AI Agent Risk & Cost Governance

Category :

AI

Posted On :

Share This :

AI agents are moving beyond experimentation and into real-world workflows across regulated industries. Financial institutions are increasingly using agents to support processes involving sensitive systems, confidential data, customer decisions, and operational activities. As adoption accelerates, however, institutions face a critical challenge: how to capture the productivity benefits of autonomous AI without creating new operational, regulatory, security, or financial risks.

 

The challenge is becoming increasingly urgent because deployment is moving faster than oversight. A Cloud Security Alliance survey of 228 IT and security professionals found that 85% of organizations now run AI agents in production environments, while 68% cannot clearly distinguish agent activity from human activity within their own systems. This creates an obvious governance problem. If an organization cannot reliably identify what an agent did, under whose authority it acted, or which systems it accessed, establishing accountability becomes significantly more difficult.

 

Regulators are paying increasing attention to this gap. The Financial Stability Board’s June 2026 consultation proposed organization-wide AI governance and AI-specific risk management practices, emphasizing the responsibility of boards and senior management for AI deployment decisions. The U.S. Government Accountability Office has also warned that AI adoption in financial services can introduce risks involving biased lending outcomes, privacy, cybersecurity, and increasing dependence on third-party technology providers.

 

The U.S. Treasury Department has since taken steps to provide institutions with a more consistent framework. In February 2026, it released a Financial Services AI Risk Management Framework alongside a shared AI Lexicon intended to establish a common, risk-based approach to AI governance.

 

Additional research illustrates the scale of the challenge. A Cloud Security Alliance study involving 235 large-enterprise security leaders found that 92% lacked full visibility into their AI identities. At the same time, 71% reported that AI systems already had access to core business platforms such as ERP, CRM, and financial systems, while only 16% said those permissions were governed effectively.

 

Against this backdrop recently hosted a conversation with Shahir Daya, Chief Product & Technology Officer at Zafin, to explore how agentic AI is changing cost structures, workflow execution, and operational discipline across financial institutions.

 

Daya brings extensive technology and financial-services experience to the discussion. Before joining Zafin, he spent 27 years at IBM, where he most recently served as IBM Distinguished Engineer and Chief Technology Officer for IBM Consulting in Canada. His career has included senior architecture and technology leadership roles involving cloud, business transformation, and financial services. He has also co-authored three IBM Redbooks focused on microservices and hybrid cloud integration and holds several issued U.S. patents.

 

The discussion highlights three important areas that financial institutions need to address as they scale AI agents: workflow-level governance, control-plane infrastructure, and variable-compute cost discipline.

 

Workflow-Level Governance for Scalable Agent Oversight

One of the central governance challenges emerges when AI agents are introduced into workflows that were originally designed around human decision-making. Financial processes such as pricing changes, offer decisions, disclosure updates, fraud reviews, and lending activities often contain regulatory requirements that assume a human is responsible for the decision.

 

Once an AI agent becomes part of that process, institutions need to answer a new set of questions. Who authorized the action? What information did the agent use? Where did human judgment occur? What controls applied at the time of the decision? What evidence remains to demonstrate how the decision was reached?

 

According to Daya, many institutions are not currently equipped to answer these questions because their operating models were not designed around agent-driven work.

 

The issue is not necessarily that AI created an entirely new governance problem. Rather, AI is accelerating an existing one. As agents spread across departments and workflows, institutions face increasing pressure to explain decisions, demonstrate accountability, satisfy regulators, control access, and manage costs using systems that were largely designed for human activity.

 

Daya emphasizes an important distinction between how organizations may think about agents and how regulators evaluate risk. Institutions may naturally focus on the individual AI systems they deploy, but regulators are more interested in the workflow itself.

 

They want to understand which workflows are within scope, what risks exist within those workflows, which controls apply at each stage, and where human judgment is required.

 

This makes workflow-level governance more scalable than agent-level governance. A single AI agent may operate across several different workflows, each with different risk profiles and control requirements. Conversely, one workflow may rely on several different agents. Building governance exclusively around individual agents therefore creates a structure that becomes increasingly difficult to maintain as deployments grow.

 

As Daya explains, regulators are ultimately interested in the decision process rather than the specific technology performing individual steps:

“Regulators don’t want to talk about your agents — they want to talk about the workflow. They want to know what the risk universe is, which workflows are in scope, which controls apply at each step, and where human judgment actually fits. If you build your controls around individual agents, they will not scale because one agent can work across many workflows and many agents can run one workflow.”

 

The practical implication is that institutions should establish the workflow as the primary unit of governance before expanding agent deployments. Each workflow should identify where human judgment is required, what controls apply at every stage, and what evidence must be retained.

 

Creating a consistent workflow taxonomy early can also help organizations maintain stable governance as the number of agents increases. Rather than continuously creating new controls for every new agent, institutions can establish principles that remain attached to the workflow regardless of which models, vendors, or agents execute individual tasks.

 

Control-Plane Infrastructure for Real-Time Agent Orchestration

Workflow-level governance establishes what needs to be controlled, but institutions also need infrastructure capable of enforcing those controls while agents are operating. This is where the concept of a control plane becomes important.

 

Daya describes the control plane as an operating layer positioned between human intent and agent execution. Instead of allowing autonomous systems to interact directly with sensitive business environments without centralized coordination, the control plane manages how agents move through approved workflows.

 

It provides visibility into agent identities, authorities, tool usage, execution status, and workflow transitions. It also creates a centralized mechanism for enforcing policies and collecting evidence while work is happening.

 

Daya compares the concept to an air traffic control system. Just as a control tower needs to know an aircraft’s identity, clearance, route, and priority, an enterprise control plane needs to know which agent is acting, what it is doing, which tools it is using, and under whose authority it is operating.

