What financial services firms should demand from an AI control plane

AI agents are already in production at financial services firms, and many are touching customer data and regulated records before any governance policy exists to control them. Our new AI Control Plane Buyer’s Guide for Financial Services distills a year of work with FSI customers into a practical framework for closing that gap.

Here’s what you’ll learn in this post:

  • Why ungoverned MCP deployments are a regulatory problem, not just a technical one
  • The five problems an AI control plane must solve before agents scale to production
  • How to sequence a vendor evaluation based on your firm’s most pressing concern

The governance gap is already open

At the firms we work with, teams and individual developers stand up MCP servers because no rule says they can’t. One insurance conglomerate with 146 subsidiaries found MCP deployments spreading across business units with no policy in place. A cybersecurity firm with roughly 8,000 employees discovered distributed teams building agents independently, with almost no cross-team visibility.

The technical debt compounds quickly, and in financial services it compounds into regulatory exposure. When a data warehouse logs an agent’s tool call against a shared service account instead of the analyst who triggered it, your audit trail is broken. The FCA, SEC, and PRA are watching how firms govern AI systems that touch regulated processes, and the senior leaders accountable for failures can be personally exposed.

Every week of delay means more shadow integrations embed themselves in developer workflows, and more patterns harden in ways that are expensive to retrofit. The buyer’s guide opens with a candid look at what this sprawl looks like on the ground today.

Five problems a control plane must solve

Before you evaluate any vendor, be explicit about the problem surface. The guide identifies five categories that consistently separate governed production deployments from experiments:

  1. Identity and audit passthrough. Downstream systems must see the actual user or agent that triggered a tool call, not a shared service principal. This is the hardest technical problem and the one with the highest regulatory stakes.
  2. Policy enforcement at scale. Governing fifty servers across multiple legal entities requires declarative, version-controlled policies that take effect at runtime, without redeployment.
  3. Discoverability without shadow IT. If the official path is painful, developers route around it. A curated registry must be frictionless enough to be the default.
  4. Observability that feeds your existing stack. Audit logs and telemetry need to flow into your SIEM in formats that satisfy regulatory inspection.
  5. Deployment flexibility. Multi-cloud Kubernetes, on-premises infrastructure, and air-gapped environments are the norm in financial services. A platform that only works in one model creates governance gaps in the others.

A capability checklist you can put in front of vendors

The core of the guide is a six-section capability checklist covering identity and audit, governance and policy, runtime security, observability, developer experience, and commercial considerations. Each row explains why the capability matters and exactly what to require, down to the specifics: OAuth token exchange (RFC 8693) for identity passthrough, SPIFFE/SPIRE workload identity for non-human agents, per-server container isolation, and OpenTelemetry-native traces that export to the observability backend you already run.

The checklist also flags where the bar separates enterprise platforms from lightweight alternatives. Runtime policy changes without redeployment and virtual MCP server composition are two capabilities most lighter-weight tools can’t deliver, and both matter once your server count grows past a handful.

Rather than reproduce all six sections here, download the full guide and bring it to your next vendor conversation.

Sequence your evaluation around your biggest concern

Not every capability carries equal weight for every firm. The guide maps five starting points to the capabilities that matter most for each:

  • If regulatory and audit readiness worries you most, start with per-user identity passthrough and SIEM-ready log export. Nothing else matters if you can’t demonstrate an attributable audit trail.
  • If you need security team buy-in, start with authentication, client-side enforcement hooks, and supply chain security. Give security teams what they need to say yes instead of blocking.
  • If developer adoption is the risk, start with the self-service portal and automatic IDE configuration. The governed path must also be the easy path.
  • If you’re scaling an existing footprint, start with the Kubernetes operator, multi-tenancy, and context optimization.
  • If you answer to the board on AI ROI, start with usage telemetry and per-team attribution. You can’t prove return on something you can’t measure.

The guide closes with a frank assessment of the current market, including where lightweight gateways, developer-tooling platforms, and cloud provider offerings fall short of financial services requirements.

Get the guide, then see it live

Read the full AI Control Plane Buyer’s Guide for Financial Services for the complete capability checklist and evaluation framework. Want to see what Stacklok can do for your organization? Book a demo or join the conversation and engage directly with our team on Discord.

July 27, 2026

Insights

Scott Buchanan

CMO

Scott Buchanan is the Chief Marketing Officer at Stacklok. Scott leads the company's first-party research efforts that define benchmarks for AI agent and MCP adoption. He's also an example of how a non-developer can lean into MCP and agentic workflows to increase productivity.

More by Scott Buchanan