As financial services firms race to harness artificial intelligence, security, compliance, legal, and IT teams face a delicate balancing act: enabling high-value AI capabilities while effectively managing exposure to risk.
In a recent session of Theta Lake’s Financial Services AI Governance Series, Theta Lake Chief Product Officer Dan Nadir discussed how organizations can navigate this shift. Drawing on nearly 25 years of product management experience delivering technology to major financial institutions, he shared insights on the rapid evolution of AI and practical steps for effective governance.
A Paradigm Shift Driven by Speed and ROI
Past technological shifts like the rise of social media and the move to cloud computing unfolded over years, giving organizations time to adapt. The current AI wave is different. According to Dan, what sets this moment apart is its velocity and the strength of its perceived return on investment.
Just a few years ago, many financial institutions actively prohibited AI usage. Today, tools that draft client communications, synthesize research, and generate summaries have created a business case too compelling to ignore with enormous pressure to deploy as fast as possible and as broadly as possible.
“The AI horse isn’t just out of the barn, it’s galloped a mile down the road, and the security, compliance, legal, governance teams, they’re all racing to catch up.”
— Dan Nadir, Chief Product Officer, Theta Lake
Historically, projects that potentially increased risk or required excessive oversight faced pressure to slow down or remain in the pilot stage. Now the pressure runs in the opposite direction, forcing risk and governance teams to rapidly build frameworks that can keep pace with the technology they’re trying to govern.
Who Owns AI Governance?
AI governance is not purely an IT or security issue; it touches security, compliance, legal, and unified communications teams simultaneously. That shared ownership is precisely what makes it complex. Defining who is responsible has become one of the more pressing organizational questions firms are still working through.
The answer, in practice, is that all of these teams share responsibility across the same set of challenges, including flagging privacy risks, conducting risk-indicator analytics, linking outbound communications with AI-generated responses, and managing retention intelligently. Comprehensive AI oversight demands that security, compliance, legal, and unified communications teams move beyond their traditional lanes and govern AI together.
The Need for Context: Uncovering Insider Risks
When security teams attempt to triage and investigate potential AI communication violations, a central challenge is the absence of context. Evaluating risk rarely comes down to a single prompt; it requires viewing and understanding the history of interactions over time. For example, a prompt like “Same as before, but make sure it can’t be traced back to me” is alarming in isolation but its true meaning hinges entirely on prior exchanges, demanding broader situational awareness to assess user intent and past activity. Combining guardrail alerts with historical communication data yields a complete picture of a user’s risk-related behavior. That picture becomes fully actionable when investigators can search, query, and reconstruct activity across all communication channels in a single, unified workflow.
Standard guardrail tools are designed to prevent immediate security breaches or block specific keywords, but they often miss suspicious interaction patterns, gradual behavioral shifts, or emerging insider threats.
Overcoming Rollout Blockers: Case Study Insight
The inability to retain and supervise AI can bring major enterprise projects to a standstill. Nadir shared an example of a client unable to roll out AI summary features due to uncertainty around legal & regulatory compliance.
The issue escalated when the firm’s legal team determined that AI summaries, once deployed, would be subject to legal hold obligations. Without a mechanism to collect, retain, and place flagged content on legal hold, the deployment stalled despite heavy internal demand. Implementing a unified governance solution enabled the firm to meet its legal requirements and unblock the rollout.
Next Steps for IT and Security Leaders
For organizations hesitant to deploy AI due to governance concerns, Nadir recommends a straightforward approach:
- Focus on Capture First: Begin by collecting and retaining AI interaction data using internal proxies, guardrail tools or dedicated governance platforms like Theta Lake. Keep in mind that in a large enterprise, much of this content is likely already inadvertently captured via other tools on the network.
- Centralize Data Visibility: Bring proxy data and AI interaction logs into a central repository alongside existing communication channels.
- Analyze and Adjust: You cannot manage what you do not measure. Once the data is captured, analyze usage patterns to refine risk policies, establish targeted workflows, and determine the maximum retention periods your organization actually needs.
To learn more about how Theta Lake helps financial institutions bridge the gap between AI adoption and compliant AI governance, visit Theta Lake.
For more expert insights and live demo examples, watch this full session on-demand.
Copyright © 2026 RegTech Analyst
Copyright © 2018 RegTech Analyst


