No banking regulator has a rule for AI agents, but eighteen documents now take a position on them. Read together they say four things: agents are outside US model risk guidance and inside ‘broader governance’; human oversight must scale up with autonomy; agent-specific security — prompt injection, memory poisoning, AI-generated code — is an open workstream; and the autonomy of frontier models has become a financial-stability topic. Every position below is dated and quoted from the primary source.
How has the regulatory picture for AI agents developed?
What has each regulator said about agentic AI in banking?
| Date | Authority | Document | What it says about agents |
|---|---|---|---|
| Aug 31, 2026 | FSB | FSB Chair's letter to G20 (Aug 2026) | Frontier models show 'increasingly sophisticated autonomy and problem-solving abilities, as well as threat capabilities'; authorities should support safe model release and deployment as a priority. |
| Jul 31, 2026 | EBA | ESA Statement on ICT risks from frontier AI models (JC 2026 25) | Keep continuously updated asset inventories including AI/ML components; move from periodic to continuous monitoring; management bodies own frontier-AI risk under DORA. |
| Jun 10, 2026 | FSB | FSB AI sound practices consultation (June 2026) | Twelve sound practices with 'specific attention to generative and agentic AI'; Sound Practice 10 asks for extra human-oversight measures for highly autonomous agents; risks named include autonomous multi-step actions, agentic memory poisoning and AI-generated code defects. |
| Jun 5, 2026 | UK (BoE / PRA / FCA) | 2026 BoE/FCA AI survey | The first BoE/FCA survey to cover agentic AI explicitly; the 2024 baseline found 2% of use cases fully autonomous; the FPC asked for further work on agentic AI in payments and markets. |
| May 27, 2026 | Federal Reserve | Cook: Opportunities and Risks of AI (May 2026) | AI-driven trading risks correlated strategies, endogenous model collusion and market concentration; AI-generated code may outpace security review. |
| May 21, 2026 | NY DFS | DFS Frontier AI Models Industry Letter (May 2026) | Put human review on AI-generated code before deployment; strengthen logging and alerting; shorten remediation timelines; map third-party dependencies. |
| May 14, 2026 | Colorado AI Act | SB 26-189 | From January 1, 2027, consequential automated decisions require notice, a 30-day explanation of an adverse outcome, and human review by trained staff with authority to override. |
| May 7, 2026 | OCC | OCC Semiannual Risk Perspective, Spring 2026 | Banks are taking a 'measured approach' to generative and agentic AI, limited to specific use cases with guardrails and human-in-the-loop accountability; lack of explainability makes governance essential before use expands to material financial decisions. |
| May 1, 2026 | Federal Reserve | Bowman: AI in the Financial System (May 2026) | Confirms the model-risk carve-out for generative and agentic AI; supervisors are assessing third-party risk expectations for vendor-provided AI; no pre-emptive AI-specific rulemaking. |
| Apr 17, 2026 | Federal Reserve | SR 26-2 | Generative and agentic AI models 'are novel and rapidly evolving' and 'are not within the scope of this guidance'; banks should use broader risk-management and governance practices for them. An interagency request for information on AI and model risk is promised. |
| Feb 24, 2026 | ECB | Machado speech: 'Technology is neutral, governance is not' (Feb 2026) | Generative and agentic AI adoption is accelerating in IT operations, legal and document analysis and front-line support; banks are accountable for outcomes regardless of how the technology performs. |
| Jan 12, 2026 | NIST | CAISI RFI on AI agent security (2026) | Defines AI agents as systems that plan and take autonomous actions affecting real-world systems; asks about indirect prompt injection, poisoning, specification gaming, and safeguards for constraining and monitoring agent access in production. |
| Nov 17, 2025 | SEC | Division of Examinations FY2026 Priorities | Examiners will focus on 'recent advancements in AI' and test whether firms have policies to monitor and supervise AI used in fraud prevention, back-office operations, AML and trading. |
| Sep 25, 2025 | EBA | EBA report: Rising application of AI in EU banking and payments (Sep 2025) | 55% of surveyed EU banks already use general-purpose or agentic AI in consumer-facing processes — fraud alerts, agent assist, self-service and digital or voice assistants. |
| Aug 14, 2025 | NIST | NIST COSAiS control overlays | Plans SP 800-53 control overlays for single-agent and multi-agent AI systems; these are the least mature of the five overlays. |
| Jul 26, 2024 | NIST | NIST AI 600-1 (Generative AI Profile) | Names information-security risks — prompt injection, data poisoning, model extraction — and confabulation among twelve generative-AI risks, with actions mapped to the AI RMF. |
| Jul 12, 2024 | EU AI Act | Regulation (EU) 2024/1689 | High-risk systems require human oversight (Art. 14) and automatic logging (Art. 12); deployers must ensure oversight, monitor operation and keep logs at least six months (Art. 26). |
| Jun 6, 2023 | CFPB | CFPB Chatbots in Consumer Finance (issue spotlight, 2023) | Institutions remain responsible for timely, accurate answers and access to a human 'regardless of the processes or technologies used'. |
What are the next dated events for AI agents in banking?
- Oct 1, 2026 · FSB final sound practices. Expected October 2026 as a G20 deliverable. FSB AI sound practices consultation (June 2026) →
- Jan 1, 2027 · Colorado ADMT Act in force. Notice, explanation and human review for consequential decisions. SB 26-189 →
- Dec 2, 2027 · EU AI Act high-risk obligations. Stand-alone Annex III systems, including credit scoring. Regulation (EU) 2024/1689 →
- Date not set · Interagency RFI on AI and model risk management. Promised in the April 2026 guidance; the first federal document that will address generative and agentic AI in bank models directly. SR 26-2 →
Is there a regulation specifically for AI agents in banking?
No. As of September 2026 no banking regulator has issued rules addressed to AI agents as such. The closest things are the April 2026 interagency model risk guidance, which explicitly places generative and agentic AI outside its scope and promises a request for information; the FSB's June 2026 consultation, whose twelve sound practices pay 'specific attention to generative and agentic AI'; and NIST's January 2026 request for information on AI agent security, which feeds its AI Agent Standards Initiative.
What is the most important regulatory statement on agentic AI for a US bank?
The carve-out in SR 26-2 / OCC Bulletin 2026-13 / FDIC FIL-15-2026: generative and agentic AI models 'are not within the scope of this guidance' and banks should manage them through broader risk-management and governance practices. It means an agent is not validated like a credit model, but it also means the bank has to show which governance program does cover it — and the agencies have said an interagency RFI on AI and model risk is coming.
Which regulators require human oversight of AI agents?
In statute: the EU AI Act (Article 14 for high-risk systems, with deployer duties in Article 26) and Colorado's ADMT Act from January 1, 2027 (human review by trained staff with authority to override). In guidance: the FSB's Sound Practice 10 asks for extra human-oversight measures for highly autonomous agentic AI; the OCC describes human-in-the-loop accountability as observed practice; the CFPB says customers must be able to reach a human; New York DFS asks for human review of AI-generated code.
The next position lands in your inbox
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →