AskAjay.ai

Reference

13 min read · ·

Nine Regulators, One Control Set for Bank AI

SR 26-2 leaves generative AI and agents out of US model risk guidance; Singapore’s draft names them, so build to the strictest bar.

Ajay Pundhir
Ajay PundhirAI Strategist & Speaker
Share
Seven translucent grey slabs stacked in staggered rows, with one solid dark blue slab near the bottom. A thin gold upright marks the blue slab’s left edge.
Art: AskAjay.ai house pattern, 'Strata' variant

Key Takeaways

  • →SR 26-2, issued on 17 April 2026 by the Federal Reserve, OCC and FDIC, replaced SR 11-7. It puts generative and agentic AI outside its scope and says non-compliance with it will not bring supervisory criticism.
  • →From 21 July 2026, Regulation B says the Equal Credit Opportunity Act does not provide an "effects test". The duty to give specific reasons for a credit denial is unchanged.
  • →Under the EU AI Act, AI used for credit scoring is high-risk from 2 December 2027, enforced, by default, by the bank’s own financial supervisor.
  • →Canada’s OSFI Guideline E-23 covers AI models at every federally regulated institution from 1 May 2027. Singapore’s proposed guidelines name generative AI and AI agents.
  • →A bank lending across these markets should run one set of controls built to the strictest bar, add local overlays where rules differ in kind, and map it to each regulator.

A bank’s credit model answers to every regulator in every market where the bank lends. In 2025 and 2026 those regulators moved apart: US banking agencies made their model risk guidance lighter and left generative AI and agents out of it, while Europe, Canada and Singapore wrote AI into theirs.

My argument is that a bank lending in more than one of these markets should run one set of controls, built to the strictest bar any of its regulators sets, and map that set to each of them, rather than one programme per regulator or a bet on the US relief lasting. Most of the controls the regulators ask for overlap, and what differs is how high each sets the bar. A few duties exist in only one regime, and a few point in different directions; those become local overlays. This reference is for the chief risk officer or head of model risk at such a bank, not for a US-only lender under $30 billion in assets. It is a practitioner’s reading of public texts, not legal advice.

Updated 6 October 2026: rebuilt as a reference around the regulators, with every instrument re-read at its source. The changes are listed at the end.

What Washington Changed in 2026

On 17 April 2026 the Federal Reserve, the OCC and the FDIC issued revised guidance on model risk management, as SR 26-2, OCC Bulletin 2026-13 and FIL-15-2026. It "supersedes and replaces" SR 11-7, the 2011 guidance that became the global reference for model risk, and SR 21-8 on anti-money-laundering models. Three changes matter for AI.

  • It is lighter. The guidance says it "does not set forth enforceable standards or prescriptive requirements" and that "non-compliance with this guidance will not result in supervisory criticism". Supervisory action can still follow from violations of law or unsafe practices. It is "most relevant" to banks with more than $30 billion in assets. The OCC also rescinded its 1997 examination guidance on credit scoring models (Bulletin 1997-24).
  • It is risk-based. Effort follows a model’s materiality, which the guidance builds from its exposure (how much the bank’s decisions rely on it) and its purpose. It keeps "effective challenge": review by people with the expertise, independence and "organizational standing and influence to effect any change".
  • It leaves generative AI and agents out. Footnote 3: "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance." Traditional models and "non-generative, non-agentic AI models" stay in. The OCC bulletin adds that the agencies plan a request for information on banks’ use of AI, "including generative AI and agentic AI".

Consumer credit law moved the same way. In May 2025 the CFPB withdrew many of its guidance documents, among them Circulars 2022-03 and 2023-03 on adverse action notices, the first written for credit decisions based on complex algorithms. On 22 April 2026 it amended Regulation B, effective 21 July 2026, so that section 1002.6 now reads: "The Act does not provide that the 'effects test' applies for determining whether there is discrimination in violation of the Act." The final rule reads the Act as giving no disparate-impact liability at all, which removes the CFPB’s usual route to a bias claim against a lending algorithm. It does not remove every route: the rule itself notes that lenders remain subject to the Fair Housing Act and to state laws similar to the Act, and a regulation’s reading of a statute binds the agency, not the courts.

