Vision paper

The Human Layer

The control plane for the people who direct, approve, and answer for AI-assisted decisions
What Fydelitics is building, why it's needed now, which verticals we're prioritizing and why, and the technical architecture we're built on
Sharmilli Ghosh · Co-Founder & CEO
Avronil Bhattacharjee · Co-founder & CTO
Fydelitics.ai
September 2026

Summary

Every layer of enterprise AI is getting a control plane except one: the human layer. Agent platforms now govern an agent's identity, access, lifecycle, and trace. But as agents enter the workforce and work alongside people on the same decisions, governing the agent addresses only part of the problem: a shared decision needs a control plane on both sides. Fydelitics builds the human side — an AI decision-readiness platform for the people who direct, approve, and answer for AI-assisted decisions — because wherever a decision has consequences, regulated or not, it is a person, not the agent, who answers for it.

The evidence favors this position.

"A computer cannot be the last actor on an audit log"

VP, senior global financial crime specialist, Tier-1 bank, in KPMG's 2026 research[1]

Governance is moving "from static policy to continuous oversight"

Grant Thornton, 2026 AI Impact Survey[2]
The case in numbers
>40%
of agentic AI projects will be canceled by the end of 2027, citing escalating costs, unclear value, or inadequate risk controls[3]
17% vs 60%+
of organizations have deployed agents today, against the share expecting to within two years[4]
54% vs 20%
of COOs, against CIOs and CTOs, are concerned about regulatory and compliance uncertainty from agentic AI[2]
55% and 51%
of financial-industry respondents and of AI vendors name loss of human oversight as a key risk[5]
25+ states
have issued insurer AI guidance built on the NAIC model bulletin, and Washington's human-review law for prior-authorization denials took effect June 11, 2026[6,7]
13
vendors in Gartner's first-ever Magic Quadrant for AI governance platforms (June 2026), a defined market for governing AI use cases, applications, and agents — that treats human review as a nested workflow feature, not yet a category of its own[8]

The unit of governance is moving from the model to the decision. As machine-side controls mature across the industry — business context, trusted data, capable and observable agents — the gap that is emerging, and that grows with every new agent workflow, is the human at the decision. As agent-side controls mature, human readiness becomes the differentiator: the one part of the loop that can be measured, strengthened, and evidenced, and the one every other control ultimately relies on.

Fydelitics delivers the human-layer control plane in three products:

Readiness Control Plane
Measures human competency in the context of AI workflows, for the individual, the organization, and groups of organizations, as one score with bands.
Think of it as a credit score for working with AI: bands that mean the same thing everywhere.
Capability Builder
A coaching conversation inside the enterprise's security, grounded in the person's domain.
Think of it as a personal coach who has already read your score and knows your field.
Decision Navigator and Decision IQ
Act when someone escalates, approves, or denies, and capture a traceable, defensible record.
Think of it as a co-pilot with a flight recorder: it helps at the moment of decision and records what happened.

Together, the three form a Human Oversight Record for every AI-assisted decision, with the depth of the record scaled to the stakes.

1. Why the human layer matters now

The numbers above tell one story: intent is running ahead of control, and the people who deploy AI and the people who answer for it see different risks[2]. In financial services, loss of human oversight is already named as a key risk[5].

1.1 Regulators already name the human in the loop

Banking

AI now auto-populates 50–70% of suspicious-activity-report narratives and clears 80–90% of sanctions false positives in targeted bank use cases[1]. Across all of that volume, a regulator still requires one person to be the final actor on the disposition: however many decisions the AI touches first, the reviewer's decision is the one accountable act.

Health insurance

Washington's SB 5395, effective June 11, 2026, allows only a licensed physician or health professional to deny a prior-authorization request on medical necessity, bars sole reliance on AI, and requires the reviewer to evaluate the provider's recommendation and the enrollee's circumstances[7]. New state statutes converge on human review of denials, individualized grounds, disclosure, accuracy review, and auditability[6,12]. The gap between naming a reviewer and readying one is real: in litigation over one insurer's algorithmic denials, reviews were reported to have averaged 1.2 seconds per claim[17].

European Union

The AI Act asks overseers to stay aware of automation bias and deployers to assign oversight to people with the competence, training, and authority to exercise it[13]. Stand-alone high-risk obligations now apply from December 2, 2027, so the runway is longer, but the obligation is unchanged[14].

Naming a human is the first step; the value comes from how ready that human is. A review of 41 policies governing government algorithms found evidence suggesting that people are unable to perform the oversight the policies assume[16]. The strongest oversight record shows not only that a person approved, but that the person was ready to.