 

As Daya puts it:

“The control plane is not a committee that meets on Wednesdays — it is operating infrastructure. It sits between human intent and agent execution, coordinating every action through deterministic transitions and full visibility. Just like a control tower knows every aircraft’s identity, clearance, route, and priority, the control plane knows every agent, what it’s doing, what tools it’s calling, and under whose authority it’s acting.”

 

This infrastructure becomes particularly important when agents interact with sensitive systems. Financial institutions cannot simply give an AI system broad access and rely on the model to behave responsibly. Agents should operate according to the same fundamental security principles applied to other sensitive enterprise identities.

 

Zero-trust and least-privilege approaches can restrict an agent’s access to only the systems, data, and tools necessary for a specific task. This reduces unnecessary exposure and makes it easier for security and risk teams to verify that agent activity remains within approved boundaries.

 

Another important concept is what Daya describes as “proof of work.” For regulated organizations, knowing that an agent completed a task is not always sufficient. Institutions may need to demonstrate how the task was performed.

 

That means capturing relevant prompts, actions, tool calls, decisions, workflow transitions, and execution history. Instead of reconstructing an agent’s behavior weeks or months later, organizations can maintain evidence as the work happens.

 

A centralized control plane can therefore serve several functions simultaneously. It can coordinate agents across different models and vendors, enforce workflow policies, manage permissions, track execution, and preserve evidence for audits and investigations.

 

This changes the role of governance from a periodic review process into a continuous operational capability.

 

Variable-Compute Cost Discipline for Sustainable Agent Deployment

Risk and security are not the only governance challenges created by agentic AI. The economics of AI-driven work are also changing.

 

Traditional enterprise software is often purchased and budgeted as a relatively predictable expense. Agentic AI introduces a more variable cost structure because spending can increase with workflow volume, model selection, token consumption, tool usage, and the number of autonomous tasks being executed.

 

Daya argues that many organizations have not yet fully internalized this shift. As agent deployments grow, AI costs increasingly become a property of operational execution rather than a simple software procurement expense.

 

He points to examples of organizations experiencing rapid increases in AI-related spending:

“Agentic AI changes the economics of work in a way most institutions have not internalized. Uber burned through its entire 2026 AI coding budget by April, and Safe Software went from $20,000 a month to $100,000 a month in six months — and these are disciplined companies. As subsidies disappear, enterprise AI bills will rise another 30 to 50 percent, which means AI becomes a variable compute cost that must be actively governed.”

 

The important issue is not simply that AI can become expensive. It is that organizations may lack sufficient visibility into why costs are increasing, which workflows are responsible, which models are being used, and whether the resulting business value justifies the compute consumption.

 

This means cost management needs to become part of the agent governance architecture itself.

 

Institutions can establish task-level spending limits, monitor token consumption, and control which models agents are allowed to use for different workloads. Not every task requires the most capable or expensive model. A lightweight model may be sufficient for routine classification or data-processing tasks, while more complex reasoning may justify a higher-cost model.

 

Real-time cost visibility can also help institutions identify unexpected spending patterns before they become significant financial liabilities. If an agent suddenly begins consuming substantially more tokens or repeatedly invoking expensive tools, the organization should be able to detect and respond to that behavior.

 

This is particularly important as AI providers increasingly move toward consumption-based pricing models. The cost of an agent-driven workflow can change depending on how frequently it runs, how much context it processes, which models it uses, and how many external tools it calls.

 

As a result, sustainable agent deployment requires financial discipline at the workflow and task level rather than relying solely on an annual AI budget.

 

Building a Governance Model That Can Scale

The common theme across governance, infrastructure, and cost management is that agent deployment cannot be treated simply as another software implementation.

 

Organizations need operating models capable of managing autonomous systems continuously. Governance needs to follow workflows rather than individual agents. Control infrastructure needs to sit between human intent and autonomous execution. Security policies need to limit agent permissions according to actual task requirements. Evidence needs to be captured as work occurs. And compute costs need to be monitored as an operational variable rather than treated as a fixed technology expense.

 

This approach also allows institutions to adapt more easily as the AI landscape changes. Models will evolve, vendors will change, and new agents will emerge. If governance is tightly coupled to individual technologies, every change can require a major redesign. If controls are attached to workflows and supported by a common control plane, organizations can replace or add agents while keeping the underlying governance structure relatively stable.

 

For regulated institutions, this distinction is critical. The goal is not simply to prevent AI agents from taking action. The goal is to create an environment in which agents can take useful action while remaining observable, authorized, auditable, and economically sustainable.

 

Conclusion

AI agents are rapidly becoming part of real operational workflows, but deployment alone does not create enterprise value. Financial institutions must also develop the infrastructure and governance required to operate these systems responsibly.

 

Workflow-level governance provides the foundation by defining where risk exists, which controls apply, and where human judgment must remain visible. A centralized control plane provides the operational layer needed to coordinate agents, enforce permissions, maintain visibility, and preserve evidence. Variable-compute cost governance ensures that increased automation does not result in uncontrolled AI spending.

 

The broader lesson is that agentic AI requires a shift from thinking about AI as an isolated technology to treating it as part of the organization’s operating infrastructure.

 

As agents become more capable and increasingly interact with sensitive systems, the institutions that scale them successfully will not necessarily be those that deploy the most agents. They will be the organizations that can demonstrate exactly what their agents are doing, why they are authorized to do it, what controls govern their actions, what evidence they leave behind, and how much those actions cost.

 

In regulated environments, responsible agentic AI is ultimately a governance and infrastructure challenge as much as it is a technology challenge. Building the right control mechanisms now can allow institutions to capture the efficiency of autonomous workflows without sacrificing accountability, security, or financial discipline.