Governed by Default

Print Friendly, PDF & Email
CCG Catalyst Commentary

Governed by Default

July 21, 2026

Part 1 contended that the regulators handed the AI pen back to the bank. The natural next question arrived almost immediately: if a bank does not pick up the pen, what actually protects it? The honest answer is two safeguards — the vendor's defaults and the examiner's hindsight. One is generic. The other is late. And the cost of relying on them is not an incident; it is the quiet surrender of three decisions every bank should be making for itself.

In Part 1 I made the case that the revised model-risk guidance did not lower the bar for AI; it moved the bar off the checklist and onto the bank's judgment. I have been making a version of that argument all year. AI governance is now a board responsibility, not a compliance function's side project. Since then, the question I keep hearing from executives is a practical one — "our governance is a work in progress, the agents are already arriving through our vendors, so what is standing between us and a problem in the meantime?" It is a fair question. It deserves a plain answer.

What Is Actually Running

Start with what the agents are doing today, because it is more than most boards realize. First Interstate Bank is piloting a commercial loan onboarding agent built on Fiserv's agentOS that moves data across systems and cuts cycle times. Boulder Dam Credit Union cut report generation from ten minutes to seconds. Salem Five, City National, Bank OZK, and SouthState go live this summer. FIS's financial-crimes agent, built with Anthropic, reads an AML alert, pulls the account history, assembles the case file, and drafts a disposition for a human analyst to approve. Oracle's agents analyze loan documents and summarize collections calls. The pattern is consistent: high-volume, procedural work where every step can be logged and a human owns the final action. This is the frontier I described in Agentic AI: Banking's Next Frontier Beyond the Chatbot — except it stopped being a frontier and started being a rollout schedule.

Underneath the agents sits the connector layer — MCP-style plumbing that grants an agent its reach into cores, document stores, and third-party data. As I noted in Part 1, every connector is an access grant, and the NSA thought the risk serious enough to issue security guidance in June. Keep that in mind as we walk through the safeguards, because the safeguards were designed for the agents. The connectors mostly ride along.

Safeguard One: Vendor's Defaults

The platform providers know exactly who their buyers are, and they have built accordingly. Fiserv says agentOS ships with kill switches, human-in-the-loop checkpoints, permission scoping, and what its former president calls bank-grade controls for "policy, governance, auditability and proper recordkeeping" — in her words, "every single thing you can think about, from a regulatory and a banking perspective, on controls, we have embedded those into the platform." FIS constrains its agent to recommend-and-document rather than act unilaterally. These controls are real, and a bank should absolutely want them.

But understand what they are — defaults, not governance. They answer what the agent can do. They do not answer what this institution should allow, who owns the risk, how drift gets detected, or what happens when the agent's output feeds a decision covered by fair-lending law. A kill switch nobody is assigned to watch is furniture. Permission scoping nobody reviews after go-live is a snapshot of day-one intentions. And as I argued in Not All AI Is the Same, agents demand different governance than models or data — controls built for a scoring model do not transfer to software that acts. The vendor tuned these defaults for a thousand institutions; your examiners will evaluate them against exactly one.

Safeguard Two: Examiner's Hindsight

The second layer is supervisory, and it is thinner than most boards assume. There is no prescriptive AI checklist — agencies said so explicitly when they carved generative and agentic AI out of the revised model-risk guidance. What remains is the general framework: the 2023 interagency third-party risk guidance, which makes the bank the owner of its vendors' risk; the body of law that applies regardless of the technology — ECOA and fair lending, BSA/AML, UDAAP; and the agencies' standing safety-and-soundness authority.

Notice what all three have in common. They operate after the fact. The third-party guidance tells you the failure was yours to prevent. Fair-lending law attaches when the harm has already reached a customer. Safety-and-soundness authority arrives with the exam. If a bank's governance is lacking, the safeguard is the vendor's generic defaults plus the examiner finding the gap later — and the space between those two is exactly where incidents and exam findings are breeding. Neither substitutes for an inventory, a policy, risk tiers, or a name attached to the risk.

Cost of Standing Still

So much for the incident risk. The strategic risk of passivity is larger, and it compounds along three lines.

First, the default-strategy problem. With three core providers serving more than 70 percent of U.S. banks, a passive institution's AI capability, pace, and risk posture are whatever its provider ships next quarter — agents and connectors switched on inside platforms the bank already runs, sometimes ahead of the bank's ability to govern them. I wrote recently about why everyone suddenly wants to own your core system; this is why. Whoever owns the core owns the default AI strategy of every bank running on it. The roadmap decision has been made — the passive bank just didn't attend the meeting.

Second, the relationship problem. McKinsey's work on gen AI agents describes consumers delegating financial decisions to personal AI agents — which means the agent, not the customer, increasingly chooses where the deposits sit and which loan gets taken. A bank that is not making itself legible and attractive to agents risks being disintermediated by them, and agentic commerce is running the same play against payments economics. This is the deposit-defense story of the next decade wearing a technology costume.

Third, the asymmetry problem. The banks co-developing agents now are building governance muscle and production experience at the same time, and that combination compounds. The passive bank adopts the same tools eventually, but on the vendor's terms, without the institutional knowledge, with governance assembled retroactively under exam pressure rather than deliberately. Late adopters do not just lose time. They lose the option to be deliberate.

What an Active Role Looks Like

None of this requires a moonshot. It requires the unglamorous work I laid out in Inside the AI Governance Program: inventory every AI system in the institution, including the ones embedded in vendor platforms and the connectors that feed them. Risk-tier them. Put a board-level policy over them and a name on each risk. Interrogate the vendor's defaults instead of inheriting them — which checkpoints are on, who reviews the permissions, what does the audit trail capture. Scale all of it to the institution — governance is not one-size-fits-all, and a $500 million bank inheriting AI through its core needs a different program than a $50 billion bank building its own. And move the discipline forward into evaluation, so the question "what will we be governing once the ink is dry?" gets asked before the signature, not after the finding.

The safeguards that exist without bank governance are the vendor's defaults and the examiner's hindsight — one generic, one late. The banks that accept that trade are not avoiding the work. They are outsourcing three decisions that used to define banking: your roadmap to your core provider, your customer relationship to someone else's agent, and your risk posture to your examiner. Taking an active role is cheaper than buying those decisions back.


CCG Catalyst advises community and regional banks, credit unions, and fintech companies on AI governance, core and payments modernization, and vendor evaluation. If your institution is inheriting AI through its vendor platforms and wants to govern it deliberately, reach out to our team at www.ccgcatalyst.com, or see the full library at CCG Insights.

See our latest announcement: CCG Catalyst's Paul Schaus Named a 2026 Top Consultant by Consulting Magazine

By: Paul Schaus | Founder & Managing Partner, CCG Catalyst Consulting


Disclaimer: The views expressed in this article represent the perspective of CCG Catalyst Consulting based on our direct experience advising financial institutions. This commentary is intended to stimulate industry discussion and does not constitute legal, accounting, or regulatory advice.

Subscribe to our Insights