Insights, research, analysis, and market developments shaping the future of institutional AI control.
AI is a given. Control is not.™

The rows are the five ecosystems of the AI stack, read from the physical base upward: Power (the electricity that runs it), Compute (the chips and servers), Data Centers (where it physically sits), Models (the systems that produce the decisions), and Agents (AI that acts on those decisions on its own). AI is not one layer of the stack; it runs through all five. The rows separate the physical substrate it runs on — power, compute, data centers — from the reasoning and action layers where the models decide and the agents act. Control of "the AI" means control across all five, which is why the Matrix is read as depth rather than as a single layer.
The columns are the five pillars through which command over any layer is exercised: Jurisdictional (where workloads run, and under whose law), Logical (who may access what, and on what terms), Technical (cryptographic and isolation control over data and models), Operational (real-time visibility into what is actually happening), and Contractual (enforceable rights to audit, exit, and hold providers accountable). Reading control as a grid rather than a single number is deliberate. An institution may command its models while renting the data centers beneath them or hold strong contractual rights while lacking real-time operational visibility. A single score would hide exactly the asymmetries that determine where an institution is exposed. The Matrix is read cell by cell and never collapsed to one figure.
The tiers reflect the completeness of publicly available disclosure reviewed under the methodology described in this report. They are not assessments, certifications, or audits of any institution’s actual internal controls. A higher tier reflects more complete public disclosure regarding AI control mechanisms; ND (Not Disclosed) reflects the absence of relevant public disclosure and should not be interpreted as evidence that control is absent.
.png/:/rs=w:600,cg:true,m)
Taken together, the research converges on a single conclusion. Of two thousand control-cell evaluations, two hundred nine — just over one in ten — disclose control at any tier above Not Disclosed. Of those, thirty-two rise to a Governed designation through named, auditable mechanisms. And of those, none achieved a Sovereign designation under the framework. The shape matters as much as the count: all thirty-two Governed cells sit at the Models layer — none at the autonomous agent layer, and none across the infrastructure layers of Power, Compute, and Data Centers. The record describes not simply a scarcity of publicly demonstrated control, but its concentration within one narrow portion of the AI stack.

Asset owners are institutions whose fiduciary obligations make AI control categorical, not optional. Entrusted with the retirement security of workers, the wealth of nations, and the long-term promises made to beneficiaries and citizens, they are the entities to whom the institutional finance ecosystem is ultimately accountable — and command of AI across the system will depend on whether they can control the systems increasingly shaping how capital is allocated across economies and generations.

Asset managers are the institutions that transform capital into investment decisions. Positioned between asset owners and markets, they serve as the engines of allocation, research, and portfolio construction. Increasingly, AI is becoming embedded within the analytical and operational layers through which those decisions are made. As a result, the question is no longer whether asset managers will employ AI, but whether they can exercise sufficient control over the systems that increasingly influence investment judgment and fiduciary outcomes.

Asset servicers are the institutions whose operational responsibilities make AI control a foundational requirement. They are not merely providers of post-trade services; they are the entities that safeguard assets, maintain records, administer funds, and enable the functioning of the institutional financial system itself. Much of the trust upon which global finance depends ultimately rests upon their ability to maintain command over the increasingly intelligent systems that support the movement, accounting, and stewardship of capital.

Banks occupy a uniquely consequential position within institutional finance. They are not merely intermediaries between savers and borrowers; they are the institutions that facilitate payments, create credit, manage liquidity, and support the functioning of the broader economy. As AI becomes embedded across these activities, control ceases to be a technology issue and becomes a matter of safety, soundness, and systemic resilience. Command of AI within banking is inseparable from command of the critical infrastructure upon which modern finance depends.

Wealth managers are the institutions whose advisory responsibilities make AI control a categorical, not optional, requirement. They are not merely intermediaries between products and clients; they are the entities entrusted with guiding individuals, families, and institutions through decisions that shape long-term financial outcomes. As AI becomes woven into planning, research, and client engagement, control becomes inseparable from fiduciary judgment and trust. The future of wealth management will depend not simply on access to intelligent systems, but on the ability to control them in service of the clients whose interests wealth managers are entrusted to protect.

Retirement providers are the institutions whose responsibilities to participants and plan sponsors make AI control a foundational requirement. They are not merely administrators of retirement plans; they are the entities entrusted with safeguarding the long-term financial well-being of millions of individuals and families. As AI becomes woven into recordkeeping, advice, operations, and participant engagement, command of intelligent systems becomes inseparable from fiduciary responsibility and trust. The strength of the retirement system itself will depend in no small measure on the ability of retirement providers to controlthe technologies that increasingly shape retirement outcomes.

Private equity firms occupy a unique position within institutional finance. They are not merely allocators of capital; they are the institutions that exercise ownership, influence management, and shape the strategic direction of thousands of enterprises worldwide. As AI becomes a core driver of productivity and value creation, command of intelligent systems becomes inseparable from command of the businesses themselves. The competitive advantage of private equity firms will increasingly be determined not only by the capital they deploy, but by their ability to control the technologies transforming the companies they own.

Insurance companies are the institutions whose promises make AI control categorical, not optional. As underwriters, claims payers, and long-term investors entrusted with safeguarding individuals, businesses, and societies against loss, they provide much of the stability modern economies depend on — and confidence in the insurance system itself will rest in no small measure on whether insurers can control the systems increasingly shaping the pricing, transfer, and management of risk.
A Note to the Board
A board that asks these twenty-five questions and records honest answers will produce, in a single sitting, the most accurate picture of its institution’s real AI control posture it has ever held.
The pattern of answers — not any single answer — is the finding:
· Identify the critical cells. Five cells — one per ecosystem — typically carry the highest fiduciary consequence. Resolve those first.
· Assign an owner and a date to every "assured only" answer. An open control gap without an owner is an unmanaged risk.
· Make this a standing review. AI control is a fiduciary matter that sits above the technology-risk layer. The twenty-five questions are a quarterly instrument, not a one-time exercise.
Third-party video provided for informational purposes only. Institutional AI is not affiliated with, endorsed by, or sponsored by the speaker(s) or the organization featured.
Our Insights content is provided for informational and educational purposes only and does not constitute legal, regulatory, investment, tax, or other professional advice. The views expressed reflect Institutional AI's analysis as of the date of publication and are based on publicly available information and general market observations.
Where third-party research, data, surveys, or organizations are referenced, citations are provided in the corresponding publications. References are for analytical and educational purposes only and do not imply endorsement, affiliation, or partnership. Original research remains the property of its respective publishers.
Institutional AI makes no representation or warranty as to the accuracy, completeness, or suitability of the information for any purpose. Readers should conduct their own due diligence and consult appropriate professional advisors before acting on any information presented.
Please see our Disclaimer page as well as the Notices section under our Research pages.
AI is a given. Control is not.™
© 2026 Institutional AI. All Rights Reserved.