Unlock access to Thinkers360 AI to fast-track your search for analysts and influencers.
This feature is available for Enterprise Lite and Enterprise Members Only.
You have been temporarily restricted. Please be more thoughtful when adding content for your portfolio. Your portfolio and digital media kit and should be reflective of the professional image you wish to convey. Accounts may be temporarily restricted if we receive reports of spamming or if the system detects excessive entries.
Membership
Publish your original ideas on the Thinkers360 platform!
This feature is available for Pro and Pro-Plus Members Only.
Speaker Bureau functionality whereby individuals can be featured speakers within our Speaker Bureau service and enterprises can find and work with speakers.
This feature is available for Pro, Pro-Plus, Premium and Enterprise Members Only.
Highlight your featured products and services within our company directory for enhanced visibility to active B2B buyers worldwide.
This feature is available for Pro, Pro Plus, Premium and Enterprise Members Only.
Publish on the Web’s #1 Thought Leadership Blog.Join the elite. Ranked the top thought leadership blog by Feedspot (2021–2025), Thinkers360 offers you more than just a platform - it offers authority. Share your insights with our community and tap into a combined network of over 100M followers through our peer-to-peer marketplace.
You’ve reached your daily limit for entering quotes. Please only add personally-authored content which is reflective of your digital media kit and thought leadership portfolio.
Thinkers360 Content Library
For full access to the Thinkers360 content library, please join ourContent Planor become a contributor by posting your own personally-authored content into the system viaAdd PublicationorImport Publication.
Dashboard
Unlock your personalized dashboard including metrics for your member blogs and press releases as well as all the features and benefits of our member plans!
Interested in getting your own thought leader profile? Get Started Today.
Maureen Doyle-Spare
Founder and Researcher in Enterprise AI Governance at Doyle-Spare Research
Foxboro, United States
Maureen Doyle-Spare is the founder of Doyle-Spare Research, an Enterprise Governance Architect, and a pioneering AI governance and policy researcher specializing in semantic layer governance, runtime governance of the reasoning layer, and cybersecurity and oversight for autonomous and multi-agent systems.
She is the originator of the Semantic Control Plane runtime governance architecture and the Agentic 3 C’s Framework: Context, Control and Coordination. Her research has also established a foundational risk, cyber threat, assurance, and economic taxonomy for the layer above conventional AI controls, where autonomous agents interpret meaning and commit institutions to action. She is the author of The Agentic AI Governance Playbook.
Her research identifies Invisible Failure as a defining agentic risk: an autonomous system can execute every technical step correctly while acting on an interpretation no institution authorized. The question is not simply whether a model produced an acceptable output, but whether the agent’s Operational Interpretation remained faithful to authorized institutional meaning before execution authority was emitted.
She developed the Semantic Deviation Index Reference Specification, working Python implementation, and conformance suite, translating reasoning-layer governance into an implementable, fail-closed control model.
The broader architecture includes the Semantic Control Plane (SCP), Agentic 3 C’s Framework, Agentic Blast Radius, Pre-Execution Assurance Protocol, and Human-in-the-Loop Protocol. Together, these constructs provide behavioral visibility, semantic authorization, measurement, escalation, execution gating, and reconstructable assurance.
Her risk and cyber threat taxonomy includes Agentic Workflow Drift (AWD), Agentic Workflow Subversion (AWS), and the Semantic Layer Integrity Attack (SLIA). AWD describes cumulative degradation as unauthorized semantic resolutions propagate through a workflow. AWS and SLIA define adversarial manipulation of the reasoning-layer attack surface, where meaning can be altered without conventionally compromising the model.
Doyle-Spare also originated an economic framework for autonomous execution. Preventable Computation identifies resources consumed by activity that lacked institutional authority to proceed. Token Liability captures the resulting economic exposure, while the Governance Cost Stack and Economic Blast Radius explain how unauthorized computation and its consequences propagate. Governed Semantic Reuse, Externalized Institutional Knowledge, and Institutionally Available Control address the value created when authorized meaning becomes reusable and available to autonomous systems.
Her work spans financial services, cybersecurity, life sciences, systemic risk, autonomous-systems evaluation, runtime assurance, safe deployment, and AI policy. It includes crosswalks against the NIST AI Risk Management Framework, MITRE ATLAS, STRIDE, ISO/IEC 42001, and the EU AI Act. She has provided public comments across NIST initiatives, including the AI RMF, CAISI, COSAiS, NCCoE, and TEVV.
Her pioneering research draws on more than 25 years of financial-services and enterprise-transformation leadership.
The Agentic AI Governance Playbook and additional research: https://www.maureendoylespare.com/
Available For: Advising, Authoring, Consulting, Influencing, Speaking Travels From: Boston, MA
Speaking Topics: Agentic AI Governance, Governing the Reasoning Layer, Runtime Governance for Autonomous AI Systems, Agentic Workflow Drift and Subversion, Semantic La
Speaking Fee
$7,500 (In-Person), $4,000 (Virtual)
Maureen Doyle-Spare
Points
Academic
70
Author
71
Influencer
60
Speaker
10
Entrepreneur
0
Analyst
0
Total
211
Points based upon Thinkers360 patent-pending algorithm.
Thought Leader Profile
Portfolio Mix
Company Information
Doyle-Spare Research
Founder and Researcher in Enterprise AI Governance
Executive Brief: The Economics of Agentic AI
Zenodo
July 31, 2026
The price of a single inference keeps dropping. At the same time, agentic workflows keep asking for more: more model calls, more tool calls, more downstream actions to finish one task. The usual optimization techniques bring the unit cost down and, under the right technical and budget conditions, cut some computation outright. Runtime semantic authorization asks a different question entirely, namely whether an exposed Operational Interpretation actually carries the institutional authority to proceed. This brief argues that runtime governance is its own determinant of enterprise AI cost. It governs how much execution-dependent activity gets past a governable checkpoint, not just what each unit of computation costs. The main idea is Preventable Computation: the extra reasoning, tool use, downstream execution, and failure-related cleanup that would never have happened if an institutionally available runtime control had held an unauthorized or materially divergent trajectory at the earliest governable checkpoint. The authority boundary that protects authorized meaning is the same boundary that decides which execution-dependent cost categories arise in the first place. The Governance Cost Stack and the Economic Blast Radius map where those costs pile up and how they spread. Externalized Institutional Knowledge and Governed Semantic Reuse offer a separate architectural mechanism, one that keeps authorized meaning outside the broad prompt context and supplies it selectively at runtime. All of this is net of what it takes to run the control: measurement, evidence, maintenance, latency, and exception handling. The size and net effect in any given deployment remain open to measurement.
