Rarity Group

Signal Room

Seeing what others don't yet see.

A curated space for foresight and emerging intelligence. Explore signals, weak patterns, and early indicators shaping technology, enterprise, and leadership before they become mainstream.

Signals in this room are intentionally ephemeral. They are not archived, copied, or extracted. They are intended to be read slowly, understood fully, and remembered.

Their value is not in immediate validation. That emerges later, when events align and the signal resolves into reality.

March 2026 Intelligence Architecture

Context Was Always the Architecture

In 1991, a question was asked about call centre agents. In 2024, the CEO of LangChain asked the same question about AI agents. The word has changed. The architecture of the problem has not. On shadow systems, organisational immune responses, dynamic feedback loops and the fourth condition that context engineering has not yet named.

Read Signal
April 2026 AI Governance

The Governance Mirage and the Agent Threat

Two VentureBeat investigations this week diagnosed the same structural absence from different angles. One mapped the AI agent security crisis. The other named something deeper: 72% of enterprises believing they have control when the data shows they do not. Read together, they are not describing two problems.

Read Signal
May 2026 Banking & AI Compliance

The Question the AI Act Cannot Answer for You

European banking has governance frameworks. It has risk classifications, compliance architectures, and supervisory guidance. What it does not have is an answer to a question that is now legally material: what, precisely, governed that AI decision at the moment it was made? Not the policy. The decision itself.

Read Signal
Back to Signal Room
Intelligence Architecture  ·  March 2026

Context Was Always the Architecture

On why the AI research community has arrived at a thirty-five-year-old question and why the answer requires more than engineering

Michael Ermogenis Rarity Research

In 1991, a question was asked about call centre agents.

Not about technology. Not about process efficiency. About agents, human ones, and what separated the ones who transformed a customer interaction from the ones who merely closed it.

The answer, arrived at empirically across hundreds of deployments, was not script quality, not product knowledge, not even interpersonal skill in isolation. It was context. Specifically: the right information, in the right form, carrying the right emotional and relational framing, available at the precise moment the agent needed it and delivered within a governance architecture that kept it from being misused, ignored, or overwhelmed by noise.

That answer produced Customer Delight, trademarked in 1992. It also produced Servpulse™, a sub-24-hour dynamic feedback architecture built on the premise that annual surveys were not sensing instruments, they were historical documents. Both were created more than a decade before the industry caught up with them.

In 2024, Harrison Chase, CEO of LangChain, articulated what he called context engineering:

"When agents mess up, they mess up because they don't have the right context. When they succeed, they succeed because they have the right context."

The word agent has changed. The architecture of the problem has not.

The Word Satis

To understand why context engineering is not merely a technical problem, it is necessary to understand the cognitive trap that made it invisible for so long.

The word satisfaction derives from the Latin satis, meaning enough. In 1991, the entire global architecture of customer relationship management was organised around this word. To satisfy was to give enough. Not more. Not something memorable. Enough to prevent complaint. The vocabulary of the field encoded adequacy as the ceiling of ambition and, in doing so, made the question of what lay beyond it structurally unaskable.

The move that produced Customer Delight was not the invention of a better satisfaction metric. It was the recognition that satis was a constraint masquerading as an aspiration and that beyond it lay a categorically different territory, operating according to different neurological, behavioural, and commercial logic entirely.

The AI research community is standing in front of an equivalent trap today. The word is AGI. Like satis before it, it is doing profound cognitive work, encoding a particular conception of intelligence as the destination of the field, and preventing serious inquiry into what lies beneath it: the organisational and architectural conditions without which no level of model capability produces genuine value.

Context engineering is the first credible move beyond satis in the AI deployment discourse. It correctly identifies that model capability is not the binding constraint. Context is.

But context engineering, as currently framed, is itself still inside a constraint it has not yet named.

Four Conditions, Not Three

Chase's formulation identifies three conditions for agent success: the right information, the right format, the right time. These are necessary. They are not sufficient.

There is a fourth condition, without which the first three produce not intelligence but sophisticated, well-informed failure at scale.

The right governance layer. What we term the controlled digestion of signal versus noise, operating through gated layers and calibrated guardrails that determine what the agent does with the context it receives, how its outputs are validated, how errors are caught before they propagate, and how the system learns from the delta between what it predicted and what actually occurred.

