An AI agent in a bank passes eight gates, and each gate is a question with evidence attached. The order matters: tiering comes before design because the tier decides which rulebook applies; vendor onboarding comes before validation because most agents are bought, not built; and the last stage loops back to the second, because a vendor model update, a new use, a new rule or an incident each re-opens the tiering question. The documents behind each gate are the ones examiners cite.
Intake
What will the agent do, for whom, and what could go wrong?
EVIDENCE AT THE GATE
- Use-case statement naming the process, the users and the affected customers
- The actions the agent will be allowed to take, listed
- Initial harm analysis
DOCUMENTS
- Treasury AI in Financial Services report (Dec 2024) · U.S. Treasury — Review each AI use case for compliance with existing law before deployment.
- Treasury FS AI RMF and AI Lexicon (Feb 2026) · U.S. Treasury — Tools to evaluate AI use cases across the lifecycle.
- NIST AI RMF 1.0 · NIST — The Map function: context, intended use, affected parties.
Risk tiering
Which tier, which autonomy level, which rulebook?
EVIDENCE AT THE GATE
- Materiality rating
- Autonomy level (0–4) proposed and approved
- Regulatory classification: model-risk scope, EU high-risk, consequential decision, consumer-facing
DOCUMENTS
- FSB AI sound practices consultation (June 2026) · FSB — Sound Practice 5: materiality and risk assessment before selection.
- SR 26-2 · Federal Reserve — Materiality drives the intensity of validation and monitoring; generative/agentic out of scope.
- Regulation (EU) 2024/1689 · EU AI Act — Annex III classification decides whether the full high-risk regime applies.
- SB 26-189 · Colorado AI Act — 'Covered ADMT' — material influence over a consequential decision — triggers notice and review duties.
Design
What is the permission envelope and where does a human sit?
EVIDENCE AT THE GATE
- Identity and entitlements specified
- Tool allow-list, limits and approval points
- Data scope and lineage plan
- Oversight design: thresholds, reviewers, recourse
DOCUMENTS
- CAISI RFI on AI agent security (2026) · NIST — Constraining and monitoring agent access designed in, not bolted on.
- Regulation (EU) 2024/1689 · EU AI Act — Human oversight (Art. 14) and logging (Art. 12) are design requirements for high-risk systems.
- NIST AI 600-1 (Generative AI Profile) · NIST — Suggested actions per generative-AI risk to select from at design time.
Build and onboard
Do we know what we are buying, and can we leave?
EVIDENCE AT THE GATE
- Vendor due diligence and contract terms (data use, audit, incident notification, exit)
- Secure development evidence; human review of AI-generated code
- Component inventory including models, retrieval stores and tools
DOCUMENTS
- SR 23-4 · Federal Reserve — Planning, due diligence, contract negotiation and exit for vendor AI.
- BCBS Third-Party Risk Principles (Dec 2025) · Basel Committee — Due diligence, binding contracts, nth-party and concentration risk.
- DFS Frontier AI Models Industry Letter (May 2026) · NY DFS — Human oversight of AI-generated code before deployment.
- ESA Statement on ICT risks from frontier AI models (JC 2026 25) · EBA — Inventories that include AI/ML components; secure-by-design.
Validate and test
Does it do what we approved, and what happens when attacked?
EVIDENCE AT THE GATE
- Evaluation results against the approval metrics
- Adversarial and red-team testing (prompt injection, poisoning, specification gaming)
- Independent validation for any in-scope model the agent calls
DOCUMENTS
- SR 26-2 · Federal Reserve — Independent validation with outcomes analysis and effective challenge for in-scope models.
- NIST AI 100-2e2025 (Adversarial ML) · NIST — Adversarial machine-learning taxonomy for attack-oriented testing.
- PRA SS1/23 · UK (BoE / PRA / FCA) — Independent validation principle, including vendor models.
- FCA FS25/5 · UK (BoE / PRA / FCA) — Supervised live testing as a path to production for AI in UK financial services.
Approve and deploy
Who signs, and is the oversight actually configured?
EVIDENCE AT THE GATE
- Sign-off by the accountable owner and the second line
- Staged rollout with rollback
- Oversight thresholds, reviewers and kill switch verified in production
DOCUMENTS
- Machado speech: 'Technology is neutral, governance is not' (Feb 2026) · ECB — Accountability for AI outcomes and effective challenge before use.
- FSB AI sound practices consultation (June 2026) · FSB — Sound Practice 2 governance and accountability; SP10 human oversight.
- Regulation (EU) 2024/1689 · EU AI Act — Deployer duties: use per instructions, ensure oversight, monitor operation (Art. 26).
Operate and monitor
Is it still doing what we approved?
EVIDENCE AT THE GATE
- Traces retained; drift and performance dashboards against approval metrics
- Security alerting for anomalous behaviour
- Oversight metrics: override rate, escalations, time-to-human
DOCUMENTS
- Regulation (EU) 2024/1689 · EU AI Act — Automatic logging and six-month retention for deployers.
- ESA Statement on ICT risks from frontier AI models (JC 2026 25) · EBA — Move from periodic to continuous monitoring.
- Division of Examinations FY2026 Priorities · SEC — Examiners test policies to monitor and supervise AI in operation.
- FSB AI sound practices consultation (June 2026) · FSB — Sound Practice 9: ongoing monitoring.
Change, incident and retirement
What changed, what broke, and when do we re-assess?
EVIDENCE AT THE GATE
- Re-assessment triggers: vendor model update, new use, new rule, incident
- Incident playbook with regulatory notification paths
- Exit executed per plan; entitlements revoked; data handled per retention
DOCUMENTS
- Treasury AI in Financial Services report (Dec 2024) · U.S. Treasury — Re-evaluate AI use cases periodically, not once.
- SB 26-189 · Colorado AI Act — Developers must notify deployers of material updates; deployers re-assess.
- BCBS Principles for Operational Resilience (2021) · Basel Committee — Incident management and recovery as a critical-operations discipline.
- SR 23-4 · Federal Reserve — Termination and exit as a lifecycle stage of third-party risk.
Know which gate just moved
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →