All reports

KYE Governed Research Rail · Playbook · Edition 2026-Q3

Roadmap to AI Governance for Financial Services — Q3 2026 Edition

seriesRoadmap to AI Governance formatPlaybook sectorFinancial Services audienceCISO / Security cadenceQuarterly Paid edition

Ed25519-sealed · fingerprint c2f9ad9f2124528c · verify it yourself ↓

KYE Protocol governs actions and authorities, not outcomes, diagnoses, or results. This report synthesises public sources under the evidence / no-hallucination gate — every claim below is pinned to a cited source.

Executive tear-sheet

Financial institutions are deploying AI into decisions that regulators already supervise — creditworthiness, fraud, market and model risk — faster than their governance programmes can keep up. The reassuring news is that nothing in front of a bank is unprecedented: every binding obligation on AI in financial services today is an extension of supervision the sector already understands. The EU treats credit-scoring AI as high-risk and attaches risk-management, data-governance, logging and human-oversight duties to it. NIST's AI Risk Management Framework gives firms a four-function backbone — Govern, Map, Measure, Manage — to organise that work. And UK supervisors fold AI and machine-learning models into existing model-risk-management and senior-management-accountability expectations rather than inventing a parallel regime. This roadmap sequences those three anchors into a programme a regulated firm can actually run, and is honest about its own boundary: KYE Protocol™ governs actions and authorities, not outcomes, diagnoses, or results.

Key findings

  • AI in financial services is governed today by extending existing supervision, not by a green-field AI regime — credit-scoring AI is high-risk under the EU AI Act, and UK supervisors place AI/ML models inside established model-risk and accountability expectations.
  • The NIST AI RMF's four functions — Govern, Map, Measure, Manage — are the practical backbone financial institutions adapt to organise an AI governance programme.
  • The binding obligations cluster around runtime evidence: logging, human oversight, validation and ongoing monitoring — duties that must be discharged while the system is in use, not only at design time.

In the full report

  • AI in financial services is already supervised — as high-risk
  • NIST AI RMF gives the programme its backbone
  • UK supervision folds AI into model risk and accountability
  • Where a runtime authority layer fits

Paid edition

Get the full report

This is the preview. 4 further sections of cited analysis remain in the full edition. The full edition is a paid KYE Governed Research Rail deliverable — every claim cited, the whole edition Ed25519-sealed and replay-verifiable.

Pinned sources

Every claim in the full edition is pinned to a cited public source (evidence gate); the 3 pinned sources are listed below. The full claim-by-claim map ships with the paid edition, sealed into evidence pack kye:evidence-pack:research:ai-governance-financial-services:2026-q3.

  1. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202401689Official Journal of the European Union (retrieved 2026-06-03T09:00:00Z)
  2. https://www.nist.gov/itl/ai-risk-management-frameworkNational Institute of Standards and Technology (retrieved 2026-06-03T09:00:00Z)
  3. https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banksBank of England — Prudential Regulation Authority (retrieved 2026-06-03T09:00:00Z)

Replay-verifiable

This edition is sealed and Ed25519-signed over the published keys. Any reader can confirm the seal offline — no KYE service required.

Signature algorithm
EdDSA
Key id
kye:key:self-audit-fixture-2026-06
Seal fingerprint
c2f9ad9f2124528c (sha256 of the signature, first 16 hex)
Published keys (JWKS)
/trust/self-audit-jwks.json
Report envelope
kye:research-report:roadmap-ai-governance-financial-services-2026-q3 · schema kye.research_report.v1

Verify it yourself: fetch the published JWKS, recompute the Ed25519 signature over this edition's canonicalised envelope (minus seal) bound to the body hash, and confirm it matches the key id above — from public keys alone, no KYE service in the loop.

How verification works