A bank executive does not need to read AI regulation; they need to know what it expects of them. As of Sep 10, 2026, 19 authorities have published 164 documents that touch AI in banking, and not one of them is an AI rulebook — they apply fair-lending, model-risk, third-party, financial-crime and cyber law to AI systems, and they increasingly address the board by name. This page is the briefing: what changed in 2026, what supervisors expect of the board, the ten questions to ask your CRO and CIO, what applies to your bank, the decision on AI agents, and a 30-day reading plan with twelve primary documents. Every statement links to its source.
What changed in 2026 that a bank board must know?
Six moves, in date order. Each one is a standing page on this tracker with the primary source linked.
| Date | What happened | Why it matters to you |
|---|---|---|
| Apr 17, 2026 | US model risk guidance rewritten after 15 years SR 26-2 | SR 26-2 / OCC Bulletin 2026-13 / FDIC FIL-15-2026 replace SR 11-7 with a risk-based, materiality-driven framework — and put generative and agentic AI outside it. Those tools are now governed by your broader risk and governance programs, which examiners will ask to see. |
| Jun 10, 2026 | The FSB proposes the global baseline: 12 sound practices FSB AI sound practices consultation (June 2026) | Practice 1 is addressed to the board — align AI with business model, risk appetite and strategy. The final report is an October 2026 G20 deliverable, so this is the yardstick every supervisor will be handed. |
| Jul 7, 2026 | The ECB writes to every significant bank's CEO ECB 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301) | Letter SSM-2026-0301 requires an action plan on AI-enabled cyber threats by 31 October 2026, with named roles and timelines. The first AI letter addressed to CEOs by name, not to compliance. |
| Jul 21, 2026 | Disparate-impact liability leaves Regulation B Regulation B final rule on disparate impact (April 2026) | The CFPB's rule says ECOA authorizes only disparate-treatment claims. The adverse-action notice duty is unchanged: a model still has to give specific reasons. Fair-lending exposure for AI underwriting narrowed; it did not disappear, and state law fills some of the gap. |
| Jul 27, 2026 | EU AI Act high-risk deadline moves to 2 December 2027 Regulation (EU) 2026/1744 (Digital Omnibus on AI) | Credit scoring of natural persons stays high-risk; the compliance date for stand-alone Annex III systems is now fixed at 2 December 2027. Transparency duties (telling customers they are dealing with AI) applied from 2 August 2026 regardless. |
| Aug 31, 2026 | Frontier AI models named a financial-stability concern FSB Chair's letter to G20 (Aug 2026) | The FSB Chair tells the G20 that frontier models' most immediate impact is on cyber risk and asks firms for robust response, recovery and third-party resilience. Read with the ECB and NY DFS letters, it is a three-regulator signal that AI cyber is now a board topic. |
What do bank regulators expect of the board and senior management on AI?
No banking regulator has written an AI-specific board rule, but at least eight of them have already told boards what they expect, using law and guidance that is in force today. The pattern is consistent across jurisdictions: the board owns the AI strategy and risk appetite, a named senior executive is accountable for model and AI risk, the use of vendors does not transfer that accountability, the data feeding AI is a board-level responsibility, and — since 2026 — AI-enabled cyber threats belong on the board agenda with a dated action plan. Supervisors test these expectations through existing examinations rather than new AI exams.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| SR 26-2 / OCC Bulletin 2026-13 | Federal Reserve | Retains board and senior-management governance of model risk, scaled to materiality; generative and agentic AI sit outside the guidance and must be governed through the bank's broader risk-management programs. | In force Apr 17, 2026 |
| Interagency third-party guidance (SR 23-4 / Bulletin 2023-17) | OCC | A bank's use of third parties — including AI vendors and cloud-hosted models — does not diminish the board's and management's responsibility to operate safely and in compliance with law. | In force |
| PRA SS1/23, Principle 2 | UK (BoE / PRA / FCA) | Accountability for the model risk management framework is allocated to a named Senior Management Function holder; effectiveness for financial reporting is reported to the audit committee. | In force May 17, 2024 |
| 23 NYCRR Part 500 §500.17(b) + DFS AI letter (Oct 2024) | NY DFS | Annual certification of the cybersecurity program signed by the highest-ranking executive and the CISO by April 15; DFS expects AI-specific threats — deepfakes, AI-enhanced attacks, vendor AI — to appear in the risk assessment that certification rests on. | In force |
