Artificial intelligence
 •  
October 5, 2026

Financial institutions no longer have to choose between AI velocity and governance

Manvir Sandhu
By
Manvir Sandhu
Founder & Chief Innovation Officer

Part 1 of 2. Why AI stalls at scale in financial services, and three shifts that fix it.

Most banks and credit unions we work with already have AI that works. They've seen agents cut loan review time, flag member risk earlier, and turn credit analysis around in hours instead of days. What most of them don't have is that AI running in production.

When we ask what's holding it back, the answer is almost always governance. Each platform can govern the AI it runs, but nothing governs AI across all of them, and an examiner asks about the whole decision.

That changed this year. Three shifts, all built on platforms most institutions already own, make institution-wide governance practical now. Here's what changed and what it means for your next deployment.

The platform gap shows up exactly when you need it most

A customer calls about a card payment they don't recognize. An AI agent in the service console picks up the case. The CRM logs the conversation in its own format, under its own definition of who the agent is. The data platform sees a service account query and checks table permissions, unaware a customer is on the line.

The model provider sees a prompt and a response, with no idea which policy applies. The integration layer logs an API call and never sees the reasoning behind it. The case closes in minutes, and each platform's governance tools did exactly what they were built to do. None of them saw the whole decision.

Six months later, an examiner asks why the agent issued that provisional credit. Your team pulls four logs in four formats and hopes the timestamps line up. No vendor sells you the governance layer above their own platform. Your team has to design it.

Govern the pattern once, then scale every deployment on it

A $10 billion regional bank we work with governed first and deployed second. That sequencing, more than any technology choice, is what let them scale. They built the governance architecture alongside the first use case instead of after it. The agent registry, identity layer, cost controls, and audit trail from that first deployment became the template every later deployment inherits.

Approve the pattern once, and every agent built to it inherits the approval. Your governance board reviews the architecture instead of each individual agent. When governance lives in the architecture from day one, each deployment after it moves faster, costs less, and holds up when any stakeholder asks how it works.

Three breakthroughs put governed AI within reach

Three shifts converged in the past year, and each one builds on platforms most institutions have already bought.

Breakthrough 1: Your trusted data platform now governs your AI too

The first breakthrough doesn't require a new purchase. The platforms financial institutions already trust with data governance have extended that trust upward into AI. Institutions can extend what they own instead of building a separate AI governance layer.

For Databricks-anchored institutions, Unity Catalog already governs data access and lineage. Databricks has now extended it to govern models, agents, MCP services, and skills, with Unity AI Gateway enforcing policy, guardrails, and cost controls on every model and agent call at runtime. For Snowflake-anchored institutions, Cortex brings AI workloads inside the same trust boundary as the data they use. For institutions with Salesforce as the CRM anchor, Data 360 and the platform's existing permission model carry that trust into the AI layer.

The payoff goes well past compliance. When an agent works on raw or poorly structured data, bad inputs stack extra variance on top of the model's own uncertainty. You get more calls, more errors, higher cost per query, and more hallucination risk.

We recommend building purpose-built, governed data products before agents go into production. Each one is scoped to a single use case, so you skip the full platform rebuild, and each is enriched with an ontology and semantic layer that gives the model context before it reasons. Unity Catalog or Snowflake Cortex governs access and lineage throughout.

A $30 billion regional bank we partner with did exactly this. They structured core data, enriched it with semantic context, and governed it through Unity Catalog. Their agents now reach confident answers faster, with fewer model calls and significantly fewer errors than the pilot that ran without that data layer. Because every answer traces back through governed data with documented lineage, the bank can reconstruct any decision end to end, and that's what audit readiness requires.

The same governed, semantically enriched data that satisfies your examiner is what makes AI accurate, cost-efficient, and audit-ready at scale.

Breakthrough 2: AI meets your people where they work, and permissions stay put

The second breakthrough came together around Dreamforce 2026. It's about how AI reaches the people who need it without leaving the governance of the systems they already trust.

Salesforce and Anthropic announced Claudeforce on August 26, and Salesforce unveiled AIforce at the Dreamforce keynote in September. Together they bring Salesforce data, workflows, and controls into the tools teams actually use, including Claude, Slack, and Microsoft Teams. Data governance, business rules, and identity controls stay inside Salesforce Financial Services Cloud. The agent works in whatever interface the user prefers, and the permission policy never moves.

A wealth technology firm shows what this looks like in practice. One advisor question, "how is this household doing?", crosses two systems. Client, household, account, and service data sit in Salesforce FSC, while positions and portfolio data sit on a separate platform. Before, the advisor juggled two logins and joined the data in their head.

