MICKAI®ArticlesBanks outpace regulators on AI, a…
Article · 30 July 2026

Banks outpace regulators on AI, and the assurance gap must close

The fastest way to close the gap between AI adoption and AI assurance is to make every model action produce its own signed, verifiable evidence as it happens.

Author
Micky Irons
Published
30 July 2026
Follow Micky Irons
LinkedInX
sovereign-aifinancial-servicesai-governanceaudit-trailexplainability
Banks outpace regulators on AI, and the assurance gap must close

Financial institutions can close the gap between AI adoption and AI assurance by making every model action generate its own signed, verifiable evidence at the moment it happens, rather than reconstructing explanations after a supervisor comes asking. That is the practical lesson we draw from the 2026 Global AI in Financial Services Report, published by the Cambridge Centre for Alternative Finance on 28 April 2026 with the World Economic Forum and other partners, which found the industry rapidly outpacing its regulators on AI adoption while explainability and governance lag behind deployment.

The finding will not surprise anyone running a model risk function. New capability arrives every quarter, supervisory guidance arrives on a slower cycle, and the space between is filled by governance designed for a smaller, slower estate of models. The question the report leaves with every regulated firm is simple. If a supervisor asked tomorrow for the working behind a single AI-influenced decision, could the firm produce evidence, or only a policy document?

What did the Cambridge report find about AI in financial services?

The 2026 Global AI in Financial Services Report found that the financial industry is adopting AI significantly faster than regulators can keep pace with, and that explainability and governance are lagging behind deployment. The study was published on 28 April 2026 by the Cambridge Centre for Alternative Finance at Cambridge Judge Business School, produced with the World Economic Forum and other partners. Its central tension is familiar: competitive pressure rewards speed of deployment, regulatory obligation rewards depth of assurance, and most institutions are accumulating the first far faster than the second.

Why is a gap between AI adoption and AI assurance dangerous?

The gap is dangerous because it converts every deployed model into deferred regulatory liability. A system that is live but not explainable is working capital today and an enforcement exposure tomorrow. When guidance catches up, and in financial services it always does, firms discover the difference between having used AI responsibly and being able to prove that they did. Reconstructing a decision history after the fact is slow, expensive and often impossible, particularly where the model ran in a third party's cloud under a vendor's terms. Assurance that depends on someone else's records is not assurance, it is hope.

How does a sovereign operating system close the assurance gap?

It closes the gap by making evidence a property of the infrastructure rather than a task for the compliance team. Mickai is a Sovereign Intelligence Operating System, a SIOS, that runs entirely on the institution's own hardware, on premise and air-gapped where the risk profile demands it. Assurance is not bolted on after deployment; it is how the operating system executes work in the first place.

Three of its subsystems bear directly on the gap the Cambridge researchers describe.

  • The Open Audit Record (OAR) cryptographically signs every action the system takes, using post-quantum cryptography, so each query, response and approval becomes a tamper-evident entry that can be verified offline, without trusting us or any third party.
  • A cooperative multi-model consensus substrate requires specialist models to agree before any sensitive action runs, so a single model's error or hallucination cannot quietly become an executed decision.
  • Voice-biometric gating and a hardware-held root of trust bind sensitive approvals to a verified human on the institution's own machines, turning human-in-the-loop from a policy statement into an enforced control.

A regulator does not want to hear that your AI is probably fine. They want to see what it did, who approved it and how you know the record is intact. We built the operating system so that answer already exists before the question is asked.

Mickai

What does provable governance look like in practice?

In practice, provable governance means every material AI interaction leaves an artefact that a model risk team, an internal auditor or a supervisor can independently verify. When an analyst asks a question, the query, the models consulted, the consensus reached and the response returned are all signed into the record as they happen. When a sensitive action is proposed, the system requires agreement between specialist models before it runs, and a gated human approval before it takes effect. None of this depends on anyone remembering to log anything; the evidence is a side effect of doing the work.

Why does it matter where the AI runs?

It matters because assurance evidence held in someone else's cloud is only as available, and only as trustworthy, as that provider on the day it is needed. When a bank runs its intelligence layer on its own hardware, the decision history never leaves the perimeter, the audit record cannot be altered upstream, and the system keeps working fully offline regardless of any external dependency. Governance also becomes far simpler to describe to a supervisor: one estate, one signed record, one accountable owner, rather than a chain of processors each holding a fragment of the truth. Sovereign models running inside the building mean the data the models reason over never becomes someone else's asset.

What should financial institutions do while regulators catch up?

They should treat the interval before formal rules arrive as time to build the evidence base those rules will demand, because retrofitting auditability into a live estate is far harder than deploying on an auditable foundation. That thinking shaped how we structured the system itself: 87 studios on one operating system, of which ten are production-ready at launch and 77 are in development, so an institution can begin with a governed core and expand without ever changing its assurance model. The architecture beneath it is covered by 104 filed UK patent applications across 2,340 claims, though we would rather be judged on what the system can prove.

The Cambridge report describes a gap. Gaps close in one of two directions: regulators slow the industry down, or the industry raises its assurance to the level of its ambition. We think the second path is better for everyone, and we built an operating system to make it the easier one to take.

Frequently asked questions

What did the 2026 Global AI in Financial Services Report find?

It found the financial industry rapidly outpacing regulators on AI adoption, with explainability and governance lagging behind deployment. The report was published on 28 April 2026 by the Cambridge Centre for Alternative Finance with the World Economic Forum and other partners.

What is the AI assurance gap?

The AI assurance gap is the distance between what an institution's AI systems actually do and what the institution can prove about them. It grows whenever deployment moves faster than the evidence, controls and explanations that regulators and auditors will eventually require.

How does the Open Audit Record support explainability?

The Open Audit Record signs every AI action cryptographically at the moment it happens, using post-quantum cryptography, producing a tamper-evident history that can be verified offline. Explanations are then drawn from evidence of what actually occurred, rather than reconstructed later from memory or from a vendor's logs.

Can a bank run Mickai without any cloud connection?

Yes. Mickai runs entirely on the institution's own hardware and is designed for fully offline, air-gapped operation with a hardware-held root of trust. No data, prompts or telemetry leave the premises, and the audit record remains verifiable without any external service.

What is MICKAI?

MICKAI is a Sovereign Intelligence Operating System (SIOS) that runs on the customer's own hardware, on premise and air-gapped, using our own sovereign models. Every action is recorded in the Open Audit Record, a cryptographically signed, post-quantum secure, tamper-evident log that can be verified offline. It brings together 87 studios on one operating system, with ten production-ready at launch and 77 in development, and its architecture is covered by 104 filed UK patent applications across 2,340 claims, filed rather than granted.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/cambridge-ai-financial-services-adoption-gap. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles