All notes
AI Agents·June 18, 2026·6 min read

Running AI agents in regulated environments

Observability, deterministic guardrails and human escalation paths — the three things auditors actually ask for.

Layered panels with a shield and circuit lines representing AI governance

Banks and healthcare operators rarely object to autonomy in principle. They object to systems that cannot explain themselves after the fact.

We instrument every agent with a structured trace: inputs, retrieved context, tool calls, rejected actions, and the final decision. Traces are retained on the same schedule as the underlying records, so an investigation never depends on model vendors.

Timeline of agent decision traces with a branching escalation path
Every run leaves a structured trace, including rejected actions.

Guardrails stay deterministic. Policy checks run as code, not as prompt instructions, and an agent that cannot satisfy a check escalates rather than improvises.

Finally, every deployment defines its human escalation path up front — who is paged, within what window, and with what authority to halt the agent.

Subscribe to the briefing

New notes on AI agents, RWAs and immersive computing — monthly.