The solution runs FSC headless, so the advisor never opens Salesforce. They ask Claude a plain-language question from wherever they already work, and Claude reaches FSC through Salesforce-hosted MCP, which exposes FSC capabilities as named, typed tools. Salesforce decides what comes back based on existing profiles, permission sets, roles, sharing rules, and field-level security. When the identity isn't entitled to something, Claude gets a denial with a reason instead of an error or an empty result. Nothing gets replicated outside Salesforce, and no existing control gets bypassed.

Advisors now get meeting-ready context in minutes, switch screens less, and decide faster. On the governance side, the engagement wrapped in four weeks with the trust architecture already in place and no security pushback on the model choice.

That last point matters for institutions that defaulted to Microsoft Copilot because it arrived pre-approved inside a security relationship they already had. With Claudeforce, Claude runs inside Salesforce's trust boundary and follows the permission rules the organization already runs. For institutions where model capability mattered but security approval was the gate, that path is now open.

Breakthrough 3: The AI control plane becomes something you can design

The third breakthrough matters most for institutions planning AI at program scale. No single product governs your full AI estate. The institutions getting this right design a layer above every platform, a control plane that follows each agent wherever it runs across the CRM, the data platform, the model provider, and the integration layer.

Salesforce put a name to this on September 10, days before Dreamforce. Its Enterprise AI Harness groups six capabilities (context, agency, action, governance, security, and models) and pairs them with a new AI Control Plane for registering agents, setting identity and policy, and controlling cost across Salesforce and third-party AI. It draws on Data 360, Informatica, MuleSoft Agent Fabric, Tableau, Agentforce, and Salesforce Guardian.

Two components carry most of the control-plane weight. Salesforce Guardian covers security and identity, including what agents may access and do at runtime. MuleSoft Agent Fabric is the operational layer that reaches past Salesforce, with an agent registry fed by auto-discovery scanners, an AI Gateway that tracks token usage and cost, and an agent kill switch that revokes a rogue agent's tokens and credentials at the identity layer as well as the network gateway.

For Databricks-anchored institutions, Unity AI Gateway acts as an enforcement node at the data and AI Model tier, carrying Breakthrough 1 into runtime. Snowflake Cortex plays a comparable role for Snowflake-anchored deployments.

Industry analysts see the same gap we do. Opus Research observed that Salesforce has built a strong harness for agents in its own ecosystem, while governing a multi-vendor agent workforce calls for a control plane no single vendor expects to own. That layer is the institution's design. Picture one governed architecture with several platforms enforcing it. Part 2 covers that architecture in detail.

Regulators raised the floor without writing a rulebook

On April 17, 2026, the OCC, Federal Reserve, and FDIC replaced SR 11-7 with revised model risk guidance, issued as SR 26-2 and OCC Bulletin 2026-13. The new guidance places generative and agentic AI outside its scope because they're novel and evolving fast. The agencies have promised a request for information on AI, which isn't the same as an agent-specific rulebook. Until one arrives, accountability sits with the institution, and that means it sits with the board.

Credit unions face the same gap. NCUA's 2026 supervisory priorities center on balance sheet management, payments fraud, and BSA/AML, and there's no standalone NCUA rule on AI. Examiners still reach AI through those priorities, especially fraud detection and third-party relationships. NCUA also can't examine the technology service providers most credit unions rely on, a gap GAO flagged in 2025, so the credit union carries its vendors' AI risk.

When an examiner engages on a specific lending agent, expect three questions. Can a person review or override before the agent acts? Can your audit trail reconstruct any decision, including the documents and identity the agent relied on? Do you have clear documentation of what the agent may access? Institutions that adopt fast and govern loosely won't have all three answers.

Every ungoverned agent is a decision your examiner can ask you to explain. Governance is the architecture that makes velocity possible.

The path from proven pilots to governed scale is shorter than ever

Most institutions today have proven AI and patchy governance. The distance from there to governed agentic velocity at scale has never been shorter. Your data platform is ready to serve as the governance foundation, your CRM is ready to anchor headless AI, and most of the control plane's components already sit in your estate.

The institutions that look back and say they got AI right will be the ones that sequenced it. They governed the architecture first, then compounded every deployment on top of it.

Part 2 of this series gets into the blueprint itself, including the seven questions every institution's AI architecture has to answer before it can scale with confidence.

Ready to start the conversation?

Zennify's AI Control engagement gives you a clear picture of how your AI systems should fit together, a recommendation for where AI oversight should live, and a step-by-step roadmap. We deliver it in four to six weeks, built around a use case already running at your institution and the oversight you already have, like model risk, vendor risk, and change management.

Talk to our team

$text$
$name$

$role$

Share this post
Facebook
LinkedIn