1.2 Trust needs to travel

We use trust portability to mean the ability of an oversight record (who reviewed, with what readiness, what they decided and why) to be produced consistently across every system in which an agent acted, and to be accepted by every party that must rely on it.

Most organizations are still building this capability: in Okta's 2026 survey, only 31% of CISOs felt fully aligned with the C-suite and board on acceptable AI risk, and agent access is often managed ad hoc[18]. One decision can now span a chat session, a partner's agent, a workflow approval, and a system of record, and one oversight record that follows it is what makes an open agent ecosystem trustworthy. The record must also travel up the organization chart: franchise systems, parents with independent subsidiaries, and partner networks each need one view of human readiness that respects the boundaries inside it.

2. The human control plane

Agent platforms across the industry are building a control plane for what agents do. Fydelitics builds the other half: a control plane for the human side of every AI-assisted decision those agents hand off.

2.1 What a control plane does

The human layer is the decision layer between AI capability and accountable action: the people who direct, approve, deny, and answer for AI-assisted work. It is not training, HR, or change management.

A control plane is the layer that decides how a system should behave and keeps the record of how it did, while the data plane does the work. Agent control planes capture five things, and the human layer needs the same five:

CapturesIn an agent control planeIn the human control plane
InventoryWhich agents exist, and who owns themWho reviews, approves, and is accountable, by role and organization
Policy and permissionsWhat each agent may doWhat each person may decide, and the readiness that decision calls for
MeasurementTraces, health, and performanceReadiness, engagement, and decision quality
GuidanceGuardrails and instructions applied at runtimeCoaching and decision support applied in the moment
EvidenceLogs and audit trailsA record of each decision, its rationale, and the guidance shown

The purpose is to govern at scale, and three things make a control plane impactful: one standard measure across every team and organization, a closed loop from measurement to action to verification, and evidence produced as the work happens rather than assembled for an audit.

2.2 What would make it the most powerful

A control plane is only as strong as its data. The most powerful human control plane combines six kinds, each answering a different question:

DataSourceWhat it tells usParty
Domain and regulatory knowledgeStandards, regulations, and guidance; curated and licensed sourcesWhat good looks like in this domain, and what has changed1P3P
Domain-aware scenariosDecision scenarios by role, industry, and decision typeHow competent a person is in the context of the decisions they face1P2P
Role and organization contextIdentity, roles, and organization structureWho does what, and how organizations roll up2P
Workflow behaviorEscalate, approve, and deny events, timing, and rationale, drawn from a customer's own workflow, productivity, and agent-trace systemsWhether readiness shows up in real work2P
Point-of-decision captureWhat a person did at the moment of review: whether they checked the AI output, and what they did with itWhether the review was meaningful2P
OutcomesQuality review and results, where the customer agrees to share themWhether readiness predicts decision quality2P

1P Fydelitics' own content and 3P curated and licensed external sources are ours to bring today. 2P enterprise operational data is the one kind we depend on customers and design partners to share under agreement.

Scenarios show what a person can do, workflow data what they do, and outcomes whether it worked. Together they make the score predictive, not just descriptive. We want every source of human-behavior data a customer or partner is willing to share, not just the most convenient one.

2.3 What Fydelitics brings

Fydelitics brings the first- and third-party knowledge from Section 2.2 and turns it into the score and the record. Second-party data, from customers and design partners, is what a data-sharing relationship adds. All of it is delivered in three products, and delivered prompt-first: every interaction runs as a metered call against our own AI infrastructure, with usage visible to the person and their organization.

Readiness Control Plane

Measures the competency of a person in the context of their AI workflows, grounded in domain-aware scenarios, and reports it as a single score — the Human Readiness Index (HRI). To our knowledge it is the only score of its kind, with bands that are easy to read and mean the same thing wherever they are used: a low band is clearly weak, a high band clearly strong, regardless of the tool or workflow. Readiness updates continuously as new decisions and outcomes come in, so it stays a live measure, not a point-in-time test.

It measures at three levels:

  • Individual. Each person's score and band, by role and domain.
  • Organization. Readiness across roles and functions, with the gaps that matter.
  • Multi-organization. One view across franchise systems, parent companies with independent subsidiaries, and partner networks.
Draws on 1P3P; adds 2P as data-sharing relationships grow
Capability Builder

A score tells a person where they stand; Capability Builder helps them improve it, in the moment they have a question. Today employees leave the enterprise to ask a public chatbot, and the moment they do, the answer is generic, with no traceability or defensibility. Capability Builder is a conversational assessment and teaching experience inside the person's logged-in enterprise session, built for a modern AI-native workforce. It knows their score and place in the control plane, tells them when an answer is right or wrong, and explains regulations and scenarios grounded in their domain — the way a domain-specialized assistant for law or medicine would.

