AI CONTROL. FOR FINANCIAL INSTITUTIONS.
AI CONTROL. FOR FINANCIAL INSTITUTIONS. AI CONTROL. FOR FINANCIAL INSTITUTIONS. AI CONTROL. FOR FINANCIAL INSTITUTIONS.AI is a given. Control is not.™
AI is a given. Control is not.™
Rad H. Pasovschi, Founder & CEO, Institutional AI

Institutional finance has built the foundations of AI adoption: strategies defined, frameworks established, governance structures created.
Necessary. But not sufficient.
Governance describes what an institution intends to do. Control is the evidence that intention holds — the named, auditable mechanism behind each use. The distance between the two is where institutional exposure now sits.
And in financial services, that control has a shape. It must be deep, and it must be wide.
The industry has largely treated AI as a new software technology — the models and agents that fill the headlines. But artificial intelligence does not begin and end there. It runs deeper — and reaches wider — than the software an institution sees. Control must therefore run in two directions at once.
Deep — through the full AI stack. Institutions think about AI at the level of models and agents — the software that reasons and acts. But that software does not run in the air. It runs on data centers, on compute, on power — physical layers, in specific jurisdictions, under someone's control. A regulator is not satisfied by application logs; the questions that decide exposure — where it executed, under whose key custody, in which jurisdiction — live beneath the software. Control is only as deep as the lowest layer an institution can account for.
Wide — across the chain. Institutions do not operate most of the AI they depend on. Consider an asset owner — a public pension or sovereign wealth fund. It holds the fiduciary duty, but the AI shaping its capital runs elsewhere: inside the managers it appoints, the servicers that administer its assets, the providers beneath them. Each is a step further from the institution that stays accountable — yet the duty travels the entire chain, even as visibility fades. Control that stops at the institution's own walls leaves the rest unguarded.
Deep across five ecosystems. Wide across the entire chain. That is the standard. Nothing narrower is AI control.


Institutional AI reviewed the publicly available disclosures of eighty of the world's leading financial institutions. The public record indicates that AI adoption is widespread, while publicly demonstrable Institutional AI Control—both deep across the AI Stack™ and wide across the institutional operating ecosystem—remains limited.
Where evidence is publicly disclosed, it is concentrated primarily at the model layer. Beyond models—into autonomous agents above and the power, compute, and data-center ecosystems beneath—publicly demonstrable control becomes markedly less evident.
For boards, executive teams, and risk leaders, the implication is straightforward: AI governance and Institutional AI Control are not the same. As artificial intelligence becomes increasingly embedded in institutional decision-making, understanding where demonstrable control exists—and where it does not—is becoming a defining question of institutional oversight.
Asset owners are the institutions whose fiduciary obligations make AI control categorical, not optional. Entrusted with the retirement security of workers, the wealth of nations, and the long-term promises made to beneficiaries and citizens, they are the entities to whom the institutional finance ecosystem is ultimately accountable — and command of AI across the system will depend on whether they can govern the systems increasingly shaping how capital is allocated across economies and generations.
Asset managers are the institutions that transform capital into investment decisions. Positioned between asset owners and markets, they serve as the engines of allocation, research, and portfolio construction. Increasingly, AI is becoming embedded within the analytical and operational layers through which those decisions are made. As a result, the question is no longer whether asset managers will employ AI, but whether they can exercise sufficient control over the systems that increasingly influence investment judgment and fiduciary outcomes.
Asset servicers are the institutions whose operational responsibilities make AI control a foundational requirement. They are not merely providers of post-trade services; they are the entities that safeguard assets, maintain records, administer funds, and enable the functioning of the institutional financial system itself. In the final analysis, much of the trust upon which global finance depends ultimately rests upon their ability to maintain command over the increasingly intelligent systems that support the movement, accounting, and stewardship of capital.
Banks occupy a uniquely consequential position within institutional finance. They are not merely intermediaries between savers and borrowers; they are the institutions that facilitate payments, create credit, manage liquidity, and support the functioning of the broader economy. As AI becomes embedded across these activities, control ceases to be a technology issue and becomes a matter of safety, soundness, and systemic resilience. In the final analysis, command of AI within banking is inseparable from command of the critical infrastructure upon which modern finance depends.
Wealth managers are the institutions whose advisory responsibilities make AI control a categorical, not optional, requirement. They are not merely intermediaries between products and clients; they are the entities entrusted with guiding individuals, families, and institutions through decisions that shape long-term financial outcomes. As AI becomes woven into planning, research, and client engagement, control becomes inseparable from fiduciary judgment and trust. In the final analysis, the future of wealth management will depend not simply on access to intelligent systems, but on the ability to govern them in service of the clients whose interests wealth managers are entrusted to protect.