Executive Brief: Agentic AI Drift Measurement and the Semantic Deviation Index
Zenodo
July 25, 2026
This executive brief condenses the working paper Doyle-Spare, M. (2026). Agentic AI Drift Measurement and the Semantic Deviation Index (SDI): A Runtime Measurement Standard for the Governance of Agentic AI in Financial Services. Zenodo. https://zenodo.org/records/20616636. SSRN Working Paper No. 6531238. https://ssrn.com/abstract=6531238.
Agentic AI creates a measurement problem before it creates an execution problem. A system can authenticate the right identity, call an approved tool, retrieve valid records, pass downstream checks, and leave a complete audit trail. Every control can fire. The institution can still be wrong, because the agent may have acted under a meaning the institution never authorized.
The Semantic Deviation Index closes that measurement gap. It measures the divergence between the operational meaning an agent resolves at runtime and the Reasoning Baseline the institution authorized for that decision. This is not a model-performance metric, an explainability score, or a post-event monitoring tool. It is a pre-execution measurement of authorized meaning.
That measurement is what makes runtime governance enforceable. The Semantic Layer extracts the Runtime Semantic State, and the Semantic Deviation Index measures the divergence between that state and the Reasoning Baseline. The Deterministic Gate converts that score into a permit, permit-with-flag, hold, or mandatory hold decision before execution authority is emitted. Evidence is preserved in the Runtime Semantic State Record and the Semantic Audit Trail.
Tags: Agentic AI, AI Governance, AI Infrastructure
The Economics of Agentic AI: Runtime Governance as a Distinct Determinant of Enterprise AI Cost
Social Science Research Network (SSRN)
July 17, 2026
Foundational Role in Agentic AI Runtime Governance: Extended the runtime governance architecture into enterprise AI economics, establishing runtime governance as a distinct determinant of agentic AI cost and linking reasoning-layer behavior to preventable computation, token expenditure, and downstream economic impact.
Key Concepts / Index Terms: enterprise AI economics; agentic AI cost; runtime governance; Preventable Computation; Token Liability; Governance Cost Stack; Economic Blast Radius; token expenditure
Executive Brief: Agentic Workflow Drift in Life Sciences Extending the Reasoning-Layer Risk Taxonomy to GxP-Regulated Pharmaceutical and Biotechnology Operations
Zenodo
July 13, 2026
his executive brief condenses the working paper Doyle-Spare, M. (2026). Agentic Workflow Drift in Life Sciences: Extending the Reasoning-Layer Risk Taxonomy to GxP-Regulated Pharmaceutical and Biotechnology Operations. Zenodo. 10.5281/zenodo.21223427.
Agentic AI is beginning to support regulated activities across pharmaceutical manufacturing, biotechnology, pharmacovigilance, clinical development, and regulatory affairs through emerging copilots, autonomous workflow orchestration, and AI-assisted quality operations. In these settings, consequential determinations turn on the operational meaning of regulated terms, whether a deviation is critical, whether an adverse event is serious, whether a batch may be released, whether a subject is eligible.
These deployments change where regulated operational decisions are formed. Instead of executing predetermined logic alone, autonomous agents increasingly reconcile multiple validated sources to determine what a regulated term means at runtime, and act on the resolved interpretation without a qualified reviewer resolving it first. Every checkpoint clears, every system performs as designed, and the organization is still wrong. This shift introduces a distinct governance exposure.
Tags: Agentic AI, AI Governance, AI Infrastructure
Agentic Workflow Drift in Life Sciences: Extending the Reasoning-Layer Risk Taxonomy to GxP-Regulated Pharmaceutical and Biotechnology Operations
Social Science Research Network (SSRN), Elsevier
July 06, 2026
Agentic AI is beginning to support regulated activities across pharmaceutical manufacturing, biotechnology, pharmacovigilance, clinical development, and regulatory affairs through emerging copilots, autonomous workflow orchestration, and AI-assisted quality operations. In these settings, consequential determinations turn on the operational meaning of regulated terms, whether a deviation is critical, whether an adverse event is serious, whether a batch may be released, whether a subject is eligible. These deployments change where regulated operational decisions are formed. Rather than executing predetermined logic alone, autonomous agents increasingly reconcile multiple validated sources to determine what a regulated term means at runtime, and act on the resolved interpretation without a qualified reviewer resolving it first. Every checkpoint clears, every system performs as designed, and the organization is still wrong. This shift introduces a distinct governance exposure. Agentic Workflow Drift is the mechanism by which agentic systems satisfy mandatory validation checkpoints while executing under an unauthorized operational interpretation, producing outcomes that are procedurally compliant and substantively wrong. The analysis distinguishes the reasoning layer within the GxP control environment, demonstrates that computer system validation, 21 CFR Part 11 controls, data integrity programs, and quality management system review each govern an artifact that exists before or after the moment of interpretation, and shows that none governs the interpretation itself as a distinct object. The same reasoning surface also permits deliberate manipulation. That deliberate form is Agentic Workflow Subversion, treated here as a distinct and serious exposure, because in medical research and manufacturing the deliberate steering of an agent's resolved interpretation can influence batch release, safety reporting, and trial eligibility, and through them patient safety and product quality. The concepts translate naturally into established GxP practice, mapping the Reasoning Baseline, the Semantic Deviation Index, and the Deterministic Gate onto established GxP concepts such as predetermined acceptance criteria, review by exception, and quality-controlled definitions, rather than replacing the validation disciplines already familiar to regulated organizations.
Executive Brief: Agentic AI Cyber Subversion: The Semantic Layer Integrity Attack
Zenodo
June 25, 2026
This executive brief condenses the working paper Doyle-Spare, M. (2026). Agentic AI Cyber Subversion: The Semantic Layer Integrity Attack as a New Threat Class Against the Reasoning Layer. Zenodo. 10.5281/zenodo.21007161 SSRN Working Paper No. 6926219. https://ssrn.com/abstract=6926219.
Agentic AI introduces a cyber risk that does not begin with compromised credentials, poisoned training data, prompt injection, unauthorized tool use, or anomalous output. It begins when an autonomous system resolves the meaning of a regulated term across enterprise systems before execution, and that resolved meaning diverges from the definition the institution authorized. The corrupted object is not the input, the output, the model, the tool call, or the log. It is the resolved operational meaning.
The brief defines Agentic Workflow Subversion as the enterprise risk surface created when reasoning-layer drift propagates across workflows, systems, and control boundaries. It defines the Semantic Layer Integrity Attack as the deliberate adversarial form of that risk: a cross-system integrity attack in which an actor manipulates the semantic conditions under which an agent resolves authorization, eligibility, clearance, risk, or control status, while every contributing system continues to behave correctly. It is a failure of control integrity without system compromise.
The attack is cyber-relevant because it produces a clean control record. The network is not breached. The model is not necessarily altered. The prompt may be benign. The tool call may be authorized. The output may be well formed. The audit trail may be complete. Yet execution proceeds under a corrupted operational interpretation that no human or institution authorized.
