skip to content

Terry Li Selected essays

AI controls architecture

I write for practitioners making AI useful and governable inside regulated institutions. These twenty essays examine controls for systems that reason, use tools, and act, then follow those controls into operating practice.

20 selected essays 412 in the archive Regulated institutions About Terry →
Start here By role
Senior business leaders The Model Is Not the Unit of Return How AI investment becomes accountable institutional return. Read essay → Technical leaders Govern the Workflow, Not the Model Why agent controls must cover tools, evidence, permissions, and execution state. Read essay → Risk and assurance leaders The Calibration Gap Why AI assurance needs measured control effectiveness, not confident review. Read essay →
01 Controls architecture
  • AI Controls Architecture

    Risk teams know risk. The open problem is designing controls for systems that are non-deterministic, probabilistic, and attackable in natural language.

  • The Risk Without an Engineering Solution

    Every other agentic AI risk has an engineering answer. Prompt injection doesn't. That changes everything about how you design controls.

  • Why Agents Break Governance

    Four interactions between agentic properties create risks that manual governance cannot address. The category boundary is not AI versus traditional — it is systems that act versus systems that advise.

  • Govern the Workflow, Not the Model

    Agent governance cannot stop at model behavior. Once AI systems use tools, the governed object is the whole workflow.

  • The Agent Is Not the Control Point

    Finance agents are evidence custody systems before they are model systems.

02 Assurance and evidence
03 Agent systems
04 Work after AI