The paper discusses how financial institutions are increasingly using AI agents in areas such as credit, fraud, and compliance, yet current governance focuses only on individual components. It introduces ARIA, a finance‑specific reference architecture that adds six capabilities—policy specification, population‑level monitoring, bounded authority, runtime containment, adaptive policy change, and preserved human oversight—to address the gap of constitutional non‑compositionality. Two simulations demonstrate how local controls can miss collective bias and how observed‑versus‑expected monitoring can provide earlier warnings of drift.
By Jose Manuel de la Chica Rodriguez, Juan Manuel Vera Diaz, Pablo Delgado Romero
Financial institutions are beginning to deploy agentic workflows in credit, fraud, collections, compliance, and operational control. Governance remains largely component-centric: each model or agent i...
arXiv:2608. 11344v1 Announce Type: cross Abstract: Financial institutions are delegating consequential decisions to agentic AI systems that decompose goals, coordinate models and tools, and act with little oversight.
By Henry Han
arXiv:2607. 04103v1 Announce Type: cross Abstract: The release of SR 26-2 marks a significant modernization of U.
By Yiqing Wang, Yixin Kang, Luyun Lin, Siqi Mao
arXiv:2609.37457v1 Announce Type: new
Abstract: Enterprise artificial-intelligence agents increasingly call tools, modify infrastructure, and process protected data, creating a need to separate actio...
By Kabeh Mohsenzadegan, Vahid Tavakkoli, Kyandoghere Kyamakya
The paper introduces Governance-as-Code (GaC), a framework that translates the EU AI Act’s technical requirements into 43 machine‑checkable acceptance criteria across six compliance modules. GaC runs within a CI/CD pipeline, producing Article‑indexed audit evidence and providing actual Rego policy code. The authors validate GaC on two enterprise deployments, showing it reproduces manual audit findings—including three penalty‑triggering violations—while reducing audit labor by about 75%.
By Rudrendu Kumar Paul, Sourav Nandy
arXiv:2607. 21345v1 Announce Type: new Abstract: Regulating activities where regulatees use autonomous and agentic AI is challenging.
By Chris Reed, Alex Austria, Anmol Bharuka, Pragnitha Mandava, Khushiya Mujawar, Luka Shakhkulashvili
arXiv:2608. 14562v1 Announce Type: new Abstract: AI governance is shifting from voluntary ethics to enforceable, risk-based regulation, yet cross-jurisdictional divergence creates compliance uncertainty for operators of high-stakes AI.
By Aasish Kumar Sharma, Dimitar Koysev, Christopher Anich, Roshni Kumari Ojha, Julian Kunkel
The paper "Operationalising AI Regulatory Sandboxes: Activities, Requirements, and Technical Assessment under the EU AI Act" outlines a detailed framework for implementing AI Regulatory Sandboxes (AIRS) under the EU AI Act. It maps the sandbox lifecycle into 29 activities, distinguishes between a Core AIRS and an Extended AIRS that includes an AI Technical Sandbox (AITS), and derives 15 infrastructural and governance requirements linked to these activities and provider obligations. The authors also introduce the Sandbox Configurator, an open‑source tool to instantiate AITS environments, aiming to provide structured workflows for regulators, robust evaluation methods for experts, and a transparent compliance pathway for AI providers.
By Alessio Buscemi, Thibault Simonetto, Daniele Pagani, German Castignani, Maxime Cordy, Jordi Cabot
The paper "Beyond Training: A Feasibility Taxonomy for Inference-Time AI Governance" presents a taxonomy of twenty inference‑time mechanisms for monitoring, verification, and enforcement, each evaluated on a four‑point readiness scale using evidence from four vendors. It applies this taxonomy to a two‑dimensional adversary model and maps the mechanisms to four governance scenarios, finding that most mechanisms are commercially available but only adequate against cooperative or low‑to‑medium‑capability users, not high‑capability state‑level deployers. The study also links inference‑stage controls to hardware‑stage mechanisms through a substitution principle and reports a second‑rater reliability of 0.74.
whyItMatters":"The work identifies the current gaps and readiness of inference‑time governance tools, highlighting that existing mechanisms are insufficient against powerful adversaries and thus informing future regulatory and technical development."
By Samar Ansari
The paper "Governing at Machine Speed: An Adaptive Intelligence Architecture for Real-Time AI Policy Enforcement" highlights a gap in enterprise AI governance, where 78% of organizations lack auditable evidence of policy enforcement. It introduces AGIL, a five-layer adaptive governance architecture that uses machine learning for real-time detection, risk classification, sub-100ms policy enforcement, continuous attestation, and policy evolution. The authors argue that the failure is organizational and architectural, not technical, and call for future empirical validation of AGIL.
By Sandeep Bokkasam, B. Durgalakshmi
arXiv:2606. 12320v1 Announce Type: new Abstract: Enterprise security was built to govern data boundaries: the protected surface was data at rest and in transit, and the controls -- access control, data-loss prevention, perimeter inspection -- governed crossings of that boundary.
By Krti Tallam