The governance gap
Eighty percent of organisations plan to be innovating with AI within the next year, according to the FinCrime Frontier 2025-26 Report, a survey of more than 250 compliance and risk leaders. In boardrooms and technology functions across every sector, the conversation has moved past whether to deploy AI agents and on to how quickly.
That momentum is real, and the underlying capability is genuinely transformative. But there is a number sitting quietly behind the confidence. Only 17% of organisations currently have fully operational AI governance frameworks in place, meaning the gap between those two figures is where the risk is gathering.
I have the same conversation with technology leaders regularly. The context changes; the pattern, however, does not.
An AI programme has delivered strong pilot results. The board of course then wants to scale. Someone then asks what happens when an agent makes a consequential error, and who is responsible when it does.
What follows is usually a working group, a governance document, and a deployment timeline that slips by six to twelve months. According to Gartner’s 2025 AI Adoption Survey, 85% of enterprise AI projects fail to reach governed production. The bottleneck is rarely the model, it is almost always the governance infrastructure that was never built.
Agents and assistants are not the same thing
The governance requirement changes entirely depending on what kind of AI system is actually running. There is a meaningful difference between AI that surfaces information and AI that takes action. A co-pilot retrieves data, summarises a document, or surfaces a recommendation. The human retains control of every consequential step.
An agent is different. Given a goal, it determines its own sequence of steps, executes them without human initiation at each stage and iterates until the task is complete or it reaches a point that requires human judgement. The accountable decision-maker in the first scenario is clearly human. In the second, that question requires a different kind of answer.
Most governance frameworks were built for the first scenario. They were not designed for systems that reason, plan, and execute across connected workflows without human initiation at each step. Applying them to agentic AI is not governance. It is the appearance of governance, and the difference becomes visible under pressure.
The security implications of this gap are already documented. OWASP published its Top 10 for Agentic Applications in December 2025. Three critical vulnerabilities in widely-deployed enterprise AI tools scored between 9.3 and 9.4 on the CVSS severity scale. These are not theoretical risks. They are active exposures in tools organisations are running in production today, on enterprise data. Financial services operates under the most intense regulatory scrutiny of any sector, which means the governance gap becomes visible there first and fastest. That does not mean financial services has resolved it. It means the consequences of not resolving it arrive sooner, and that the pressure driving more rigorous governance practice in that sector is instructive for the rest of enterprise.
Three things that cannot wait
Three requirements have emerged from organisations building governance infrastructure that survives scrutiny.
The first is explainability by design. Every agent decision must be traceable to the data, the rule, and the reasoning that produced it, not as a retrofit, but as a structural property of the system from the start. In its Emerging Tech: Tech Innovators in Generative AI Workflow Orchestration report (2025), Gartner identified AI workflow orchestration as an essential emerging category for competitive advantage. The institutions gaining that advantage are the ones where explainability is native to the architecture. An agent that produces a correct output but cannot explain how it reached it is not an asset in any environment where accountability matters. It is a liability.
The second is continuous oversight at scale. This is distinct from approving every individual agent action, which does not scale to the volumes that make agentic AI worth deploying. It means a governance function that operates at the system level. Monitoring agent behaviour continuously, sampling outputs for policy compliance, detecting model drift before it creates exposure. The practical implication is that governance is not a configuration setting. It is an ongoing operating discipline that requires dedicated people, process, and tooling, not just a one-time technical implementation.
The third is the one most consistently underestimated. Governance before capability. The instinct in most technology organisations is to prove value first and formalise governance once results are visible. The problem with that sequencing is that the cost of retrofitting governance after deployment is substantially higher than building it in from the beginning.
Every agent action taken without embedded lineage, auditability, and explainability is an action that cannot be defended when scrutiny arrives. In any environment where AI is making or informing consequential decisions, scrutiny will arrive.
The regulatory reckoning is here
The regulatory calendar is already making this question urgent. In April 2026, FinCEN proposed the most consequential reforms to BSA/AML programme requirements in years, explicitly shifting the compliance standard from procedural box-checking to demonstrable effectiveness.
The EU’s Anti-Money Laundering Authority has open consultations closing in June and July 2026, with direct supervision of cross-border institutions beginning in 2028. The FCA has moved to outcome-based supervision, assessing AI-driven decisions on evidence rather than process documentation. The direction across jurisdictions is consistent: regulators are no longer asking whether you have a governance policy. They are asking whether you can prove it is working.
The question for every technology leader deploying agents is not whether the technology works. The pilots are compelling, the results are measurable, and the capability is real.
The question is whether you can prove it works, on demand, to the standard that the people who will eventually ask of you require. The organisations that build governance infrastructure now will gain specific advantages; faster resolution when a regulator or auditor questions an AI decision, lower remediation cost when a model drifts from its intended behaviour, and shorter deployment cycles for subsequent agents because the governance scaffolding already exists. The ones that treat governance as a later-stage concern will find it becomes the constraint that limits everything else.