Diagrid
Back to Infrastructure
compliancegovernance

The 2026 Compliance Checklist for AI Agents in Banking

As of August 2026, a bank deploying AI agents faces five live obligations and one governance vacuum. The requirements that remain are operational, which means they land on infrastructure rather than on a model-validation document.

Tony Graham

Tony Graham

Director, Product Marketing

August 31, 202616 min read

The short answer. As of August 2026, a bank deploying AI agents faces five live obligations and one governance vacuum. Live: EU AI Act Article 50 disclosure, in force since 2 August 2026; DORA's four-hour major-incident notification clock; DORA's contractual audit and data-residency requirements; SEC Rule 17a-4 recordkeeping for agent communications; and ECOA adverse action notices, which survived the April 2026 Regulation B rewrite. The vacuum: US model risk guidance SR 11-7 was replaced on 17 April 2026 by guidance that explicitly excludes generative and agentic AI from scope, and the EU AI Act's high-risk obligations covering credit scoring were deferred to 2 December 2027. The obligations that remain are operational, which means they land on infrastructure rather than on a model-validation document.

I talk to financial-services CTOs about agent deployments most weeks, and the most common thing I hear is a version of "we're waiting for the rules to settle." That's the wrong read of 2026, because the two things that moved this year both moved away from you.

What changed in 2026?

First: the EU AI Act's high-risk obligations, the ones covering creditworthiness scoring, were deferred to 2 December 2027 by the Digital Omnibus regulation. That is not relief. It is fifteen extra months during which the standards that would tell you what "compliant" means remain in draft at CEN-CENELEC. Harmonised standards confer a presumption of conformity; their lateness is a documented driver of the deferral. The deadline moved because the rulebook wasn't finished, not because the risk went away.

Second, and larger for US institutions: SR 11-7 is gone. On 17 April 2026 the federal banking agencies replaced it with SR 26-2 and OCC Bulletin 2026-13. Read the scope sentence twice:

"Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance."

Fifteen years of model risk practice, including validation, developmental evidence and independent challenge, no longer formally applies to the technology you are deploying. The agencies expect "broader risk management and governance practices" instead. Federal Reserve Vice Chair for Supervision Michelle Bowman confirmed the narrowing in a speech on 1 May 2026: "The revised guidance now applies narrowly to traditional models and basic AI applications."

Three details compound it. The revised guidance drops the annual validation cadence that SR 11-7 required. It applies a uniform $30 billion asset threshold across all three agencies. And it takes a lighter approach to vendor models, focused on understanding and monitoring rather than developmental evidence and independent validation. An interagency request for information covering gen-AI and agentic AI was promised in April; as of late August I can find no Federal Register publication of it.

So the obligation didn't disappear. It moved into a space where nobody has a template. Which is why the surviving requirements deserve your attention: they are all operational, and they all land on infrastructure.

What is live today?

Article 50 of the EU AI Act took effect on 2 August 2026. If a customer is talking to your agent, they must be told, "at the latest at the time of the first interaction," unless it would be obvious to a reasonably well-informed person. In Germany, BaFin is already the market surveillance authority for exactly this, for financial firms, now, and its remit extends to prohibited practices and staff competence. Penalties under Article 99 have applied since August 2025: up to €15m or 3% of worldwide turnover for operator breaches, and up to €35m or 7% for prohibited practices.

How fast must you report an AI agent incident?

This is the number most agent programmes have not planned for. Under DORA, a major ICT incident requires initial notification within four hours of classification as major, and no later than 24 hours from awareness; an intermediate report at 72 hours; a final report within a month (Austrian FMA, on Commission Implementing Regulation (EU) 2025/302).

Compare the AI Act's serious-incident clocks: fifteen days generally, two days for widespread infringements or critical infrastructure, ten days where a death has occurred. An agent failure that degrades a critical or important function is usually both an ICT incident and an AI incident, and the ICT clock governs. Build to four hours.

Four hours has an architectural consequence. You cannot classify severity in four hours from raw logs and a Slack thread. You need impact telemetry that can answer, in minutes, which customers were affected, which function degraded, and whether the agent completed or abandoned work mid-flight. That is a property of the runtime, not of the incident-response runbook.

The contract clause to go and read

DORA Article 30(3)(e) requires, for critical or important functions, "unrestricted rights of access, inspection and audit by the financial entity, or an appointed third party, and by the competent authority." Article 30(2)(b) requires the contract to name the regions or countries where functions are provided and where data is processed and stored. Article 30(3)(f) requires a mandatory transition period on exit, and Article 28(8) requires documented exit strategies covering provider failure, service deterioration and termination, with identified alternatives.

Go and check whether your frontier-model API terms grant any of that. In my experience they mostly grant the residency clause and not the audit clause. This is the concrete gap between "we call a model API" and "we are DORA-compliant."