Retirement providers are the institutions whose responsibilities to participants and plan sponsors make AI control a foundational requirement. They are not merely administrators of retirement plans; they are the entities entrusted with safeguarding the long-term financial well-being of millions of individuals and families. As AI becomes woven into recordkeeping, advice, operations, and participant engagement, command of intelligent systems becomes inseparable from fiduciary responsibility and trust. In the final analysis, the strength of the retirement system itself will depend in no small measure on the ability of retirement providers to govern the technologies that increasingly shape retirement outcomes.
Private equity firms occupy a unique position within institutional finance. They are not merely allocators of capital; they are the institutions that exercise ownership, influence management, and shape the strategic direction of thousands of enterprises worldwide. As AI becomes a core driver of productivity and value creation, command of intelligent systems becomes inseparable from command of the businesses themselves. In the final analysis, the competitive advantage of private equity firms will increasingly be determined not only by the capital they deploy, but by their ability to govern the technologies transforming the companies they own.
Insurance companies are the institutions whose promises make AI control categorical, not optional. As underwriters, claims payers, and long-term investors entrusted with safeguarding individuals, businesses, and societies against loss, they provide much of the stability modern economies depend on — and confidence in the insurance system itself will rest in no small measure on whether insurers can govern the systems increasingly shaping the pricing, transfer, and management of risk.

Deep control begins with the Institutional AI Stack™ — the five ecosystems institutional AI runs on: Power, Compute, Data Centers, Models, and Agents. Most institutions see AI at the top of the stack — the models and agents in the headlines. But those run on data centers, compute, and power an institution rarely owns and often cannot see.
Deep AI control reaches through every layer, owned or rented, to the lowest one an institution can account for. What you rent, you are still accountable for.

The 5×5 Control Matrix™ is the instrument that measures how much control an institution can demonstrate over the AI it depends on. It reads the five ecosystems of the Institutional AI Stack™ — Power, Compute, Data Centers, Models, and Agents — against five pillars of control: Jurisdictional, Logical, Technical, Operational, and Contractual. Twenty-five intersections, evaluated cell by cell rather than collapsed into a single score — because an institution can command its models while renting the data centers beneath them, and a single number would hide exactly that.
The Matrix documents where control is evidenced, where it is assumed, and where it is absent. It is applied through the AI Control Assessment™, which runs it in two directions — deep within the institution, and wide across every material relationship in its delegation chain.

The Assessment is where the instrument is applied. It runs the 5×5 Control Matrix™ across an institution's full AI footprint, in two directions.
Deep — the institution's own matrix. For an asset owner such as a public pension fund, this is one 5×5 reading its demonstrable control over the AI it operates directly, from power to agents.
Wide — a matrix for every material relationship in its chain. A pension fund does not operate most of the AI it depends on: it runs inside the asset managers it appoints, the asset servicers that custody and administer its assets, and the technology, infrastructure, and model providers beneath them. The Assessment maps that chain and runs the Matrix on each node — a distinct 5×5 per relationship. The same provider reads differently for every institution, because control lives in the contract and the reach it grants, not in the vendor.
The AI Control Assessment™ establishes the institution's demonstrable control position — deep, and wide across the chain — and sets the priorities to close the gaps: where control is evidenced, where it is assumed, where it is absent, and where the duty extends further than the institution can currently reach.
The output is not a policy binder. It is a control position a steward of capital can stand behind — before the board, the regulator, and the client.
.png/:/rs=w:600,cg:true,m)
The Stack defines the architecture; OLTAIX™ makes it operational. From a single control position it coordinates and verifies control across the five ecosystems while enforcing the five pillars — turning periodic review and policy assertion into control that is continuous, operational, and demonstrable.
Not a software product: the institutional control capability through which the architecture is put into practice

Institutional AI Control is not four separate ideas — it is one system.
The Institutional AI Stack™ is the architecture: the five ecosystems every institution's AI runs on, from power to agents. The 5×5 Control Matrix™ measures control across it — five ecosystems by five pillars, twenty-five intersections, read cell by cell rather than reduced to a single score. The AI Control Assessment™ reads that Matrix and defines the program. And OLTAIX™ operates the Stack under continuous control.
The architecture, the measure, the diagnosis, and the means to hold it — one system, deep across the stack and wide across the chain.
We work with the world's leading stewards of capital — across all eight sectors of institutional finance — to address one of the defining challenges of the AI era: establishing demonstrable Institutional AI Control. Our work is grounded in independent research and evidence-based methodology; our flagship study, The State of AI Control in Institutional Finance, examines eighty institutions across eight sectors and introduces the 5×5 Control Matrix™.
Not a consulting firm. Not a software vendor. Not a systems integrator.
Institutional AI maintains no hyperscaler alliances, no model-provider partnerships, no systems-integration practice, and no resale economics with technology vendors. Independence is not a marketing claim — it is the structure of the firm.
AI is a given. Control is not.™
A board that asks these three questions and records honest answers will produce, in a single sitting, the most accurate picture of its real AI control posture it has ever held.
Governance is policy. Control is evidence. These three questions separate the two. A board that can get them answered with technical proof — not provider assurance — has control. One that cannot has just found its exposure.
And these are only the beginning.
All engagements and discussions are conducted under confidentiality protections, including non-disclosure agreements where applicable. Control Tiers represent Institutional AI’s analytical interpretation of the depth, specificity, and visibility of publicly disclosed AI control information and are not assessments, audits, certifications, or determinations of any institution’s actual control environment, governance practices, or operational capabilities.

AI is a given. Control is not.™
© 2026 Institutional AI. All Rights Reserved.