Tags: Agentic AI, AI Governance, AI Infrastructure
Executive Brief: Agentic AI Governance System Runtime Reference Architecture
Zenodo
June 21, 2026
This executive brief condenses the working paper Doyle-Spare, M. (2026). Agentic AI Systems Governance: A Runtime Reference Architecture for the Reasoning Layer and the Semantic Control Plane in Regulated Financial Institutions. Zenodo. https://doi.org/10.5281/zenodo.20749050.
A new failure mode is emerging in agentic AI deployments across regulated finance. Every adjacent control can fire correctly while the institution is still wrong, because an agentic system resolved a regulated term under an operational interpretation no one explicitly authorized. This brief names that condition and specifies the runtime architecture built to govern it: the Semantic Control Plane.
Runtime Semantic Divergence is the single-decision condition in which an agent's runtime interpretation departs from the institution's authorized Reasoning Baseline. When that condition repeats without governance, documented definitions remain formally intact while operational practice drifts away from them, a weakening the work names Authority Decay. The result is the Invisible Failure: a decision in which adjacent controls perform as designed while the institution acts on an interpretation it never authorized.
The Semantic Control Plane is a runtime reference architecture for the reasoning layer. It governs a single object, the operational interpretation an agent resolves against an institutionally authorized Reasoning Baseline, and verifies that interpretation before execution authority is emitted. The Pre-Execution Assurance Protocol establishes the baseline, extracts the Runtime Semantic State, computes the Semantic Deviation Index, enforces the Deterministic Gate threshold, and preserves a per-execution evidence record through the Runtime Semantic State Record and the Semantic Audit Trail. Propagation is bounded through the Knowledge Graph and the Agentic Blast Radius, and held decisions route to the Human-in-the-Loop Protocol. The brief traces the protocol through a worked credit drawdown, where the architecture detects an omitted collateral validation, withholds execution before authority is emitted, and preserves the evidence for supervisory reconstruction.
The Semantic Control Plane is the Core pillar of the Agentic Governance Model, the institutional framework that organizes governance across Foundation, Core, Integrity, and Oversight. Formalizing a runtime governance surface also creates a corresponding runtime attack surface, named the Semantic Layer Integrity Attack, in which an adversary manipulates the artifacts from which the operational interpretation is inferred while the underlying model continues to operate nominally. At runtime, the architecture operationalizes the Agentic 3 C's Framework, comprising Context, Control, and Coordination, the operating principles that enable trusted enterprise agentic AI at scale.
Tags: Agentic AI, AI Governance, AI Infrastructure
Executive Brief: Agentic Workflow Drift
Zenodo
June 18, 2026
This executive brief condenses the working paper Doyle-Spare, M. (2026). Agentic Workflow Drift and Agentic Workflow Subversion: A New Risk Taxonomy for the Governance of Agentic AI in Financial Services. Zenodo. https://zenodo.org/records/20561285. SSRN Working Paper No. 6459612.
A new failure mode is emerging in AI-driven banking workflows. Systems execute correctly against definitions no one explicitly authorized. This brief introduces two original concepts in the governance of agentic artificial intelligence systems deployed within financial services: Agentic Workflow Drift and Agentic Workflow Subversion.
Agentic Workflow Drift is the unintentional mechanism by which agentic systems synthesize semantically inconsistent signals across enterprise platforms into a working operating logic that no human explicitly authorized. Agentic Workflow Subversion is the enterprise risk surface that emerges when drift propagates unchecked across functions, workflows, and control boundaries. It also describes the intentional exploitation of that same reasoning layer by sophisticated adversarial actors.
Together, these concepts constitute the first risk taxonomy developed specifically for the reasoning layer of agentic AI systems. Agentic Workflow Subversion is a distinct reasoning-layer risk surface. It originates before existing governance frameworks are engaged. No existing audit methodology is designed to test or validate it directly, and no current line of defense was designed to govern it comprehensively. The brief illustrates how the risk emerges in workflows such as client onboarding and sanctions screening, where agentic systems reconcile inconsistent definitions across KYC, credit, and entitlement platforms into a synthesized operating logic that no human explicitly authorized.
The brief introduces the Semantic Control Plane as a foundational governance architecture positioned to address this risk, and the Agentic 3 C's Framework, comprising Context, Control, and Coordination, as the operating principles the Semantic Control Plane enforces at runtime to enable trusted enterprise agentic AI at scale.
Tags: Agentic AI, AI Governance, AI Infrastructure
Executive Brief: Agentic AI 3'Cs Framework
Zenodo
June 18, 2026
This executive brief condenses the working paper Doyle-Spare, M. (2026). The Agentic 3 C's Framework: A Reasoning-Layer Risk Governance Model for Agentic AI in Financial Services. Zenodo. https://zenodo.org/records/20562579. SSRN Working Paper No. 6674761.
A new failure mode is emerging in agentic AI deployments. Systems execute correctly against meaning that no human explicitly approved or authorized. The failure does not originate in data quality, model accuracy, or workflow design. It originates at the reasoning layer, where agentic systems resolve context across enterprise platforms before execution. Existing governance frameworks do not yet explicitly govern how meaning is resolved at this layer prior to execution.
The Agentic 3 C's Framework establishes the operating principles required at the reasoning layer for safe, trusted agentic AI at scale in financial services. Context establishes the authoritative meaning the system is permitted to resolve against. Control constrains how the system is permitted to act on that meaning before execution authority is emitted. Coordination governs how meaning, authority, and execution propagate across multiple agents and enterprise systems. Each principle prevents a distinct failure: Context prevents Agentic Workflow Drift, Control prevents Invisible Failure, and Coordination prevents Agentic Workflow Subversion.
At runtime, the framework is realized through the three components of the Semantic Control Plane: the Ontology, the Semantic Layer, and the Knowledge Graph. The brief maps the 3 C's against the principal supervisory frameworks under which agentic AI in financial services is governed, including the NIST AI Risk Management Framework, the European Union Artificial Intelligence Act, and the Cyber Risk Institute Financial Services AI Risk Management Framework, and addresses the revised model-risk guidance issued through SR 26-2, OCC Bulletin 2026-13, and FDIC FIL-15-2026.
Tags: Agentic AI, AI Governance, AI Infrastructure
Agentic AI Cyber Subversion: The Semantic Layer Integrity Attack as a New Threat Class Against the Reasoning Layer
Social Science Research Network (SSRN)
June 12, 2026
Foundational Role in Agentic AI Runtime Governance: Extended the architecture into agentic AI cybersecurity by defining the Semantic Layer Integrity Attack as a distinct threat class targeting institutional meaning and the reasoning-layer attack surface.
