Summary
Every layer of enterprise AI is getting a control plane except one: the human layer. Agent platforms now govern an agent's identity, access, lifecycle, and trace. But as agents enter the workforce and work alongside people on the same decisions, governing the agent addresses only part of the problem: a shared decision needs a control plane on both sides. Fydelitics builds the human side — an AI decision-readiness platform for the people who direct, approve, and answer for AI-assisted decisions — because wherever a decision has consequences, regulated or not, it is a person, not the agent, who answers for it.
The evidence favors this position.
"A computer cannot be the last actor on an audit log"
VP, senior global financial crime specialist, Tier-1 bank, in KPMG's 2026 research[1]
Governance is moving "from static policy to continuous oversight"
Grant Thornton, 2026 AI Impact Survey[2]
The unit of governance is moving from the model to the decision. As machine-side controls mature across the industry — business context, trusted data, capable and observable agents — the gap that is emerging, and that grows with every new agent workflow, is the human at the decision. As agent-side controls mature, human readiness becomes the differentiator: the one part of the loop that can be measured, strengthened, and evidenced, and the one every other control ultimately relies on.
Fydelitics delivers the human-layer control plane in three products:
Together, the three form a Human Oversight Record for every AI-assisted decision, with the depth of the record scaled to the stakes.
1. Why the human layer matters now
The numbers above tell one story: intent is running ahead of control, and the people who deploy AI and the people who answer for it see different risks[2]. In financial services, loss of human oversight is already named as a key risk[5].
1.1 Regulators already name the human in the loop
AI now auto-populates 50–70% of suspicious-activity-report narratives and clears 80–90% of sanctions false positives in targeted bank use cases[1]. Across all of that volume, a regulator still requires one person to be the final actor on the disposition: however many decisions the AI touches first, the reviewer's decision is the one accountable act.
Washington's SB 5395, effective June 11, 2026, allows only a licensed physician or health professional to deny a prior-authorization request on medical necessity, bars sole reliance on AI, and requires the reviewer to evaluate the provider's recommendation and the enrollee's circumstances[7]. New state statutes converge on human review of denials, individualized grounds, disclosure, accuracy review, and auditability[6,12]. The gap between naming a reviewer and readying one is real: in litigation over one insurer's algorithmic denials, reviews were reported to have averaged 1.2 seconds per claim[17].
The AI Act asks overseers to stay aware of automation bias and deployers to assign oversight to people with the competence, training, and authority to exercise it[13]. Stand-alone high-risk obligations now apply from December 2, 2027, so the runway is longer, but the obligation is unchanged[14].
Naming a human is the first step; the value comes from how ready that human is. A review of 41 policies governing government algorithms found evidence suggesting that people are unable to perform the oversight the policies assume[16]. The strongest oversight record shows not only that a person approved, but that the person was ready to.
1.2 Trust needs to travel
We use trust portability to mean the ability of an oversight record (who reviewed, with what readiness, what they decided and why) to be produced consistently across every system in which an agent acted, and to be accepted by every party that must rely on it.
Most organizations are still building this capability: in Okta's 2026 survey, only 31% of CISOs felt fully aligned with the C-suite and board on acceptable AI risk, and agent access is often managed ad hoc[18]. One decision can now span a chat session, a partner's agent, a workflow approval, and a system of record, and one oversight record that follows it is what makes an open agent ecosystem trustworthy. The record must also travel up the organization chart: franchise systems, parents with independent subsidiaries, and partner networks each need one view of human readiness that respects the boundaries inside it.
2. The human control plane
Agent platforms across the industry are building a control plane for what agents do. Fydelitics builds the other half: a control plane for the human side of every AI-assisted decision those agents hand off.
2.1 What a control plane does
The human layer is the decision layer between AI capability and accountable action: the people who direct, approve, deny, and answer for AI-assisted work. It is not training, HR, or change management.
