Close Cookie Notice

Welcome to the MIT CISR website!

This site uses cookies. Review our Privacy Statement.

Red briefing graphic
Research Briefing

Establishing Guardrails on the AI Roller Coaster

Discover four domains where guardrails can enable organizations to implement AI faster and more safely while managing risks, complexity, and costs.
Abstract

A surge of energy, investment, and optimism is driving organizations to adopt artificial intelligence (AI). However, these efforts carry risks, including wasted resources from redundant investments and added operational complexity and costs. Like a roller coaster, AI initiatives require carefully designed safeguards to move fast but avoid calamity. As these initiatives proliferate throughout the organization, implementing unique controls for every AI application becomes unsustainable. Drawing on interviews, this briefing identifies four domains where guardrails matter most for managing AI and effective controls, illustrated by a case vignette about fintech Tunic Pay.

Access More Research!

Any visitor to the website can read many MIT CISR Research Briefings in the webpage. But site users who have signed up on the site and are logged in can download all available briefings, plus get access to additional content. Even more content is available to members of MIT CISR member organizations.

A surge of energy, investment, and optimism is driving organizations to adopt artificial intelligence (AI). However, these efforts carry risks, including wasted resources from redundant investments and added operational complexity and costs. Like a roller coaster, AI initiatives require carefully designed safeguards to move fast but avoid calamity. As these initiatives proliferate throughout the organization, implementing unique controls for every AI application becomes unsustainable. Leaders should instead establish consistent organizational controls where they can have the greatest impact. Where can controls enable speed without sacrificing safety?

Drawing on interviews,[foot]Between May 2024 and August 2026, we interviewed 48 leaders from 28 organizations in APAC, Europe, and the US about barriers to AI value creation. We categorized responses about how to manage AI effectively into four domains: architecture compliance, innovation management, workforce enablement, and supplier governance. From those, we extracted essential controls (key policies or processes) respondents identified for effective oversight and intervention. [/foot] this briefing[foot]The authors thank Stephanie Woerner and Cheryl Miller of MIT CISR for their assistance in shaping and refining the briefing text.[/foot] identifies four domains where guardrails matter most for managing AI and effective controls, illustrated by a case vignette about Tunic Pay.[foot]The Tunic Pay vignette draws on July and August 2026 interviews with the UK fintech’s chief executive officer and chief operating officer and public sources. [/foot]

Four Domains to Govern for Faster, Safer AI

Our research identified four domains where organizations must retain visibility, oversight, and the ability to intervene to keep control: architecture compliance, innovation management, workforce enablement, and supplier governance.

Architecture Compliance

A well-designed AI architecture enables the organization’s business units to apply AI faster and with less risk. One example of an AI architecture partitions data, AI models, and AI agents into separate but integrated governance-embedded platforms operating on cloud infrastructure (see figure 1).

In this AI architecture, the data platform makes finding and accessing structured and unstructured data fast and secure. Increasingly, organizations are applying a semantic layer[foot]See a description of a semantic layer in H. Lefebvre, B. H. Wixom, C. Legner, and N. van der Meulen, “The Case for a Semantic Layer,” MIT CISR Research Briefing, Vol. XXVI, No. 5, May 2026, https://cisr.mit.edu/publication/2026_0501_SemanticLayer_LefebvreWixomLegnerVandermeulenBeath.[/foot] across the data, maintaining context for AI and humans about data products and their relationships with other data, along with acceptable usage, access methods, and security roles.

The AI platform establishes a place for the organization to deploy, evaluate, and monitor AI models. It provides consistent model testing, version and performance tracking, and identification of dependencies on specific models and suppliers.

The agentic platform manages a shared library of AI agents along with orchestration and workflows that decompose tasks and coordinate execution across multiple steps and agents. It provides a unified location to log each agent call and action, verify what each agent can access, and route escalations for human review and decisions. This type of platform is less mature than data and AI platforms, but its governance capabilities are advancing rapidly.

Figure 1: An Emerging AI Architecture

This example AI architecture separates data, AI models, and AI agents into independent governance-embedded platforms operating on cloud infrastructure. Adapted from Asif Gill, Architecting Human-Centric AI Systems: Augmented Intelligence (World Scientific Publishing, forthcoming), https://doi.org/10.1142/14870.

Maintaining distinct platforms enables business units to develop and deploy AI use cases faster because it promotes reuse of existing capabilities. Importantly, it also clarifies where to implement oversight and auditing, making compliance faster and simpler.

Innovation Management

AI is enabling all parts of the organization to ideate and prototype rapidly. The pace and level of decentralization are straining conventional innovation management processes, with business units choosing which initiatives to pursue, how many resources to dedicate, and what risks to take. However, this jeopardizes organizational value because so much distributed activity can produce duplication and AI initiatives that never add value or scale.

