Langlotz.AI
Operating model

The Model Was the Easy Part

· 860 words

Most AI in banks never reaches production. It impresses a steering committee, wins a budget line, and then quietly dies as a pilot. If you carry the AI mandate in a regulated institution, you already know the graveyard. I want to walk through one agent that made it out, inside the compliance function of a global systemically important bank, under the regulator's eye, and what actually got it across the line. The short version: the model was the easy part, even though we were using new technology. Everything that decided whether it shipped was human.

The problem was not noise, it was late risk

Start with the problem, because it is not the one people assume. Compliance surveillance generates far more alerts than any team can clear. In this kind of triage, false positive rates of 80 to 99 percent are normal, so skilled people spend their days confirming that alerts are nothing. That is the visible cost. The dangerous cost is quieter. When analysts are buried under noise, a genuine issue, a true positive, surfaces late. In surveillance, late is the failure that matters. The old control was a four eyes review, two people looking at the same thing to catch what one might miss. Thorough, and slow, and still a race against the backlog.

What we actually built

We did not point a clever model at the problem and hope. We codified the standard operating procedure first, the exact steps a good analyst already followed, and then had an AI agent execute that procedure.

The agent fetched the source information, and the fetch was grounded, so there was no hallucination where it would have mattered. It used the model only to understand meaning, which is what let it cope when a source changed shape. It compared what it found against the alert, and it kept a full record of every step. The human then reviewed the agent's audit trail rather than repeating the research by hand. The four eyes became human and machine: the machine did the legwork and produced alerts and drafts, the person judged and decided.

Notice what the model was doing. Not deciding. Interpreting, under a procedure, with its work written down. That distinction is the whole game.

Why it reached production

Here is the moment it went from experiment to sanctioned. Model risk management assessed the model and rated it low risk. Not because we argued for leniency, but because of how it was built: a human stayed the decision maker, the retrieval was grounded so it could not invent a source, and every step was auditable. Low risk was not luck. It was a design target we engineered toward from the first week.

And we engineered toward it together. Compliance, model risk, the data provider team, and technology were all in the room from day one. Governance was designed together, not sought as an approval at the end. Every function that could have blocked the thing had helped build it instead. This is the part most teams skip, and it is why most pilots never ship. They build in isolation and then present to the control functions as a finished object to be judged. We built with them, so there was nothing left to litigate.

The barrier was mundane, and human

The hardest part was not the AI. It was access. The agent needed paid data sources and external pages, and access to them was blocked. No model solves that. What solved it was going to the source provider directly, showing them the end to end solution, and explaining why it mattered. A relationship and a clear reason, not a technical fix. That is usually where production actually stalls, in the plumbing and the permissions, not in the model.

Who owned it

Roles were clear. The business owned and sponsored the work, so it was never an AI team pushing something no one in the business had asked for. The AI team owned the model and shared responsibility for the build. Above that sat the thing no architecture gives you: support from the top and buy in from middle management for the change itself. An AI agent alters how people work, and the people whose work it changes have to want it, or it dies on contact with the floor.

The lesson for anyone carrying the mandate

If you are a C level leader whose AI keeps stalling before production, the instinct is to look for a better model. That is almost never the constraint. We used new technology and the model was still the easy part.

Getting AI into production in a regulated institution is a trust achievement, not a technical one. You earn it by engineering for a low risk rating: codify the procedure, keep the human deciding, ground the system so it cannot invent, and make everything auditable. You earn it by designing governance with every control function from day one, not seeking their blessing at the end. And you earn it with sponsorship from the top and buy in from the middle, because the technology changes how people work and only people can carry that.

Governance is not the thing that slows AI down. Built in from the start, it is the only thing that gets AI to production at all. The model was the easy part. The trust was the work.