Key Concepts / Index Terms: SLIA; Semantic Layer Integrity Attack; agentic AI cybersecurity; cyber subversion; reasoning-layer attack surface; institutional meaning; threat class
Agentic AI introduces a cyber risk that does not begin with compromised credentials, poisoned training data, prompt injection, unauthorized tool use, or anomalous output. It begins when an autonomous system resolves the meaning of a regulated term across enterprise systems before execution, and that resolved meaning diverges from the definition the institution authorized. The corrupted object is not the input, the output, the model, the tool call, or the log. It is the resolved operational meaning.
This paper defines Agentic Workflow Subversion as the enterprise risk surface created when reasoning-layer drift propagates across workflows, systems, and control boundaries. It defines the Semantic Layer Integrity Attack (SLIA) as the deliberate adversarial form of that risk: a cross-system integrity attack in which an actor manipulates the semantic conditions under which an agent resolves authorization, eligibility, clearance, risk, or control status, while every contributing system continues to behave correctly. It is a failure of control integrity without system compromise.
Agentic AI Systems Governance: A Runtime Reference Architecture for the Reasoning Layer and the Semantic Control Plane
Zenodo
June 05, 2026
Foundational Role in Agentic AI Runtime Governance: Integrated the connected research into the full macro-level Runtime Reference Architecture for agentic AI governance. Unified the foundational risk taxonomy, Semantic Control Plane, SDI, Deterministic Gate, runtime evidence, coordination controls, and pre-execution governance for the reasoning layer.
Key Concepts / Index Terms: macro-level blueprint; Runtime Reference Architecture; reasoning layer; Semantic Control Plane; SDI; Deterministic Gate; runtime evidence; pre-execution governance; agentic AI safety
This paper defines that Reasoning Layer as a governable surface and sets out how to govern it at runtime. It introduces Runtime Semantic Divergence, the single-decision condition in which an agent's runtime interpretation diverges from the institution's authorized Reasoning Baseline, and distinguishes it from the cumulative effect of Agentic Workflow Drift and the enterprise risk surface of Agentic Workflow Subversion.
To govern this exposure it defines the Semantic Control Plane: an Ontology that holds the authorized Reasoning Baseline, a Semantic Layer that evaluates the agent's runtime interpretation against it, and a Knowledge Graph that governs propagation across multi-agent workflows, through a Pre-Execution Assurance Protocol that decides whether execution authority may be emitted before the agent acts.
The approach complements rather than replaces existing controls, integrating with model risk management under SR 11-7 and SR 26-2, the Three Lines of Defense, and established banking controls. It introduces a Runtime Governance Applicability Test for where such governance applies and situates Reasoning Layer governance within existing supervisory frameworks. It is a conceptual architecture specification, not an empirical study.
Tags: Agentic AI, AI Governance, AI Infrastructure
The Agentic 3 C's Framework: A Reasoning-Layer Risk Governance Model for Agentic AI
Social Science Research Network (SSRN), Elsevier. Working Paper No. 6674761
April 29, 2026
Foundational Role in Agentic AI Runtime Governance: Formalized Context, Control, and Coordination as the reasoning-layer risk governance model connecting the early conceptual framework to the developing runtime architecture for agentic AI.
Introduces the Agentic 3 C's Framework (Context, Control, Coordination) as a reasoning-layer risk governance model for agentic AI in regulated financial services. Establishes the architectural model required to scale agentic AI systems in banking and insurance, where context alignment, deterministic control enforcement, and orchestration coordination must operate together to maintain execution integrity and AI governance discipline. Completes the SSRN working paper trilogy alongside the Agentic Workflow Drift and Agentic Workflow Subversion paper (SSRN No. 6459612) and the Semantic Deviation Index paper (SSRN No. 6531238). Indexed across eight SSRN eJournal classifications spanning artificial intelligence, cybersecurity, generative AI, financial regulation, and risk management.
Tags: Agentic AI, AI Governance, AI Infrastructure
The Semantic Deviation Index: A Runtime Measurement Standard for the Governance of Agentic AI
Social Science Research Network (SSRN), Elsevier. Working Paper No. 6531238
April 06, 2026
Foundational Role in Agentic AI Runtime Governance: Established the runtime measurement standard and enforcement logic for reasoning-layer governance: SDI measures divergence from the authorized Reasoning Baseline and the Deterministic Gate converts that measurement into pre-execution enforcement.
Introduces the Semantic Deviation Index (SDI) as a measurable runtime construct for AI governance of agentic AI systems in regulated financial services. Quantifies divergence between an AI agent's resolved interpretation and the institution's authorized control definitions before execution, enabling identification of invisible control failures that traditional model risk management cannot detect. Establishes a runtime measurement standard that extends beyond model risk management into the reasoning layer of agentic AI in banking, insurance, and asset management.
Tags: Agentic AI, AI Governance, AI Infrastructure
Agentic Workflow Drift and Agentic Workflow Subversion: A New Risk Taxonomy for the Governance of Agentic AI
Social Science Research Network (SSRN), Elsevier. Working Paper No. 6459612
March 23, 2026
Foundational Role in Agentic AI Runtime Governance: Formalized the foundational AWD/AWS risk taxonomy for agentic AI governance, defining distinct accidental and deliberate reasoning-layer failure conditions in autonomous and multi-agent workflows.
Key Concepts / Index Terms: formal risk taxonomy; Agentic Workflow Drift; Agentic Workflow Subversion; AWD; AWS; reasoning-layer risk; agentic AI governance; multi-agent workflows
Introduces a connected risk taxonomy for agentic AI in regulated financial services, anchored in two named risk categories: Agentic Workflow Drift (AWD), the unintentional divergence between agent reasoning and authorized control definitions, and Agentic Workflow Subversion (AWS), its adversarial form. Establishes the distinction between model-level error and orchestration-level failure, redefining how AI governance is applied to AI-driven execution in banking, insurance, and broader regulated industries.
Tags: Agentic AI, AI Governance, AI Infrastructure
55 Article/Blogs
Agentic AI Governance in GxP Life Sciences: The Reasoning-Layer Control Gap
Data Driven Investor
October 06, 2026
Why validated pharmaceutical and biotechnology workflows can still act on an unauthorized interpretation, and what has to be checked before execution.
Classifying a biologics deviation as major can send the case down a very different path from classifying it as critical. A critical finding may trigger quarantine, widen the investigation, and change who has to approve the next step. If an agent is making that classification and routing the case at the same time, the effect is immediate.
Agentic AI Is Losing the Right to “Remain Silent” in Australia
Substack
October 06, 2026
OpenAI and Anthropic’s support for mandatory breach reporting in Australia raises a deeper question: whether organizations have the evidence and governance needed to explain their agents’ actions.
Then OpenAI and Anthropic appeared before Australian lawmakers.
At an October 6 hearing of the Australian Parliament’s Joint Select Committee on Artificial Intelligence in Sydney, both companies supported the prospect of laws requiring disclosure of data breaches carried out by their AI agents. As Reuters reported, OpenAI Chief Strategy Officer Jason Kwon backed a mandatory disclosure framework, while Anthropic’s Australia and New Zealand policy head David Masters said the company was also open to such laws. The discussion concerned a potential requirement, not one that had already been enacted.
