Skip to main content
Guide

Owning the AI Operating Model: Security, Control, and Choice

Resiliq enterprise AI security architecture showing tenant isolation, sandboxed execution, and data boundaries

Owning the AI Operating Model: Security, Control, and Choice

Institutional buyers are often shown an AI feature list when they need an operating model. The practical questions are different. Which data can the system access? Who can launch work? Which tools can an agent use? What may leave the environment? What requires approval? What evidence remains after a failure?

Owning the operating model means turning those questions into enforceable policy. A broad promise of enterprise readiness is not enough, and a model choice menu does not by itself provide control.

The need is already visible in financial services. A 2024 Bank of England and Financial Conduct Authority survey of 118 firms found that 75% were using AI and one third of reported use cases relied on third-party implementations. Yet 46% of respondents described their understanding of the AI they used as partial, compared with 34% reporting complete understanding.[4] Adoption can therefore outrun operational understanding unless ownership, authority, and review are designed into each workflow.

Enterprise AI Data Governance: Access Control, Tenant Isolation, and Egress Boundaries

NIST's Zero Trust Architecture shifts security away from implicit trust based on network location and toward users, assets, and resources.[1]Applied to AI, access decisions should account for identity, organisation, purpose, and the resource being used. Access should also be reviewed as context changes.

In supported protected workflows, Resiliq applies identity and workspace controls that separate shared from personal resources. These restrictions are enforced by product security controls rather than model instructions.

NIST SP 800-53 organizes security controls around access control, information flow enforcement, least privilege, audit, monitoring, incident response, and boundary protection.[2] The operating implication is straightforward. Public research, internal investment material, personal data, and confidential deal documents do not belong in one authority envelope. Classification should determine eligible workflows, retrieval sources, model destinations, external connections, retention, and reviewer requirements.

A useful design starts with the most sensitive data a workflow can receive, including data reached through connected services. It then grants the minimum capabilities needed for that purpose. The combined workflow matters because connected components can introduce an access path that no individual component exposes alone.

For supported diligence workflows, Resiliq applies controls that keep confidential diligence separated from external research channels.

When external research is allowed, the workflow should minimise or anonymise the information that crosses the boundary. The system should preserve an audit record of the delegation without placing confidential content in public requests or operational logs.

ISO/IEC 42001 frames AI governance as a management system that organisations establish, implement, maintain, and continually improve.[5] That approach moves governance beyond a one-off risk assessment. In practice, the organisation needs a current inventory of AI use cases, named owners, approved data and tool boundaries, change controls, evaluation evidence, incident procedures, and periodic review. The controls must follow the workflow as models, data sources, and delegated services change.

Agent Execution Boundaries: Permission Scopes and Risk Controls

The NIST AI Risk Management Framework calls for documented roles, intended context, human oversight, controls for third parties, monitoring, and incident handling across the AI lifecycle.[3]A buyer should therefore be able to inspect a workflow's effective authority before use:

  • who can launch, approve, cancel, retry, and review it;
  • which data classes, projects, tools, models, and external services it can reach;
  • resource, retry, and concurrency limits;
  • cancellation, timeout, partial result, retention, and failure behaviour;
  • the evidence, warnings, decisions, and audit events retained.

Supported Resiliq tasks apply configured bounds for duration, compute use, retries, and cancellation, ensuring high-impact actions require human review.

Material outputs should preserve source context, methodology provenance, assumptions, warnings, state transitions, and reviewer decisions. Operational records should support incident reconstruction while excluding secrets and raw confidential content. Resiliq applies content minimisation and redaction to operational logging.

Research on internal algorithmic auditing reaches a similar conclusion. Raji and co-authors propose an end-to-end audit framework in which each lifecycle stage produces documentation that supports later review and accountability.[6] For an investment workflow, that record should connect the original mandate, source material, model and tool versions, assumptions, policy decisions, human approvals, and final deliverable. A polished answer without that chain is difficult to challenge and harder to reproduce.

The Four-Tier Enterprise AI Security & Isolation Boundary

Institutional financial firms maintain strict security and compliance controls. A production-ready AI operating model enforces defense-in-depth across four isolated architectural tiers:

  • Tier 1: Row-Level Tenant Isolation: Every database query and vector search is hard-partitioned by tenant ID at the database engine level, guaranteeing zero cross-customer data leakage.
  • Tier 2: Sandboxed gVisor Execution: AI agent code interpreters and quantitative models execute within dedicated, kernel-isolated gVisor sandboxes with strict CPU, memory, and runtime bounds.
  • Tier 3: Zero-Egress Confidential Boundary: Confidential deal room data and internal workbooks are strictly air-gapped from public network egress; external research tools run through isolated, anonymised proxies.
  • Tier 4: Human-in-the-Loop Authority Gates: Workflow runs are pinned to immutable revisions. High-impact operations—such as memo exports, model overrides, or team handoffs—require explicit human sign-off.

Evaluating AI Infrastructure: Vendor Independence and Deployment Flexibility

Choice is not a row of cloud and model provider logos. It is the ability to decide which workflows may use which data, where review is mandatory, whether external research is disabled, which results are retained, and who can change those settings. A choice is real only when the product enforces it and the audit record shows which policy applied.

Buyers should separate four states: implemented control, customer configuration, contractual commitment, and roadmap. Each needs different evidence. A live control can be exercised during diligence. A configuration should identify who may change it and leave an audit event. A contractual commitment belongs in signed terms. A roadmap item has no present control value. Certifications, deployment options, residency, key custody, model selection, and data use terms should be assessed on that basis rather than grouped under an "enterprise" label.

Choose one workflow with material consequences and ask the vendor to walk it from identity to failure. Inspect data classification, access, external connections, approval, limits, cancellation, retention, and incident evidence. Then change one policy condition and confirm that the control changes the outcome, not merely the explanation.

Consider a diligence workflow preparing material for an investment committee. The analyst should see which workspace and documents are in scope before launch. Confidential material should remain unavailable to external research tools. Quantitative outputs should retain their inputs, assumptions, and model version. A senior reviewer should approve any consequential export or action. If the task times out or retries, the same authority and data rules should still apply. This is what operational ownership looks like: policy expressed through system behaviour, with enough evidence for a reviewer to reconstruct the result.

Map one live workflow in Resiliq and see what changes when identity, data boundaries, authority, and human review become part of the operating model.

References

  1. NIST SP 800-207, Zero Trust Architecture, 2020
  2. NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations
  3. NIST, Artificial Intelligence Risk Management Framework 1.0, AI RMF Core
  4. Bank of England and Financial Conduct Authority, Artificial intelligence in UK financial services, 2024
  5. ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system
  6. Raji et al., Closing the AI Accountability Gap: Defining an End-to-End Framework for Internal Algorithmic Auditing, ACM FAccT, 2020
Owning the AI Operating Model: Security, Control, and Choice | Resiliq