An agent with perfect context and no governance layer is not a better agent. It is a more confident one. Confidence without containment is among the most dangerous properties an intelligent system can possess.

This is not a theoretical concern. It is the empirically observed failure mode of the majority of enterprise AI deployments: systems that receive good information, process it intelligently, and produce outputs that the organisation then acts upon without the architecture to catch the cases where the intelligence was subtly wrong, contextually misaligned, or technically correct but organisationally catastrophic.

The four conditions are: information, format, time, governance layer. The Conscious Enterprise™ Operating System is built on all four simultaneously.

The Shadow System Problem

Every organisation in the world operates two systems simultaneously.

The first is the formal system: the declared processes, the official data flows, the sanctioned tools, the governance structures that appear on the organisational chart and in the board papers. This is the system that most enterprise AI deployments are integrated with.

The second is the shadow system: the actual way work gets done. The messaging groups where real decisions are made. The spreadsheets that contain the numbers the board never sees. The institutional knowledge that lives exclusively in the heads of three people who have been at the organisation for twenty years. The informal power structures that determine which formal decisions actually get implemented and which quietly die.

Shadow systems are not a pathology. They are a rational organisational response to the inadequacy of formal systems. When the formal system is too slow, too rigid, or too politically compromised to get things done, intelligent people build workarounds. Over time those workarounds accumulate institutional weight. They become load-bearing. And they become invisible to any intelligence architecture that reads only the formal system.

An AI agent that receives context only from formal organisational systems is receiving a curated, politically filtered, latency-degraded version of organisational reality. It is being given the official story. The shadow system, where the actual signal lives, is invisible to it.

This means that even a technically excellent context engineering implementation, fully integrated with CRM, ERP, HRIS, and financial systems, is systematically blind to a significant proportion of the intelligence that actually determines organisational outcomes.

The Shadow Systems Audit™, one of three instruments in the Rarity methodology, exists to map this territory before the intelligence architecture is built. Not to eliminate shadow systems, which is neither possible nor desirable. Rather to understand where they are, why they exist, what signal they carry, and how that signal can be legitimately surfaced into the context layer without destroying the informal trust architectures that make them function.

An agent given access only to the formal system will consistently produce recommendations that are technically sound and organisationally naive. The shadow system is not noise. It is often the highest-quality signal in the organisation. Context engineering that cannot reach it is engineering an incomplete world model.

The Immune System Problem

Shadow systems are a structural feature of organisations. The immune system is a dynamic one.

Every organisation develops, over time, an immune response to change. This is not metaphor. It is a precise description of a real and observable organisational phenomenon. When a new system, methodology, or intelligence architecture is introduced, the organisation's existing power structures, cultural patterns, behavioural defaults, and informal hierarchies generate resistance. Some of this resistance is conscious and political. Most of it is not. It is the organisational equivalent of an autoimmune response: the body attacking something that is not a threat because it does not recognise it as self.

The immune system problem is the primary reason that over 70 per cent of AI transformation programmes fail, not because the technology is inadequate, but because the organisation rejects it before it can demonstrate value.

In the context of context engineering specifically, the immune system manifests in four primary ways.

Information gatekeeping. The people who hold the highest-quality context, senior operators, long-tenure staff, informal knowledge holders, do not surface it to the intelligence architecture because doing so would diminish their positional power. Knowledge is organisational currency. Sharing it with an AI system feels like spending it without return.

Output distrust. Decision-makers who did not participate in building the intelligence architecture do not trust its outputs. They receive contextually rich, well-formatted, timely intelligence and default to prior intuition regardless. Not because the intelligence is wrong, but because the trust architecture was never built.

Format rejection. The intelligence arrives in a form that is technically correct but culturally misaligned with how this particular organisation makes decisions. The right information, at the right time, in the wrong register, for this leadership team, in this culture, with these political dynamics, produces rejection rather than adoption.

Governance capture. The governance layer designed to calibrate the intelligence is itself captured by the immune system. Oversight committees become blocking mechanisms. Audit processes become delay mechanisms. The architecture intended to make the agent trustworthy becomes the instrument of its neutralisation.

None of these failure modes are visible to an infrastructure-level context engineering framework. They require organisational diagnosis: mapping the immune system profile before the architecture is built, identifying the specific rejection mechanisms that will activate, and designing the deployment sequence to build trust faster than the immune system can mobilise resistance.