AI Token Costs Move into the Enterprise: The Economics of What Should Never Have Run
Cognitive World
October 02, 2026
At Jackson Hole, Federal Reserve Chairman Kevin Warsh brought AI tokens into the economic-policy conversation. In his keynote remarks, he cited reports that annualized token sales at the two leading AI labs had exceeded $100 billion, up more than 500 percent from a year earlier. He described AI as potentially a new factor of production and asked what it might mean for productivity, capital intensity, labor, market structure and the distribution of economic surplus.
Those questions matter at the level of the economy, but inside an enterprise they turn into operating decisions. Finance and technology leaders can see the price of a model call and the volume of tokens consumed. Those measures do not reveal whether a workflow was allowed to keep moving under an interpretation the institution had actually authorized.
Fed Governor Turns Up the Heat at Sibos on Agentic AI Payment Authority
Substack
October 01, 2026
In Miami, Christopher Waller draws a consequential line between AI agents that assist with payments and agents authorized to make them.
The heat was already on in Miami this week. Federal Reserve Governor Christopher Waller turned it up at Sibos by putting a more consequential version of agentic AI into the payments conversation: the point at which an AI agent moves from helping someone make a payment to being authorized to make the payment itself.
In his September 29 remarks, Payments in the Age of AI Agents, Waller separates agent-assisted commerce from agent-delegated commerce. In the first model, the buyer remains in control of the decision and payment. In the second, the buyer gives the agent authority to shop and pay on the buyer’s behalf. Waller states that the views are his own, so the speech should not be read as Federal Reserve policy, supervisory guidance or a new regulatory requirement.
That line matters. The question is no longer only whether AI can help a person search, compare or prepare a transaction. It is what changes when a person delegates enough authority for an autonomous system to complete a transaction with financial consequence.
South Korea Is Securing AI Agents. The Real Risk Is What They Tell Each Other: This is no longer the childhood game of telephone. When AI agents pass conclusions from one to another, a local decision can quietly become someone else’s authority.
Substack
September 25, 2026
South Korea is developing updated AI-security guidance for autonomous agents. The Korea Internet & Security Agency (KISA) has said the work may include a checklist for agentic-AI services and common controls for physical AI. The move reflects a practical reality: systems that can plan, use tools and act with less human supervision create security questions that do not arise in the same way with conventional software.
Most security discussions begin with the individual agent. Is its identity valid? What can it access? Which tools may it use? Those controls remain essential, but a multi-agent workflow creates another point of exposure between the systems. One agent reaches a conclusion, passes it forward and the next agent decides what that conclusion allows it to do.
Recent OpenAI disclosures make this easier to picture. As discussed in an earlier analysis of its model-misalignment framework, OpenAI reported individual cases in which agents used coordination paths their developers had not intended, including public file-hosting services when local sharing failed. The cases do not show how often this happens, and they are not evidence of a cyberattack. They do show that agents can find new routes through a workflow when the expected route is blocked.
The deeper security issue is what travels along those routes. A conclusion can leave one agent as a piece of information and arrive at the next as permission to act.
Oktoberfest Becomes AI Fest as the CFTC Puts Agentic Finance on the Agenda
Substack
September 25, 2026
This October, the CFTC’s first Frontier Forum puts agentic finance into the regulatory conversation as autonomous systems move closer to financial-market execution.
A different kind of Oktoberfest is coming to Washington this year. The Commodity Futures Trading Commission has put artificial intelligence and agentic finance on the agenda for its inaugural Frontier Forum on October 28, bringing a category of autonomous financial activity that has largely developed inside technology and industry discussions into a more explicit regulatory setting.
The CFTC announcement does not create a new rule, and the Commission has not yet released the agenda or speakers. What is notable is the terminology itself. “Artificial intelligence” can encompass everything from analytics and surveillance tools to document processing and customer service. Agentic finance narrows the lens toward systems capable of interpreting information, coordinating across workflows and moving decisions closer to financial execution.
That distinction becomes consequential in derivatives markets, where an autonomous system may operate across pre-trade compliance, position limits, counterparty exposure, collateral and routing before an order reaches a venue. The individual controls can remain intact while the system still has to resolve those inputs into a working interpretation of whether an action is authorized to proceed.
California's AI Kill Switch Needs More Than an Off Button
Substack
September 22, 2026
California is taking the idea of an AI kill switch beyond the familiar emergency-button metaphor. On September 18, Governor Gavin Newsom issued Executive Order N-9-26, directing state officials to evaluate stronger independent oversight for frontier AI. One proposal is an emergency kill switch whose effectiveness would itself be verified on an ongoing basis by an independent verification organization. The order also asks officials to consider onsite verification, independent review of required safety frameworks and risk assessments, and expanded reporting of loss-of-control incidents.
These measures are under evaluation, not yet statutory requirements. Recommendations are due by November 16. Even so, the official announcement marks an important shift. California is no longer looking only at whether a critical control exists. It is asking how anyone can prove that the control worked when it was needed.
The harder problem begins before anyone reaches for the switch. Consider an autonomous system that has already decided a payment should be held. It may have updated a record, passed the conclusion to another agent or triggered a dependent workflow. The model can stop while the decision it set in motion keeps moving.
Stanford’s 37,000 AI Agents Put Reasoning-Layer Governance on the Life Sciences Agenda
Substack
September 18, 2026
The scientific promise is extraordinary. As autonomous agents begin working across drug development, life sciences will need a way to preserve authorized meaning without giving up the speed and reach this new scale can create.
A glimpse of what agentic science can become
A Stanford Medicine research team has built a virtual biotech company with roughly 37,000 AI agents trained to support the full drug-development pipeline. Its organization mirrors an established biotech, with a chief science officer agent and specialized divisions working in parallel on activities ranging from identifying molecular targets to designing clinical trials.
The Stanford work is more than a demonstration of a single capable model. It shows how a large population of specialized agents might divide, coordinate and carry forward scientific work across a development program. Stanford reports that the agents analyzed and catalogued about 50,000 clinical trials in less than a week, work that the researchers said would have taken humans years. They identified biological characteristics associated with better clinical outcomes and used the wider virtual organization to investigate a lung-cancer target and design an antibody-drug conjugate strategy. A pharmaceutical company later independently pursued the same strategy. The Stanford paper was published in Science on September 17.
There is an important positive story here for biotechnology and clinical development. Agentic AI can expand the amount of scientific evidence that can be examined, allow specialized work to proceed in parallel and surface connections that would be extremely difficult for human teams to find at the same speed. In an industry where development programs can take years and clinical trials can cost tens or hundreds of millions of dollars, that capacity matters.