Worth knowing where the model layer actually sits in your register. When the European Supervisory Authorities designated the first critical ICT third-party providers in November 2025, the list named AWS, Google Cloud, Microsoft, Oracle, IBM and SAP, and no pure-play model provider. Frontier models reach EU banks wrapped inside cloud contracts that are already under oversight. That is either reassuring or a blind spot, depending entirely on whether your register of information captures the model and agent layers separately from the infrastructure beneath them. Your next examination will ask.

The regulator who has actually described agents

FINRA's 2026 Annual Regulatory Oversight Report, published December 2025, is the clearest statement anywhere. It defines agents as systems "capable of autonomously performing and completing tasks on behalf of a user," flags "AI agents acting autonomously without human validation and approval," and warns about agents acting "beyond the user's actual or intended scope and authority" and about "difficult-to-audit complex processes."

Then it names the controls: human-in-the-loop oversight protocols, "guardrails or control mechanisms to limit or restrict agent behaviors, actions or decisions," and monitoring comprising "prompt and output logging, model version tracking, and human-in-the-loop validation." That is an infrastructure specification written by a regulator. It also restates the principle that governs everything else: FINRA's rules are technology-neutral and "continue to apply when firms use GenAI or similar technologies."

It pairs with 17 CFR 240.17a-4, which since the 2022 amendment permits electronic records either in WORM format or in a system maintaining "a complete time-stamped audit trail" including "all modifications to and deletions of the record" and "the date and time of actions that create, modify, or delete the record." Communications are retained three years, the first two easily accessible; certain records six. An agent's prompt, decision and tool-call sequence is a record when it constitutes a communication sent or received, and that audit-trail alternative is, almost word for word, a description of an append-only event log.

The logging clause worth exploiting

Here is a piece of the AI Act that rewards reading closely. Article 12 requires high-risk systems to "technically allow for the automatic recording of events (logs) over the lifetime of the system." Article 26(6) requires deployers to keep those logs for "at least six months."

Then it adds this, for you specifically: deployers that are financial institutions subject to internal governance requirements under Union financial services law "shall maintain the logs as part of the documentation kept pursuant to the relevant Union financial service law."

Read that as an invitation. You are not being asked to stand up a parallel AI log store with its own retention policy, access model and audit trail. You are being told to fold agent logs into the regulated recordkeeping you already operate, defend and get examined on. Banks that build a separate "AI observability" silo are creating a second system of record to be asked about. Banks that route agent execution history into existing retention are answering two regimes with one artefact.

The controls that arrive in December 2027, which procurement will ask about in 2026

The high-risk obligations are deferred, not cancelled, and they are specific about mechanism. Article 14(4)(e) requires the ability "to intervene in the operation of the high-risk AI system or interrupt the system through a 'stop' button or a similar procedure that allows the system to come to a halt in a safe state." Note "safe state," not "terminated": killing a process mid-transaction is not compliance. Article 14(4)(d) requires the ability to "disregard, override or reverse the output." Article 14(4)(b) requires oversight designed against automation bias. Article 26(2) requires human oversight assigned to named people with "the necessary competence, training and authority." Article 26(5) requires suspending use and notifying the authority when a risk emerges. Article 86 gives affected people a right to "clear and meaningful explanations of the role of the AI system in the decision-making procedure."

None of that is a policy document. A stop button that halts safely, an override that reverses an action, and an explanation of a decision sequence are all runtime capabilities. If you procure an agent platform in 2026 without them, you are buying a 2027 remediation project.

On the US consumer side, less changed than the headlines suggest

The April 2026 Regulation B amendments removed the effects test and disparate-impact liability under federal ECOA. But per the National Consumer Law Center, the adverse action provisions at § 1002.9 were "untouched." If an agent contributes to a denial, you still owe specific principal reasons under 15 U.S.C. § 1691(d). Disparate impact also survives under the Fair Housing Act for residential lending and under state fair-lending law, and FCRA duties continue to bite where agent outputs feed consumer reports.

If you are a global bank, your scope is not uniform

This is the trap. The US narrowed model risk management to exclude gen-AI and agentic AI. The UK did not. The Bank of England's April 2026 letter to the Treasury Committee reaffirms building on the 2023 Model Risk Management Principles, SS1/23, commits to AI-specific stress testing by end-2026, and records that the Financial Policy Committee asked regulators to do further work on "agentic AI, focused on use cases in payments and financial markets." A UK subsidiary of a US group may therefore sit inside a broader model risk perimeter than its parent.

Singapore is heading the same way: MAS consulted on Guidelines on AI Risk Management with a proposed twelve-month transition after issuance, requiring firms to "identify, inventorise, and assess the risk materiality of all AI use cases, systems, or models," and its industry consortium published an executive handbook in January 2026 that explicitly addresses agentic AI and traceability. Hong Kong launched a joint GenA.I. Sandbox++ across the HKMA, SFC, Insurance Authority and MPFA in March 2026.