Our research identified two controls that organizations are focusing on to accelerate their efforts while managing risk. The first is early triage, which assigns each initiative to either a centrally managed organizational portfolio or a business unit’s portfolio. Triage is fast because it involves only one decision: which portfolio should manage the initiative.

The second is disciplined selection of ideas. Portfolio managers are adding criteria—including data readiness, integration complexity, production performance, inference costs, observability, and explainability—to AI business case evaluation to filter out concepts that demo well but will never scale across the organization.

Workforce Enablement

Organizations are recruiting AI talent, but new hires alone won’t close skills gaps. Executives we interviewed described challenges accessing engineers and central AI and data teams and the needs to reskill the workforce and design roles for AI-augmented work.

Pressure to move quickly is driving business unit leaders to take control of workforce enablement and the resources that support it. For example, one bank brought product, operations, and technology, including nearly six hundred engineers, under a business leader accountable for outcomes. Decentralizing development like this gives business units end-to-end accountability for AI applications and helps engineers develop domain expertise—but introduces risks such as unsupportable applications and siloed data.

Our research identified three workforce controls that should remain with central functions. First, central technology teams should own the process of moving AI applications into production. While controlling access, approvals, security, and integration, these teams can also verify compliance and spot duplicated operating costs. Second, AI centers of excellence, which concentrate specialist capabilities, should define standards, tools, and architecture and provide secure sandboxes for rapid prototyping. Finally, although business units should take responsibility for their own recruiting and reskilling, human resources teams should provide consistency by establishing common hiring practices, career levels, training, and structures for AI-related skills and roles.

Supplier Governance

AI’s rapid evolution is pushing organizations to rely more on partners and suppliers for their advanced technology and expertise. Each new frontier model brings new capabilities, but it also introduces new risks. In addition, AI pricing structures are changing, and usage-based charges make costs difficult to predict.

We identified controls in AI governance forums, procurement teams, and financial operations (FinOps[foot]FinOps is a cross-functional practice that maximizes the business value of technology through data-driven decisions and shared financial accountability. See “What is FinOps?” FinOps Foundation, updated March 2026, accessed September 4, 2026, https://www.finops.org/introduction/what-is-finops/. [/foot]). AI governance forums set guidelines for AI use and partnerships, and approve specific third-party suppliers and product versions. The forums increasingly extend risk monitoring to fourth- and fifth-party suppliers, despite the added complexity and cost. To keep pace with changing AI risk profiles, they are replacing one-time supplier approvals with continual, expedited supplier risk reviews and timely decision-making.

Procurement teams are strengthening contract terms to address AI risks, secure audit rights, and protect against price increases. These teams increasingly involve architects and FinOps specialists in contract review to assess technical fit and financial exposure. But contracts cannot address capabilities that do not yet exist. Each frontier model release brings new capabilities and new risks, so each organization must keep judging for itself whether the added capability is worth the added risk and update its guardrails accordingly.

Finally, FinOps reviews help track AI costs and provide frequent, detailed reporting that improves responsiveness, financial management, and business case reliability.

Controls in Practice with Tunic Pay

Tunic Pay, a fintech, helps global banks protect customers from fraud, which evolves quickly as criminals try to evade traditional detection. Before payment transfers, Tunic Pay’s real-time AI system flags potential scams for payers and the bank’s human fraud investigators. Each bank oversees its use of Tunic Pay’s AI solution within its transaction flow, establishing controls across the four domains.

Architecture Compliance

Banks work with Tunic Pay to strengthen their AI architecture controls in three areas: the data they collect and manage, AI models’ behavior, and AI agents’ actions.

Data: Traditional fraud scoring systems rely on a bank’s knowledge of its customer and their prior transactions—but with scams, any given bank only ever sees half the equation: either the victim or the perpetrator. Typically, banks ask customers a static set of questions to confirm that they trust who they are paying and are not being pressured into an urgent payment as part of a scam. With Tunic Pay, banks can ask a dynamic set of questions based on Tunic Pay’s analysis of potential scam typologies, gathering additional data on the counterparty, such as a screenshot of a payment request. How far that interaction goes and how autonomously it is served to customers depend on each bank’s risk appetite. Tunic Pay can then analyze responses and compare them to external data sources such as business registries and fraud databases, as well as its database of scam and fraud patterns across banks.

AI models: Tunic Pay’s AI models use the data they collect to score transaction risk. Rather than using large language models (LLMs) in the scoring process, Tunic Pay uses narrower, task-specific predictive models for scoring, because banking regulations require that models are explainable and predictable, and LLMs are ​still hard to explain and ​prone to hallucinating in edge cases. Banks must be able to explain any payment misclassification and identify the rule or evidence behind it. While LLMs are very effective at reading the unstructured evidence and synthesizing findings, banks prefer to limit their scope in risk decisions.

