If your AI compliance notes for financial services were written before April, they cite a supervisory framework that no longer exists. On April 17, 2026, the Federal Reserve, OCC, and FDIC retired SR 11-7 — the fifteen-year backbone of US model risk management — and replaced it with SR 26-2. The replacement contains a sentence every bank CISO should read twice: generative and agentic AI are "novel and rapidly evolving. As such, they are not within the scope of this guidance."
Read that plainly: the models your workforce uses daily are, by the regulators' own statement, outside the current model-risk framework, pending a future request for information. There is no supervisory safety net to inherit. Governance is on you — while the ECB has given every significant European institution a hard deadline of October 31, 2026 to submit AI-cybersecurity action plans, NYDFS has issued two AI warning letters, and the EU AI Act's transparency rules went live in August. The regulators have stopped talking about AI in the abstract. In 2026, they set dates.
This playbook is the one-map version: every regulator that touches financial-services AI, what each actually requires, when, and who in your organization owns it.
Last verified: August 20, 2026. Practitioner analysis, not legal advice — verify against rule text with counsel.
The map
| Regulator / instrument | What it says about AI | Key dates | Who owns it |
|---|---|---|---|
| Fed/OCC/FDIC — SR 26-2 (replaces SR 11-7) | Model risk management modernized — with genAI and agentic AI explicitly carved out pending an interagency RFI | Issued Apr 17, 2026; RFI pending | CRO / model risk, with security supplying the AI inventory |
| ECB supervisory letter | All significant institutions must address AI-enabled cyber threats across six areas | Action plans due Oct 31, 2026 | CISO, reporting to the board |
| NYDFS Part 500 + AI letters | AI risk falls under existing Part 500 (Oct 2024 letter); frontier models "amplify the potency, scale, and speed" of exploitation (May 21, 2026 dual guidance); final MFA/asset-inventory phase fully in force since Nov 1, 2025 | In force now; enforcement live (PayPal, $2M, Jan 2025) | CISO / compliance |
| DORA | Your AI tools are ICT services: register of information, Art. 30 contract terms, incident reporting; 19 critical ICT providers (AWS, Microsoft, Google Cloud, IBM, Oracle among them) under direct ESA oversight; ESAs' July 31, 2026 statement extends the frontier-AI risk expectation EU-wide | Applicable since Jan 2025; CTPP oversight from 2026 | CIO / third-party risk |
| EU AI Act | Credit scoring (Annex III 5(b)) and life/health insurance pricing (5(c)) are high-risk — deferred to Dec 2, 2027; Article 50 transparency and GPAI enforcement live since Aug 2, 2026 | Two clocks: now, and Dec 2, 2027 | CCO / DPO |
| FINRA / SEC | FINRA's 2026 report treats genAI — and, for the first time, agentic AI — as supervised technology; SEC FY2026 exam priorities embed AI supervision and disclosure accuracy; AI-washing enforcement active since 2024 | Exam cycle now | CCO / supervision |
| US Treasury FS AI RMF | Voluntary framework, Feb 19, 2026: 230 control objectives adapting NIST AI RMF to financial services — the de facto scaffold while the banking agencies draft | Available now | Whoever owns the control library |
The SR 26-2 vacuum — and why it doesn't mean relief
The genAI carve-out is not a pass; it is a transfer of responsibility. Examiners still expect safe and sound operations, FINRA still expects supervision of the technology your registered people use, and when the promised RFI matures into guidance, it will be applied to estates that exist today. The banks handling this well are extending model-risk discipline to LLMs by analogy — inventory, validation-style testing, monitoring, documented human checkpoints — so the eventual framework describes what they already do. The ones treating the carve-out as breathing room are building the remediation backlog now.
Under DORA, your AI vendor is an ICT vendor
DORA never says "artificial intelligence," and it doesn't need to. An AI tool is an ICT service: it belongs in the register of information, its contract must carry Article 30's mandatory provisions (audit rights, exit plans, incident cooperation), and incidents involving it feed the Articles 17–23 reporting machine — whose first year produced 3,383 major incident reports, with the ESAs explicitly flagging AI as an attack amplifier. Article 28's opening rule is the one to pin on the wall: the financial entity remains fully responsible regardless of outsourcing. The hyperscalers hosting your AI workloads are now directly supervised critical providers — but their designation is not your safe harbour.
NYDFS said it twice; the second time it named frontier models
The October 2024 letter established the frame: AI risk is Part 500 risk — deepfake social engineering, AI-accelerated attacks, NPI concentrated in training datasets, vendor AI dependencies — governed by the risk assessments, MFA, vendor policies, and training you already owe. The May 21, 2026 dual guidance escalated the language: frontier models "amplify the potency, scale, and speed" of vulnerability exploitation, and firms should accelerate patching, map third-party dependencies, and keep humans reviewing AI-generated code. Neither letter created new requirements — which is precisely the point. When the examiner arrives, "we hadn't updated our program for AI" is a Part 500 finding, not a novel-technology defense. The $2M PayPal order (the first under amended Part 500) shows the enforcement appetite for fundamentals.