And at the global level the Financial Stability Board's June 2026 consultation on sound practices says the part everyone has been avoiding: "AI agents pose a distinct challenge for human oversight, given the impracticality of real-time human monitoring of agent decisions as their use scales." Its twelve practices include explainability, human oversight and third-party risk, and it recommends "chain-of-thought logging to help explain outputs."

Where the sector actually is

Two datasets are worth having in front of a board. The Cambridge Centre for Alternative Finance's 2026 report, surveying industry alongside 130 central banks and regulators across 151 jurisdictions, found 81% of financial services firms adopting AI at some level and 52% reporting some level of agentic AI adoption, with 23% actively deployed. The governance side of the same survey is the uncomfortable half: only about 50% of industry respondents have adopted explainable AI methods while 79% of regulators rate explainability critical or important; 55% of industry find it difficult to measure the value of AI deployment, rising to 76% among large institutions; and about two-thirds are not monitoring for bias or arbitrary discrimination.

The ECB puts adoption higher still. Pedro Machado, ECB representative to the Supervisory Board, February 2026: "more than 85% of them already use AI in some form," alongside the sentence I would put on the wall of any AI governance committee: "If a bank cannot explain why an AI model behaves the way it does, in terms that are meaningful for decision-making, then it cannot truly control that model."

Set against that, the cross-industry operational picture. The Cloud Security Alliance, with Token Security, reported in April 2026 that 65% of organisations had at least one security incident related to AI agent use in the past year, and 82% discovered previously unknown agents on their networks, while only 20% have a formal process for decommissioning an agent. That is a vendor-affiliated survey and not bank-specific, so weight it accordingly, but the shadow-agent finding maps onto a DORA register obligation with uncomfortable precision. You cannot register what you have not discovered.

And the honest part

I could not find a single enforcement action, consent order, or published supervisory finding against a bank arising from an autonomous AI agent. Not one, anywhere, in 2025 or 2026.

The four financial-sector AI enforcement actions on record are AI-adjacent. The largest is Two Sigma's $45m over unauthorised access to trading model parameters, where a modeller made unauthorised changes to fourteen live-trading models. That is a change-management and access-control failure rather than an AI one, which is exactly why it should worry you: it is the failure mode an agent platform without versioning, approval gates and an audit trail actively invites, and it carries the biggest penalty on the list.

That absence of agent-specific precedent is the reason to build carefully now. Regulators have published expectations, including FINRA, the FSB, the ESRB with a formal warning on frontier AI in July 2026, the ECB with a supervisory letter requiring significant institutions to submit an AI cyber action plan by 31 October 2026, and MAS, far faster than they have built precedent. The first enforcement action here will be litigated against whatever audit trail happens to exist. Make sure yours is the one you'd want read out.

Quick reference: what applies, and when

ObligationRegimeStatus as of Aug 2026
Disclose the agent is AI at first interactionEU AI Act Art. 50Live since 2 Aug 2026
Major ICT incident: initial notificationDORA, CIR 2025/302Live, 4 hours from classification
Regulator audit rights over ICT providersDORA Art. 30(3)(e)Live for critical functions
Data processing and storage locations namedDORA Art. 30(2)(b)Live
Exit strategy with identified alternativesDORA Art. 28(8)Live for critical functions
Agent communications retained and auditable17 CFR 240.17a-4Live, 3 or 6 years
Specific principal reasons for adverse actionECOA § 1691(d), Reg B § 1002.9Live, unchanged by the 2026 rewrite
Model risk management for gen-AI and agentic AISR 26-2, OCC 2026-13Out of scope since 17 Apr 2026
UK model risk management, incl. gen-AIPRA SS1/23Live, never narrowed
Automatic event logging over system lifetimeEU AI Act Art. 12From 2 Dec 2027
Log retention, min. 6 months or per financial lawEU AI Act Art. 26(6)From 2 Dec 2027
Stop button halting in a safe stateEU AI Act Art. 14(4)(e)From 2 Dec 2027
Override or reverse an agent outputEU AI Act Art. 14(4)(d)From 2 Dec 2027
Explanation of the AI system's role in a decisionEU AI Act Art. 86From 2 Dec 2027
High-risk duties including credit scoringEU AI Act Ch. IIIDeferred to 2 Dec 2027
AI cyber action plan, significant institutionsECB SSM-2026-0301Due 31 Oct 2026
Certifiable AI management systemISO/IEC 42001Voluntary, certifiable today

FAQ

Next step: the control expectations above map to roughly a dozen infrastructure requirements. Grab the mapping table, with citation, obligation, and the platform capability that evidences it, and take it into your next architecture review.