Summary Supervisory expectations for artificial intelligence in US banking are being set through examination practice rather than rulemaking. The OCC and Federal Reserve have made AI oversight a standing topic in every routine examination, which means the operative standard is whatever an examiner can be shown.
Source: Quartz / Reuters · 12 June 2026 · read the original article
The examination questions Reported examiner focus clusters around five areas: technical limits placed on model behaviour, how human review is structured, whether an emergency shutdown capability exists, vendor risk management, and whether AI systems respect data boundaries.
Each of these is an evidence question rather than a policy question. A statement that human review occurs is not responsive; a record showing who reviewed which decisions, what proportion were overridden and on what grounds, is.
The model risk management gap Three banking regulators issued updated model risk management guidance on 17 April 2026 while noting that generative and agentic AI fall outside its current scope. That carve-out is significant. It means the most rapidly deployed category of AI sits outside the framework most banks would otherwise point to, and firms must construct an equivalent control set themselves.
A workable approach is to keep the existing validation taxonomy — conceptual soundness, ongoing monitoring, outcomes analysis — and re-specify each element for systems without a stable specification. Conceptual soundness becomes documented use-case boundaries and prompt or tool constraints. Ongoing monitoring becomes output sampling against defined failure modes. Outcomes analysis becomes tracking of downstream decisions and complaints.
Agentic systems raise the bar Plans by large institutions to deploy autonomous agents shift the control question from review to containment. An agent that can take actions requires defined authority limits, logging of every action taken, a tested kill switch, and reconciliation between intended and actual actions. These are operational resilience controls more than model controls, and they usually sit with a different team than the one that owns model validation — a gap worth closing before an examiner finds it.
What to have ready - A current inventory of AI systems, including embedded vendor capability, with accountable owners - Written boundaries for each system: permitted use, prohibited use, data it may access - Human review records with override rates - Evidence that emergency shutdown has been tested, not merely designed - Vendor agreements covering change notification, evaluation access and exit
Methodology and limitations This summarises publicly reported supervisory practice as at the date shown and links to the original report. Examination emphasis varies by institution size, charter and portfolio, and nothing here should be read as guidance from any agency.
Related reading See [Banking Risk](/expertise/banking-risk), [Model Risk](/expertise/model-risk), [Regulatory Compliance](/expertise/regulatory-compliance) and the overview in [AI governance in insurance and banking](/insights/ai-governance-insurance-banking-2026).
Frequently asked questions
What should risk leaders know about the examination questions?
Reported examiner focus clusters around five areas: technical limits placed on model behaviour, how human review is structured, whether an emergency shutdown capability exists, vendor risk management, and whether AI systems respect data boundaries.
What should risk leaders know about the model risk management gap?
Three banking regulators issued updated model risk management guidance on 17 April 2026 while noting that generative and agentic AI fall outside its current scope. That carve-out is significant. It means the most rapidly deployed category of AI sits outside the framework most banks would otherwise point to, and firms must construct an equivalent control set themselves.
What should risk leaders know about agentic systems raise the bar?
Plans by large institutions to deploy autonomous agents shift the control question from review to containment. An agent that can take actions requires defined authority limits, logging of every action taken, a tested kill switch, and reconciliation between intended and actual actions. These are operational resilience controls more than model controls, and they usually sit with a different team than the one that owns model validation — a gap worth closing before an examiner finds it.
What should risk leaders know about methodology and limitations?
This summarises publicly reported supervisory practice as at the date shown and links to the original report. Examination emphasis varies by institution size, charter and portfolio, and nothing here should be read as guidance from any agency.
What should risk leaders know about related reading?
See [Banking Risk](/expertise/banking-risk), [Model Risk](/expertise/model-risk), [Regulatory Compliance](/expertise/regulatory-compliance) and the overview in [AI governance in insurance and banking](/insights/ai-governance-insurance-banking-2026).