A control plane is the layer that decides how a system should behave and keeps the record of how it did, while the data plane does the work. Agent control planes capture five things, and the human layer needs the same five:
| Captures | In an agent control plane | In the human control plane |
|---|---|---|
| Inventory | Which agents exist, and who owns them | Who reviews, approves, and is accountable, by role and organization |
| Policy and permissions | What each agent may do | What each person may decide, and the readiness that decision calls for |
| Measurement | Traces, health, and performance | Readiness, engagement, and decision quality |
| Guidance | Guardrails and instructions applied at runtime | Coaching and decision support applied in the moment |
| Evidence | Logs and audit trails | A record of each decision, its rationale, and the guidance shown |
The purpose is to govern at scale, and three things make a control plane impactful: one standard measure across every team and organization, a closed loop from measurement to action to verification, and evidence produced as the work happens rather than assembled for an audit.
2.2 What would make it the most powerful
A control plane is only as strong as its data. The most powerful human control plane combines six kinds, each answering a different question:
| Data | Source | What it tells us | Party |
|---|---|---|---|
| Domain and regulatory knowledge | Standards, regulations, and guidance; curated and licensed sources | What good looks like in this domain, and what has changed | 1P3P |
| Domain-aware scenarios | Decision scenarios by role, industry, and decision type | How competent a person is in the context of the decisions they face | 1P2P |
| Role and organization context | Identity, roles, and organization structure | Who does what, and how organizations roll up | 2P |
| Workflow behavior | Escalate, approve, and deny events, timing, and rationale, drawn from a customer's own workflow, productivity, and agent-trace systems | Whether readiness shows up in real work | 2P |
| Point-of-decision capture | What a person did at the moment of review: whether they checked the AI output, and what they did with it | Whether the review was meaningful | 2P |
| Outcomes | Quality review and results, where the customer agrees to share them | Whether readiness predicts decision quality | 2P |
1P Fydelitics' own content and 3P curated and licensed external sources are ours to bring today. 2P enterprise operational data is the one kind we depend on customers and design partners to share under agreement.
Scenarios show what a person can do, workflow data what they do, and outcomes whether it worked. Together they make the score predictive, not just descriptive. We want every source of human-behavior data a customer or partner is willing to share, not just the most convenient one.
2.3 What Fydelitics brings
Fydelitics brings the first- and third-party knowledge from Section 2.2 and turns it into the score and the record. Second-party data, from customers and design partners, is what a data-sharing relationship adds. All of it is delivered in three products, and delivered prompt-first: every interaction runs as a metered call against our own AI infrastructure, with usage visible to the person and their organization.
Measures the competency of a person in the context of their AI workflows, grounded in domain-aware scenarios, and reports it as a single score — the Human Readiness Index (HRI). To our knowledge it is the only score of its kind, with bands that are easy to read and mean the same thing wherever they are used: a low band is clearly weak, a high band clearly strong, regardless of the tool or workflow. Readiness updates continuously as new decisions and outcomes come in, so it stays a live measure, not a point-in-time test.
It measures at three levels:
- Individual. Each person's score and band, by role and domain.
- Organization. Readiness across roles and functions, with the gaps that matter.
- Multi-organization. One view across franchise systems, parent companies with independent subsidiaries, and partner networks.
A score tells a person where they stand; Capability Builder helps them improve it, in the moment they have a question. Today employees leave the enterprise to ask a public chatbot, and the moment they do, the answer is generic, with no traceability or defensibility. Capability Builder is a conversational assessment and teaching experience inside the person's logged-in enterprise session, built for a modern AI-native workforce. It knows their score and place in the control plane, tells them when an answer is right or wrong, and explains regulations and scenarios grounded in their domain — the way a domain-specialized assistant for law or medicine would.
With access to enterprise operational data — logs and behavioral data from a customer's own systems — the system becomes agentic. It is triggered by an action (escalate, approve, deny), supports the person in that moment, and captures a traceable, defensible record of what happened. These two products need operational data to be designed, trained, and proven, and they complete the control plane across all three kinds of data above.
3. Where Fydelitics is going: vertical priorities
Fydelitics already publishes five verticals — Legal, Tax, Audit, HR/Talent, and Healthcare. Beyond those five, we rank expansion candidates on the locked priority list (POR), scored on two axes kept separate rather than blended into one score: Regulatory Pressure and Commercialization Speed.