Draws on 1P3P
Decision Navigator and Decision IQ

With access to enterprise operational data — logs and behavioral data from a customer's own systems — the system becomes agentic. It is triggered by an action (escalate, approve, deny), supports the person in that moment, and captures a traceable, defensible record of what happened. These two products need operational data to be designed, trained, and proven, and they complete the control plane across all three kinds of data above.

Draws on 1P3P2P

3. Where Fydelitics is going: vertical priorities

Fydelitics already publishes five verticals — Legal, Tax, Audit, HR/Talent, and Healthcare. Beyond those five, we rank expansion candidates on the locked priority list (POR), scored on two axes kept separate rather than blended into one score: Regulatory Pressure and Commercialization Speed.

Regulatory Pressure asks a narrow question of each candidate vertical: is there a rule that is binding (not just guidance), dated (a real forcing clock or standing exam obligation), and on-point (about AI decision-accountability specifically, not just "AI exists in this industry")? A vertical with no binding AI-specific rule rates Low regardless of harm severity or litigation heat. Commercialization Speed asks how fast a sale actually closes: a direct buyer with its own budget authority is Fast; a buyer reached mainly through a franchise/distribution network, or a contested competitive field, is Moderate; no forcing mechanism and/or an unbuilt buyer profile is Slow. Regulatory Pressure sets the tier; Commercialization Speed only breaks ties within it.

View the full vertical priority rankings →

Where a vertical splits into an external "Track A" (a firm serving many clients) and an internal "Track B" (an enterprise's own function), Regulatory Pressure can differ by track; the table shows the range where it does — Banking and Healthcare's Track A is a third party accountable to the regulated entity by contract rather than directly examined, so each reads lower than its Track B. Watch List (researched, parked — no live authoritative AI-specific framework was found, so these aren't ranked): Pharma/Biotech, Government/Defense, Telemarketing/Telecom — AI Voice, Healthcare — Radiology, Technology/SaaS, Education, Aviation, VC/Investment Advisers, Accounting/Audit (non-tax).

Health is staged deliberately in two steps. A state human-review statute gives a design partner a live, dated deadline to build against immediately, with a shorter sales cycle than a federal engagement typically allows. CMS-0057-F and CMS's related Medicare Advantage AI guidance become the stronger, national-scale anchor once that state-level partner has produced evidence — a federal payer engagement is a longer sales cycle that expects proof before it moves, and the state-level phase is what supplies it.

4. Technical architecture

Fydelitics is AI-native, cloud-native, and multi-tenant. The platform runs on Microsoft Azure and its related identity and AI services — a factual description of the stack we're built on, independent of any specific go-to-market partnership.

LayerWhat it doesWhat it runs on
Identity and accessAuthenticates users and organizations, and enforces role- and organization-scoped access to the readiness data and oversight records aboveMicrosoft Entra ID
Model inferenceGenerates guidance, scoring, and decision-navigator responses from first-, second-, and third-party knowledge, grounded and citedAzure OpenAI / Azure AI Foundry
Application and data platformHosts the Readiness Control Plane, Capability Builder, and Decision Navigator services; stores scores, event metadata, and oversight recordsAzure compute, storage, and managed data services
Trust boundaryEvery interaction is prompt- and token-metered inside a customer's or Fydelitics' Azure trust boundary, so usage telemetry is visible and auditableAzure tenancy and network isolation

Guidance is generated from first-, third-, and second-party knowledge and cites its sources, and decision support is designed around actions rather than open-ended questions. Running prompt-first on Azure means every readiness check, coaching session, and decision-navigator interaction is a metered, auditable call — the same architecture choice that, independently, also makes every interaction attributable Azure consumption wherever a cloud go-to-market partnership is in place.

5. Principles

6. Conclusion

Agent platforms across the industry have built strong control planes for what agents do. The layer still missing, everywhere, is the one for the person who directs, approves, and answers for the decision the agent helped make. Fydelitics is building that layer: a Readiness Control Plane, a Capability Builder, and a Decision Navigator, delivered as a Human Oversight Record with depth scaled to the stakes — starting with the verticals where the regulatory clock is running fastest and the human cost of getting it wrong is highest, and built on infrastructure designed to be trustworthy, auditable, and portable from day one.

