Capital One outlines governance for agentic AI

Capital One VP Rashmi Shetty outlines a governance framework to protect PII, enforce GDPR and control public LLM use in multi-agent AI systems.

Rashmi Shetty, vice president of enterprise AI at Capital One, described a governance framework for agentic AI in a recent podcast. The framework is designed to protect personally identifiable information, enforce GDPR controls and manage when external large language models are used.

The bank has updated its technology stack and data ecosystem and has adjusted its risk, compliance and policy functions to match those changes. Shetty said the effort combines policy and technical guardrails that limit data access across multiple collaborating AI agents and that control when external models are queried.

One immediate decision for IT leaders is whether to allow public LLMs or to run models only inside the corporate network. Public models can provide broader knowledge but can incorporate submitted queries into their training data, which risks exposing sensitive information. Capital One’s approach is to default to internally hosted models where possible and to restrict the use of public models through governance rather than imposing an outright ban.

The governance scheme focuses on data flow between agents. Each AI component should receive only the specific data it needs to perform its task. Policies are defined at a granular, or “atomic,” level so permissions follow the sequence of actions across agents instead of granting broad, persistent access.

Shetty described how the framework is layered on the bank’s platform strategy to make controls operational. The framework sets boundaries on which tools and datasets LLM-powered agents may access and enforces GDPR requirements for handling PII. “You’re taking a highly stochastic, probabilistic system, which can make dynamic decisions and trying to define a deterministic boundary using a safety and governance mechanism in order to increase your velocity towards autonomous decision-making,” she said.

Technical measures include preventing sensitive data from being included in queries to external models and defaulting to internal models when feasible. The framework also governs how data is handed off between agents so each agent receives the minimum information needed for its role.

Shetty framed governance as the next phase after organisations have established a technical blueprint and data strategy for AI. She noted that, alongside infrastructure work, organisations must define who or what can access data, when access is allowed and for what purpose, and then encode those limits into policy and technology.

Articles by this author