Ghost in the Org Chart · If you can't name it, you can't govern it.

A regulator asks for a complete list of every AI agent in your production environment. What do you produce?

Most US banks cannot produce this document.

By the time a human reviews the agent's final output, dozens of autonomous decisions have already executed. Your controls are reviewing ancient history.

Take the Quiz
Diagnostic Snapshot
EXPOSURE: CRITICAL

Agentic deployment velocity now outpaces visibility gaps in autonomous events that cannot be tracked.

Regulatory Intelligence Ghost Watch →

Diagnostic Indicator

Answer five quick yes/no indicators

Do agents in production use unique, non-human credentials?
Can you enumerate every autonomous process that executes trades, approvals, or customer-facing actions?
Are agent requests to production systems enforced by infrastructure-level boundaries rather than prompt instructions?
Does your audit trail clearly link actions to named agents (not just service accounts)?
Has any team deployed an AI agent without an architectural onboarding ticket?
Diagnostic Outcome

Low Elevated Critical

Regulatory Horizon

Signals from the supervisory horizon

FINRA· Jan 2026

FINRA lists autonomy, scope, and auditability among agentic AI risks to member firms.

Translation: FINRA has moved from watching agentic AI to naming its risks.

Read the Guidance ↗
OCC / FED / FDIC· Apr 2026

"Generative AI and agentic AI models are novel and rapidly evolving... not within the scope of this guidance."

Translation: The model rules regulators just refreshed deliberately skip the AI you are actually deploying.

Read the Bulletin ↗
IMF· Apr 2026

IMF maps where agentic AI meets payment authorization, settlement, and compliance.

Translation: The payment rails were built for deterministic instructions, not autonomous agents.

Read the IMF Note ↗
FCA / Bank of England / HMT· May 2026

UK authorities tell firms to treat frontier AI as a live cyber threat to operational resilience.

Translation: Britain's regulators are already writing the agentic-risk playbook US supervisors are still drafting.

Read the Statement ↗

Organizational Archetypes

Identifying internal exposure sectors

The Optimist
"We don't have ghosts. We have AI productivity gains."
Ghost DensityHigh
The Deflector
"Our agents are just tools. They don't need special oversight."
Ghost DensityHigh
The Procrastinator
"We'll deal with this after the next deployment."
Ghost DensityMedium
The Pilot Hoarder
"We have dozens of isolated pilot agents. They're not in production."
Ghost DensityMedium
The Inventor
"We're building agent identity and authority scoping into the product spec from day one."
Ghost DensityLow

The Three Primitives

Foundational controls for agentic deployments

An Identity
Unique agent credentials and cryptographic provenance.

Every agent in production requires a verifiable, non-human identity — not a shared service account, not a developer's personal token.

Establish non-human identity registry
A Boundary
API-governed enforcement and strictly size-limited orchestration.

Agents operate within defined boundaries. Every external call, every approval chain, every data access is mediated by policy — not trust.

Deploy execution firewalls
A Visible Signal
Full immutable audit trail and agent-attributable logs.

When something happens, you know which agent did it, when, and under what authority. Ambiguity in the audit trail is a regulatory liability.

Enforce action-logging contracts
Further Reading · A Dispatch Log