AI has been enthusiastically adopted across a host of different industries, yet many have lacked the governance frameworks and data visibility required for these initiatives to truly succeed. Currently, firms risk implementing AI on top of data environments that are often not fully prepared to support AI capabilities.
With more than 75 percent of UK financial services firms using AI, the UK Parliament Treasury Committee has warned that action is needed to ensure that the UK capitalises on AI’s opportunities safely. Financial institutions are responsible for vast amounts of valuable, sensitive data held across a range of IT environments and critical systems, some of which are decades old. Coupled with rigorous regulation in the industry, the rush to innovate bumps up against increased risk factors and data blind spots within sprawling enterprise systems that were not built with next-generation technologies in mind. Without prioritising governance first, institutions cannot truly understand, explain, and unlock the value of their data and achieve AI readiness securely.
What financial institutions are getting wrong in governance frameworks
At its core, data governance is about defining and continuously improving the life cycle policies, processes, rules, and roles by which data is managed and consumed across an organisation. In the financial sector, data is a critically important asset to leverage, enabling innovation and driving customer satisfaction. AI is of particular use in areas like risk assessment, fraud detection, customer service automation and credit scoring. In fact, the UK Parliament has revealed that the financial sector “substantially outpaces” other sectors in AI adoption. However, without modern governance strategies in place, financial institutions cannot ensure trust in the data that increasingly assists these AI-driven insights and decisions and the risk factor of the initiative skyrockets as a result.
The challenge for the financial sector starts with its infrastructure. It is not alone in that struggle: a recent study has shown that despite AI readiness being a top priority for organisations, only 25 percent of IT leaders currently feel confident that their infrastructure can support AI workloads. This is due in large part to the lack of visibility when it comes to how data moves through the different environments. Siloed, unstructured, unverified data makes any IT modernisation initiative increasingly challenging. Consequently, financial institutions face growing pressure to overhaul their data foundation and create a governed data pipeline that ensures compliance, auditability and security.
Making clean, trusted data available to AI across the enterprise must now be a priority, as poor-quality data, low visibility, fragmented architectures, and inadequate oversight can quickly turn AI initiatives from a competitive business advantage into a costly compliance risk.
The operational, financial and compliance risks of poor governance in the agentic era
Unlike generative AI systems and LLMs (large language models), which are trained on text and language data to generate text-based outputs in response to prompts, AI agents act with autonomy, based on the data that they have access to. While most AI agents currently operate under strict human supervision, IBM research has revealed that by 2027, 57 percent of executives expect AI agents to make autonomous decisions in processes and workflows.
For the financial sector, there is little room for error. Regulations such as GDPR, DORA and the EU AI Act have created a strict framework with increased visibility requirements, demanding every decision to be traceable and explainable. Implementing autonomous AI agents without a robust governance framework can increase the risk of unauthorised data access, incorrect credit loaning, or flawed tax filings. These risks emanate from a lack of oversight, and can lead to incorrect audit findings, regulatory fines, and reputational damage.
The scale of this challenge is increasing. Alongside the EU AI Act, 157 new laws, rules and regulations relevant to the use of AI have come into effect between June 2024 and May 2025 in the financial sector alone and we can only expect this tendency to continue as AI capabilities develop. These increasing regulations around data are pushing financial institutions to reassess how and where data is stored, processed, and analysed. Without these frameworks, AI becomes a liability, potentially exposing sensitive intellectual property or hallucinating based on outdated information.
How financial institutions can govern agentic AI effectively
Due to this, the financial sector now requires rigorous, clear frameworks to ensure data pipelines are not just secure and compliant, but also of high enough quality to support automation and decision-making. In order to ensure effective governance, institutions should prioritise building a unified, AI‑ready data foundation that connects mainframe, cloud, and distributed systems in real time. This single move accelerates everything by providing a consistent data substrate for agentic AI. This substrate needs to provide the governance around the data as it is used within the agentic interactions.
To achieve this, governance must be considered right from the architecture stage to ensure compliance, efficiency and ultimately, ROI. As Gartner warns, by 2027, 60 percent of organisations will fail to realise the expected value of their AI use cases due to inconsistent data governance frameworks. This is a clear signal: without a reliable foundation, the sector’s investment in AI will fall short.
Controls need to be embedded directly into data pipelines and platforms, ensuring that access rules, lineage tracing, and audit logging are enforced automatically. Institutions must be able to demonstrate what their AI software has access to, where that data is stored, and how outcomes can be explained or reversed if necessary.
A comprehensive governance framework ultimately creates a stable environment in which data quality, model behaviour and oversight practices evolve together, providing the visibility required for informed and autonomous decisions. When these conditions are met, AI can operate within a clearly defined framework of trust, and support complex tasks with the clarity and consistency expected in critical environments.
Institutions that invest in robust, adaptive governance frameworks will be overall in a stronger position to scale AI responsibly, respond to regulatory change, and maintain stakeholder and customer trust. Those that do not will face increasing challenges down the line, operationally, financially, and strategically.