Two things did not move. Section 1002.9 still requires "a statement of specific reasons for the action taken", and still says reasons such as failing "to achieve a qualifying score on the creditor's credit scoring system" are insufficient. And the states kept their own laws. In July 2025 the Massachusetts Attorney General settled with Earnest Operations, a student lender, for $2.5 million. Her office alleged that a "Cohort Default Rate" variable in Earnest’s algorithmic model "resulted in disparate impact in approval rates and loan terms", with Black and Hispanic applicants more likely to be penalised, and that Earnest had failed "to test its models for disparate impact". Federal guidance got lighter and the CFPB dropped the effects test. State law did not change.

What the Other Regulators Expect

The EU AI Act lists as high-risk any AI system "intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud" (Annex III, point 5(b)), and AI used to price life and health insurance (point 5(c)). After the Digital Omnibus, Regulation (EU) 2026/1744, those duties apply from 2 December 2027. That date is itself a deferral: the Omnibus moved the high-risk duties back from August 2026 and simplified parts of the Act. Deployers of both kinds must also assess the impact on fundamental rights before use (Article 27). Annex III turns on what a system is used for, not how it is built, so on my reading a large language model that scores credit is as high-risk as any other model doing that job.

Who enforces it matters more than the date. Under Article 74(6), for AI systems used by banks "in direct connection with the provision of those financial services", the market surveillance authority is "the relevant national authority responsible for the financial supervision of those institutions". By default, then, the AI Act regulator is the bank’s own supervisor, though a member state may name another authority if it ensures coordination (Article 74(7)). The Act also folds itself into banking law: a bank that builds a high-risk system meets most of the quality-management duty by complying with its internal-governance rules under financial services law (Article 17(4)), and a bank that deploys one meets the monitoring duty the same way (Article 26(5)).

The European Banking Authority mapped the Act against EU banking law in November 2025 and found "no significant contradictions". The Act is "complementary" to banking law, "which already provides a comprehensive framework to manage risks", the EBA wrote, though "the co-existence of multiple authorities" means supervisors must cooperate. The EBA says the mapping is not "guidance or supervisory expectations", and it saw no "immediate need" for new guidelines. DORA, applicable to banks since 17 January 2025, covers the AI a bank buys: a bank using ICT services "shall, at all times, remain fully responsible for compliance" with its obligations (Article 28(1)(a)).

In the UK, the Prudential Regulation Authority’s SS1/23, in effect since 17 May 2024, applies to UK-incorporated banks with internal model approval for capital. It names a senior manager accountable for model risk and covers AI "to the extent that it applies to the use of models more generally", for models "regardless of technology". The Financial Conduct Authority, which supervises the same banks’ conduct, says it does not plan to introduce extra regulations for AI; its AI Update of 2024 sets out how existing rules, including the Consumer Duty in effect since July 2023, apply to AI. Canada’s OSFI published Guideline E-23 on 11 September 2025, effective 1 May 2027 for every federally regulated financial institution. It defines a model to include "AI/ML methods" and asks validators to evaluate "the level of explainability" of AI models. Singapore’s MAS set out its FEAT principles in 2018 and in November 2025 proposed Guidelines on AI Risk Management for all financial institutions. The draft names generative AI and AI agents, and proposes a 12-month transition after it is issued. The consultation closed on 31 January 2026.

The Nine Regulators, Side by Side

For a bank that lends in the United States, the EU, the UK, Canada and Singapore, nine regulators supervise it or enforce rules against it and have published rules or guidance that reach its credit model. This is what each has said about the newest AI.

RegulatorGenerative AI and agentsWhat it has published
Federal Reserve

Out of scope

SR 26-2, 17 April 2026: model risk guidance, not enforceable standards

OCC

Out of scope; a request for information is planned

Bulletin 2026-13, the same guidance

FDIC

Out of scope

FIL-15-2026, the same guidance

CFPB

Covered: the duty applies whatever the model

Regulation B: specific reasons for every denial; no effects test from 21 July 2026

EU financial supervisor (home state)

Covered: any AI system used for credit scoring

Enforces the AI Act for banks by default (Article 74(6)); credit scoring high-risk from 2 December 2027; DORA since 17 January 2025