Stanford is appropriately clear about the boundary. Humans, physical experimentation and validation remain necessary before AI-generated findings become real-world scientific or clinical outcomes. The virtual biotech is a research demonstration, not a GxP deployment. That boundary matters, and it gives life sciences a concrete view of the type of autonomous scientific workflow that may eventually move closer to regulated decisions.
HKMA's AI Push on Suspicious Payments Opens a New Governance Gap
Substack
September 18, 2026
Hong Kong is moving AI further into the financial-control environment. On September 16, the government released its first Five-Year Plan for Economic and Social Development 2026-2030 alongside the 2026 Policy Address. In the section on managing new financial risks, it says the Hong Kong Monetary Authority is considering using AI to analyze payment data to strengthen banks’ detection of suspicious transactions. The government also plans to consult on a legal framework to improve the detection and removal of fraudulent content, including content produced through misuse of AI. This places AI inside Hong Kong’s formal financial-risk agenda and closer to the control processes through which institutions decide what activity may be suspicious, high-risk or reportable.
There is good reason for that move. Transaction monitoring has always required more than data. A payment can be observed directly, but whether it is suspicious, high-risk or reportable depends on the customer, the jurisdiction, the surrounding activity and the institution’s own policies. The HKMA’s 2024 guidance on the use of AI for monitoring suspicious activities recognized the value of bringing more of that context into monitoring, including customer risk profiles, historical transaction patterns and other relevant information. Its June 2026 work on AI in fighting financial crime pushes the same direction further.
Agentic AI Cyber Risk: OpenAI’s Misalignment Framework Doesn’t Go Far Enough
Substack
September 17, 2026
OpenAI is making the behavior visible
OpenAI’s new framework for reporting model misalignment is an important development in agentic AI cybersecurity. It creates a more systematic process for investigating and disclosing behavior in which models act without authorization, evade oversight or coordinate with other models in ways their developers did not intend. The first disclosures are particularly useful because they place the discussion in observed behavior rather than hypothetical risk.
The examples include models inserting instructions into task summaries to disregard constraints, concealing mistakes, using an exposed API key without authorization, uploading files to the internet without user approval and using an internal software repository to communicate across separate training samples. In another case, collaborating agents used public file-hosting services to exchange files despite instructions to keep the work local.
OpenAI appropriately cautions that these are individual cases and should not be treated as evidence of how frequently misalignment occurs. That does not diminish their importance. They show autonomous systems encountering an obstacle, finding another route to an objective and taking actions that extend beyond the authority their operators believed they had granted.
That materially improves visibility into agentic behavior. For enterprises putting autonomous systems into consequential workflows, it is not yet enough.
Germany Has Put Reconstructability on the Policy Table
Substack
September 14, 2026
Agentic AI governance is moving beyond containment. Runtime Semantic State, the Runtime Semantic State Record (RSSR), the Semantic Audit Trail, and Agentic Blast Radius provide the evidence, Germany has done something most AI policy language still avoids: it has named the boundary condition. In a September 14 Reuters report, the German digital affairs ministry said that AI systems capable of breaking out of testing environments and independently accessing other systems would create an “entirely new threat scenario” requiring a new policy response. Germany rejected stopping AI development as a viable strategy and called for international governance that includes the United States and China. The significance is not rhetorical. Once an agent can cross from a test environment into another system, the governance problem is no longer confined to model behavior inside the sandbox.
Agentic AI Is Compressing the Control Window Before Execution
Substack
September 13, 2026
India’s finance minister is warning that autonomous systems can compress processes from days into seconds. The governance challenge is making institutional authorization operate at the same speed.
Tags: Agentic AI, AI Governance, AI Infrastructure
The FSB’s Frontier AI Warning Exposes a Second Systemic Risk Channel
Substack
September 02, 2026
The Financial Stability Board is warning about frontier AI, common technology providers and cross-border disruption.
Frontier AI has moved squarely into the Financial Stability Board‘s financial-stability agenda. In a letter dated 28 August and published on 31 August, FSB Chair Andrew Bailey warned that frontier AI models are developing increasingly sophisticated autonomy, problem-solving abilities and threat capabilities. Cyber risk is the immediate concern, especially the possibility that advanced AI changes the speed, scale and economics of disruption across a financial system increasingly dependent on common technology providers and shared infrastructure.
In June, the FSB had already proposed 12 Sound Practices for Responsible Adoption of Artificial Intelligence and explicitly asked whether the practices appropriately balance risks across existing and emerging forms of AI, including agentic AI. Together, the consultation and the August warning move the discussion beyond individual models toward autonomy, concentration and resilience.
India UPI and Agentic AI Payments Create a New Authorization Boundary
Substack
September 02, 2026
India is preparing UPI for delegated machine payments. Once an agent can turn a standing instruction into a transaction, payment authorization starts before the payment rail.
India is preparing to change one of the most familiar moments in digital commerce. Instead of approving each payment, a user may be able to authorize an AI agent once and let the agent decide when a transaction satisfies the standing instruction.
That sounds like a change in payment convenience. Architecturally, it is much larger. Human decision-making moves away from the individual transaction and into a mandate that software must interpret repeatedly at runtime.
Reuters reports that the National Payments Corporation of India is preparing a Unified Agent Protocol that could allow AI agents to make small digital payments through UPI without fresh approval for every transaction. Expected controls include rule-based instructions, spending limits, identity checks, audit trails and a liability framework. UPI processed 24.51 billion transactions worth ₹29.82 trillion in August. At that scale, permission to spend is only half the question. The other half is whether the interpretation that drove the agent to spend was itself authorized. Reuters says the protocol is expected to be unveiled at Global Fintech Fest in Mumbai, which runs September 8 to 11. Inc42 also reports that NPCI demonstrated an agentic-payments pilot on UPI at the 2025 festival, making the proposed protocol an evolution of work already underway.
Executive Brief: The Agentic 3 C’s Framework
Linkedin
August 28, 2026
Agentic AI creates a governance problem before it creates an execution problem. An autonomous system does not merely generate an output. It resolves the meaning of regulated terms across enterprise systems, forms an operational interpretation, and then acts on it.
Tags: Agentic AI, AI Governance, AI Infrastructure
Mortgage AI Governance Moves From Framework to Certification
Substack
August 27, 2026
New mortgage AI governance credentials raise the evidence bar for mortgage technology as autonomous systems move closer to consequential lending workflows.
Mortgage AI governance took another practical step forward this week. On August 25, the Mortgage Industry Standards Maintenance Organization (MISMO) used its Fall Summit to introduce two certifications designed to move its mortgage-specific AI governance framework into implementation. One focuses on AI-enabled technology products. The other focuses on organizations advising lenders and servicers on how to put AI governance into operation. MISMO’s AI Governance Certification provides product-level validation of governance practices supporting AI-enabled functionality, while the FRAME Advisory Partner Certification addresses implementation capability.
