Buy tickets

24–25 March 2027 · Munich

Governance · 19 November 2026 · 7 min read

Governance is not the brake. It is the gearbox.

Under the EU AI Act, DORA and GDPR, the institutions that govern AI well are the ones able to move fastest — because they can defend what they deploy.

Abstract structured grid representing AI governance and model risk controls in financial services

As AI moves into consequential workflows, the question is not only whether a model works. It is whether it can be governed across its lifecycle: explainability, data quality, model risk, cybersecurity, third-party dependency, operational resilience and clear accountability for AI-driven decisions.

The ECB has been specific about the gaps banks still need to close, particularly AI-specific risk management, data-quality controls and full lifecycle model governance.

Agentic AI raises the bar again. A system that can act across multiple tools requires a control model closer to that of an employee with delegated authority than to that of a reporting model.

In practice, the institutions that treat governance as an operating capability — owned, staffed and measured — ship more AI, not less. That is the argument FINOVAI 2027 puts on the main stage.

More reading