Eighty Institutions · Eight Sectors
Key Findings

We analyzed eighty of the world's leading financial institutions across eight sectors against a single core question: not whether they utilize AI, but whether their public record outlines evidence of structural control frameworks over the systems on which they increasingly depend.
The poles are far apart: Banks outlined the strongest framework elements observed within their publicly available disclosures among all sectors reviewed, while Private Equity firms presented the least public disclosure at the median sector level.
The pattern is structurally consistent. Where institutions disclose AI control frameworks, the evidence concentrates primarily at the model layer—specifically how models are governed, validated, and operated—and rapidly thins across the broader AI stack. Public disclosure regarding autonomous agentic frameworks remains limited across the institutions reviewed. On the infrastructure layers beneath them—compute, data centers, and power—the public record is comparatively sparse.
Sector-level observations reflect Institutional AI's qualitative analysis of publicly available disclosures accessible as of June 30, 2026, for the institutions included in the baseline data pool of The State of AI Control in Institutional Finance — 2026 Edition.
These findings describe macro-level patterns observed exclusively within the public record. They represent Institutional AI's analytical opinions based on the methodology described herein and must not be interpreted as compliance certifications, legal audits, attestations, or operational assessments of any individual institution's actual internal controls, risk management practices, governance processes, or technical capabilities.


Documented Governed designations appear overwhelmingly within model governance and operations, with limited public disclosure across agentic systems and the infrastructure layers beneath them.
The analysis identifies where documented AI control framework elements appear across the stack: thirty-nine Governed evaluations at Models/Operational, twenty-five at Models/Logical, thirteen at Models/Technical, two at agentic operation, and none identified across the remaining ecosystem layers.
One cell illustrates the difference between sector-level and institution-level views: Models/Technical appears unfilled in the composite sector baseline while containing thirteen individual Governed designations across the reviewed institutions. The leading profiles are sufficiently advanced in their public disclosures that the same analytical cell can appear absent in the sector view while being clearly represented at the individual institution level.

Across every sector reviewed, differences between individual institutional profiles exceed differences between sector medians—revealing a landscape defined by unevenly disclosed AI control maturity.
That variation, repeated across every sector, is a central finding: the difference between the strongest and weakest anonymized institutional profiles within a single sector is materially greater than the difference between sector medians. This is why our underlying model evaluates the landscape institution by institution, even as we present macro-level observations sector by sector.
The arithmetic reinforces this distinction: across the two thousand individual cell evaluations conducted to develop these sector baselines, only seventy-nine cells—fewer than 4%—received a Governed designation.
These findings should be understood as evidence of significant institutional variation in publicly disclosed AI control frameworks, not as a uniform assessment of any sector or individual institution.
.png/:/rs=w:600,cg:true,m)
Taken together, the research converges on a single conclusion. Of two thousand control-cell evaluations, two hundred nine — just over one in ten — disclose control at any tier above Not Disclosed. Of those, thirty-two rise to a Governed designation through named, auditable mechanisms. And of those, none achieved a Sovereign designation under the framework. The shape matters as much as the count: all thirty-two Governed cells sit at the Models layer — none at the autonomous agent layer, and none across the infrastructure layers of Power, Compute, and Data Centers. The record describes not simply a scarcity of publicly demonstrated control, but its concentration within one narrow portion of the AI stack.

Asset owners are institutions whose fiduciary obligations make AI control categorical, not optional. Entrusted with the retirement security of workers, the wealth of nations, and the long-term promises made to beneficiaries and citizens, they are the entities to whom the institutional finance ecosystem is ultimately accountable — and command of AI across the system will depend on whether they can control the systems increasingly shaping how capital is allocated across economies and generations.

Asset managers are the institutions that transform capital into investment decisions. Positioned between asset owners and markets, they serve as the engines of allocation, research, and portfolio construction. Increasingly, AI is becoming embedded within the analytical and operational layers through which those decisions are made. As a result, the question is no longer whether asset managers will employ AI, but whether they can exercise sufficient control over the systems that increasingly influence investment judgment and fiduciary outcomes.

Asset servicers are the institutions whose operational responsibilities make AI control a foundational requirement. They are not merely providers of post-trade services; they are the entities that safeguard assets, maintain records, administer funds, and enable the functioning of the institutional financial system itself. Much of the trust upon which global finance depends ultimately rests upon their ability to maintain command over the increasingly intelligent systems that support the movement, accounting, and stewardship of capital.