Prudential Regulation Authority (UK)

Covered where the system is a model

SS1/23, in effect since 17 May 2024, for banks with internal model approval

Financial Conduct Authority (UK)

Covered by existing conduct rules

AI Update, 2024: existing rules, including the Consumer Duty, apply to AI; no extra AI rules planned

OSFI (Canada)

Covered: its model definition includes AI/ML methods

Guideline E-23, effective 1 May 2027

MAS (Singapore)

Named in the draft

FEAT principles, 2018; proposed AI risk guidelines, November 2025

Read down the second column and the gap is in one place. Only the MAS draft names generative AI and agents. The AI Act reaches them by use, OSFI by definition, the PRA where they work as models, and Regulation B and the FCA’s conduct rules reach whatever system makes the decision. The three US banking agencies, writing one shared text, are the only ones that set them aside. A bank that sizes its controls for generative AI to SR 26-2 is sizing them to the three regulators on the list that have not yet said what they expect.

One Control Set, Built to the Strictest Bar

The nine documents use different words for a short list of controls. Run each control once, to the highest bar among your regulators, add local overlays where a rule differs in kind or conflicts, and keep a map showing which clause each control answers. Seven controls cover most of what the nine ask for.

  1. One inventory, including what US guidance leaves out. SR 26-2 describes a model inventory as "common industry practice"; SS1/23 starts with model identification; OSFI and the MAS draft expect the same. Put generative tools, agents and vendor models in the same list, because Europe and Singapore will ask for them even though Washington does not.
  2. Tier by materiality, then by who is affected. SR 26-2 tiers by exposure and purpose. Add a second test the US guidance lacks: does the system decide something about a person? Under the AI Act, credit scoring and life and health insurance pricing are high-risk however small the portfolio.
  3. Independent challenge with power. Effective challenge in SR 26-2, independent validation in SS1/23 and validation in E-23 describe the same function. Staff it once, with people who can stop a model, and give them the generative and agent systems too.
  4. An explanation ready on the day of challenge. Regulation B requires specific reasons for every denial; in the EU, the GDPR already reaches credit scores, as The GDPR Was Not Written for AI. It Governs It Anyway explains. Build the explanation into the system before launch, not into the complaints process after it.
  5. Fairness testing kept after the federal effects test went. The Massachusetts settlement turned on a variable that produced a disparate impact and on a failure to test for one. The AI Act requires providers, though not deployers, to examine training data "in view of possible biases" that could lead to prohibited discrimination (Article 10(2)(f)), and fairness is the first of the FEAT principles. Keep testing for disparate impact across every market, even in the one that stopped requiring it. Testing is lawful everywhere; remedies differ. The same US rule bars for-profit special purpose credit programmes from using race, colour, national origin or sex as eligibility criteria, and the EU lets deployers use sensitive data for bias work only under strict conditions, without obliging them to (Article 4a). Fix a finding first by changing the model, as Earnest agreed to stop using its default-rate variable, and decide any group-conscious remedy market by market.
  6. Vendor models under the same rules. SR 26-2 says the principles of model risk management "remain applicable" to vendor products, and DORA keeps the bank "fully responsible". On 15 September 2026 the US agencies proposed new third-party risk guidance, open for comment until 16 November 2026. The AI That Hurts You Is Not the AI You Own sets out the contract terms.
  7. A plan now for the systems SR 26-2 left out. SR 26-2 itself says a bank’s risk management "should guide" controls for systems it does not cover. The MAS draft is the most detailed public text on what those controls look like. Use it as the working standard until the US request for information produces something.

The three lines most banks run still fit: the business owns the model, the risk function challenges it, and internal audit, in SR 26-2’s words, evaluates "whether the model risk management practices are rigorous and effective". What changes is scope. The second line now has to challenge systems that write text and take actions, and audit has to test whether that challenge changed anything.