Regulatory Pressure asks a narrow question of each candidate vertical: is there a rule that is binding (not just guidance), dated (a real forcing clock or standing exam obligation), and on-point (about AI decision-accountability specifically, not just "AI exists in this industry")? A vertical with no binding AI-specific rule rates Low regardless of harm severity or litigation heat. Commercialization Speed asks how fast a sale actually closes: a direct buyer with its own budget authority is Fast; a buyer reached mainly through a franchise/distribution network, or a contested competitive field, is Moderate; no forcing mechanism and/or an unbuilt buyer profile is Slow. Regulatory Pressure sets the tier; Commercialization Speed only breaks ties within it.
View the full vertical priority rankings →Where a vertical splits into an external "Track A" (a firm serving many clients) and an internal "Track B" (an enterprise's own function), Regulatory Pressure can differ by track; the table shows the range where it does — Banking and Healthcare's Track A is a third party accountable to the regulated entity by contract rather than directly examined, so each reads lower than its Track B. Watch List (researched, parked — no live authoritative AI-specific framework was found, so these aren't ranked): Pharma/Biotech, Government/Defense, Telemarketing/Telecom — AI Voice, Healthcare — Radiology, Technology/SaaS, Education, Aviation, VC/Investment Advisers, Accounting/Audit (non-tax).
Health is staged deliberately in two steps. A state human-review statute gives a design partner a live, dated deadline to build against immediately, with a shorter sales cycle than a federal engagement typically allows. CMS-0057-F and CMS's related Medicare Advantage AI guidance become the stronger, national-scale anchor once that state-level partner has produced evidence — a federal payer engagement is a longer sales cycle that expects proof before it moves, and the state-level phase is what supplies it.
4. Technical architecture
Fydelitics is AI-native, cloud-native, and multi-tenant. The platform runs on Microsoft Azure and its related identity and AI services — a factual description of the stack we're built on, independent of any specific go-to-market partnership.
| Layer | What it does | What it runs on |
|---|---|---|
| Identity and access | Authenticates users and organizations, and enforces role- and organization-scoped access to the readiness data and oversight records above | Microsoft Entra ID |
| Model inference | Generates guidance, scoring, and decision-navigator responses from first-, second-, and third-party knowledge, grounded and cited | Azure OpenAI / Azure AI Foundry |
| Application and data platform | Hosts the Readiness Control Plane, Capability Builder, and Decision Navigator services; stores scores, event metadata, and oversight records | Azure compute, storage, and managed data services |
| Trust boundary | Every interaction is prompt- and token-metered inside a customer's or Fydelitics' Azure trust boundary, so usage telemetry is visible and auditable | Azure tenancy and network isolation |
Guidance is generated from first-, third-, and second-party knowledge and cites its sources, and decision support is designed around actions rather than open-ended questions. Running prompt-first on Azure means every readiness check, coaching session, and decision-navigator interaction is a metered, auditable call — the same architecture choice that, independently, also makes every interaction attributable Azure consumption wherever a cloud go-to-market partnership is in place.
5. Principles
- Minimum data, inside the boundary. Scores and event metadata move; customer conversation content stays where the customer already governs it.
- Consent and purpose. Employees are told what is measured. Readiness is used for coaching, decision support, and routing recommendations, and never for hiring, firing, promotion, or pay.
- Portability. The record is independently verifiable and travels with the decision across agents, systems, organizations, and jurisdictions.
6. Conclusion
Agent platforms across the industry have built strong control planes for what agents do. The layer still missing, everywhere, is the one for the person who directs, approves, and answers for the decision the agent helped make. Fydelitics is building that layer: a Readiness Control Plane, a Capability Builder, and a Decision Navigator, delivered as a Human Oversight Record with depth scaled to the stakes — starting with the verticals where the regulatory clock is running fastest and the human cost of getting it wrong is highest, and built on infrastructure designed to be trustworthy, auditable, and portable from day one.
Appendix A. Definitions
- Human layer
- The people who direct, approve, deny, and answer for AI-assisted decisions — distinct from the agents and models that assist them.
- Control plane
- The layer that decides how a system should behave and keeps the record of how it did, while a separate data plane does the work.
- Readiness Control Plane
- Fydelitics' product that measures human competency in AI-assisted decisions and reports it as a single score with bands, at the individual, organization, and multi-organization level.
- Human Readiness Index (HRI)
- The single readiness score the Readiness Control Plane produces, with bands that mean the same thing across tools and workflows.
- Human Oversight Record
- The joined record of an agent's trace, a human's decision and rationale, and the human's readiness at the time of the decision.
- Multi-organization
- Franchise systems, parent companies with independent subsidiaries, and partner networks that need one readiness and risk view while their internal boundaries stay respected.
- First-, second-, and third-party data
- First-party: Fydelitics' own content. Third-party: curated and licensed external sources. Second-party: enterprise operational data shared by customers and design partners under agreement.
- Trust portability
- The ability of an oversight record to be produced consistently across systems and organizations and accepted by every party that must rely on it.
- Regulatory Pressure
- The Section 3 axis that sorts vertical priority: whether a rule governing a vertical is binding, dated, and on-point for AI decision-accountability specifically. A vertical with no binding AI-specific rule rates Low regardless of harm severity or litigation heat.
- Commercialization Speed
- The Section 3 axis that breaks ties within a Regulatory Pressure tier: how fast a sale actually closes, based on direct buyer budget authority, franchise/distribution reach, and how contested the field is.
Appendix B. Sources
- KPMG, "Mind the gaps: Scaling agentic AI in financial compliance," July 2026 (qualitative research with 20 U.S. compliance operations leaders, Q1–Q2 2026). https://kpmg.com/us/en/articles/2026/scaling-agentic-ai-in-financial-compliance.html
- Grant Thornton, 2026 AI Impact Survey. https://www.grantthornton.com/services/advisory-services/artificial-intelligence/2026-ai-impact-survey
- Gartner, "Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027," press release, June 25, 2025. https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027
- Cambridge Centre for Alternative Finance, 2026 Global AI in Financial Services Report, May 28, 2026. https://www.jbs.cam.ac.uk/faculty-research/centres/alternative-finance/publications/2026-global-ai-in-financial-services-report/
- KFF, "Regulation of AI in Prior Authorization and Claims Review: A Look at Federal and State Consumer Protections," May 6, 2026. https://www.kff.org/patient-consumer-protections/regulation-of-ai-in-prior-authorization-and-claims-review-a-look-at-federal-and-state-consumer-protections/
- Sheppard Mullin, "Additional States Continue Legislative Trend with New Laws Limiting Use of Artificial Intelligence in Health Insurance Determinations," July 2, 2026. https://www.sheppard.com/insights/blogs/additional-states-continue-legislative-trend-with-new-laws-limiting-use-of-artificial-intelligence-in-health-insurance-determinations
- Gartner, "Magic Quadrant for AI Governance Platforms," June 16, 2026 (abstract). https://www.gartner.com/en/documents/8006369
- Breaking News ABA, "Six States Restrict AI Claim Denials as ABA Audits Tighten," June 12, 2026 (summarizing KFF's May 2026 brief). https://breakingnewsaba.com/policy/six-states-restrict-ai-claim-denials-as-aba-audits-tighten
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 14 and 26. https://eur-lex.europa.eu/eli/reg/2024/1689/oj
- Cloud Security Alliance, "EU AI Act's High-Risk Deadline: Deferred, Not Cancelled," August 1, 2026 (on Regulation (EU) 2026/1744). https://labs.cloudsecurityalliance.org/research/csa-research-note-eu-ai-act-high-risk-deadline-omnibus-20260/
- NAIC model bulletin on the use of artificial intelligence systems by insurers, as adopted by state insurance regulators, 2024–2026 (see also source 6).
- Washington State Senate Bill 5395 (2025–26 session), effective June 11, 2026 (see also source 7).
- Ben Green, "The flaws of policies requiring human oversight of government algorithms," Computer Law & Security Review 45 (2022), 105681. https://doi.org/10.1016/j.clsr.2022.105681
- AI2Work, "AI Claims Denial Lawsuits Are Forcing Payers to Rethink Strategy," March 16, 2026. https://ai2.work/blog/ai-claims-denial-lawsuits-are-forcing-payers-to-rethink-strategy
- Okta, Global CISO Insights 2026 (survey of 306 security executives), July 29, 2026. https://www.okta.com/newsroom/articles/global-ciso-insights-2026/
- Federal Register, "Quality Control Standards for Automated Valuation Models," interagency final rule (Dodd-Frank §1125), effective October 1, 2025. https://www.federalregister.gov/documents/2024/08/07/2024-16197/quality-control-standards-for-automated-valuation-models
Survey results are as reported by the cited publishers.