Risk and Cost Governance for AI Agents in Regulated Institutions - with Shahir Daya of Zafin artwork

Risk and Cost Governance for AI Agents in Regulated Institutions - with Shahir Daya of Zafin

The AI in Business Podcast

July 29, 2026

As AI agents move from pilots into live financial workflows, most institutions still can't answer a basic question: who authorized this action, and what evidence backs it up?
Speakers: Daniel Faggella, Shahir Daya
**Daniel Faggella** (0:12)
Welcome, everyone, to the Emerge AI in Business Podcast. Today's guest is Shahir Zaya, Chief Product and Technology Officer at Zafin. Zafin is an AI platform company that provides governed agent orchestration and control capabilities for regulated institutions. Shahir discusses why regulated institutions need different levels of oversight for different AI agents, rather than applying one policy across the board, and how a centralized control layer can track what each agent is authorized to do, what it acted on, and what it cost. He explains what separates an agent that's ready for live production from one still running as a pilot, and why institutions that skip these controls early on face a much harder path adding them back in later. Today's episode is sponsored by Zafin. If you offer AI products or services into the enterprise, you need to find enterprise leaders with relevance. That means the right title at the right type of organization, and of course, readiness. Emerge attracts VP and higher ranking enterprise audiences who are already convinced that they need to move beyond traditional IT. To learn the exact strategies we use to help leading AI brands and startups connect with their ideal enterprise AI buyers, visit emerge.com.ad1. That's emerj.com.ad1.
Now the conversation with Shahir.
Zafin, welcome to the Emerge AI in Business Podcast.

**Shahir Daya** (1:59)
Thank you so much, Yolande. Thank you for having me.

**Daniel Faggella** (2:01)
Great conversation waiting for us, and I'm excited to pick your brain on something that I think needs more attention. It feels like everyone's racing to get agents to do the work, right? Approving things and moving money and touching records and doing all of these things. But this is happening before anyone's fully worked out who's going to be watching those agents once they're in it, once they're doing it. And that is going to be the big part of our conversation today is figuring out how that is supposed to work. So where are you seeing the biggest gap between how fast banks want to put AI agents into real workflows and how ready their governance is to handle all of that?

**Shahir Daya** (2:42)
So that's a really good starting question. Look, let's start with an analogy, because I think it will help frame the whole conversation around regulated organization, implementing agents, and risk, because there is some significant risk inflection points that are emerging. OK, and I think there's maybe three, maybe four risk inflection points that I see. But if you think more than a decade ago, right, cybersecurity was not a standing item on the agenda of board meetings. It is now, right? But it took high profile failures, very public high profile failures. It took significant pressures from the regulators, sustained pressure from the regulators. And the institutions that acted early were positioned much, much better than the ones that waited for a crisis to happen. And I think that decisioning governance, the ability for an institution, a bank, to explain the decisions it makes, is on the same kind of trajectory as cybersecurity. And to give you an example, two similar customers get a different offer, or a rate that was negotiated at the deal table doesn't match the actual rate that gets billed. Or a compliance officer asking to demonstrate pricing consistency has a lot of manual reconstruction of the decisions that were made. And these processes are not designed to be reconstructed. That's the baseline governance risk. Okay, this already exists at the banks. AI didn't really create it, but AI is accelerating it much faster than the governance frameworks we have today can actually respond. It's really amplifying it. And from where I sit, as someone who's responsible for product and technology at a organization that works with banks, and we have a product that's with the banks, I see four key risk inflection points that are very urgent right now. The first is distributed work. Every team is running agents. Engineering has coding agents. The operations guys have workflow agents. They have SRE agents. The legal has agents around documents and understanding documents. The customer service organization has service agents. Everyone is delivering agents. Now, these agents are really producing defensible productivity gains. I'm not saying that they aren't. They are producing real gains, but it's on their own turf.
So if you zoom out, and as we zoomed out, you're looking at a very different picture. You've got hundreds of these agents running across the enterprise using different models. They're coming from different providers. They're acting on different data. They're producing different kinds of output, and no single view of who authorized what, what actually got done, and what did it cost.
That's not a governance model, right? That ambient automation. And I'd argue we've seen this movie before, right? Digital channels moved faster than the operating models around them. Cloud adoption moved faster than the control frameworks around cloud. API is the same thing. So agentic AI is in the same place, except it's compressed because of how fast all of this is actually moving. And I think that the second reflection point is this governance gap. When you insert an agent in a workflow, see, we've all got these workflows, but they are human-centric workflows, and we're trying to insert agents into the workflows.

19 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000778919155