New Series: The Regulated AI Operating Model
Every regulated financial institution is having the same two conversations. We need to move faster on AI agents. And, in the next breath: we had an incident — can we produce the log the regulator wants?
These are not two conversations. They are one, and the gap between them is what my new series with Roberto Barbosa is about.
The Regulated AI Operating Model — five volumes, out now — is written for CIOs, CTOs, CROs, and boards in regulated finance. It does not ask which model to buy or which vendor to sign. It answers the operating-model question: what your organisation must look like, operationally, to run AI agents safely and accountably at scale.
Three numbers
Three numbers explain the state of AI agents in regulated finance: 99% of firms are planning agent deployments, 11% have shipped them safely to production, and 95% of those that shipped have already had an incident.
The comfortable reading is that the technology is immature. The uncomfortable reading — the one we hold — is that the technology arrived before the operating model, and most firms are trying to close the gap with policy documents that nothing enforces.
An AI agent is not another application category. It is an operational actor inside your firm. It needs an envelope — Mandate, Means, Memory, Monitoring — enforced by the platform, not declared in a PDF.
The five volumes
Each volume serves a different conversation inside a deployment programme:
- Vol I — The Adoption Gap. The argument, short enough to read before a steering committee. For CIOs, CTOs, CEOs, and boards.
- Vol II — The Governance Spine. DORA, the EU AI Act, ITIL, COBIT, ISO 42001, CIS, and OWASP read as one operating model, not parallel compliance exercises. For CROs and Heads of Compliance.
- Vol III — The Platform Foundation. The identity and network control planes that must exist before any agent runs safely — across Azure, AWS, and GCP. For Heads of Cloud, Platform Architects, and CISOs.
- Vol IV — The Agent Operating Model. The enterprise agent control plane, the agent wrangler role, MCP governance, and the nine-question Audit Evidence Schema. If you read only one volume, this is the one. For Heads of AI Engineering and Model Risk.
- Vol V — Building and Shipping. Extending the SDLC, data governance, and change control you already run — plus the 18-month roadmap and a playbook by institution size. For Heads of Engineering and Programme Directors.
You do not need to read all five. Each volume opens with a who-reads-what map that tells you which one is yours — from the board-level argument in Volume I to the Monday-morning implementation plan in Volume V.
Peer-to-peer, not consultant-to-client
Roberto is Head of AI Engineering at a major Gulf bank; I have built cloud and AI platforms in Swiss and European regulated finance since 2004. We wrote the series we wished someone had handed us: no aspirational frameworks, no vendor pitches — what we have found that works, at the level of detail operating institutions require.
Browse the series and buy links here.
If you read a volume and it earns it, an honest review on Amazon — two sentences is plenty — is the most useful thing you can do for a book like this. And if it sparks anything about what you are building, I would rather hear that over a call than in a review: get in touch.