By Justin DiPietro, Co-Founder and Chief Strategy Officer, Glia
“Move fast or get left behind” and “slow down until it’s safe” are the dominant narratives on banking AI. Neither is a viable strategy.

Banks know they need to accelerate AI adoption. The value is already proven, from customer service and fraud detection to automating routine back-office work. But we’re also seeing theoretical AI disaster scenarios come to life, as generalist AI agents go rogue and cause serious damage in pursuit of a directive.
That’s why AI governance is a defining topic. The conversation has shifted from finding AI that’s capable (that vendor list gets bigger every day) to finding banking AI that’s controllable.
Here’s the problem: Everyone says they need AI governance. Few can explain what it actually looks like.
Vendor governance vs. operational AI governance
Most AI governance discussions focus on the architecture of the technology and performance of the model: Can the platform encrypt data? Does it meet regulatory requirements? How does it protect against prompt injection? Can it prevent hallucinations?
These are all vendor governance questions — and they’re critical. You need to know whether an AI platform is secure, reliable and compliant.
But the other half of the AI governance story is about how your institution actually uses the technology: where AI participates, what it has authority to do, how controlled vs. deterministic its outputs are, and where and how humans remain involved.
That’s operational AI governance.
4 key principles for effective operational AI governance
Operational AI governance is still a new frontier for most financial institutions. One way to make this new discipline less opaque is to frame some key principles that contrast common misconceptions with emerging best practices for effective operational AI governance.
- AI governance can’t be one-size-fits-all.
One of the most common mistakes banks make while setting up an operational AI governance model is defining rules in absolute terms: This type of data can never be accessed; this type of AI action can never be authorized; every customer interaction must receive the same level of control.
Trying to paint with such broad strokes inevitably ends with policies that are either overly permissive or overly restrictive.
Best practice is always to follow the principle of least privilege. Start with an inventory of your primary AI use cases and interaction/workflow scenarios. Define the risks of each.
For example, within customer service, the risk profile of a wire transfer is different from the risk of a customer calling for a branch address. Customer expectations, regulatory requirements and the consequences of an inaccurate answer are not the same. Operational AI strategy should be built around those case-specific risk profiles and your institution’s appetite.
- “Generative” and “deterministic” aren’t competing philosophies.
Debates on AI present a false binary: Either pick the “limitless” value of generative models and accept the risk, or opt for the control of deterministic models and accept limited variability.
Banking AI use cases don’t fall neatly along a fault line with “risky” on one side and “non-risky” on the other. Risk is variable, even within a specific use case like customer service.
Just as risk exists on a spectrum, AI behavior should, too. At one end, an institution may need an answer to match approved language exactly. In the middle, it may want the AI to rephrase approved information in a customer’s own language and context, without adding new information. At the other end, it may allow the AI to compose a more natural response using institution-approved policy documents and product information.
There’s tremendous value in calibrating the right mix of generative outputs and deterministic controls. That’s how you turn case-specific risk into operational AI strategy.
AI vendors need to offer this flexibility and make it intuitive to deploy. You shouldn’t need an in-house engineering team to calibrate AI response controls for different use cases.
- The conversation should never be “AI” vs. “humans.”
Another common narrative in AI debates is, “Which workflows can be handed off to AI — and which must be kept human?” That framing is too black-and-white.
Many of the most valuable banking AI use cases sit between these poles. AI can support human-driven workflows by giving employees immediate access to a wider knowledge base and helping them get to an answer faster. It can handle routine, low-risk interactions — and escalate exceptions or sensitive conversations to a person with relevant context preserved.
Likewise, human oversight can be built into more automated workflows, providing necessary checks on generative outputs so AI can be applied confidently in sensitive situations.
The good news is that we’re seeing leading banking AI platforms offer purpose-built workflows that deliver these additive AI-plus-human experiences.
- Simplify governance by simplifying your AI ecosystem.
The simplest principle may also be the most impactful: Fewer “AI brains” are easier to govern.
Today, most institutions have amassed an “AI stack” made up of multiple tools from vendors. That proliferation is a natural outcome in the early days of any new tech market. Point solutions emerge first, but the result is a fragmented environment where an institution must manage inconsistent policies, overlapping data access and a growing number of vendors.
Now is the time to step back, take stock of your AI stack and look for opportunities to streamline: Where can you consolidate AI workflows and use cases under one platform?
Banking AI value lives between the extremes
For years now, AI strategy has been framed as a dichotomy between innovation and control. Effective operational AI governance is the only path to achieving both.
Importantly, operational AI governance goes beyond the tools themselves. Security, reliability and compliance should be table stakes for any platform, but that doesn’t mean institutions can count on all tools delivering equally. The fundamental building blocks of operational AI governance vary meaningfully across providers and must be scrutinized when choosing a solution. Institutions should demand solutions that calibrate authority and control according to the risk profile and appetite of each individual use case, rather than forcing every interaction into the same model.
Because, as is so often the case, the real value lives in the messy middle.
About the author
Justin DiPietro is the co-founder and chief strategy officer at Glia. Glia’s Banking AI Platform is a central intelligence layer on top of existing tech stacks, activating an AI workforce of specialized agents that draw from banking data, interaction history, and integrated systems of record. These banking-trained agents automate workflows across voice and digital — from front office to back office — resulting in decreased operational costs and the Universal Banker model.


