Risk and Cost Governance for AI Agents in Regulated Institutions
This interview analysis is sponsored by Zafin and was written, edited, and published in alignment with our Emerj sponsored content guidelines. Learn more about our thought leadership and content creation services on our Emerj Media Services page. Regulated institutions are deploying AI agents into real workflows. This requires the governance, control, auditability, and cost discipline […]
This interview analysis is sponsored by Zafin and was written, edited, and published in alignment with our Emerj sponsored content guidelines. Learn more about our thought leadership and content creation services on our Emerj Media Services page. Regulated institutions are deploying AI agents into real workflows. This requires the governance, control, auditability, and cost discipline needed to enable agents to interact with sensitive systems, data, and decisions without introducing new operational, regulatory, or financial risk. Deployment is already outrunning oversight. A Cloud Security Alliance survey of 228 IT and security professionals found that 85% of organizations now run AI agents in production environments, yet 68% of those same organizations cannot clearly distinguish agent activity from human activity inside their own systems. Regulators are increasingly responding to the governance challenges created by AI adoption in financial services.The Financial Stability Board’s June 2026 consultation proposed organization-wide AI governance and AI-specific risk management practices, emphasizing board and senior management accountability for AI deployment decisions. The U.S. Government Accountability Office has warned that AI use in financial services poses risks, including biased lending outcomes, privacy concerns, cybersecurity threats, and growing dependence on third-party technology providers, necessitating stronger model risk and oversight practices. The Treasury Department has since moved to close that gap: in February 2026, it released a Financial Services AI Risk Management Framework alongside a shared AI Lexicon, aiming to give institutions a common, risk-based standard for governing AI deployment. Layered on top, a Cloud Security Alliance research note on 235 large-enterprise security leaders found that 92% lack full visibility into their AI identities, and that 71% report AI systems already have access to core business platforms — ERP, CRM, and financial systems — while only 16% govern that access effectively. Emerj’s Yolandi de Weerdt recently hosted a conversation with Shahir Daya, Chief Product & Technology Officer at Zafin, to examine how agentic AI is reshaping cost structures, workflow execution, and operational discipline across financial institutions. This article distills actionable insights for leaders responsible for scaling AI agents in regulated environments: Workflow‑level governance for scalable agent oversight: Define controls at the workflow layer so every agent action carries built‑in authorization, human judgment, and evidence that can be surfaced instantly rather than reconstructed weeks later. Control‑plane infrastructure for real‑time agent orchestration: Insert a centralized operating layer between human intent and agent execution so autonomous work moves through sensitive systems with deterministic transitions and full auditability. Variable‑compute cost discipline for sustainable agent deployment: Govern model choice and token spend at the task level so that agent workloads stay within predictable economic bounds rather than ballooning into uncontrolled compute liabilities. Listen to the full episode below: Episode: Risk and Cost Governance for AI Agents in Regulated Institutions – with Shahir Daya of Zafin Guest: Shahir Daya, Chief Product & Technology Officer at Zafin. Expertise: Enterprise Technology Strategy, Cloud & Hybrid Cloud, Financial Services Technology, Product & Technology Leadership Brief Recognition: Shahir Daya is Chief Product & Technology Officer at Zafin, following a 27-year career at IBM, where he most recently served as IBM Distinguished Engineer and Chief Technology Officer for IBM Consulting in Canada. At IBM, he held senior architecture and technology leadership roles across cloud, business transformation, and financial services. Daya has co-authored three IBM Redbooks on microservices and hybrid cloud integration and is an inventor with several issued U.S. patents. He also mentors through the University of Toronto Engineering Alumni Mentorship Program and WISE. He holds a B.A.Sc. in Computer Engineering from the University of Toronto. Workflow‑Level Governance For Scalable Agent Oversight Shahir Daya identifies a governance gap that arises when agents are inserted into workflows designed for humans. Pricing changes, offer outcomes, disclosure updates, fraud reviews, and lending workflows all carry regulatory questions that assume a human made the decision. Once an agent participates, institutions must be able to show who authorized the action, what data the agent used, where human judgment occurred, and what evidence remains. Daya notes that most banks cannot answer these questions because their operating models were never built to account for agent‑driven decisions. Daya notes that AI did not create this governance problem, but is accelerating it. As agents spread across business units, institutions face growing pressure to explain decisions, demonstrate accountability, control costs, and satisfy regulators, all using operating models not designed for agent-driven work. He distinguishes how institutions govern agents and how regulators evaluate risk. Regulators focus on the workflow: which workflows are in scope what the risk surface looks like what controls apply at each step where human judgment fits what evidence is retained. Shahir emphasizes that these questions apply across financial services and that current operating models cannot produce immediate answers when an agent is involved. He further explains why agent‑level controls fail. One agent may work across multiple