What the Enforcement Record Teaches

The best-known bank AI case is usually told wrongly. In November 2019 a customer posted that Apple Card had given him 20 times his wife’s credit limit, and New York’s Department of Financial Services investigated. In March 2021 it reported that its analysis of underwriting data for about 400,000 applicants "did not produce evidence of unlawful discrimination". The money came later and for something else. In October 2024 the CFPB ordered Goldman Sachs Bank USA to pay a $45 million civil penalty and $19.8 million in redress, and Apple a $25 million penalty, for failures in handling transaction disputes and in enrolling customers in Apple Card Monthly Installments. The CFPB terminated Apple’s order on 22 September 2025; on 6 October 2026 its page still listed Goldman’s as "Post Order/Post Judgment".

Read together with Earnest, the record makes two points. Regulators fined the systems around the model, the disputes and the notices, as readily as the model itself, so a control set that stops at validation misses where the penalties landed. And the bias case that ended in a settlement was brought by a state, under state law, against a lender that had not tested its models. Neither lesson depends on which federal agency is in charge this year.

Where This Argument Is Weakest

The first objection is cost. A US-only bank under $30 billion in assets is, by SR 26-2’s own words, mostly outside its main audience, and building to Europe’s bar would waste its money. I agree. The argument is for banks that lend in more than one of these markets, where the strictest regulator sets the bar whatever the others do.

The second is that nine is this bank’s footprint, and a different map gives a different count. If its EU arm is a significant bank, the European Central Bank supervises it directly and makes ten. The European Banking Authority writes EU banking guidelines but supervises no bank, so it is not counted. And a US state attorney general can act without any of them, as Massachusetts did. The number changes with the map. The argument holds: every regulator added makes one control set worth more.

The third is timing. The MAS guidelines are still a draft, the AI Act’s high-risk duties start in December 2027, OSFI’s in May 2027, and the US request for information has not been published. A bank could wait for all of them. But the inventory, the challenge function and the explanations take longer to build than any of those deadlines leave, and none of them will be wasted whichever way the drafts land.

Sources and Changes

All sources checked on 6 October 2026.

Changes on 6 October 2026. Cut from about 5,300 words to a reference under a new headline (formerly "Responsible AI in Financial Services: The Governance Framework for Banks and Insurers"). The piece is now built around the regulators and their own texts. Removed: statements that SR 26-2 cites the three lines of defence, a Treasury framework with 230 control objectives and survey figures that could not be traced to a primary source, the 20-point checklist, the insurance, trading and chatbot sections, and a download box pointing to a missing file. Added: what SR 26-2 leaves out, the 2026 Regulation B rule, OSFI E-23, the PRA’s SS1/23, the FCA’s approach to AI, the MAS draft guidelines and the EBA’s mapping. The correction of 4 October 2026 on the Apple Card penalties stands: New York found no unlawful sex discrimination, and the 2024 CFPB orders were for dispute handling and instalment enrolment.

Questions readers ask

Does SR 26-2 cover generative AI or AI agents?

No. The guidance attached to SR 26-2 says generative and agentic AI models "are novel and rapidly evolving" and "are not within the scope of this guidance". It still expects a bank’s own risk management and governance practices to guide controls for those systems, and OCC Bulletin 2026-13 says the agencies plan a request for information on banks’ use of AI, "including generative AI and agentic AI".

Is a bank credit-scoring model high-risk under the EU AI Act?

Yes, if it is an AI system. Annex III, point 5(b) of the AI Act lists AI systems used "to evaluate the creditworthiness of natural persons or establish their credit score", with an exception for fraud detection. After the Digital Omnibus, the high-risk duties for Annex III systems apply from 2 December 2027. For banks, the market surveillance authority is by default the national financial supervisor (Article 74(6)), though a member state may name another authority (Article 74(7)).

Do US lenders still have to explain AI credit denials?

Yes. Regulation B, section 1002.9, requires a statement of specific reasons for adverse action, and says that failing "to achieve a qualifying score on the creditor's credit scoring system" is not enough. The CFPB withdrew its 2022 and 2023 circulars on complex algorithms in May 2025, but the regulation itself did not change.


Ajay Pundhir
Ajay Pundhir

Senior AI strategist helping leaders make AI real across four continents. Forbes Technology Council member, IEEE Senior Member.

Let's Talk

Ajay's views, from 15 years in the field. Not legal or compliance advice. See full disclaimers →
Published by AI Exponent LLC

Get The Brief

Original thinking on AI strategy, governance, and durability. Every other Tuesday.