GOVERNED AUTONOMY

Governed Autonomy I

Governed Autonomy I · Publication record

Errata and clarifications

Adrien Pesa

· Applies to version 1

This record accompanies Governed Autonomy: How Private Banks Can Industrialise AI Within Regulatory Boundaries, published on 25 March 2026. The entries below supersede the identified passages. Page references use the paper’s printed pagination.

The original version 1 PDF remains unchanged. These corrections concern the interpretation of the governance matrix and the description of an institutional archetype; they do not revise the proposed architecture.

Pages 24–25 · Exhibit 3 and accompanying interpretation

Mapped coverage and governance intensity

The claim that suitability, communication and audit trail carry the “broadest governance coverage” is not supported by Exhibit 3. Its populated columns number eight for transaction monitoring, nine for client risk profiling, eight for suitability analysis, nine for document generation, seven for client communication, and ten for agent routing / audit trail. These counts include the observed-practice column.

In the caption on page 24, replace the sentence beginning “Regulatory density increases” with:

The displayed mapping shows different combinations of governance sources across capabilities. Agent routing / audit trail intersects all ten displayed columns; suitability analysis and client communication do not have the broadest mapped coverage. The number of populated columns does not measure legal force, governance intensity or control effectiveness.

In the paragraph following the exhibit, replace the passage beginning “Regulatory density increases as AI capabilities move closer to customer outcomes” on page 24 and ending “the more governance instruments must constrain it” on page 25 with:

Different capabilities intersect different combinations of sources in this mapping. These intersections support the argument for instrument complementarity, but do not establish that governance coverage increases uniformly with proximity to customer outcomes.

The exhibit should be read as a selective mapping, alongside the provision-level discussion in Appendix A. A populated cell identifies a mapped source; it does not imply that every provision applies to every implementation. A dash identifies an unmapped relationship in the exhibit and should not be treated as a determination of legal inapplicability. Applicable obligations and expectations depend on the institution, activity and relevant provisions.

This clarification also supersedes the caption’s description of a dash. The matrix cells themselves are unchanged.

Page 31 · Compliance First archetype

Technology choice and supervisory acceptability

The phrases “ML where regulation demands it” and “stable and supervisory-safe” conflate an institution’s technology choice with its regulatory obligations and imply supervisory assurance. Replace the first two sentences of the Compliance First description on page 31 with:

The Compliance First archetype describes an institution that uses machine learning in compliance functions—transaction monitoring, name screening and sanctions filtering—and confines its AI adoption to those functions. Model adoption alone does not establish compliance or supervisory acceptability; these depend on the applicable requirements, control effectiveness and governance.

This clarification is consistent with the paper’s discussion on page 25. For related context on the use of AI in anti-money-laundering controls, see the Basel Committee on Banking Supervision, Digitalisation of finance (May 2024), Box 3, printed page 8.

Citation and record

Pesa, A. (2026). Errata and clarifications to Governed Autonomy I, version 1. Governed Autonomy. 7 September 2026. https://governed-autonomy.com/papers/governed-autonomy-i/errata/

7 September 2026 — Initial record: Exhibit 3 interpretation and Compliance First archetype.