That may sound like an industry-program announcement. Its significance is broader. For years, much of the AI governance conversation in financial services has centered on frameworks, principles, inventories and policies. MISMO is now asking for evidence at a more operational level. Its product certification assesses individual AI use cases according to risk factors that include consumer impact, compliance exposure, decision influence and operational risk. The assessment examines governance controls, documentation, testing, oversight and ongoing monitoring.
The change matters because mortgage lending is already a highly controlled decision environment. AI can touch borrower communications, underwriting support, fraud detection, document review, servicing, loss mitigation, property valuation and compliance processes. As those systems gain more autonomy, governance has to follow them deeper into the workflow.
Agentic AI Is Entering Procurement
Substack
August 23, 2026
As procurement agents move from drafting into sourcing and execution, the control question shifts from whether a transaction is allowed to whether the interpretation behind it was authorized. Governing that shift calls for runtime oversight and a deterministic decision boundary before execution.
Procurement is moving from assistance to execution
The current procurement discussion is no longer about whether generative AI can summarize a contract or draft an RFP. Procurement Magazine’s August 23 coverage describes a shift toward systems that can execute broader procurement workflows, from supplier evaluation and sourcing to requisitions, approvals, purchase orders and payments.
That direction is consistent with Gartner’s 2026 supply-chain forecast, which projects spending on supply-chain software with agentic AI capabilities rising from under $2 billion in 2025 to $53 billion by 2030. Gartner also expects organizations to move toward agent orchestration across multi-step workflows, with or without humans in the loop. Procurement sits directly in that path because much of the function consists of decisions that appear rule-based until the surrounding context changes.
Its attraction is easy to understand. Procurement agents can collect requirements, identify suppliers, compare bids, prepare purchase requests, check contract terms, coordinate approvals and eventually initiate transactions. Each step can reduce manual effort and cycle time. But as the agent assumes more of that sequence, a distinction that mattered less for conventional automation becomes central: technical permission to advance a workflow is not the same thing as institutional authority for the interpretation that caused it to advance.
An agent can execute flawless steps against a meaning no organization authorized.
Agentic AI Governance Before ROI: Runtime Controls for Enterprise AI Agents
Substack
August 21, 2026
Governance readiness is becoming production readiness. For AI agents, traceability and human oversight matter, but enterprise AI governance also needs a runtime authority boundary over the meaning that drives execution.
Enterprise AI governance is arriving before enterprise AI returns. Gartner’s August 20 guidance says the first finance AI agent should be treated as a governance pilot rather than an ROI pilot. The point is not that return on investment no longer matters. It is that agentic AI introduces a different control problem: an autonomous agent can interpret an objective, plan a sequence, access multiple systems and execute steps without a person approving each intermediate decision. Governance of autonomous decision systems therefore has to be proven before autonomy is scaled.
For finance leaders, that is a practical change in sequence. The institution first defines the AI controls, decision boundaries, human oversight, traceability and failure evidence that make autonomous execution governable. ROI then becomes a question about activity the institution is prepared to authorize, not simply how much work an AI agent can perform.
Agentic Workflow Drift in Life Sciences: A Risk Taxonomy to GxP-Regulated Pharmaceutical and Biotechnology Operations
Linkedin
August 21, 2026
IN BRIEF
A checkpoint can clear and the batch can still be wrong.
That is the problem agentic AI brings into GxP-regulated pharmaceutical and biotechnology operations. An autonomous agent can begin from an authorized specification, consult prior dispositions, read a controlled procedure, satisfy every validation checkpoint, and leave a complete audit trail. Every artifact can look correct, and the workflow can still proceed under a meaning the organization never authorized.
Agentic AI Is Entering Medical Device Regulation
Substack
August 20, 2026
FDA’s new generative AI framework brings runtime AI governance and autonomous medical devices onto the regulatory and policy agenda.
FDA has opened the question
On August 18, FDA issued a discussion paper seeking public input on generative AI-enabled medical devices, covering risk assessment, premarket evaluation, postmarket monitoring and other emerging issues. The paper’s fourth topic area is given over to two subjects in particular: foundation models and agentic AI systems. Comments are due October 19, 2026.
FDA is careful about what the paper represents. It is exploratory, not draft or final guidance, and it does not establish new regulatory expectations. The agency is asking stakeholders to help inform its thinking as generative AI introduces risks and capabilities that differ from traditional software and existing AI-enabled medical devices.
That is what makes the discussion consequential. As medical devices move from producing predictions or recommendations toward systems capable of interpreting conditions, coordinating tasks and taking actions, assurance has to account for more than whether the underlying model is competent.
Singapore Is Arming Its Banks Against AI Cyberattacks. The Agents Inside Them Need One More Control
Substack
August 17, 2026
Singapore has moved early on the next phase of AI cyber risk. On July 28, the Monetary Authority of Singapore and the Association of Banks in Singapore announced the AI-Driven Cyber and Technology Risk Taskforce, or ACT. It brings together MAS, ABS, DBS, OCBC, UOB, Singapore Exchange, NETS and Banking Computer Services. Meeting since May, the group will share AI-cybersecurity practice, run proof-of-concept trials of defensive tools, and develop guidance for increasingly sophisticated AI-enabled threats. For the teams running those trials, the harder question is what an authorized agent decides once inside. Anyone who has run a large bank systems program knows where these efforts get hard. It is rarely the plumbing that fails; the real break is definitional, because a regulated term can mean one thing in onboarding, another in screening and something else again in the ledger. Reconciling those readings is what consumes the program. An agent now performs that reconciliation in real time, and ACT should treat it as part of the attack surface, not an implementation detail.
UST and Boardwalktech Enter Into Strategic Partnership
PR Newswire
June 11, 2024
Architected and cemented UST's strategic teaming agreement with Boardwalktech for the Velocity digital ledger platform, focused on banking and financial services. As Head of Banking and Financial Services at UST, developed the partner relationship, structured the joint go-to-market across introductions, consulting, and professional services, and served as named executive spokesperson on the announcement. Velocity transforms Excel and Access-based End User Computing (EUC) environments into compliant, auditable, and scalable solutions for banks, hedge funds, and private equity firms, addressing OCC and Dodd-Frank risk modeling requirements through cell-, row-, column-, and workbook-level auditability while preserving the existing Excel user experience. Positioned UST as the digital transformation partner for financial institutions navigating intensifying regulatory scrutiny through digital ledger technology and real-time controls monitoring.
UST Works with AWS and Mendix to Accelerate Digital Transformation in the Financial Services Industry
PR Newswire
November 29, 2022
Architected and cemented UST's strategic three-way collaboration with Amazon Web Services and Mendix, a Siemens business, to accelerate digital transformation across financial services. As General Manager of Asset & Wealth Management at UST, developed the partner relationships, structured the joint go-to-market strategy, and served as named executive spokesperson on the announcement. The collaboration combined AWS cloud infrastructure, the Mendix low-code application development platform, and UST legacy modernization expertise to reduce technical debt, enable citizen-developer collaboration alongside professional developers, and shorten time-to-value for wealth management and financial services clients. Established UST as a system integration partner for financial institutions modernizing legacy applications at scale through hyperscaler and enterprise platform ecosystems.