Appendix A. Definitions

Human layer
The people who direct, approve, deny, and answer for AI-assisted decisions — distinct from the agents and models that assist them.
Control plane
The layer that decides how a system should behave and keeps the record of how it did, while a separate data plane does the work.
Readiness Control Plane
Fydelitics' product that measures human competency in AI-assisted decisions and reports it as a single score with bands, at the individual, organization, and multi-organization level.
Human Readiness Index (HRI)
The single readiness score the Readiness Control Plane produces, with bands that mean the same thing across tools and workflows.
Human Oversight Record
The joined record of an agent's trace, a human's decision and rationale, and the human's readiness at the time of the decision.
Multi-organization
Franchise systems, parent companies with independent subsidiaries, and partner networks that need one readiness and risk view while their internal boundaries stay respected.
First-, second-, and third-party data
First-party: Fydelitics' own content. Third-party: curated and licensed external sources. Second-party: enterprise operational data shared by customers and design partners under agreement.
Trust portability
The ability of an oversight record to be produced consistently across systems and organizations and accepted by every party that must rely on it.
Regulatory Pressure
The Section 3 axis that sorts vertical priority: whether a rule governing a vertical is binding, dated, and on-point for AI decision-accountability specifically. A vertical with no binding AI-specific rule rates Low regardless of harm severity or litigation heat.
Commercialization Speed
The Section 3 axis that breaks ties within a Regulatory Pressure tier: how fast a sale actually closes, based on direct buyer budget authority, franchise/distribution reach, and how contested the field is.

Appendix B. Sources

  1. KPMG, "Mind the gaps: Scaling agentic AI in financial compliance," July 2026 (qualitative research with 20 U.S. compliance operations leaders, Q1–Q2 2026). https://kpmg.com/us/en/articles/2026/scaling-agentic-ai-in-financial-compliance.html
  2. Grant Thornton, 2026 AI Impact Survey. https://www.grantthornton.com/services/advisory-services/artificial-intelligence/2026-ai-impact-survey
  3. Gartner, "Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027," press release, June 25, 2025. https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027
  4. Cambridge Centre for Alternative Finance, 2026 Global AI in Financial Services Report, May 28, 2026. https://www.jbs.cam.ac.uk/faculty-research/centres/alternative-finance/publications/2026-global-ai-in-financial-services-report/
  5. KFF, "Regulation of AI in Prior Authorization and Claims Review: A Look at Federal and State Consumer Protections," May 6, 2026. https://www.kff.org/patient-consumer-protections/regulation-of-ai-in-prior-authorization-and-claims-review-a-look-at-federal-and-state-consumer-protections/
  6. Sheppard Mullin, "Additional States Continue Legislative Trend with New Laws Limiting Use of Artificial Intelligence in Health Insurance Determinations," July 2, 2026. https://www.sheppard.com/insights/blogs/additional-states-continue-legislative-trend-with-new-laws-limiting-use-of-artificial-intelligence-in-health-insurance-determinations
  7. Gartner, "Magic Quadrant for AI Governance Platforms," June 16, 2026 (abstract). https://www.gartner.com/en/documents/8006369
  8. Breaking News ABA, "Six States Restrict AI Claim Denials as ABA Audits Tighten," June 12, 2026 (summarizing KFF's May 2026 brief). https://breakingnewsaba.com/policy/six-states-restrict-ai-claim-denials-as-aba-audits-tighten
  9. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 14 and 26. https://eur-lex.europa.eu/eli/reg/2024/1689/oj
  10. Cloud Security Alliance, "EU AI Act's High-Risk Deadline: Deferred, Not Cancelled," August 1, 2026 (on Regulation (EU) 2026/1744). https://labs.cloudsecurityalliance.org/research/csa-research-note-eu-ai-act-high-risk-deadline-omnibus-20260/
  11. NAIC model bulletin on the use of artificial intelligence systems by insurers, as adopted by state insurance regulators, 2024–2026 (see also source 6).
  12. Washington State Senate Bill 5395 (2025–26 session), effective June 11, 2026 (see also source 7).
  13. Ben Green, "The flaws of policies requiring human oversight of government algorithms," Computer Law & Security Review 45 (2022), 105681. https://doi.org/10.1016/j.clsr.2022.105681
  14. AI2Work, "AI Claims Denial Lawsuits Are Forcing Payers to Rethink Strategy," March 16, 2026. https://ai2.work/blog/ai-claims-denial-lawsuits-are-forcing-payers-to-rethink-strategy
  15. Okta, Global CISO Insights 2026 (survey of 306 security executives), July 29, 2026. https://www.okta.com/newsroom/articles/global-ciso-insights-2026/
  16. Federal Register, "Quality Control Standards for Automated Valuation Models," interagency final rule (Dodd-Frank §1125), effective October 1, 2025. https://www.federalregister.gov/documents/2024/08/07/2024-16197/quality-control-standards-for-automated-valuation-models

Survey results are as reported by the cited publishers.