OVERVIEW
Eighty Institutions · Eight Sectors
One independent assessment of publicly disclosed AI control.

The 2026 research evaluated eighty institutions across eight sectors of institutional finance using Institutional AI's proprietary 5×5 Control Matrix™. Each institution's publicly available disclosures were evaluated across five AI ecosystems and five pillars of control, resulting in two thousand individual AI Control cell evaluations. These evaluations provide the analytical basis for the aggregated sector observations, charts, and benchmarks presented on this website.
The analysis relies exclusively on publicly available information. No institution was interviewed, surveyed, or asked to provide confidential information, and no institution reviewed or approved the findings prior to publication.
Tier assignments, sector composites, and related findings reflect Institutional AI's analytical opinions based on the methodology described in the report and the publicly available information reviewed. They are opinions regarding publicly disclosed information and do not constitute audits, examinations, certifications, regulatory findings, or assessments of any institution's actual controls, governance, or operational capabilities.
The complete methodology is available in:
The State of AI Control in Institutional Finance — 2026 Edition

The Institutional AI 5×5 Control Matrix™ is the analytical framework used across Institutional AI's research and advisory work. It evaluates AI control across five AI ecosystems and five pillars of control, creating a consistent structure for assessing publicly available evidence of institutional AI control.
AI operates across the entire technology stack—not within a single layer. The Matrix evaluates five ecosystems:
Each ecosystem is evaluated across five dimensions of institutional control:
Together, these dimensions form the Institutional AI 5×5 Control Matrix™, providing a structured view of AI control across the full technology stack.
The Matrix uses five qualitative tiers:
Tier assignments reflect Institutional AI's analytical interpretation of publicly available information under its published methodology. They are not audits, certifications, regulatory findings, or assessments of an institution's actual internal controls.

.png/:/rs=w:1240,cg:true,m)
The research identifies five themes emerging from the public record. AI adoption is widespread, but publicly demonstrated AI control remains limited. Under Institutional AI's methodology, approximately 4% of evaluated AI Control cells reached the Governed tier, with nearly all of those occurring within a single ecosystem of the AI stack.
Every institution reviewed publicly describes active AI deployment or production use. AI adoption is now widespread across institutional finance. Public evidence of demonstrable AI control, however, remains limited.
Public evidence of AI control is concentrated almost entirely within the Models layer of the AI stack. Across the industry, disclosures regarding Power, Compute, and Data Centers remain limited, while only a small number of institutions publicly demonstrate governed control over autonomous agents. Publicly demonstrated control is therefore concentrated in one part of the stack rather than across it.
Differences between institutions operating in the same sector are often greater than differences between sectors themselves. In most sectors, at least one institution publicly demonstrates governed AI control while the sector median remains substantially lower. The principal gap is therefore within sectors—not between them.
Public disclosures commonly describe AI capabilities, deployments, pilots, and platform integrations. Far fewer describe the governance mechanisms, technical controls, and operational evidence needed to demonstrate governed AI control. Capability and demonstrable control are not the same.
Accountability cannot be delegated simply because infrastructure is outsourced. Public disclosures are strongest where institutions describe the mechanisms they use to retain oversight and control. Disclosure becomes progressively more limited across the underlying infrastructure on which AI ultimately depends.
All engagements and discussions are conducted under confidentiality protections, including non-disclosure agreements where applicable. Control Tiers represent Institutional AI’s analytical interpretation of the depth, specificity, and visibility of publicly disclosed AI control information and are not assessments, audits, certifications, or determinations of any institution’s actual control environment, governance practices, or operational capabilities.
See the full Legal Notices section below.