The two-clock EU AI Act message
What applies now: Article 50 transparency (your customer-facing chatbots must disclose themselves; AI-generated content needs marking) and the Commission's GPAI enforcement powers — both live since August 2, 2026. What has runway: credit scoring and life/health insurance pricing as Annex III high-risk, deferred to December 2, 2027 by the omnibus (Regulation 2026/1744, in force July 27, 2026). Sixteen months for conformity assessments, data-governance documentation, and human-oversight design on the models that decide who gets credit and at what price — work with six-to-twelve-month lead times. Runway, not reprieve.
FINRA, the SEC, and the record you're not keeping
FINRA's December 2025 oversight report did two notable things: it treated genAI as ordinary supervised technology (chatbot output to a customer is a firm communication — capture it), and it became the first US regulator to address agentic AI — agents exceeding authority, transparency gaps, the need for prompt and output logs. Put that next to the SEC's books-and-records regime — where "record" includes "machine language" and the off-channel communications sweep produced over $2B in fines — and the analogy writes itself: unlogged AI interactions are the next off-channel texting. No rule says it explicitly yet. Neither did one about WhatsApp, until the fines. Meanwhile the enforcement front that IS explicit — AI-washing — has run from Delphia and Global Predictions (March 2024, $400K) to Presto Automation (January 2025, first public-company case): say only what your AI actually does, in prospectuses and in RFP responses alike.
Adoption has outrun governance — the numbers
JPMorgan's LLM Suite reaches roughly 250,000 employees. Citi has put 175,000 staff through mandatory AI prompt training. Over 98% of Morgan Stanley advisor teams use their genAI assistant. Ninety-two percent of S&P 500 financial-sector earnings calls in Q1 2026 mentioned AI. Against that: industry surveys put active AI usage at 65% of financial firms (up from 45% in a year) with over half piloting agentic AI — while Deloitte projects US genAI-enabled fraud reaching $40B by 2027, and the canonical incident remains a $25M wire authorized on a video call where every other participant was a deepfake. The gap between those two paragraphs is this playbook's reason to exist.
The 90-day program
- Days 1–30 — Inventory and map. Discover actual AI usage (including the unsanctioned layer and agents); classify against the map above: which tools touch credit decisions (AI Act high-risk), customer communications (FINRA), NPI (NYDFS), or run on DORA-registered vendors. This single artifact feeds every regulator's first question — and the ECB's October 31 action plan.
- Days 31–60 — Control and contract. Guardrails at the AI boundary (data rules by class, redaction, human checkpoints on decision-adjacent tools); Article 30 terms and AI-specific due diligence into vendor contracts; logging switched on for AI interactions in supervised functions.
- Days 61–90 — Evidence and report. Map controls to the Treasury FS AI RMF's objectives as your scaffold; wire AI events to the SIEM; produce the first board-grade report — because between the ECB letter, NYDFS, and your D&O insurers, the board is now in every one of these loops.
Download the complete playbook — the regulator map with citations, the control matrix, and the 90-day program in checklist form.
FAQ
We're a US bank — does DORA touch us?
If you operate EU-regulated entities or serve EU financial customers through them, yes. And its logic (AI vendor = ICT vendor, register, contract terms) is becoming the global template — building to it once is cheaper than retrofitting per jurisdiction.
Is there any binding US rule on genAI models in banking today?
No — that is the SR 26-2 vacuum, stated by the agencies themselves. Which is why examiners lean on adjacent hooks (safety and soundness, third-party risk, FINRA supervision) and why the voluntary Treasury framework is worth adopting: it is the likely shape of what binding guidance will assume.
Which deadline should drive our planning?
European institutions: October 31, 2026 (ECB action plans). Everyone with EU credit or insurance products: December 2, 2027, minus your conformity lead time. US broker-dealers and advisers: the current exam cycle — FINRA and the SEC are asking now.
What's the one artifact that serves every regulator on the map?
The AI inventory with usage evidence. DORA's register assumes it, NYDFS's risk assessment assumes it, FINRA's supervision assumes it, the AI Act's classification exercise starts from it, and your insurer now asks for it. It is also the artifact organizations cannot produce by survey — only by discovery.
Sources: Federal Reserve SR 26-2 · OCC Bulletin 2026-13 · ECB supervisory letter on AI-enabled cyber threats (Jul 7, 2026) · NYDFS AI letter (Oct 16, 2024) · NYDFS frontier-AI guidance (May 21, 2026) · ESAs designate 19 CTPPs (Nov 18, 2025) · ESAs frontier-AI statement (Jul 31, 2026) · Regulation (EU) 2026/1744 (AI omnibus) · FINRA 2026 Regulatory Oversight Report · SEC FY2026 exam priorities · SEC AI-washing actions · US Treasury FS AI RMF (Feb 19, 2026) · Deloitte genAI fraud projection.
Related: AccuroAI for Financial Services · The AI Questions on Your Next Cyber Insurance Renewal · Why AI Governance Just Became a Board-Level Job · The NIST × ISO × EU AI Act Crosswalk.