<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Notes from the AI Operating Layer]]></title><description><![CDATA[The operating layer of a company – operations, finance, compliance, and cross-border structure – by an operator who’s worked inside regulated banks, AI startups, and scale-ups.]]></description><link>https://onlenasmind.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!nMEH!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6401dd3-aaae-47d5-acc6-6a6a5779601a_1024x1024.png</url><title>Notes from the AI Operating Layer</title><link>https://onlenasmind.substack.com</link></image><generator>Substack</generator><lastBuildDate>Tue, 04 Aug 2026 21:02:40 GMT</lastBuildDate><atom:link href="https://onlenasmind.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Lena Schaefer]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[onlenasmind@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[onlenasmind@substack.com]]></itunes:email><itunes:name><![CDATA[Lena Schaefer]]></itunes:name></itunes:owner><itunes:author><![CDATA[Lena Schaefer]]></itunes:author><googleplay:owner><![CDATA[onlenasmind@substack.com]]></googleplay:owner><googleplay:email><![CDATA[onlenasmind@substack.com]]></googleplay:email><googleplay:author><![CDATA[Lena Schaefer]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Compliance is architecture, not paperwork]]></title><description><![CDATA[The AI Act deadline moved. The work it demands clearly didn&#8217;t.]]></description><link>https://onlenasmind.substack.com/p/compliance-is-architecture-not-paperwork</link><guid isPermaLink="false">https://onlenasmind.substack.com/p/compliance-is-architecture-not-paperwork</guid><dc:creator><![CDATA[Lena Schaefer]]></dc:creator><pubDate>Fri, 12 Jun 2026 09:31:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!nMEH!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6401dd3-aaae-47d5-acc6-6a6a5779601a_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>We had our first ISO 27001 surveillance audit half a year ago. Passed with zero non&#8211;conformities &#8211; which is what happens when the company has gotten used to taking micro actions throughout the year instead of cramming evidence into a folder the week before the audit happens. The evidence gets generated alongside the work. The controls match operations because operations changed to match the controls a year ago, not because someone backfilled a folder the night before. Honestly, that feels great.</p><p>The same week, I was on a customer legal review call. The compliance team had questions about how we process data, which of our use cases the EU AI Act applies to, and where GDPR lives in our pipeline. Routine questions, the kind I have heard versions of for two years now &#8211; the conversation enterprise customers run before contracting with an AI vendor, especially one based in the EU. Several of those questions were already answered in a one-pager I had written months earlier on our exposure to the EU AI Act, which their lead counsel had read before the call. The remaining questions did not take long.</p><p><strong>That is what the architecture frame buys you</strong>. Not less compliance work. The same compliance work, distributed across the year and into the artifacts the company already produces, so that the audit and the customer call both read back what is already true.</p><p>This is the difference compliance teams understate, and engineers who have never worked under examination tend to miss entirely. Compliance is not paperwork. Paperwork is a one-shot artifact you produce, file, and return to in twelve months. Compliance, done as architecture, is a pattern that other parts of the company hang off. ISO 27001 done as paperwork is a weeks-long sprint of setting up policies and evidence that decays the day the audit is over. Done as architecture, it has the same shape as your access controls, vendor onboarding, incident response playbook, and hiring filter. The audit just mirrors it back to you.</p><p>I am writing this from a particular seat. Six years in retail banking at TARGOBANK, the institution that was formerly Citigroup&#8217;s German consumer banking arm before Cr&#233;dit Mutuel acquired it in 2008 and rebranded it in 2010. Then 1.5 years of Big4 audit at Deloitte FSI, auditing BaFin-supervised banks and insurance companies. An LL.B in banking and capital markets law on top of that. Since 2022, finance and operations at an AI company with European and US entities, where I own ISO 27001 and the EU AI Act readiness work and the fundraise infrastructure, and where I build internal tooling against the same operational layer with Claude Code. The reason for the listing is that I have sat on both sides of the audit, in both jurisdictions, and the architecture framing is the one that survives across all of those vantage points. The paperwork framing only survives in places where compliance is somebody else&#8217;s problem.</p><h2>The regulatory wave is not what most operators think it is</h2><p>If you have been reading the trade press, you have probably absorbed a particular narrative. The EU AI Act high-risk obligations were due to become enforceable on August 2, 2026. Penalties up to &#8364;15M or 3% of global annual turnover for non-compliance with high-risk obligations, separate from the &#8364;35M / 7% ceiling for prohibited practices (<a href="https://artificialintelligenceact.eu/">European Commission AI Act</a>). Substack posts have been counting down the weeks. Some of them have been doing it since January.</p><p>That narrative is now wrong, or at least conditionally wrong. On May 7, 2026, the Council and the Parliament reached a provisional political agreement under the so-called Digital Omnibus on AI, deferring the Annex III high-risk application date to December 2, 2027 for standalone systems and August 2, 2028 for high-risk AI embedded in products (<a href="https://www.consilium.europa.eu/en/press/press-releases/2026/05/07/artificial-intelligence-council-and-parliament-agree-to-simplify-and-streamline-rules/">Consilium, May 2026</a>; <a href="https://www.hoganlovells.com/en/publications/eu-legislators-agree-to-delay-for-highrisk-ai-rules">Hogan Lovells, 2026</a>). If the package is formally adopted before August 2, the original deadline no longer binds, and every operator who treated the AI Act as the central reason to invest now has, on paper, been given eighteen months back.</p><p>Read the room. The paperwork camp reads this as a reprieve. The architecture camp reads it as confirmation. The architecture you build for the AI Act is the same architecture you build for DORA and the GENIUS Act, and the same architecture the OCC will read against internal controls under a national bank charter. The statute you point at when you go to the board to justify the work is interchangeable. The work itself is not.</p><p>DORA has been live since January 17, 2025 (<a href="https://www.jonesday.com/en/insights/2025/01/digital-operational-resilience-act-now-in-effect-for-financial-sector">Jones Day, 2025</a>). It harmonizes operational resilience requirements across roughly 22,000 EU financial entities plus their ICT third-party providers (<a href="https://www.pwc.com/mt/en/services/pwc-digital-services/cyber-security-and-privacy/cyber-security-services/dora.html">PwC, 2025</a>). Penalties for in-scope financial entities reach up to 2% of annual worldwide turnover; designated critical ICT providers can be charged periodic penalties of up to 1% of average daily worldwide turnover by the Lead Overseer (<a href="https://doragrc.com/dora-penalties">DORA GRC</a>). DORA is not coming. DORA is fifteen months in.</p><p>The GENIUS Act was signed on July 18, 2025, the first federal regulatory framework for payment stablecoins in the United States, requiring 1:1 reserve backing in high-quality liquid assets and prohibiting yield to holders (<a href="https://www.whitehouse.gov/fact-sheets/2025/07/fact-sheet-president-donald-j-trump-signs-genius-act-into-law/">White House, 2025</a>; <a href="https://www.gtlaw.com/en/insights/2025/7/genius-act-enacted-establishing-a-regulatory-framework-for-payment-stablecoins-issued-or-sold-in-the-united-states">Greenberg Traurig, 2025</a>). The OCC&#8217;s implementing notice of proposed rulemaking was published in the Federal Register on March 2, 2026; the comment period closed May 1 (<a href="https://www.federalregister.gov/documents/2026/03/02/2026-04089/implementing-the-guiding-and-establishing-national-innovation-for-us-stablecoins-act-for-the">Federal Register, March 2026</a>). The effective date will be the earlier of January 18, 2027 or 120 days after final regs land. That is not a far horizon for a stablecoin issuer, and the operators who began designing reserve segregation, attestation cadence, and BSA/AML controls in mid-2025 are already a year ahead of the operators waiting for the final text.</p><h2>Architecture and paperwork, played out at the entity level</h2><p>The cleanest case studies are not at the workflow layer. They are at the entity level, in the choice of charter.</p><p>On January 13, 2021, the OCC granted Anchorage Digital the first national trust charter for a crypto firm (<a href="https://www.coindesk.com/policy/2021/01/13/anchorage-becomes-first-occ-approved-national-crypto-bank">CoinDesk, 2021</a>). Nathan McCauley&#8217;s five-year retrospective, published in January 2026, is worth reading directly: the bet was that submitting every process, control, and policy to OCC examiner discipline would itself become the moat (<a href="https://www.anchorage.com/insights/writing-playbook-anchorage-digital-marks-five-years-federal-regulation-crypto-banking">Anchorage, 2026</a>). They held effective monopoly on federally-supervised digital-asset custody for about five years.