workflows, while a single workflow may involve multiple agents. Because regulators evaluate decision processes rather than individual technologies, workflow‑level controls provide a more scalable foundation for accountability and explainability. The practical implications follow directly from Daya’s statements: Define the workflow as the unit of governance before deploying agents. Map the points where human judgment must remain visible and auditable. Specify the controls that apply at each workflow step rather than at the agent level. Separate workflow principles from agent principles to keep controls stable as agents multiply. Establish a consistent workflow taxonomy early so governance controls remain stable as agent adoption expands. Daya describes what regulators want to understand: “Regulators don’t want to talk about your agents — they want to talk about the workflow. They want to know what the risk universe is, which workflows are in scope, which controls apply at each step, and where human judgment actually fits. If you build your controls around individual agents, they will not scale because one agent can work across many workflows and many agents can run one workflow.” – Shahir Daya, Chief Product and Technology Officer, Zafin Control‑Plane Infrastructure For Real‑Time Agent Orchestration Daya describes the control plane as the operating infrastructure that sits between human intent and agent execution. It coordinates agent activity through deterministic workflow transitions while maintaining visibility into authority, tool usage, and execution history. Beyond orchestration, it also provides the guardrails and evidence needed to govern agent activity at scale. To clarify how orchestration works, Shahir outlines the mechanics of the control plane: “The control plane is not a committee that meets on Wednesdays — it is operating infrastructure. It sits between human intent and agent execution, coordinating every action through deterministic transitions and full visibility. Just like a control tower knows every aircraft’s identity, clearance, route, and priority, the control plane knows every agent, what it’s doing, what tools it’s calling, and under whose authority it’s acting.” – Shahir Daya, Chief Product & Technology Officer at Zafin Daya also argues that agents should be held to the same governance standards as employees. Rather than granting broad permissions, institutions should apply zero-trust and least-privilege principles so agents receive only the access required for a specific task. This limits unnecessary exposure to sensitive systems and helps risk teams verify that agent activity remains within approved boundaries. Daya also emphasizes the importance of “proof of work.” By recording prompts, actions, and execution history, institutions can review how an agent completed a task rather than reconstructing decisions after the fact. The operational requirements follow directly from Daya’s description: Position the control plane between human intent and agent execution so autonomous work follows governed workflows. Use deterministic workflow transitions to maintain consistent and auditable execution paths. Apply zero-trust and least-privilege controls so that agents access only the systems required for a specific task. Maintain visibility into agents’ identities, authorities, tool usage, and workflow status. Capture evidence of agent actions, decisions, and execution history as proof of work. Provide a common operating layer that coordinates agents across models, vendors, and environments. Treat orchestration, governance, and evidence collection as continuous operational functions rather than periodic reviews. Shahir’s broader point is that scaling agents requires governance infrastructure, not just automation. The control plane provides the coordination, visibility, and evidence needed to operate agent-driven workflows in regulated environments. Variable‑Compute Cost Discipline For Sustainable Agent Deployment Agentic AI changes the economics of work by shifting AI spending from a predictable software expense to a variable compute cost. Daya argues that many institutions continue to govern AI as a fixed budget item even though consumption grows with workflow volume, model usage, and agent activity. As deployment expands, costs become a property of operational execution rather than software procurement. To illustrate the shift, Shahir points to recent industry examples: “Agentic AI changes the economics of work in a way most institutions have not internalized. Uber burned through its entire 2026 AI coding budget by April, and Safe Software went from $20,000 a month to $100,000 a month in six months — and these are disciplined companies. As subsidies disappear, enterprise AI bills will rise another 30 to 50 percent, which means AI becomes a variable compute cost that must be actively governed.” – Shahir Daya, Chief Product & Technology Officer at Zafin For Daya, the challenge is not simply rising costs but limited visibility into where spending originates, which models generate it, and whether the resulting outcomes justify the underlying compute consumption. Shahir’s examples reveal a different kind of discipline institutions must adopt as agent workloads expand: Recognize AI as variable compute, not a fixed software line item. Set task‑level spending limits so usage cannot quietly escalate. Control model selection to avoid unnecessary high‑cost inference. Track token consumption to detect emerging cost spikes early. Build real‑time cost visibility into orchestration systems so spending reflects actual workflow behavior. Build cost models that account for changing pricing structures as AI providers move toward consumption-based economics. Anchor agent deployment to durable cost boundaries, not exploratory budgets. Daya’s broader point is that cost governance must be integrated into agent governance. As agent activity scales, institutions need the same level of visibility into compute consumption that they already expect for operational risk, compliance, and workflow performance.