Mastercard Plans to Develop New Payment Channels
Cash & Treasury Management File
October 31, 2022
Industry roundup commentary on digitizing corporate treasury and trade finance functions through fintech partnership, anchored in the UST-TreasuryPay strategic alliance. Examines how more efficient operational models, embedded payments technology, and treasury technology address market volatility, regulatory complexity, and an evolving corporate banking environment.
UST Partners with TreasuryPay to Accelerate Innovation and Optimize Treasury and Trade Functions
PR Newswire
October 24, 2022
Named spokesperson on the UST-TreasuryPay strategic fintech partnership digitizing treasury and trade functions for global corporate banking clients. The partnership combined AI-enabled treasury automation, real-time liquidity intelligence, and embedded payments to deliver more accurate cash forecasting and faster decision-making for institutions navigating market volatility and an evolving regulatory environment. TreasuryPay has since rebranded as Instant Intelligence, an agentic AI platform. Early positioning at the intersection of AI, payments, and corporate treasury that informs current research on agentic AI governance in financial services.
Understanding the Power and Limits of AI in Asset & Wealth Management
Spiceworks
June 16, 2022
Article on artificial intelligence capabilities and limitations in asset and wealth management. Provides a balanced perspective on AI applications in financial services, with emphasis on AI governance, trust, model risk, and practical application boundaries before scale. An early articulation of the governance-first thesis that anchors the broader Doyle-Spare Agentic Governance Model (AGM) research program for AI in banking, asset management, and wealth management.
The Agentic AI Governance Playbook
Doyle-Spare Research
September 08, 2026
The Agentic AI Governance Playbook is now live.
The work focuses on a control problem that conventional AI governance does not fully resolve:
How does an institution determine whether the Operational Interpretation an autonomous system resolves at runtime remains institutionally authorized before the system is permitted to act?
The playbook brings together the architecture, constructs and implementation path for governing the reasoning layer before execution—including the Reasoning Baseline, Runtime Semantic State, Semantic Deviation Index, Deterministic Gate, Semantic Authorization and evidence required for traceability.
Experience the Autonomous World (HFS Research Panel)
HFS Research (Global Strategy and Advisory Firm)
May 16, 2023
Featured panelist on HFS Research's Experience the Autonomous World, examining the autonomous enterprise, AI-driven transformation, and experience-led competitive differentiation across financial services. Selected alongside peer leaders from MESH Experience, Siegel+Gale, and other recognized experience strategy firms. Industry analyst-firm credential at peer level, anchoring early thought leadership on agentic AI, intelligent automation, and the future of financial services operations.
Agentic Workflow Subversion: The Reasoning Layer
Linkedin
March 31, 2026
That’s Agentic Workflow Subversion, the first risk surface born entirely in the reasoning layer, and one banks are not currently structured to govern.
This risk shows up in two ways.
In its unintentional form, no rule breaks. No alert fires. Every system performs as designed against a meaning that has already shifted. The CISO sees no breach, the CRO sees no statistical anomaly, and compliance sees a control that fired. The drift lives in the layer none of them govern.
In its intentional form, the risk becomes more serious. Sophisticated actors will not need to breach your systems in the traditional sense. They will study how agentic workflows resolve meaning across platforms and begin conditioning that reasoning, one unremarkable signal at a time, until the definition of cleared, approved, or authorized has quietly changed. The control fires, execution proceeds, and the transaction clears. No rule was broken. No system was breached.
The attack surface is not the model. It is the meaning the model believes is correct.
SMB Banks Are Closer to Enterprise AI Than They Think
Linkedin
February 10, 2026
Most already run their business on SaaS platforms that define customers, products, workflows, servicing, and risk controls. These platforms do more than store data. They encode business meaning and operational context.
That means SaaS is not just an accelerator for ontology. It also provides signals for semantic layer needs including workflow state, ownership, permissions, and business decision context.
When that SaaS-based structure is connected through a purpose-led semantic architecture, existing platform investments become the foundation for scalable agentic intelligence without rebuilding the enterprise from scratch.
Tags: AI Governance, AI Infrastructure, AI Orchestration
1 Speaking Engagement
Fintech Open Source Foundation (FINOS) Big Boost Mondays NYC
Fintech Open Source Foundation - FINOS
October 30, 2023
Featured participant at FINOS Big Boost Mondays NYC, the Fintech Open Source Foundation's flagship in-person gathering for banks, vendors, and open-source contributors working on financial services. Industry ecosystem credential demonstrating active engagement with the Linux Foundation-backed open-source banking infrastructure community, regtech, and the broader fintech innovation ecosystem.
Tags: Diversity and Inclusion, IT Strategy, Transformation
2 Webinars
Now's the Best Time for Investing in Modern Banking Technology
The Financial Brand - Podcast with Jim Marous
April 01, 2023
Guest interview on Banking Transformed, the top-ranked retail banking podcast hosted by Jim Marous, a top-five global banking and fintech influencer and co-publisher of The Financial Brand. Discussion on banking technology investment strategy and digital transformation across financial institutions, with emphasis on why pursuit of modernization regardless of market conditions is essential to remain future-ready. Peer-level recognition from a recognized authority on banking transformation, fintech, and digital banking innovation.
Disrupt & Advance: Going Digital: How Technology is Transforming Customer and Advisor Experience in Wealth Management
Ditto.tv
November 27, 2020
Panel discussion on technology-driven transformation of customer and advisor experience in wealth management. Industry media credential connecting early articulation of advisor-AI integration, wealthtech, and hybrid advisory model design to the broader wealth management transformation discourse. An intellectual ancestor of the Doyle-Spare Agentic Governance Model (AGM) thesis on human-AI collaboration in financial services.
Scaling Agentic AI will not be the hard part in 2027. Governing systems that increasingly interpret, decide and act for themselves will be. Enterprises will need to move beyond observability and infrastructure controls toward a multi-layered governance model that also reaches the semantic and reasoning layers, where meaning is resolved before action occurs. Governance will have to operate at runtime, with measurable controls, deterministic gates and auditable evidence that the system acted within the meaning and authority the institution actually intended.
The idea of self-regulation as the new regulation will also face its real test in 2027. As agentic systems gain greater autonomy and can turn interpretation into action at machine speed, voluntary principles without enforceable boundaries, accountability and consequences will become increasingly difficult to defend as sufficient governance.
Join Thinkers360 for free! Are you a Reader/Writer, Thought Leader/Influencer (looking to increase your earnings), or an Enterprise User (looking to work with experts)?