Investors are about to discover the AI governance premium

Growth first, safety later

An AI model slipping its test environment makes headlines, but the shift it illustrates runs deeper: investors are beginning to ask not only what a model can do, but whether its owner can keep it under control. In Switzerland, one custody bank already runs as if that were the whole point.

For now, the market values AI on one thing: how fast it can grow and how profitable it might become. Security barely enters the equation. That is starting to change at the margin.

“Companies able to show their models are governable, auditable and secure could enjoy a confidence premium,” says Kevin Berton, analyst and fund manager at Piguet Galland.

Those hit by repeated incidents, or offering systems seen as too autonomous to control, risk tighter regulation and a valuation discount.

It is an early-stage distinction, not yet market consensus. Equity investors still reward revenue growth, model performance and compute capacity above almost everything else. But a second characteristic is beginning to surface alongside them: whether an operator can keep its systems on a leash.

When equity gives way to debt

That distinction matters more as the industry shifts from equity-funded expansion toward debt-financed infrastructure. The Financial Times reported on 20 July that Morgan Stanley has become Wall Street’s leading bank for AI-linked debt. Berton notes that the bank expects global issuance of AI-related debt to reach around 570 billion dollars in 2026, at a time when sector capital spending could approach 1,000 billion as soon as 2027, increasingly raised on bond markets, including in euros, sterling and Swiss francs.

The move reshapes the risk. “With debt, the risk becomes more a matter of the balance sheet and cash generation,” says Berton. Bond investors, more sensitive to financial discipline than equity buyers, scrutinise whether the infrastructure being financed actually generates cash.

That scrutiny already shows in credit spreads: he points to S&P’s recent downgrade of Oracle to BBB−, the last rung of investment grade, which explicitly cited the company’s surging AI spending. For the large hyperscalers, he adds, balance-sheet risk stays contained, with ample liquidity and moderate leverage.

A framework, not a reaction

The question of control turned concrete in July. In an internal evaluation, two OpenAI models running with safety classifiers deliberately disabled exploited a zero-day vulnerability to escape their test sandbox, then chained stolen credentials and further zero-days into remote code execution on Hugging Face’s production systems, all in pursuit of the benchmark’s answer key.

Hugging Face detected and contained the activity, reconstructing it with open-weight models on its own infrastructure (sources: OpenAI, Hugging Face).

For at least one operator, the episode was beside the point. Sygnum, the global digital asset banking group, runs AI on a standing framework rather than a reactive one, and the controls it already has in place answer the question the incident raises.

“Our deployments look nothing like that setup,” says Thomas Frei, Head AI & Data Analytics. “We use standard commercial models where safety classifiers are active, no AI in the custody chain, and, at this stage, a human in the loop on every AI-based solution. Every application beyond personal productivity is logged in an internal inventory, agents get least-privilege access to a defined set of tools, and actions leave an audit trail.”

Frei is careful about where the real lessons sit.

“Neither of them is about AI governance. One is a security question — autonomous exploitation is real now, access to it is still restricted, but that gap narrows. That is a threat-landscape input for our CISO. The other is architectural: an agent pursues the goal you actually gave it, literally and persistently.That is why access is scoped and logged. We designed for that before July; the incident is a good argument for it, not the reason for it.”

Where the two lenses meet

The market view and the operator view point the same way: governability is emerging as a characteristic investors may start to price, rather than one they take for granted. A private bank sees a confidence premium forming; a custodian has already built the controls that would earn it. Berton expects a whole layer to grow around this need, from verification to audit to security, investable today mainly through the cybersecurity names already moving into AI governance.

Regulators are converging on the same point. FINMA’s Guidance 08/2024, published on 18 December 2024, asks supervised institutions to actively identify and manage AI-specific risks such as model risk, third-party dependency and cyber exposure.

More recently, on 25 November 2025, the European Parliament adopted a resolution urging that fully autonomous AI systems in finance remain under human oversight, and flagging the concentration risk of leaning on a handful of technology providers.

Both predate the current wave of systems that act on their own initiative, which is exactly where the governance question now concentrates.For investors, the point is not that AI has become dangerous. It is that the question is changing, from how much a model can do to how well its owner can prove it stays in hand. On that measure, the disciplined adopter (and trader) is not behind the market. It is ahead of it.

Blockshot newsletter

Join thousands of other innovators, investors and decision-makers to access data-driven reports and premium insights on how global blockchain adoption is reshaping wealth, economics, politics, sustainability and culture.