| BCBS 239, Principle 1 | Basel Committee | The board and senior management are accountable for risk data aggregation and reporting — the data discipline the Basel Committee said in January 2026 is still 'a work in progress' and on which AI depends. | In force |
| BCBS third-party risk principles, Principle 1 | Basel Committee | The board of directors has ultimate responsibility for oversight of third-party risk, including nth-party supply chains and concentration in a few AI and cloud providers. | Dec 10, 2025 |
| FSB Sound Practices 1–2 | FSB | Board and senior management align AI with the business model, risk appetite and strategy (SP1) and set clear governance and accountability for AI outcomes (SP2). | Proposed; final Oct 2026 |
| ECB supervisory expectations (Machado, Feb 2026) | ECB | Clear accountability for AI decisions, senior-management oversight matching AI's strategic importance, and effective challenge from risk, compliance and internal audit — 'technology is neutral, governance is not'. | Expectation |
| ECB 'Dear CEO' letter SSM-2026-0301 | ECB | Every significant institution submits an AI-cyber action plan to its supervisory team with concrete measures, resources, named roles and timelines. | Due Oct 31, 2026 |
| BoE / FCA / HMT joint statement (May 2026) | UK (BoE / PRA / FCA) | Boards and senior management must understand frontier-AI cyber risk, and investment — including in end-of-life systems and insurance — should reflect the threat. | In force |
| EU AI Act, Article 4 (AI literacy) | EU AI Act | Providers and deployers must support the development of AI literacy among the staff who operate and use AI systems — a duty that reaches the board room as well as the first line. | Since Feb 2, 2025 |
The US federal position is deliberately not AI-specific: Vice Chair Bowman said in May 2026 that existing frameworks, regularly reviewed, should accommodate AI's evolution, and the OCC's Spring 2026 Risk Perspective observed that banks are taking a 'measured approach' to generative and agentic AI with guardrails and human-in-the-loop accountability. What that means for a board is that AI is examined through the model-risk, third-party, BSA/AML, fair-lending and cyber lenses that already exist — and that an AI program which cannot be described in those terms will not survive an examination.
Europe and the UK are more explicit about accountability. The PRA names a Senior Management Function holder; the ECB's Supervisory Board says accountability for outcomes sits with the bank regardless of how the technology performs; New York makes the CEO and CISO sign. The FSB's 12 practices, once final, will give every supervisor a common checklist — and its first two items are written for the board.
WHAT THIS MEANS IN PRACTICE
- Minute an AI risk appetite: which decisions AI may make or materially influence, at what autonomy level, and which it may not.
- Name the accountable executive for AI and model risk, and confirm internal audit has AI in its plan — supervisors ask for both by name.
- Ask for the inventory: every AI system that touches a customer decision, its owner, its vendor, and whether it sits inside or outside model risk management.
- Put AI-enabled cyber on the board calendar with a dated plan — the ECB, NY DFS and the UK authorities have each asked for one in 2026.
- Make AI literacy a board item, not only a staff item: the EU AI Act's Article 4 duty and NY DFS's training expectations both reach the top.
Which ten questions should a bank board ask about AI?
Each question comes with what a good answer contains and the documents it should reference. A management team that can answer all ten in writing has, in effect, the AI governance program supervisors describe.
| # | Ask | A good answer contains | Sources |
|---|---|---|---|
| 1 | Which of our AI systems make or materially influence decisions about customers, and who owns each one? | A written inventory with an accountable owner per system, tagged by use case (credit, fraud, AML, service, marketing) and by whether it is in-house or vendor-supplied. Materiality is the organising principle of the revised US guidance; Annex III of the EU AI Act and Colorado's ADMT Act both turn on whether a system materially influences a consequential decision. | SR 26-2 Regulation (EU) 2024/1689 SB 26-189 |
| 2 | Which of those are inside our model risk management framework, which are outside it, and what governs the ones outside? | The revised US guidance excludes generative and agentic AI by name. A good answer shows a second governance path for those tools — use-case approval, guardrails, human oversight, monitoring — rather than silence. The Treasury FS AI RMF and NIST's generative-AI profile are the frameworks banks are borrowing for that path. | OCC Bulletin 2026-13 Treasury FS AI RMF and AI Lexicon (Feb 2026) NIST AI 600-1 (Generative AI Profile) |