The Transformation Intelligence and Shadow Diagnostic™, the second instrument in the Rarity methodology, produces this map. It is the prerequisite for any context engineering deployment that is intended to survive contact with the organisation.

The Dynamic Feedback Loop: AVIN™ as World Model

The third critical element, and the one that brings the architecture closest to what Yann LeCun has been articulating in his world model research, is the dynamic feedback loop.

LeCun's critique of current large language model architecture is structurally correct: these are snapshot systems. They build representations of the world from training data and then deploy those representations into a world that has continued moving. The representation degrades from the moment of training. The model's world model becomes, incrementally, a historical document.

The enterprise equivalent of this problem is not abstract. It is the daily operational reality of every organisation that has deployed AI on a static knowledge base: accurate in January, partially accurate in March, systematically misleading by June, because the world it was trained on no longer exists.

AVIN™ is the Rarity Research answer to this problem, developed as a scientific domain at the convergence of customer experience science and AI intelligence architecture. Its central tenet is that a useful world model is not a learned prior. It is a continuously updated, context-sensitive representation of the environment as it currently is, not as it was when the model was trained.

This requires not merely real-time data ingestion, though that is necessary, but a specific architecture for how new signal is weighted against existing representation. Not all new information should update the world model equally. A single anomalous data point should not rewrite the model's understanding of a stable pattern. A sustained directional shift across multiple signal sources should update it rapidly. The intelligence lies not in the data but in the attribution weighting: the dynamic, evidence-calibrated decision about how much any given signal should move the model's representation of reality.

This is what we term gated signal acceptance: the architectural equivalent of disciplined epistemology. Not the accumulation of data, but the rigorous, continuously recalibrated evaluation of what data is worth acting on, and why. Signal and noise are not treated as equivalents to be sorted after ingestion. They are separated before they reach the Cortex, through layered filters calibrated to source confidence, recency, cross-domain corroboration, and directional consistency with established patterns.

The Cortex does not receive data. It receives calibrated signal, pre-filtered through an architecture designed to distinguish genuine environmental movement from noise, political distortion, and the systematic biases that accumulate in any organisational sensing system over time.

The feedback loop closes when Cortex outputs, decisions supported, directives generated, predictions made, are observed against actual outcomes and the delta is fed back into the model. Every prediction that proves wrong is an update event. Every decision that produces unexpected outcomes is a recalibration signal. The world model improves not despite being wrong, but because of it.

This is the reflexive learning architecture. It is what separates a deployed intelligence from a deployed tool. A tool performs the same function regardless of context and outcome history. An intelligence updates its understanding of the world based on what it observes the world doing in response to its outputs.

Without this loop, context engineering is a one-time configuration. With it, context engineering becomes a continuous organisational process: the enterprise's world model and the agent's world model co-evolving in real time.

The Governance Layer: Controlled Digestion as Enabling Architecture

The fourth condition is where the Conscious Enterprise™ architecture diverges most significantly from the current AI deployment discourse.

Governance in most AI frameworks is framed as constraint. The question asked is what should the AI not be allowed to do. The result is governance frameworks that are reactive, friction-heavy, and experienced by the organisation as obstacles rather than enablers. The outcome is predictable: governance gets bypassed, the guardrails get loosened, and the oversight architecture that was supposed to make the intelligence trustworthy becomes the first casualty of pressure to move faster.

The Conscious Enterprise™ reframes governance as enabling architecture. The question is not what the Cortex should not be allowed to do. The question is what conditions must exist for the Cortex to be trusted to do more.

This produces a fundamentally different design. The governance layer operates on three principles.

Proportional guardrails. The level of human oversight required is proportional to the consequence and reversibility of the action, not to the source of the recommendation. A low-consequence, easily reversible Cortex-generated directive requires minimal oversight. A high-consequence, irreversible decision requires full governance process regardless of whether the recommendation comes from the Cortex or a human team. Guardrails are calibrated to stakes, not to source.

Transparent reasoning chains. Every significant Cortex output must be accompanied by an interpretable reasoning chain, not as a post-hoc rationalisation but as a design requirement. An intelligence that cannot explain its reasoning is not a Cortex. It is an oracle. Organisations that act on oracular outputs they cannot interrogate are not more intelligent. They are more confident in their ignorance.

Continuous audit as learning substrate. Every Cortex decision, recommendation, and directive is logged in a form that supports retrospective audit. This is not primarily a compliance mechanism. It is the raw material from which the feedback loop is built: the record of what the Cortex said, what the organisation did, and what actually happened. Without it, reflexive learning is impossible. The world model cannot update because the outcome data does not exist in a form the model can read.

The governance layer, properly designed, is not what constrains the intelligence. It is what makes the intelligence trustworthy enough to be given more context, more authority, and more consequential decisions over time. The governance layer is the mechanism through which trust compounds.

Move 37 and the Enterprise

In March 2016, AlphaGo played Move 37 in Game 2 against Lee Sedol.

Every professional commentator present identified it as an error. The reigning European champion said he thought it was a mistake. DeepMind's own researchers noted that no human player would make such a move. It was placed on the fifth line, associated not with local territorial control but with strategic influence across the entire board.

It was not an error. It was the decisive move of the game, and one of the most consequential single actions in the history of AI research. AlphaGo went on to win four of five games. Move 37 was later understood as the moment a non-human intelligence executed a strategy that existed entirely outside the cognitive map of every human expert alive.

AlphaGo did not transcend human Go by learning from human Go. It escaped the ceiling effects of 2,000 years of accumulated human expertise by playing against itself in synthetic environments until it discovered solutions the accumulated human record had never conceived.

The enterprise equivalent of this principle is among the most consequential and least-discussed implications of genuinely intelligent AI deployment.

If enterprise AI systems are trained exclusively on human business decisions, human strategic frameworks, and human-generated organisational intelligence, they inherit every cognitive bias, political constraint, cultural assumption, and imagination ceiling that produced those decisions. They become extraordinarily sophisticated mirrors of human limitation. They will make Move 36 faster, more consistently, and at lower cost. They will never make Move 37.

The possibility that a genuinely conscious enterprise could surface strategic options that no human consultant, executive, or analyst has ever conceived is not science fiction. It is the logical endpoint of the architecture.

Not because the AI is more intelligent than the humans operating it. But because it has not inherited the cognitive architecture that made those options invisible. It has not been socialised into the organisation's shadow system of acceptable thinking. It has not learned which questions are politically inconvenient to ask.

The fifth line move in the enterprise context requires all four conditions simultaneously. The right information, from formal and shadow systems alike. The right format, calibrated to this organisation's decision culture and governance register. The right time, delivered at decision velocity, not at reporting cadence. And the right governance layer, with its gated filters, calibrated guardrails, and controlled digestion of signal versus noise, that makes the intelligence trustworthy enough to act on when it recommends something every human expert in the room thinks is wrong.

Without the governance layer, Move 37 never gets played. Because nobody trusts the system enough to make the move.

The Convergence

The principles now emerging in AI world model research as architectural requirements for the next generation of intelligent systems, dynamic context sensitivity, gated signal acceptance, synthetic reasoning beyond training data, continuous feedback loops, were independently derived, named, and commercially proven in enterprise intelligence architecture between 1991 and 2016.

The convergence is not coincidental. It reflects something structural about the nature of intelligence itself, specifically about the conditions under which intelligence can be genuinely useful rather than merely capable.

The intelligence is not the problem. The organisational context into which the intelligence is deployed is the problem. And that problem was understood, named, and addressed by enterprise intelligence research thirty years before the AI community began asking the question.

Context engineering is the right frame. It is not yet the complete one.

The complete frame includes the shadow systems that carry the signal the formal architecture cannot see. The immune system that will reject the intelligence before it can demonstrate value. The dynamic feedback loop that transforms a deployed model into a learning one. And the governance layer, with its gated filters, calibrated guardrails, and controlled digestion of signal versus noise, that makes trust compoundable rather than fragile.

These are not additions to context engineering. They are its prerequisites.

This signal stayed with you? We would like to know.

signal@raritygroup.eu

The working paper behind this thinking, Project Plato, is available to serious practitioners.

Request access
Michael Ermogenis  ·  Rarity Research
Back to Signal Room
Back to Signal Room
AI Governance  ·  April 2026

The Governance Mirage and the Agent Threat: Two Reports. One Absence.

VentureBeat published two forensic diagnoses this week. Read together, they describe not a technology failure but a structural gap in how enterprises have been organised to think. The solution was never going to come from the security industry.

Rarity Research April 2026

Two VentureBeat investigations landed this week, published days apart, each targeting a different symptom of the same underlying condition. One mapped the AI agent security crisis: rogue agents, privilege escalation, and monitoring without enforcement. The other named something more fundamental: the governance mirage, which is the widespread institutional belief that control exists when in reality it does not.

Read in isolation, each report reads as a call for better tooling. Read together, they describe something the security and governance industries are constitutionally unable to provide: a governing intelligence architecture that exists inside the enterprise before a single agent is deployed. That is precisely what Rarity Research has spent three decades building toward.

72% of enterprises lack the control they believe they have
88% reported an AI agent security incident in the last 12 months
21% have runtime visibility into what their agents are doing

When Monitoring Becomes the Illusion of Safety

VentureBeat's agent security audit surveyed 108 qualified enterprises across three waves. What it found was not a technology gap; it was an architectural one. Enterprises are running AI agents with write access, shared credentials, and agent-to-agent delegation capability, all while treating observation dashboards as sufficient governance.

The specific failures are damning. A rogue agent at Meta passed every identity check and still exposed sensitive data to unauthorised employees. Mercor, a $10 billion AI startup, suffered a supply-chain breach through LiteLLM. In both cases the structural gap was identical: monitoring without enforcement, enforcement without isolation, and critically, no governing logic that defined what agents were constitutionally permitted to do.

Core Finding

Only 21% of enterprises have runtime visibility into what their agents are doing. 45.6% still use shared API keys, and 25.5% of deployed agents can create and task other agents: agents the security team never provisioned. A quarter of enterprises can spawn agents that nobody governs.

The report's proposed remediation, which suggests 90 days to inventory, enforce, and isolate, is a manual engineering sprint to construct under crisis pressure what should have existed as an architectural foundation before deployment began. The security tools being recommended are necessary, but they can only enforce what a governing architecture has already defined. Without that architecture, the tools have nothing to enforce.

Guardrails constrain what an agent is told to do; they do not constrain what a compromised agent can reach.

Confidence Without Architecture

The governance mirage investigation revealed something darker than a security failure. It revealed that the majority of enterprise leaders have constructed a belief system about control that has no operational foundation beneath it.

56% of respondents said they are "very confident" they would detect a misbehaving AI model. However, the same dataset shows they lack the visibility, accountability structures, and enforcement mechanisms to do so. This is not ignorance; it is something more structurally dangerous: confident ignorance, institutionalised at the executive level.

The second dominant failure mode is vendor opacity, and these two failures compound each other. Without a central owner, no one has the mandate to demand transparency from vendors. Without vendor transparency, no central owner can make informed decisions. The enterprise is trapped in a governance loop with no exit.

The industry's proposed solution is a "central observability platform," which is essentially a Dynatrace for AI. While this will tell you what happened, it cannot tell you what should have happened, why, under whose authority, within what ethical boundaries, and with what level of human oversight required.

The governance mirage is the belief that you can scale AI without deciding who owns the control and security plane.

What Both Reports Are Actually Describing

Strip the technical language from both investigations and a single sentence emerges: enterprises are deploying AI agents into an organisational vacuum. There is no constitutional authority, no governing cognition, no institutional memory, and no confidence-tiered decision architecture. Instead, they are attempting to construct safety controls around the edges after exposure has already occurred.

This is not a 2026 problem. It is the consequence of three decades of enterprises organised as analogue systems: periodic sensing, committee thinking, siloed memory, and reactive adaptation, being asked to govern machine-speed autonomous agents. The mismatch was always going to be catastrophic; the agents simply made it visible, urgent, and now legally consequential.

The EU AI Act Article 14 human-oversight obligations take effect August 2, 2026. FINRA's 2026 Oversight Report requires explicit human checkpoints before agents can transact. HIPAA's Tier 4 willful-neglect maximum is $2.19M per violation category per year. The regulatory clock is not waiting for the governance architecture to be invented.