Nature and Purpose
This report is published by Institutional AI, LLC (“Institutional AI,” “we,” “our,” or “us”) solely for informational and educational purposes. It does not constitute legal, regulatory, investment, fiduciary, accounting, tax, cybersecurity, technology, or other professional advice, and it does not create an attorney-client, advisory, fiduciary, or other professional relationship between Institutional AI and any reader. Readers should consult their own professional advisors regarding matters discussed in this report.
Unnamed Entries
The per-institution sections of this report describe reviewed institutions without naming them. Any identification a reader may make is the reader's own inference and is not made, confirmed, or endorsed by Institutional AI. Each entry states an analytical opinion regarding the completeness of a public disclosure record as of the review cutoff date, derived solely from publicly available sources under the methodology described herein. No entry constitutes a statement of fact about any institution's actual controls, capabilities, governance, or operations, and no entry should be read as an evaluation, rating, certification, or benchmark of any institution.
Sources and Scope of Review
The analyses, observations, and conclusions presented in this report are derived exclusively from publicly available information, including public filings, annual reports, earnings calls, investor presentations, press releases, speeches, interviews, conference materials, corporate websites, and other publicly disclosed materials available.
Our review is limited to interpreting publicly available information. We have not audited, inspected, tested, or independently verified any institution’s internal practices, systems, controls, or operations. Accordingly, we make no representation or warranty, express or implied, regarding the completeness, accuracy, currency, or fitness of any underlying information. Public disclosures may be incomplete, may change after the review cutoff date, and may not reflect an institution’s actual practices.
Opinions and Methodology
The findings, frameworks, classifications, matrices, observations, indices, tiers, maturity descriptions, and other analytical constructs presented in this report reflect Institutional AI’s opinions and interpretations based on the methodology described herein and the publicly available information reviewed.
These analytical constructs are intended solely to facilitate discussion, research, and analysis on matters of public interest. Reasonable institutions, regulators, investors, academics, practitioners, and other observers may reasonably reach different conclusions based on the same or additional information. Where this report assigns a tier or classification, that assignment reflects Institutional AI's professional judgment under the methodology described herein. Other reasonable reviewers applying the same methodology to the same public record may assign a different tier or classification.
AI Control Observations
The AI Control observations, matrices, tiers, and related assessments presented in this report are analytical opinions derived solely from publicly available information.
They do not constitute audits, examinations, certifications, regulatory findings, assurance engagements, or statements regarding any institution’s actual AI governance, cybersecurity, operational resilience, technology architecture, fiduciary practices, regulatory compliance, or internal control environment.
Institutions may possess capabilities, controls, governance mechanisms, or operational practices that are not publicly disclosed and therefore are not reflected in this report. Because these observations are opinions based on the specific public disclosures and methodology described herein, readers may examine the same public record and form their own conclusions, which may differ from ours.
Public Disclosure Limitations
The absence of public disclosure regarding a capability, safeguard, policy, process, or control should not be interpreted as evidence that it does not exist.
Similarly, a lower tier, lower assessment, or Not Disclosed classification reflects only Institutional AI’s interpretation of the extent of publicly available disclosure under the methodology described herein. It should not be interpreted as a conclusion that an institution’s actual controls, governance, or operational capabilities are inadequate, deficient, or inferior to those of any other institution.
Conversely, references to publicly disclosed practices should not be interpreted as endorsements, guarantees, or representations regarding their existence in practice or their effectiveness.
No Endorsement; Third-Party Marks
References to institutions, organizations, products, technologies, services, vendors, partnerships, or other third parties are made solely for descriptive, analytical, educational, or nominative purposes and do not imply endorsement, sponsorship, affiliation, approval, or any commercial relationship with Institutional AI.
All trademarks, trade names, service marks, company names, and logos remain the property of their respective owners.
No Rating or Assurance
This report is not a credit rating, investment rating, regulatory assessment, cybersecurity assessment, governance assessment, operational review, assurance engagement, or certification of any kind.
Nothing contained in this report expresses an opinion regarding the financial condition, safety and soundness, solvency, investment merit, fiduciary standards, operational effectiveness, regulatory standing, cybersecurity maturity, or overall risk profile of any institution.
Nothing in this report is intended to rank, score, benchmark, or compare one identified institution against another. Sector-level observations describe disclosure patterns within categories and should not be interpreted as comparative evaluations of individual institutions.
Forward-Looking Statements; No Reliance; Limitation of Liability
Any forward-looking statements, expectations, projections, scenarios, assumptions, or opinions regarding future developments are inherently uncertain.
Readers should not rely upon this report as the sole basis for any investment, governance, technology, cybersecurity, compliance, operational, strategic, or business decision.
To the fullest extent permitted by applicable law, Institutional AI, LLC and its members, managers, officers, directors, employees, contractors, advisors, and agents disclaim all liability for any direct, indirect, incidental, consequential, special, exemplary, or punitive damages arising from or relating to the use of, or reliance upon, this report.
Governing Law
These Important Notices shall be governed by and construed in accordance with the laws of the State of New Hampshire, without regard to conflict-of-law principles.
Any dispute arising from or relating to this report shall be subject to the exclusive jurisdiction of the state and federal courts located in New Hampshire.
If any provision of these Important Notices is determined to be unenforceable, the remaining provisions shall remain in full force and effect.
Headings are provided solely for convenience and do not affect interpretation.
Brief excerpts may be quoted with attribution to Institutional AI for the purpose of comment or review. All other reproduction or distribution requires prior written permission.
Requests for permission to reproduce or distribute this publication should be submitted at research@institutionalai.net
AI is a given. Control is not.™
© 2026 Institutional AI. All Rights Reserved.