</p><p>Custodia Bank ran the inverse experiment, although Caitlin Long and her team would resent the framing. It pursued the Wyoming SPDI charter, the state route, on the bet that a friendlier state regime would secure the company access to a Fed master account. The master-account application went in October 2020. The Federal Reserve Bank of Kansas City rejected it in January 2023. The Wyoming district court ruled in March 2024 that the Fed had discretion to deny. The Tenth Circuit denied an en banc rehearing 7-3 on March 13, 2026, effectively closing the door (<a href="https://www.bankingdive.com/news/custodia-fed-appeals-court-master-account-waller-caitlin-long/804795/">Banking Dive, 2026</a>; <a href="https://www.coindesk.com/policy/2026/03/13/court-closes-custodia-fight-with-federal-reserve-just-as-fed-opens-master-account-door">CoinDesk, March 2026</a>). Five-plus years burned. The state charter was paperwork in the sense that mattered: a piece of paper that did not deliver the master-account access it had been bought for.</p><p>Mercury is mid-charter as I write this. For years we have used Mercury for our US entity &#8211; not as a bank, because until now it has not been one, but as a fintech front end with FDIC-insured partner banks holding the actual deposits. The caveat I had to add whenever I mentioned our U.S. banking setup to peers and other founders was that Mercury is a layer, not a charter holder. With the conditional OCC approval, that caveat goes away. Mercury applied for an OCC national bank charter in 2025 and received preliminary conditional approval on April 27, 2026 in OCC Corporate Decision #1372, a Salt Lake City de novo (<a href="https://www.occ.gov/topics/charters-and-licensing/interpretations-and-decisions/2026/cd1372.pdf">OCC CD #1372, 2026</a>; <a href="https://www.bankingdive.com/news/mercury-nabs-conditional-occ-charter/818674/">Banking Dive, 2026</a>). The conditions enumerated in CD #1372 &#8211; covering capital, governance, policy, and audit &#8211; are not paperwork to be filed. They are the operating model for the next three years. Reading the document, you can see which company in the United States is going to be examiner-ready and which company is going to be examiner-surprised.</p><p>Mercury is one signal of a larger thaw. After the 2008 financial crisis, de novo national bank charter activity in the United States effectively collapsed and stayed near-zero for years; the OCC approved only a handful per year, and almost none of them digital-native. The posture started to soften in the early 2020s, and the queue has been growing since. The next wave is AI- and blockchain-native, not crypto-native: Augustus (formerly Ivy), which took its own conditional OCC approval on May 11, 2026 (<a href="https://www.bankingdive.com/news/augustus-occ-charter-conditional-ai/819871/">Banking Dive, 2026</a>), and the AI-native applicants behind it. What they share with Anchorage is the strategic choice to chase the OCC route rather than the SPDI shortcut, precisely because the OCC route is harder. The regulatory bar becomes the moat &#8211; the regime itself does the gatekeeping, and the next entrant has to clear the same bar.</p><h2>The honest counterargument: moats are brittle</h2><p>If the architecture frame were free, everyone would have it. The honest cost is that regulatory moats erode the moment the regulator decides they should.</p><p>Anchorage&#8217;s roughly five-year monopoly was eroded in about 83 days. Between December 2025 and March 2026, eleven additional firms filed for or received conditional OCC national trust charters; Coinbase took its conditional approval on April 2, 2026 (<a href="https://www.fintechweekly.com/news/occ-national-trust-bank-charter-crypto-fintech-2026">FinTech Weekly, 2026</a>; <a href="https://www.coindesk.com/policy/2026/04/02/coinbase-wins-initial-occ-nod-for-trust-charter-boosting-sustody-push">CoinDesk, April 2026</a>). The same regime change that validated the architecture frame commoditized the moat. The tens of millions of dollars Anchorage publicly says it spent building federally-supervised compliance infrastructure (<a href="https://www.anchorage.com/insights/writing-playbook-anchorage-digital-marks-five-years-federal-regulation-crypto-banking">Anchorage, 2026</a>) bought a five-year head start. Not permanence.</p><p>Bruce Schneier&#8217;s <em>Beyond Fear</em> (Copernicus Books, 2003) introduced &#8220;security theater,&#8221; countermeasures that produce the feeling of security without the substance, and his July 2004 essay extends the critique to compliance as a category: controls written for the auditor rather than the threat model (<a href="https://www.schneier.com/essays/archives/2004/07/security_and_complia.html">Schneier, 2004</a>). The architecture frame is exposed to the same critique. Controls labeled &#8220;architecture&#8221; can be just as theatrical as controls labeled &#8220;policy&#8221; if they are designed for examiner-readability rather than for the operational reality they purport to govern. The label is not what makes them architecture. Whether anything actually relies on them is.</p><p>This is the part the marketing layer flattens. SOC 2 maintenance is heavier than the marketing literature warns. Year-three drift on the control framework alone costs more hours than the first audit. We let our own SOC 2 lapse on purpose: ISO 27001 covers the overlap that matters to enterprise security teams, and US procurement organizations who know how strict EU compliance has gotten now read ISO as a stronger signal than SOC 2 for an EU-based vendor. That is one of the architectural decisions year three forces on you. (Most companies never make it explicitly. They let the cert lapse and call it cost-cutting, or they pay a consultant to refresh the policies in advance of the surveillance audit, which means the controls are paperwork by another name.) The architecture frame is not a get-out-of-cost-free card. It is a different cost structure with a different decay profile.