Banks occupy a uniquely consequential position within institutional finance. They are not merely intermediaries between savers and borrowers; they are the institutions that facilitate payments, create credit, manage liquidity, and support the functioning of the broader economy. As AI becomes embedded across these activities, control ceases to be a technology issue and becomes a matter of safety, soundness, and systemic resilience. Command of AI within banking is inseparable from command of the critical infrastructure upon which modern finance depends.

Wealth managers are the institutions whose advisory responsibilities make AI control a categorical, not optional, requirement. They are not merely intermediaries between products and clients; they are the entities entrusted with guiding individuals, families, and institutions through decisions that shape long-term financial outcomes. As AI becomes woven into planning, research, and client engagement, control becomes inseparable from fiduciary judgment and trust. The future of wealth management will depend not simply on access to intelligent systems, but on the ability to control them in service of the clients whose interests wealth managers are entrusted to protect.

Retirement providers are the institutions whose responsibilities to participants and plan sponsors make AI control a foundational requirement. They are not merely administrators of retirement plans; they are the entities entrusted with safeguarding the long-term financial well-being of millions of individuals and families. As AI becomes woven into recordkeeping, advice, operations, and participant engagement, command of intelligent systems becomes inseparable from fiduciary responsibility and trust. The strength of the retirement system itself will depend in no small measure on the ability of retirement providers to controlthe technologies that increasingly shape retirement outcomes.

Private equity firms occupy a unique position within institutional finance. They are not merely allocators of capital; they are the institutions that exercise ownership, influence management, and shape the strategic direction of thousands of enterprises worldwide. As AI becomes a core driver of productivity and value creation, command of intelligent systems becomes inseparable from command of the businesses themselves. The competitive advantage of private equity firms will increasingly be determined not only by the capital they deploy, but by their ability to control the technologies transforming the companies they own.

Insurance companies are the institutions whose promises make AI control categorical, not optional. As underwriters, claims payers, and long-term investors entrusted with safeguarding individuals, businesses, and societies against loss, they provide much of the stability modern economies depend on — and confidence in the insurance system itself will rest in no small measure on whether insurers can control the systems increasingly shaping the pricing, transfer, and management of risk.

This report reads eighty institutions against twenty-five cells each — on the public record, which is all a report can read. The matrix that matters is not in these pages. It is your own, drawn from what your institution can demonstrate rather than what it has disclosed, and right now you cannot draw it. Direct management to produce it, cell by cell, with evidence rather than attestation.
The chain of asset managers, asset servicers, and other providers transfers the work, never the obligation. An institution can command its own five layers completely and still fall short of its duty, because most of the AI it depends on runs inside firms it does not operate. Control that stops at your own walls stops short of your duty.
Which model touched which decision; where, physically and jurisdictionally, it executed; who could access it and on what terms; what a third party could audit. Demonstrable control answers all four. Policies, attestations, and contractual assurances cannot — and control you cannot demonstrate is control you do not have.
All engagements and discussions are conducted under confidentiality protections, including non-disclosure agreements where applicable. Control Tiers represent Institutional AI’s analytical interpretation of the depth, specificity, and visibility of publicly disclosed AI control information and are not assessments, audits, certifications, or determinations of any institution’s actual control environment, governance practices, or operational capabilities.
See the full Legal Notices section below.

