Short answer. An AI governance operating model in a bank is the standing structure that decides which AI systems can go live, who is accountable for each one, and how each is monitored after launch. Build it around four parts: a live inventory of every AI use case, a risk classification that flags high-risk uses, control gates a system must pass before production, and named owners inside a three lines of defense structure. Ableneo shipped 34 production AI projects in 2025 and roughly 4 of 5 reached production, and the ones that ship decide this structure before the build starts, not after an audit finds it missing.
A governance policy and a governance operating model are not the same thing. A policy is a document that states intent. An operating model is the machinery that runs every day: it names who approves a use case, what evidence a system produces, and which committee reviews it when something drifts. Banks that treat governance as a PDF get stuck at the pilot stage, because nobody owns the decision to move a system into production.
An operating model that works has four moving parts:
Ableneo shipped 34 production AI projects across 4 countries in 2025, and 94% of them use large language models. That delivery rate, roughly 4 of 5 to production, comes from deciding the gates and owners up front. When the inventory and classification exist on day one, a use case moves through review in weeks instead of stalling in a committee that has no mandate to say yes.
The regulatory clock is real, and it recently changed. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and deferred the obligations for standalone high-risk AI systems under Annex III from August 2026 to 2 December 2027. AI embedded in regulated products under Annex I moves to 2 August 2028. The transparency obligations in Article 50, telling a customer they are dealing with a machine and labelling AI-generated content, still apply from 2 August 2026. A deferral is not a pause. It is more time to build the operating model the same rules will still demand.
DORA has applied to financial entities since 17 January 2025 and already requires banks to manage the resilience, testing, and third-party risk of the systems that support critical functions, AI included. The European Central Bank named risks from banks’ use of AI a supervisory priority for 2026 to 2028. Under the EU AI Act, accountability sits with the deployer as well as the provider, so a bank cannot outsource responsibility to a vendor. The operating model is how a bank holds that accountability in a form a supervisor can inspect.
An AI governance operating model rests on four parts: a live inventory, a risk classification, control gates, and named owners across three lines of defense.
Five components carry the model. The inventory is the foundation: a register of every AI system, its purpose, its owner, and its risk tier, kept current rather than compiled once for an audit. Risk classification maps each system to the EU AI Act tiers and the bank’s own impact scale, which decides how much control each one carries. Control gates turn policy into checkpoints a system passes before launch: data quality, a documented risk management process in the shape of Article 9, human oversight designed in line with Article 14, and logging under Article 12. A quality management system, the Article 17 requirement, holds the written procedures that make those gates repeatable. Ownership assigns each control to a named role so no gate is everyone’s job and therefore no one’s.
An AI governance committee is small and senior enough to say yes or no. In a bank it usually pairs a business sponsor, the Chief Risk Officer or a delegate, the Chief Data Officer, compliance, information security, and the model risk function. It decides three things: whether a proposed use case is allowed at all, what risk tier and controls apply, and whether a system that has drifted stays live or is pulled. The committee does not build models. It owns the go and no-go decision and the evidence trail behind it. Meeting monthly with a standing agenda beats an ad hoc group that convenes only when a project is already late, because the second version has no time to challenge anything.
The deferral changed the deadline, not the direction. Standalone high-risk obligations now apply from 2 December 2027 rather than August 2026, which gives a bank more time to build the inventory, classification, and gates. It does not remove the DORA duties that already apply, the Article 50 transparency rules that apply from August 2026, or the ECB’s supervisory attention on AI through 2028. Banks that read the deferral as permission to wait will build the same operating model later under more pressure and with more systems already live and ungoverned. The banks that use the extra time build the model against real use cases now, so the December 2027 date arrives as a checkpoint rather than a scramble.
Do not stand up a parallel structure. Most banks already run model risk management and a DORA operational resilience framework, and AI governance extends both rather than replacing them. Route AI systems through the existing model inventory and validation process, with added checks for the behaviours that classical models do not have, such as prompt injection, data leakage, and output drift. Map AI systems that support critical functions into the DORA register and testing programme. The result is one governance spine with AI-specific controls attached, which a supervisor can follow, instead of two frameworks that disagree about who owns a system.
Start with the inventory. A bank cannot govern what it cannot see, and the first surprise in almost every programme is how many AI use cases already run outside central view. Build the register, classify each use case by risk, then define the control gates for the highest tier and the roles that own them. That sequence produces a working model in weeks and gives the governance committee something concrete to decide on. A bank that starts with a 40-page policy and no inventory has a document. A bank that starts with the inventory has control.
Ableneo builds the governance structure at the same time as the AI system, not after it. Across 34 production projects in 2025 in regulated Central European financial services, the operating model, the inventory, the risk classification, the control gates, and the named owners, is what moved roughly 4 of 5 projects into production and kept them auditable once live. Ableneo’s AI transformation work designs governance a bank’s own risk, compliance, and audit functions can run, aligned to the EU AI Act and DORA, so the model holds up under supervision rather than sitting in a binder.
Key takeaways
Planning AI in a regulated business? Ableneo takes systems from classification to governed production.