</p><h2>What the technology layer worked out a decade ago</h2><p>The software side of the house solved a version of this years ago. Engineers stopped writing rules as documents that sit in a folder and started writing them as code that runs continuously against the system, so the rule checks itself every time something changes instead of waiting for someone to notice the document went stale. They call it policy-as-code. It is the same point I keep coming back to: a policy that lives only in a document is a policy that has already started drifting from what the company actually does.</p><p>The compliance side has its own version of the same idea, and the vendor category is the most visible signal: Vanta, Drata, Secureframe, the audit-as-platform players. They auto-collect evidence from your stack instead of leaving you to fill spreadsheets the night before the audit. Used well, the architecture frame works: the controls reference live system state, evidence accumulates as the company operates, and the surveillance audit becomes a read-back rather than a re-construction.</p><p>The failure mode is at the opposite end of the automation spectrum, in vendors who layer AI on top of the evidence-collection step without keeping verification honest. There has already been a public case of a compliance-automation startup whose AI-generated attestations did not match the systems they were meant to describe; a customer of theirs experienced a serious security incident (<a href="https://techcrunch.com/2026/04/23/another-customer-of-troubled-startup-delve-suffered-a-big-security-incident/">TechCrunch, April 2026</a>). The lesson is not that automation is bad. It is that automation that bypasses verification is paperwork by another name, one with a bad reputation &#8211; the controls look architectural on the dashboard, but nothing actually rests on them. The real cost of outsourcing the whole compliance stack to a vendor badge is not the SaaS line item on the P&amp;L. It is the back-end cost the first time a control was attested to but never held, and the gap is the one demonstrated by a customer&#8217;s incident.</p><h2>What it costs, and where the cost falls</h2><p>Thomson Reuters&#8217; 2023 Cost of Compliance survey reports that large financial institutions can spend more than $10,000 per employee per year on compliance, and more than 60% of respondents expected their compliance budget to increase in 2022 (<a href="https://www.thomsonreuters.com/en-us/posts/investigation-fraud-and-risk/2023-cost-of-compliance-report/">Thomson Reuters, 2023</a>). The Bank Policy Institute separately reports that bank compliance-related IT expenditure rose from less than 10% of total IT spend in 2016 to almost 14% in 2023, alongside a 75% increase in C-suite devoted to regulatory or supervisory compliance over the same period (<a href="https://bpi.com/survey-finds-compliance-is-growing-demand-on-bank-resources/">Bank Policy Institute</a>).</p><p>The architecture frame does not lower those numbers. It changes where they fall. Paperwork compliance front-loads cost onto the audit window and back-loads it onto the regulator&#8217;s next surprise. Architecture compliance spreads the cost across the year and into tooling, which means the budget shows up as engineering hours and platform spend rather than as outside-counsel invoices and last-minute consultancy fees. The Thomson Reuters and BPI numbers are aggregate; they do not tell you which company spent its $10K per head on policies in PDF format and which company spent it on automated evidence collection and a runbook that lives in code. Year three of either approach tells you.</p><h2>Where this lands</h2><p>The August 2 deadline may move. DORA already moved through the calendar without moving any of the work. The OCC has spent eighteen months in a row issuing decisions that read like the regulator answering one question (which operators have built operations that hold up and which have built shiny PDF files) and approving the first kind. The GENIUS Act framework is shaping the same answer for the next generation of stablecoin issuers, with the implementing regulations now expected from the OCC inside this calendar year.</p><p>I am writing this from the operating layer, which is where the argument actually lives. The CCO and the BSA Officer and the CRO have their seats; this argument is not about them. It is about the operational substrate beneath those seats. That substrate is what determines whether the controls the regulator reads on paper match the controls the company is actually running. It is, in the literal sense, the architecture.</p><p>Year three of any compliance program is when you find out which one you built.</p>]]></content:encoded></item></channel></rss>