Nature and Purpose
This report is published by Institutional AI, LLC (“Institutional AI,” “we,” “our,” or “us”) solely for informational and educational purposes. It does not constitute legal, regulatory, investment, fiduciary, accounting, tax, cybersecurity, technology, or other professional advice, and it does not create an attorney-client, advisory, fiduciary, or other professional relationship between Institutional AI and any reader. Readers should consult their own professional advisors regarding matters discussed in this report.
Unnamed Entries
The per-institution sections of this report describe reviewed institutions without naming them. Any identification a reader may make is the reader's own inference and is not made, confirmed, or endorsed by Institutional AI. Each entry states an analytical opinion regarding the completeness of a public disclosure record as of the review cutoff date, derived solely from publicly available sources under the methodology described herein. No entry constitutes a statement of fact about any institution's actual controls, capabilities, governance, or operations, and no entry should be read as an evaluation, rating, certification, or benchmark of any institution.
Sources and Scope of Review
The analyses, observations, and conclusions presented in this report are derived exclusively from publicly available information, including public filings, annual reports, earnings calls, investor presentations, press releases, speeches, interviews, conference materials, corporate websites, and other publicly disclosed materials available.
Our review is limited to interpreting publicly available information. We have not audited, inspected, tested, or independently verified any institution’s internal practices, systems, controls, or operations. Accordingly, we make no representation or warranty, express or implied, regarding the completeness, accuracy, currency, or fitness of any underlying information. Public disclosures may be incomplete, may change after the review cutoff date, and may not reflect an institution’s actual practices.
Opinions and Methodology
The findings, frameworks, classifications, matrices, observations, indices, tiers, maturity descriptions, and other analytical constructs presented in this report reflect Institutional AI’s opinions and interpretations based on the methodology described herein and the publicly available information reviewed.
These analytical constructs are intended solely to facilitate discussion, research, and analysis on matters of public interest. Reasonable institutions, regulators, investors, academics, practitioners, and other observers may reasonably reach different conclusions based on the same or additional information. Where this report assigns a tier or classification, that assignment reflects Institutional AI's professional judgment under the methodology described herein. Other reasonable reviewers applying the same methodology to the same public record may assign a different tier or classification.
AI Control Observations
The AI Control observations, matrices, tiers, and related assessments presented in this report are analytical opinions derived solely from publicly available information.
They do not constitute audits, examinations, certifications, regulatory findings, assurance engagements, or statements regarding any institution’s actual AI governance, cybersecurity, operational resilience, technology architecture, fiduciary practices, regulatory compliance, or internal control environment.
Institutions may possess capabilities, controls, governance mechanisms, or operational practices that are not publicly disclosed and therefore are not reflected in this report. Because these observations are opinions based on the specific public disclosures and methodology described herein, readers may examine the same public record and form their own conclusions, which may differ from ours.
Public Disclosure Limitations
The absence of public disclosure regarding a capability, safeguard, policy, process, or control should not be interpreted as evidence that it does not exist.
Similarly, a lower tier, lower assessment, or Not Disclosed classification reflects only Institutional AI’s interpretation of the extent of publicly available disclosure under the methodology described herein. It should not be interpreted as a conclusion that an institution’s actual controls, governance, or operational capabilities are inadequate, deficient, or inferior to those of any other institution.
Conversely, references to publicly disclosed practices should not be interpreted as endorsements, guarantees, or representations regarding their existence in practice or their effectiveness.
No Endorsement; Third-Party Marks
References to institutions, organizations, products, technologies, services, vendors, partnerships, or other third parties are made solely for descriptive, analytical, educational, or nominative purposes and do not imply endorsement, sponsorship, affiliation, approval, or any commercial relationship with Institutional AI.
All trademarks, trade names, service marks, company names, and logos remain the property of their respective owners.
No Rating or Assurance
This report is not a credit rating, investment rating, regulatory assessment, cybersecurity assessment, governance assessment, operational review, assurance engagement, or certification of any kind.
Nothing contained in this report expresses an opinion regarding the financial condition, safety and soundness, solvency, investment merit, fiduciary standards, operational effectiveness, regulatory standing, cybersecurity maturity, or overall risk profile of any institution.
Nothing in this report is intended to rank, score, benchmark, or compare one identified institution against another. Sector-level observations describe disclosure patterns within categories and should not be interpreted as comparative evaluations of individual institutions.
Forward-Looking Statements; No Reliance; Limitation of Liability
Any forward-looking statements, expectations, projections, scenarios, assumptions, or opinions regarding future developments are inherently uncertain.
Readers should not rely upon this report as the sole basis for any investment, governance, technology, cybersecurity, compliance, operational, strategic, or business decision.
To the fullest extent permitted by applicable law, Institutional AI, LLC and its members, managers, officers, directors, employees, contractors, advisors, and agents disclaim all liability for any direct, indirect, incidental, consequential, special, exemplary, or punitive damages arising from or relating to the use of, or reliance upon, this report.
Governing Law
These Important Notices shall be governed by and construed in accordance with the laws of the State of New Hampshire, without regard to conflict-of-law principles.
Any dispute arising from or relating to this report shall be subject to the exclusive jurisdiction of the state and federal courts located in New Hampshire.
If any provision of these Important Notices is determined to be unenforceable, the remaining provisions shall remain in full force and effect.
Headings are provided solely for convenience and do not affect interpretation.
Brief excerpts may be quoted with attribution to Institutional AI for the purpose of comment or review. All other reproduction or distribution requires prior written permission.
Requests for permission to reproduce or distribute this publication should be submitted at research@institutionalai.net
AI is a given. Control is not.™
© 2026 Institutional AI. All Rights Reserved.