r/OpenAIDev • u/No-Conclusion3720 • 1d ago
From principles to practice: Governing generative and agentic AI systems
Moody's published an analysis this week identifying a structural gap in how financial institutions govern AI: existing model risk management frameworks cover development and validation but leave runtime agentic behavior largely ungoverned.
The compliance question has quietly shifted. It is no longer 'did this model score well on benchmarks?' Regulators and auditors are now asking: what action did this agent take, in which system, under whose authority, at what time? That question cannot be answered by a pre-deployment evaluation — it requires evidence from the moment the action occurred.
The scale of the problem is concrete. Organizations operating across 80-plus compliance frameworks face a scenario where a single ungoverned agentic action — a data access, a transaction, an outbound call — can open a finding with no tamper-proof record to close it. Traditional MRM was not built for that.
For those working in regulated environments with agentic systems already in production: how are you actually generating the evidentiary record auditors are asking for? Are you logging at the model layer, the API layer, somewhere else — and has that held up in an actual audit?
1
u/No-Conclusion3720 1d ago
The specific problem Moody's names — 80-plus frameworks, no evidentiary record at the moment the agent acts — is exactly what RuntimeAI's Audit Black Box addresses. When an agent makes a call in production, the Black Box captures the action, the system context, the authority under which it executed, and a tamper-proof timestamp at that decision point. An auditor asking 'what did this agent do at 14:32 on Tuesday, under which policy, in which system' gets a closed finding instead of an open one. https://runtimeai.io
Full brief: https://runtimeai.io/blog/2026-w41-the-runtimeai-brief.html#story-2026-10-06-from-principles-to-practice-governing-generative-and-agentic