from huge market swings, AI risks can be more subtle, raising the stakes for reasoning governance.

Early generations of AI are probabilistic in that they generate statistically probable outputs, not answers grounded in domain knowledge. Agentic systems layer deterministic orchestration on top of these models: defined tools, structured data access, and explicit rules. That orchestration narrows the range of outcomes, but even well-scoped agents can follow different reasoning paths to arrive at the same result. That element of deterministic systems makes explainability essential. You can’t tell a regulator that you don’t know how you derived a number just because an agent you built said so. Human operators need to understand an agent’s reasoning as it happens, while others in your firm will need to know how it happened after the fact. Both make human-in-the-loop a critical principle.

Where the line falls

The firms making the most progress are making scoping decisions at the tool, data, environment, and model layers. Without scope discipline now, firms will find themselves governing agents they didn’t design and can’t audit. It also allows them to embed careful governance and risk management as they progress.

There can also be a gap between standards and actual behavior. Using WhatsApp or Telegram to communicate with a limited partner or client seemed implausible until people did exactly that when such apps began to hit the mainstream. The parallel for AI is direct: once people start using personal AI tools for work, the behavior embeds quickly and becomes difficult to reverse. Firms need to get ahead of that by establishing sanctioned AI environments and governing how both people and systems use AI in production.

Keep in mind, too, that we’re still talking about a relatively early generation of AI. Agentic AI is only one level of capability. What’s coming next is autonomous AI, where agents orchestrate other agents with minimal human intervention. That’s still ahead of current production use, but AI capability is compounding quickly. Agents that govern other agents will be exponentially harder to justify to a regulator or explain to a board. The firms building governance infrastructure now — clear scope, auditable reasoning, human review at critical junctures — will be the ones equipped to extend it when that next generation arrives. Just as AI goes from experimentation to production, governance goes from theoretical to operational.

Is Your Firm Ready for Full-Spectrum Crypto Operations?

Discover how your operating model compares to the next generation of institutional digital asset investing.

Authored By

Vera Shulgina

Vera is responsible for Arcesium's data strategy with a focus on driving value for clients through data solutions and data partner integrations.

View Author Profile

Share This Post

Sources:

[i] EU, 2024. https://artificialintelligenceact.eu/high-level-summary/

[ii] SSRN Working Paper, 2026. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6674761

[iii] Data Governance Institute, 2026. https://datagovernance.com/goals-and-principles-for-data-governance/

Subscribe Today

No spam. Just the latest releases and tips, interesting articles, and exclusive interviews in your inbox every week.