AI agents: If the model flags a transaction as potentially fraudulent, Tunic Pay uses LLMs to assemble a warning from the specific counterparty facts surfaced during the investigation. The agent serves the customer this tailored warning to encourage them to reconsider the payment; scammers coach customers to expect and ignore generic warnings. Alternatively, the bank can slow the transaction and pass the analysis to its internal investigators. Banks are deliberately very careful of the usage of AI in the ultimate payment approval decision to maintain clear auditability.

Innovation Management

Banks’ business unit teams work directly with Tunic Pay to reimagine their transaction flow. The initiative typically sits within the business unit’s portfolio, selected against key AI business case criteria—improving customer experience, increasing operational efficiency, and reducing fraud losses—always maintaining explainability and predictability.

Workforce Enablement

Business unit teams introduce Tunic Pay, and the fraud and financial crime teams identify the use case, reimagine the customer journey with Tunic Pay, and build the business case. Central teams own the path into production, from procurement and assessing supplier risk to maintaining security and data protection and managing model risk—an intensive process that takes significant time. Bank staff build AI literacy and skills as they supervise Tunic Pay’s AI-assisted decisions; Tunic Pay’s transaction assessments are made in parallel with a bank’s own, augmenting staff judgment rather than replacing it.

Supplier Governance

Each bank’s AI governance framework sets the scope and boundaries for AI use, specifies model versions, requires demonstrated model predictability, highlights fourth- and fifth-party risks, and maintains strict change management. Tunic Pay operates within these obligations. 

Three Moves to Get on Track

AI use is spreading rapidly throughout your organization and gaining speed whether your guardrails are ready or not. Leaders can start with three moves. First, examine the four domains that emerged from our interviews and assess the controls discussed. Second, develop practices around each control you identify. You do not need to deploy all controls on day one: implement the ones that gate your biggest current risks. And third, measure progress and correct course when necessary.

© 2026 MIT Center for Information Systems Research, Thorogood, Reynolds, and Gill. MIT CISR Research Briefings are published monthly to update the center’s member organizations on current research projects.

About the Researchers

Profile picture for user preynold@mit.edu

Peter Reynolds, Industry Research Fellow, MIT CISR

Profile picture for user asif.gill@uts.edu.au

Asif Gill, Professor and Researcher, School of Computer Science, University of Technology Sydney and Research Collaborator, MIT CISR

MIT CENTER FOR INFORMATION SYSTEMS RESEARCH (CISR)

Founded in 1974 and grounded in MIT's tradition of combining academic knowledge and practical purpose, MIT CISR helps executives meet the challenge of leading increasingly digital and data-driven organizations. We work directly with digital leaders, executives, and boards to develop our insights. Our research is funded by member organizations that support our work and participate in our consortium. 

MIT CISR Patrons
AlixPartners
Avanade
Cognizant
Collibra
IFS
PwC
MIT CISR Sponsors
ABN Group
Alcon Vision
ANZ Banking Group (Australia)
AustralianSuper
Banco Bradesco S.A. (Brazil)
Barclays (UK)
BNP Paribas (France)
Bupa
CalSTRS
Caterpillar, Inc.
Cemex (Mexico)
Cencora
CIBC (Canada)
Commonwealth Superannuation Corp. (Australia)
Cuscal Limited (Australia)
DBS Bank Ltd. (Singapore)
Ericsson (Sweden)
Fidelity Investments
Fomento Economico Mexicano, S.A.B., de C.V.
Genentech
HCF (Australia)
Hunter Water (Australia)
International Motors
JERA Co., Inc. (Japan)
JPMorgan Chase
Keurig Dr Pepper
Mallesons (Australia)
Mater Private Hospital (Ireland)
National Australia Bank Ltd.
Nomura Holdings, Inc. (Japan)
Nomura Research Institute, Ltd. Systems Consulting Division (Japan)
Novo Nordisk A/S (Denmark)
OCP Group
Pentagon Federal Credit Union
Principal Life Insurance Company
Ralliant
Reserve Bank of Australia
RTX
Saint-Gobain
Scentre Group Limited (Australia)
Schneider Electric Industries SAS (France)
Telstra Limited (Australia)
Terumo Corporation (Japan)
Vanguard
WestRock Company
Xenco Medical
Find Us
Center for Information Systems Research
Massachusetts Institute of Technology
Sloan School of Management
One Main Street, E90-9th Floor
Cambridge, MA 02142
617-253-2348