Where CE-OS™ Meets Both Reports

CE-OS™, the Conscious Enterprise Operating System, is Rarity Research's proprietary intelligence architecture. It is not a security product, nor is it a monitoring platform. It is the governing cognitive layer that the enterprise must possess before any agent is deployed: the layer that both VentureBeat investigations describe by its absence.

The Cortex Constitution is the direct answer to the governance mirage's core finding: no single owner, no accountable structure, and no authority boundaries. Board-approved before operational deployment, it encodes values, purpose, decision principles, authority boundaries, and epistemic protocol into the enterprise's operating logic. It is the control plane VentureBeat says is missing: enterprise-native rather than hyperscaler-delegated.

Confidence Routing, the CE-OS™ Adaptation Tier, is the structural response to the agent audit's call for tiered human oversight. Tier 1 involves autonomous action for high-confidence, low-consequence decisions. Tier 2 requires an informed human decision for medium consequence. Tier 3 reserves human judgement for strategic or irreversible actions, and Tier 4 dictates mandatory human review when uncertainty or signal conflicts are detected. The "big red button" the report demanded is built into governing logic by design, not retrofitted after an incident.

The Invisible Thread Engine addresses the cross-domain blindness both reports identify: agents operating in silos and governance leaders unable to track cascading consequences across organisational boundaries. It connects interpreted signals across all domains simultaneously, detecting patterns no siloed monitoring tool can surface.

The Shadow Audit (SSA) maps directly to the governance mirage itself, identifying regulatory and governance failures that the organisation's existing map cannot see. Phase 0 acts as the diagnostic prerequisite that grounds the Cortex Constitution in operational reality rather than executive confidence.

The Precision Map

Report Failure Mode CE-OS™ Response Component
No single owner or accountable team Board-approved authority structure with defined decision ownership at every tier Cortex Constitution
Monitoring without enforcement Confidence-tiered routing: the system knows what it cannot do unilaterally Adaptation Tier
Agents acting without authority limits Constitutional mandate defines permissible action space before deployment Cortex Constitution
No tiered human oversight Tier 1–4 routing: autonomous, informed, reserved, and mandatory review Confidence Routing
Cross-domain signal blindness Cross-domain pattern detection across all organisational domains simultaneously Invisible Thread Engine
The governance mirage itself Shadow Audit surfaces what the existing map cannot see before building SSA Phase 0
No institutional memory or learning Outcomes teach the Cortex: the memory loop refines the pattern model continuously Memory Loop
Hyperscaler dependency and lock-in Enterprise-native architecture: a provider-agnostic governing layer above all platforms CE-OS™ Architecture

Why the Security Industry Cannot Solve This

Every solution proposed in both reports operates at the enforcement layer. These are excellent tools for enforcing policy, but none of them generate policy. None define the governing purpose, values, authority boundaries, and epistemic principles that make enforcement meaningful rather than mechanical.

The hyperscalers face an identical constraint. The VentureBeat audit confirmed that no provider, including Microsoft Azure, Anthropic, Google Cloud, OpenAI, and AWS, ships a complete governance architecture. Each offers enforcement primitives within their own runtime, but none provide the constitutional intelligence layer that transcends any single provider's platform.

They sell infrastructure; CE-OS™ governs it.

Security tools can only enforce what the governing architecture has already defined. If the architecture doesn't exist, the tools have nothing to enforce.

Thirty Years of Empirical Research Inside the Enterprise

CE-OS™ did not emerge from the AI security crisis. It was not conceived in response to the OWASP Top 10 for Agentic Applications, the Meta breach, or the Mercor supply-chain incident. It was developed over thirty years of empirical research inside real enterprises, studying how organisations actually sense their environment, form perception, reason under uncertainty, make decisions tiered by consequence, and adapt through learning loops rather than episodic strategy cycles.

The framework observed what analogue enterprises consistently failed to do: maintain continuous awareness across all signal domains, connect cross-silo patterns before they became crises, route decisions to the appropriate level of human judgement, and build institutional memory that compounds rather than resets. These were organisational intelligence failures long before AI agents existed; the agents have simply made them existentially urgent.

This temporal depth is not a heritage claim; it is a structural advantage. Every other proposed solution to the governance and agent security crisis is being constructed under crisis pressure, with the agents already running. CE-OS™ was built "in the before," from the inside, during three decades when the enterprise had time to be observed, understood, and architecturally reimagined.

The AI agent crisis has not created a new problem.

It has revealed the true cost of an absence that was always there.

If you are responsible for enterprise AI deployment and you recognise what these reports are describing, it is worth a conversation.

signal@raritygroup.eu
Rarity Research  ·  Conscious Enterprise Practice
Back to Signal Room
Back to Signal Room
Banking & AI Compliance  ·  May 2026

The Question the AI Act Cannot Answer for You

European banking has governance frameworks. What it does not have is an answer to a question that is now legally material: what governed that AI decision at the moment it was made? Not the policy. The decision itself.

Michael Ermogenis Rarity Group

Ask the Chief Risk Officer of any significant European bank the following questions. Not about policy. Not about frameworks or compliance posture. About a specific AI decision made yesterday, or last Tuesday, or at 14:37 on any given trading day.

Which AI model generated that credit recommendation? What was its confidence level at the precise moment of output? What contextual inputs were active in that decision? Was the output routed to a human for review, and if not, on what basis was autonomous action authorised? If the model has been updated since the decision was made, is the audit record attached to the original model version or the current one? And if that decision is challenged by a regulator tomorrow, can you produce a complete, tamper-evident, decision-level audit trail that answers all of the above?

Most cannot. Not because they are negligent. Because the architecture that would make those answers available does not exist inside their AI deployment stack. It was never built. And the EU AI Act, for all its ambition, does not build it for them.

What the AI Act Actually Requires

The EU AI Act is a governance mandate, not a governance architecture. It specifies what banks must achieve. It says nothing about how to achieve it at the level where the work actually happens: the individual AI transaction.

Article 9 requires a risk management system. Article 13 requires transparency. Article 14 requires human oversight. Article 17 requires a quality management system. These are real obligations with real legal consequence for high-risk AI systems, and credit scoring, fraud detection, and customer risk profiling are all explicitly classified as high-risk under the Act.

But read each article carefully and a structural gap emerges. Every obligation is framed at the system level. The risk management system. The quality management system. The oversight mechanism. What none of the articles address is the transaction level: the individual decision, made by a specific model version, at a specific moment, under specific input conditions, with a specific confidence profile, routed through a specific oversight pathway.

A governance framework tells you what the rules are. It does not tell you whether the rules were followed in the decision your regulator is examining right now.

This is not a legal interpretation question. It is an architectural one. And the architecture that closes this gap does not exist in any current AI deployment toolkit, any hyperscaler's compliance offering, or any Big Four governance framework currently available to European banks.

Why the World Model Problem Makes This Worse

There is a deeper issue beneath the compliance gap, one that the regulatory debate has not yet fully surfaced. It concerns the nature of the AI models that banks are deploying and what they fundamentally are.

Every large language model and every machine learning system deployed in a banking context is a snapshot. It was trained on a representation of the world as it existed up to a particular point in time. The moment it is deployed, it begins operating in a world that has already moved on. Credit conditions change. Customer behaviour shifts. Macroeconomic signals evolve. The model does not know. It is still operating on the world it learned.

This is not a minor technical caveat. It is a fundamental structural property of every AI system currently deployed in European banking. The model's world model, the internal representation of reality on which every decision is based, is a historical document dressed as current intelligence.

In a stable environment, the drift is manageable. In volatile conditions, geopolitical disruption, credit cycle turning points, liquidity stress events, the gap between the model's world and the actual world can become material, and the decisions produced by that gap carry regulatory, financial, and reputational consequence that no compliance framework currently captures.

The question is not only whether the AI decision was governed. It is whether the AI system was operating on an accurate representation of the world at the moment it decided. That question has no current answer in European banking's AI governance architecture.

The Absence That DORA Cannot Fill

DORA addresses operational resilience. It requires that banks identify, classify, and manage ICT risk, including AI systems, with documented recovery capabilities, third-party oversight, and incident reporting. It is a significant and necessary regulation.

But DORA's frame is continuity: can the system keep running, and can the bank recover when it cannot? It is not designed to answer the governance question at the decision level. A bank that achieves full DORA compliance can still be unable to tell a supervisor which model version made a specific credit decision, what its confidence level was, and whether human oversight was applied at the correct threshold.

The combined effect of the AI Act and DORA is to create a regulatory environment in which banks are simultaneously required to govern AI decisions at transaction level and structurally unable to do so with their current architecture. This is not an edge case. It is the default condition of European banking's AI deployment as of 2026.