| 3 | If a model declines a customer, can we state the specific reasons the law requires? | Yes, with an example notice. Regulation B §1002.9 still requires specific principal reasons within 30 days; 'did not achieve a qualifying score' is expressly insufficient. The April 2026 rule removed disparate-impact liability but left this duty untouched, and Colorado's Act accepts an ECOA notice as satisfying its own explanation duty from January 1, 2027. | ECOA / Regulation B adverse action (15 U.S.C. 1691(d); 12 CFR 1002.9) Regulation B final rule on disparate impact (April 2026) SB 26-189 |
| 4 | What do we depend on from outside — models, cloud, data — and what happens if a provider fails, changes the model, or is compromised? | A map of critical AI third parties with contracts, exit plans and concentration analysis. The interagency third-party guidance sets the lifecycle; the Basel Committee's December 2025 principles make the board responsible for nth-party and concentration risk; the FSB names reliance on a few chip, cloud and model providers as a systemic vulnerability. | SR 23-4 BCBS Third-Party Risk Principles (Dec 2025) FSB AI financial stability report (Nov 2024) |
| 5 | What is our exposure to AI-enabled fraud and cyber attack, and what did we change this year? | Specific changes: phishing-resistant MFA, live verification at onboarding, deepfake training, shortened patch timelines, monitoring of AI tool outputs. FinCEN's deepfake alert, the NY DFS letters and the OCC's Spring 2026 Risk Perspective describe the threat; the ECB's July 2026 letter tells you what a plan must contain. | FIN-2024-Alert004 (Deepfake Media) DFS Frontier AI Models Industry Letter (May 2026) OCC Semiannual Risk Perspective, Spring 2026 ECB 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301) |
| 6 | Is the data feeding our models good enough that we would sign our name to it? | Evidence of lineage from model output back to source, and an honest gap list. BCBS 239 makes the board accountable for risk data; the Basel Committee's January 2026 newsletter says lineage and data culture are still 'a work in progress' at many banks and that AI depends on the same data. | BCBS 239 BCBS 239 Implementation Newsletter (Jan 2026) |
| 7 | Where are we running AI agents, at what level of autonomy, and who can stop them? | A list of agentic deployments with the human approval points and a kill switch per agent. The OCC reports banks keeping agents to specific cases with human-in-the-loop accountability; the FSB's Practice 10 asks for extra oversight of highly autonomous agents; the revised US guidance leaves agents to your broader governance. | OCC Semiannual Risk Perspective, Spring 2026 FSB AI sound practices consultation (June 2026) SR 26-2 |
| 8 | Which dates in the next eighteen months bind us, and who owns each one? | A calendar with an owner per date. For most banks: the ECB action plan (31 October 2026, significant institutions), the FSB final practices (October 2026), Colorado's ADMT Act (1 January 2027), the EU AI Act high-risk regime (2 December 2027), and New York's annual certification (15 April, every year). | ECB 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301) SB 26-189 Regulation (EU) 2026/1744 (Digital Omnibus on AI) 23 NYCRR Part 500 |
| 9 | What did our supervisors say about AI in their last examination, letter or priorities document — and what did we say back? | The actual text, not a summary. The ECB's 2026–28 priorities, the SEC's FY2026 exam priorities, the NCUA's 2026 letter (which does not mention AI at all) and the OCC's Risk Perspective each tell you the lens your examiner will use. | SSM supervisory priorities 2026–28 Division of Examinations FY2026 Priorities NCUA Letter 26-CU-01 OCC Semiannual Risk Perspective, Spring 2026 |
| 10 | How are we building AI literacy — on this board, in the executive team and in the first line? | A program with names and dates. The EU AI Act's Article 4 duty has applied since February 2025; NY DFS expects annual training to cover deepfakes and AI social engineering; the FSB's Practice 4 asks for organisational adaptability — skills and resourcing — as a governance matter. | Regulation (EU) 2024/1689 DFS AI Cybersecurity Industry Letter (Oct 2024) FSB AI sound practices consultation (June 2026) |
Which AI rules apply to my bank?
It depends on charter, size and where your customers are. The strictest rules follow the use case, not the technology; the use-case matrix maps every system type to its governing documents. This is the executive summary by footprint.
