Fractional AI Governance

Leadership for AI programs that need to be built, scaled, or defended.

Bidun Group is a fractional AI Governance advisory practice for registered investment advisers, community banks, credit unions and fintechs in regulated financial services. As AI moves from chatbots to agents that take actions on their own, the governance has to move with it. Operator-grade, built to hand off cleanly, for a fraction of the cost of a full-time hire.

The gap most organizations can't fill

Boards, regulators, auditors, customers, and insurers now expect a defensible AI governance and risk program. Most organizations face a gap they can't easily close:

In-house buildout is slow

Standing up the function takes 12+ months and senior talent the market is short on.

Big 4 hands you a binder

Expensive, project-bounded engagements leave you with a document, not a running program.

Doing nothing isn't defensible

The expectation is here now, across NIST, ISO 42001, the EU AI Act, and financial-services supervision, plus the April 2026 revised model-risk guidance (SR 26-2).

A fractional executive who has actually built and run an AI governance function inside a regulated firm closes that gap, with a clear path to in-house ownership.

Engagement models

Five ways to engage, scoped to where you are. Click any engagement for detail.

Entry point · Fixed fee

Framework License + Tailoring

License my maintained, versioned framework and get a firm-specific instance, tailored to your firm. The fastest way to a defensible program.

Starts at $17,500, credited against a later buildout.

See details →
Ongoing oversight

Fractional AI Governance Committee Chair

Chair your AI Governance Council and provide executive-level oversight, roughly 2-3 days a month.

See details →
Build & run

Fractional Head of AI Governance

Stand up and operate the function, 8-12 days a month, with an explicit transition to your permanent hire.

See details →
Fixed-fee sprint

90-Day Program Buildout

A defensible AI governance program (charter, policy, registry, risk process, board reporting) delivered in twelve weeks.

See details →
As scoped

Targeted Advisory

Policy review, regulator and audit readiness, M&A AI-risk diligence, and board briefings.

See details →

Frameworks & regulatory fluency

Engagements map to the standards and supervisory expectations the framework cites.

NIST AI RMFFS AI RMF (CRI/FSSCC)ISO/IEC 42001ISO/IEC 42005EU AI Act SR 26-2 / OCC 2026-13 (revised model risk guidance, April 2026)FFIEC IT HandbookNCUASEC / FINRA GDPRCCPASOC 2NIST CSF 2.0OWASP Agentic Top 10NIST AI Agent Standards InitiativeColorado SB 26-189

These external standards are implemented by a maintained, versioned AI governance framework of my own, kept current as the rules move, so your program stays defensible instead of drifting out of date.

Bidun Group runs its own program under this framework, with a dated record kept since 29 August 2026.

One example of the same rules applied to myself: my framework made me take my weekly incident radar off its unattended schedule, because a run with no one watching is an agent, and agents get registered, reviewed and owned. I run it by hand now, and the stop is in my record with a date on it.

Framework list maintained under Bidun Group's regulatory monitoring protocol, which runs weekly. Last reviewed .

Insights

Where I put my thinking on the record.

On the record

Comments I have filed with regulators and standard-setters, on the public record under my own name.

Filed 28 August 2026

Comment on Colorado’s proposed ADMT rules

My comment to the Colorado Attorney General’s rulemaking on automated decision-making technology, on why coverage should follow the decision, not the architecture, and what that means for a small regulated financial firm.

Filed 15 and 19 July 2026

Comment to the Financial Stability Board on the responsible adoption of AI

My comment, with a supplemental, to the FSB’s consultation on sound practices for adopting AI in financial services, on how to govern agentic AI: the systems that don’t just answer questions but take actions on their own.

Explainers

Plain-language pieces on governing AI inside regulated financial firms.

Posted 13 September 2026

Built-in governance is a feature, not your record

A product that says governance is built in can show what the agent did. It cannot show that you oversaw it, and your oversight is what an examiner asks you to show. What the gap is, why it does not survive a change of model, and the clause and the record that narrow it.

Posted 9 September 2026

The wiki the agents used

What a swarm of AI agents loose on a public wiki teaches any firm running agents: inventory every channel an agent can write to, do not trust a log an agent can alter, and do not wait for the vendor’s disclosure.

Posted 7 September 2026

The folder someone sends you

Why a working code folder someone sends you can run a command on your machine the moment an AI coding agent opens it, and the one-minute habit that prevents it.

Posted 3 September 2026

Credit union or vendor: who has the answer when the AI says no?

NCUA has issued no AI-specific rules, and its technology-neutral rules apply whatever sits behind the loan. Where oversight sits, what record a credit union has to be able to produce, and what its vendor contract should oblige.

Posted 26 August 2026

The carve-out is not a grace period

Banks waited fifteen years for new model risk guidance. SR 26-2 arrived in April and put generative and agentic AI out of scope, pointing institutions at their own governance instead. Why routing every agent to the top committee fails, and what to route by instead.

Posted 23 August 2026

The agent that opened a GitHub account

A UK government test agent impersonated a real project participant and attempted a supply-chain compromise. A human maintainer caught it. What AISI changed afterward, and the four questions that apply to any agent in your firm with network access.

Posted 16 August 2026

What exactly are we governing?

An AI agent can stay below its authorization limit and still exceed it, because it may not act alone. Why the governed unit should often be the delegation tree rather than the individual agent, and what the FSB consultation responses left open.

Operator, not advisor

Bidun Group is led by Mike Bidun, a senior AI Governance operator. Most recently, as Director of AI Governance and End-User Enablement at CAIS Group, a FINRA-regulated alternative-investments fintech, he built the enterprise AI governance program from nothing and ran the full lifecycle: use-case intake, risk classification, assessment, control requirements, monitoring, issue management and reporting. He authored the governance charter, the end-user policy and the LLM usage standards, and set the decision rights and approval thresholds that told the business what it could do and what had to be escalated.

He defined risk-based tiering by data sensitivity, autonomy, business criticality and regulatory exposure, so control requirements stayed proportionate to actual risk instead of uniform. He established and chaired the AI Governance Council, and prepared the firm's AI Governance Audit.

Prior leadership at Citi's Internal Audit Innovation Lab and Morgan Stanley's Internal Audit Innovation & Research group. Built to transition: engagements are designed to hand off cleanly, leaving you with a running program, not a dependency.

Track record

  • Built & ran AI governance in a FINRA-regulated firm, zero to audit-ready
  • Adoption up 24%, power users up 40% in four months, with control evidence intact
  • Established and chaired the AI Governance Council, with Legal, Risk and Security
  • Built the AI Registry: every model, agent and vendor AI tool, with named owners and evidence
  • Gated model providers into production through vendor and security due diligence
  • Monthly portfolio and risk reporting to the Operational Risk Management Committee
  • Citi Internal Audit Innovation Lab & Morgan Stanley Internal Audit Innovation & Research
  • BS, Computer Science, Brown University; early career in Unix kernel work

Let's talk

If you're a CRO, CCO, Head of Model Risk, or board member wrestling with an AI governance gap, reach out. Built to work with whoever owns compliance at your firm today, whether that is a CCO wearing two other hats or an outside consultant on retainer. It adds the AI piece. It does not replace them.

Book a 30-min intro call mike@bidun.com