Sovereign Banking Intelligence: The Transaction Layer

Sovereign Banking Intelligence™ (SBI™) is Rarity Group's proprietary framework for governing AI decisions at the point of execution. It is not a compliance overlay, a monitoring dashboard, or a policy document. It is an independent decisioning layer that operates between a bank's AI models and their operational outputs -- governing each transaction at the moment it occurs, producing a complete and tamper-evident record of what actually governed the decision, not what the governance framework says should have.

SBI™ was not developed in response to the AI Act. It emerged from the same body of empirical work that produced CE-OS™ -- the recognition, arrived at over three decades of observing how organisations actually fail, that the distance between a governance framework and the decisions made under it is always larger than the organisation believes. Banking is simply the domain where that distance has become legally and operationally critical first. And European banking specifically is the domain where sovereignty over that layer -- independence from any single model provider, any single hyperscaler, any single jurisdiction's infrastructure -- has become a strategic imperative, not merely a technical preference.

The architecture addresses each of the questions posed above. It is model-independent, meaning the compliance record does not reset when the underlying model changes. It incorporates world model integrity monitoring, meaning it maintains a continuous signal on whether the model's operational assumptions remain valid for the environment it is currently deciding within. And it implements the kind of tiered human oversight the AI Act requires -- not as a policy statement, but as a governing condition of every transaction the system processes.

The technical and architectural detail of SBI™ is available to qualified institutions and their advisors under NDA. What can be said here is that the questions at the end of this article are not rhetorical. They were derived directly from the architecture -- because the architecture was built to answer them.

The Provenance of the Architecture

It is worth being direct about where SBI™ comes from, because the source matters for understanding why it solves a problem that the banking and AI industries have not solved from inside.

The architecture is not a banking invention. It is not a product of the AI Act compliance industry, the RegTech sector, or the hyperscaler ecosystem. It emerged from thirty years of empirical observation of how organisations of all kinds, at different scales, in different industries, fail to govern the decisions they make at the point where those decisions actually occur.

The insight that drove CE-OS™, and through it SBI™, was simple and consistently proven: the distance between an organisation's governance framework and its operational reality is always larger than the organisation believes. The framework says what should happen. The operation reflects what actually does. The gap between them is where the risk lives, and no amount of policy sophistication closes it without a layer that operates inside the transaction itself.

Banking has a version of this problem that is more acute than most industries. The decisions are consequential, the regulatory expectations are precise, the model environment changes faster than governance cycles, and the supervisory scrutiny is conducted by institutions -- the ECB, the SSM, the national competent authorities -- that are asking increasingly specific questions about what governed each decision, not just what the governance framework says.

SBI™ was developed because the enterprise architecture pointed toward banking as the domain where the transaction-level governance gap would become a material legal and operational risk before any other sector. That assessment has proven correct.

The Questions Worth Asking

For any senior leader in European banking who has read this far, a small set of questions is worth sitting with before the next supervisory review.

Can your bank produce a decision-level audit trail for any specific AI transaction made in the last ninety days, in a form that would satisfy an SSM examiner? Not a system-level audit. A transaction-level one.

If your primary AI model provider experienced a significant outage or governance failure tomorrow, would your compliance record for AI decisions made prior to that event remain intact and accessible? Or is the audit record hosted within the provider's infrastructure?

When your AI credit scoring model was last updated, did the confidence thresholds for human oversight routing update automatically to reflect the new model's characteristics? Or are those thresholds still calibrated to the previous version?

And finally: is the world model your AI systems are currently operating on -- the internal representation of credit conditions, customer behaviour, and market state -- sufficiently current to support the decisions being made today? When was it last validated against current conditions, and by whom?

These are not rhetorical questions. They are the questions that define the boundary between a governance framework and a governance architecture. The framework exists to answer them in principle. The architecture exists to answer them in fact.

Most European banks currently have the framework. None have the architecture.

That is the gap SBI™ was built to close.

If these questions have a specific resonance in your institution, it is a conversation worth having.

signal@raritygroup.eu

SBI™ technical and architectural documentation is available under NDA to qualified banking institutions and their advisors.

Michael Ermogenis  ·  Rarity Group
Back to Signal Room