| If you are… | What applies | Authorities |
|---|---|---|
| Every US bank | ECOA / Regulation B adverse-action duties, FCRA, UDAAP, BSA/AML program expectations, interagency third-party guidance; the revised model risk guidance where model risk is significant. | CFPB FinCEN OCC |
| US banks above about $30 billion | The revised interagency model risk management guidance (SR 26-2 / Bulletin 2026-13 / FIL-15-2026) is expected to be most relevant to you; generative and agentic AI need a governance path of their own. | Federal Reserve OCC FDIC |
| New York-regulated institutions | 23 NYCRR Part 500 with the DFS AI letters layered on it: AI threats in the risk assessment, deepfake-aware training and MFA, frontier-AI preparedness, and the CEO/CISO certification each April 15. | NY DFS |
| Lending into Colorado | The Automated Decision-Making Technology Act from January 1, 2027: consumer notice, a plain-language explanation within 30 days of an adverse outcome, human review; an ECOA notice satisfies the disclosure duty. Plus the conversational-AI disclosure law for chatbots. | Colorado AI Act |
| Doing business in California | The CPPA's automated decision-making, risk-assessment and cybersecurity-audit regulations, operative January 1, 2026, for businesses in CCPA scope. | California CPPA |
| EU operations | The AI Act (credit scoring high-risk from December 2, 2027; transparency since August 2, 2026), ECB supervisory expectations and the 2026–28 priorities, DORA for the cyber and third-party side, and the October 31, 2026 action-plan deadline for significant institutions. | EU AI Act ECB EBA |
| UK operations | PRA SS1/23 model risk principles with a named accountable executive, the May 2026 joint statement on frontier-AI cyber resilience, and an outcomes-focused regime the PRA says it will build on rather than replace. | UK (BoE / PRA / FCA) |
Should a bank deploy AI agents in 2026, and what will supervisors expect if it does?
Supervisors are not stopping banks from deploying agents; they are telling banks that agents fall outside the model-risk rulebook and inside everything else. The revised US model risk guidance excludes agentic AI by name and points to the bank's broader governance; the OCC reports that banks are keeping agents to specific use cases with guardrails and human-in-the-loop accountability; the FSB's proposed practices ask for extra human oversight of highly autonomous agents and name agentic memory poisoning and AI-generated code defects as risks. The executive decision is therefore not 'agents or no agents' but which autonomy level each use case is allowed, who approves the step up, and whether the bank has one set of controls every agent inherits rather than controls rebuilt per project.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| SR 26-2 / OCC Bulletin 2026-13 | Federal Reserve | Agentic AI is 'novel and rapidly evolving' and outside model risk guidance; banks apply broader risk-management and governance practices, and an interagency request for information on AI is promised. | In force Apr 17, 2026 |
| OCC Semiannual Risk Perspective, Spring 2026 | OCC | Bank use of generative and agentic AI is 'primarily productivity and customer experience' tools with guardrails and human-in-the-loop accountability; banks may expand to material financial decisions, where governance is 'essential'. | May 7, 2026 |
| FSB Sound Practice 10 (human oversight) | FSB | Human oversight proportionate to autonomy, with additional measures for highly autonomous agentic AI; risks named include autonomous multi-step actions and agentic memory poisoning. | Proposed; final Oct 2026 |
| FPC Financial Stability in Focus + April 2026 Record | UK (BoE / PRA / FCA) | Generative and agentic AI not yet at systemically risky scale, but agentic AI 'presents particular risks' and the Bank and FCA were asked for further work on agents in payments and markets. | In force |
| BoE / FCA 2026 AI survey | UK (BoE / PRA / FCA) | The first regulator survey to cover agentic AI explicitly; its results, expected later in 2026, will be the first supervisory dataset on agent deployment in banks. | Results late 2026 |
The practical shape of that answer is an operating model rather than a policy: an identity and entitlement per agent, an action gateway that limits what agents may do, entitlement-aware data access with lineage, a budgeted and sandboxed runtime, observability, and human escalation. The agents section of this site lays out that control plane layer by layer, with every regulator's documented position on agents and a lifecycle from use-case approval to retirement.
WHAT THIS MEANS IN PRACTICE
- Adopt an autonomy ladder and require a named approver for every step up — it is the single control every supervisor's language maps to.
- Insist on a kill switch that revokes an agent's entitlements in one step, and test it.
- Ask whether new agents inherit the bank's controls by default or re-implement them; the answer tells you whether you have a platform or a pile of pilots.
The operating system for AI agents in your bank →
How can a bank executive get up to speed on AI regulation in 30 days?
Twelve primary documents in four weeks, three a week, in an order that builds: the frame, then the law, then the threat, then the dependencies. Each document has a standing page here with the direct answer first and the official source linked, and each week ends with one question to put to the executive team.
WEEK 1 · THE FRAME
Understand how supervisors think about AI risk before reading any single rule.
| SR 26-2 Federal Reserve · Apr 17, 2026 | What is inside model risk management after April 2026 — and that generative and agentic AI are outside it. |
| NIST AI RMF 1.0 NIST · Jan 26, 2023 | The Govern–Map–Measure–Manage vocabulary your risk team is using, and the seven characteristics of trustworthy AI. |
| FSB AI sound practices consultation (June 2026) FSB · Jun 10, 2026 | The 12 practices that will become the global checklist; read Practices 1–4 as if addressed to you, because they are. |
Then: Ask the CRO which of the 12 FSB practices the bank could evidence today.
WEEK 2 · WHAT BINDS YOU
Know the law that already applies to AI decisions about your customers.
| ECOA / Regulation B adverse action (15 U.S.C. 1691(d); 12 CFR 1002.9) CFPB · Oct 28, 1974 | The 30-day specific-reasons duty that applies identically to a model and a human underwriter. |
| Regulation (EU) 2024/1689 EU AI Act · Jul 12, 2024 | Why credit scoring is high-risk, what a deployer must do, and the December 2, 2027 date. |
| 23 NYCRR Part 500 NY DFS · Nov 1, 2023 | The certification you or your CISO sign, and the risk assessment that DFS's AI letters hang on. |
Then: Ask general counsel for the list of jurisdictions where the bank's AI decisions carry a notice or explanation duty.
WEEK 3 · THE THREAT SIDE
See AI as the attacker's tool, and know what regulators asked for in 2026.
| FIN-2024-Alert004 (Deepfake Media) FinCEN · Nov 13, 2024 | How deepfake identity documents defeat onboarding, and the red flags FinCEN lists. |
| ECB 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301) ECB · Jul 7, 2026 | What an AI-cyber action plan must contain — measures, resources, named roles, timelines. |
| FSB Chair's letter to G20 (Aug 2026) FSB · Aug 31, 2026 | Why frontier models are now a financial-stability concern, and what firms are asked to do. |
Then: Ask the CISO how many days it takes to patch an internet-facing system, and what the target is.
WEEK 4 · DATA, VENDORS, AGENTS
Follow the dependencies: the data AI learns from, the providers it runs on, the agents it becomes.
| BCBS 239 Basel Committee · Jan 9, 2013 | The 14 principles behind every supervisory question about the data feeding your models. |
| BCBS Third-Party Risk Principles (Dec 2025) Basel Committee · Dec 10, 2025 | Board responsibility for third-party risk, now including nth-party supply chains and provider concentration. |
| OCC Semiannual Risk Perspective, Spring 2026 OCC · May 7, 2026 | The regulator's own description of how banks are using generative and agentic AI, and where it sees the risk. |
Then: Ask the CIO which AI vendors are critical, and whether each has an exit plan that has been tested.
12 documents · all 164 in the library →
Which AI regulatory dates should be on the board calendar?
| Date | Authority | What |
|---|---|---|
| Oct 20, 2026 | CFTC | CFTC Compute Derivatives RFC: comment period closes · Comment deadline |
| Oct 26, 2026 | Colorado AI Act | Colorado AG proposed ADMT rules: comment period closes · Comment deadline |
| Oct 31, 2026 | ECB | Deadline for significant institutions to submit AI-cyber action plans to their JSTs · Milestone |
| Nov 20, 2026 | EU AI Act | Consumer Credit Directive (EU) 2023/2225 takes effect · Takes effect |
| Jan 1, 2027 | Colorado AI Act | SB 26-189 takes effect · Takes effect |
| Jan 1, 2027 | Colorado AI Act | HB 26-1263 takes effect · Takes effect |
Recomputed daily from the tracker. The full calendar → · The checklist, quarter by quarter →
Is there an AI regulation for banks?
Not a single one. The EU AI Act is the only binding cross-sector AI law that reaches banks, and its high-risk obligations for credit scoring apply from December 2, 2027. Everywhere else, AI in banking is governed by existing law and guidance — fair lending, model risk, third-party risk, BSA/AML, cybersecurity — applied to AI systems, plus state laws such as Colorado's ADMT Act. This tracker follows 19 authorities and every document they have published on the subject.
Does the board need AI training?
In the EU, supporting staff AI literacy has been a legal duty under Article 4 of the AI Act since February 2, 2025. In New York, DFS expects annual cybersecurity training to cover deepfakes and AI social engineering. The FSB's proposed practices treat skills and resourcing as a governance matter. None of these names the board specifically, but each is difficult to evidence if the board itself cannot describe the bank's AI risk in its own words — which is what this briefing is for.
How long does this briefing take?
The page itself is a single sitting. The 30-day plan is twelve primary documents over four weeks — each has a standing page on this site with the direct answer first, the key points, and a link to the official source, so a reading takes minutes rather than an afternoon. The tracker's deadlines calendar and compliance checklist then keep the dated items current without any further reading.
How does this briefing stay current?
The dates and deadlines on this page are computed daily from the tracker's document data, and every new regulatory document is added as a standing page the week it appears. The daily brief carries each regulatory move the morning after it happens; subscribing is the simplest way to keep this briefing current without re-reading it.
This briefing keeps itself current — every morning
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →