In May, EU lawmakers agreed to push the AI Act's high-risk obligations back by sixteen months, to December 2027. The stated reason was not politics. It was that the standards and tooling needed to comply do not exist yet.

Council of the EU: Artificial intelligence — Council and Parliament agree to simplify and streamline rules

So, the most advanced AI regulation in the world slipped its main deadline because most of the key players have not yet built the machinery to govern these systems.

I find that strange, because I spent a few years inside that machinery. It just had a different name.

Every quarter brings a new responsible-AI framework. A principles deck. “Fairness, accountability, transparency”...the usual subjects. They describe what good governance looks like. Almost none of them tell you how to do it, which unfortunately is how regulation works - tells you the “what”, but the “how” (although for consultants and lawyers the what/how gap is a billing paradise!).

Meanwhile, agentic systems are moving from chat into action. An agent no longer scores a decision and hands it to a human. It plans, calls tools, moves money, and books the next step before anyone reviews the last one. The oversight on these systems is often weaker than what a bank applies to a pricing spreadsheet.

In my view, this gap is not a future problem but is a 2008-GFC-shaped problem waiting for its trigger.

The European Central Bank tower and the Euro sign sculpture in Frankfurt

The AI industry is missing what Banks already solved under years of pressure, with real money, and a supervisor who could block the use of your internal-ratings-based models and cost you billions in unoptimized capital.

It is called Model Risk Management. After the financial crisis, regulators stopped trusting banks to mark their own homework. In the US, the Federal Reserve codified it in SR 11-7. In Europe, the ECB ran a multi-year review that tore into every assumption behind the internal models of the continent's largest banks. If you have worked inside that world, you know the models banks built could (and were) challenged by an inspector line by line (discounting the role of Audit as 3LoD).

Model risk management is not principles. It is plumbing. And the plumbing is exactly what AI governance lacks.

Strip out the banking vocabulary and the controls map almost one to one onto agentic AI.

  • Independent validation: In a bank, the team that builds a model never signs off on it. A separate function tries to break it. AI teams evaluate their own agents and call it done. The validator has to be someone with no stake in the launch.
  • Three lines of defense: Who owns the agent, who challenges it, who audits it. Three different people. Most AI deployments collapse all three into the builder.
  • Continuous monitoring: A model is not validated once. Its performance is tracked in production, and degradation triggers review. Agent evals are mostly pre-launch snapshots. Behavior in the wild drifts, and nobody is watching the dials.
  • Documented limits: Every bank model ships with a written statement of where it works, where it breaks, and what it must never be used for. Agents ship with a system prompt and a prayer.
  • Approved use only: A bank model is authorized for specific decisions. Using it elsewhere is a breach. Agents get handed open tool access and broad autonomy by default.
  • Model ownership. Someone is personally accountable and holds the authority to halt the system. Name that person for your agents. If you cannot, you do not have governance. You have hope.
View looking up at financial district skyscrapers including Lloyd's of London

My main objection to all this is: banking is slow, bureaucratic, and almost seems allergic to shipping. But we do not have to import the bureaucracy. Just import the controls.

The cost of model risk management was real: headcount, process, friction. But the alternative had a price too, and the market paid it in 2008. The lesson of that decade was not that risk is bad. It was that unpriced risk is fatal.

Risk is not the enemy of speed. Unmeasured risk is.

I believe that the teams that win the agent era will not be the ones with the best model. Models are commoditizing. The winners will be the ones who can prove their agents are safe to run, to a customer, an auditor, or a regulator who shows up in December 2027.

That proof is a discipline. It already exists, refined over a decade under tough regulatory conditions.

The AI industry does not need to invent AI governance. It needs to read what banking already wrote, and stop pretending there is no infrastructure.

Hope you enjoyed the reading.

Álvaro T.