For two decades, bank model governance rested on a stable idea: a model produces an estimate, a person decides. Validation, monitoring and challenge were built around that separation. Agentic AI dissolves it. An agent can read a file, call a system, write a record and trigger the next step without a person in between — and its behaviour can change with a prompt, a tool or a new piece of context rather than a retrained parameter.
Supervisors are responding, but not in unison. That makes it tempting to wait for the rules to settle. We think that would be a mistake: the underlying control disciplines are converging even where the legal texts are not.
Where the rulebook stands
European Union. The AI Act classifies AI systems used to evaluate the creditworthiness of natural persons or establish their credit score as high-risk, with an exception for systems used to detect financial fraud3. Regulation (EU) 2026/1744 — the Digital Omnibus on AI — was published on 24 July 2026 and entered into force on 27 July 2026, deferring obligations for stand-alone Annex III high-risk systems from 2 August 2026 to 2 December 2027, and for AI embedded in regulated products to 2 August 20281. Prohibited practices and AI literacy obligations have applied since 2 February 2025, and general-purpose AI obligations since 2 August 20252. Breaches of high-risk and other operator obligations can attract fines of up to €15 million or 3% of worldwide annual turnover, and prohibited practices up to €35 million or 7%3.
Key AI governance milestones for banks
Selected regulatory and standards dates
| Date | Instrument | Why it matters for banks |
|---|---|---|
| 26 Jan 2023 | NIST AI Risk Management Framework 1.0 | Voluntary Govern–Map–Measure–Manage structure used widely in US programmes8 |
| Dec 2023 | ISO/IEC 42001 | Certifiable AI management system standard9 |
| 17 May 2024 | PRA SS1/23 takes effect | UK model risk principles, explicitly covering AI/ML where used in models6 |
| 2 Feb 2025 | EU AI Act prohibitions and AI literacy | Already applicable2 |
| 2 Aug 2025 | EU AI Act general-purpose AI obligations | Already applicable2 |
| 13 Nov 2025 | MAS AI risk management guidelines (consultation) | Explicitly covers generative AI and AI agents7 |
| 17 Apr 2026 | US SR 26-2 / OCC 2026-13 replace SR 11-7 | Principles-based; generative and agentic AI excluded pending an RFI45 |
| 27 Jul 2026 | EU Digital Omnibus on AI in force | Defers high-risk deadlines1 |
| 2 Dec 2027 | EU AI Act Annex III high-risk obligations | Includes credit scoring and creditworthiness13 |
Source: K&L Gates (Cyber Law Watch), “EU Digital Omnibus on AI enters into force” (2026)
United States. On 17 April 2026 the Federal Reserve, OCC and FDIC replaced SR 11-7 and related guidance with a revised, risk-based framework (SR 26-2), most relevant for Federal Reserve-supervised organisations with more than $30 billion in assets4. The agencies stated that generative and agentic AI models are novel and rapidly evolving and are excluded from the guidance's scope, and committed to a request for information on AI model risk5. In practice this leaves agentic AI governed by general safety-and-soundness, third-party and operational-risk expectations while specific guidance is developed.
United Kingdom and Asia. The PRA's SS1/23 model risk principles took effect on 17 May 2024 and apply expressly to AI and machine-learning techniques used in models6. In Singapore, MAS's proposed AI risk management guidelines, issued for consultation in November 2025, cover AI agents explicitly and expect board oversight, accurate AI inventories, risk-materiality assessment and proportionate lifecycle controls, including human oversight7.
The industry starting point
Governance maturity lags deployment. In the Bank of England and FCA's 2024 survey of 118 firms, 75% were already using AI, but 46% reported only a ‘partial understanding’ of the AI technologies they use — driven partly by third-party models, which made up a third of use cases10. Published 2026 AI trust research found average responsible-AI maturity rising to 2.3 (from 2.0) on a four-point scale, but only about one-third of organisations at level three or higher in strategy, governance and agentic AI controls; nearly two-thirds named security and risk concerns as the top barrier to scaling agents11.
UK financial services: AI use is outpacing understanding
Share of respondent firms or of AI use cases, %, 2024 (%)
Note: Third-party share reported as 'a third' of use cases.
Third-party dependency makes this harder. Most banks will run agents on foundation models they did not build and cannot fully inspect, often through software vendors who embed AI in products the bank already owns. That shifts emphasis from inspecting model internals to testing behaviour: structured evaluation before deployment, continuous monitoring after it, contractual rights to information and change notification, and the ability to swap or suspend a model provider without stopping the business process.
Why agents break classic model risk management
- They act, not advise. The risk shifts from a wrong estimate that a person can catch to a wrong action that has already happened.
- They are composite. An agent is a foundation model plus prompts, tools, retrieval and memory; each can change independently of the others.
- They are often third-party. Banks validate behaviour they cannot fully inspect, which puts weight on testing, monitoring and contractual controls.
- They multiply. Inventories built for hundreds of models must now track agents, their entitlements and their supervisors.
A control framework that travels
The practical answer is one framework mapped to many regimes. NIST's AI RMF provides the Govern, Map, Measure and Manage structure8; ISO/IEC 42001 provides a certifiable management system around it9. Within that, five controls do most of the work for agents:
- Unified inventory and tiering of models and agents, with materiality driving the depth of validation.
- Autonomy levels — observe, recommend, act with approval, act within limits — each with entry criteria and named owners.
- Kill switches and circuit breakers that suspend an agent or revoke its credentials instantly, tested like any other resilience control.
- Complete audit trails of inputs, retrieved context, tool calls, outputs and human approvals, retained to regulatory standards.
- Continuous evaluation against golden test sets and live outcome metrics, with drift and incident thresholds.
The question an examiner will ask about an agent is the same one they ask about a trader: who authorised it to do that, and how would you know if it stopped behaving? (SCIKIQ view)
None of this requires waiting for final rules. A bank that can produce, on request, a complete list of its models and agents, the autonomy each is permitted, the human accountable for each, and a reconstructable record of what each did last Tuesday is well placed under any of the regimes described here. A bank that cannot will struggle under all of them.