Industry Intel - Conference Recaps and Thought Leadership Article
In April 2026, regulators pulled generative and agentic AI out of SR 11-7, the model-risk framework everyone assumed governed it. That is not a reprieve. It means accountability for every agent now sits squarely with you.
For years, the reflexive answer to “how is your AI governed?” was SR 11-7, the interagency model risk management guidance. It was the anchor every compliance team reached for. As of an April 17, 2026 interagency rewrite (OCC Bulletin 2026-13), that answer is no longer correct. The OCC, the Federal Reserve, and the FDIC formally placed generative and agentic AI outside the scope of SR 11-7, with an AI-specific request for information expected to follow.
It is tempting to read that as a reprieve: the rulebook that governed AI just stepped back. It is the opposite. The absence of an agent-specific rule is not the absence of expectations. Human oversight, explainability, accountability, and the effectiveness standard all still apply, drawn now from consumer-protection and fair-lending law, from cross-border frameworks like the EU AI Act, and from your own governance commitments. The load did not lift. It shifted onto you, and it got less legible.
Regulators did not lighten the load on AI agents. They handed it to you, and took away the map.
Here is the question every board should be able to answer before an agent touches a compliance decision: who owns this agent? Not who built it, not which vendor supplies it. Who is accountable, by name, when it acts.
Because an AI agent does not absorb accountability. It has no license to lose, no career at stake, no signature on an attestation. When an agentic system clears an alert it should have escalated, the institution answers for it, and inside the institution, a person answers for it. If you cannot name that person, you do not have a governance gap. You have an ungoverned agent.
Most model governance was built to validate a model: an input, an output, a measurable error rate. An agent is not that. An agent is a model wrapped in tools, data access, permissions, memory, and a set of actions it is allowed to take in the real world. Governing the model while ignoring the tools it can call is like vetting a new hire’s background and never asking which systems you handed them keys to.
The failure modes live in that wider surface: agents acting on partial or stale data, agents whose autonomy has quietly outrun the institution’s ability to audit them, and multi-agent chains where no single step is clearly accountable. None of that can be governed by validating a model in isolation. The unit of governance is now the whole workflow.
Before you govern an agent, inventory it honestly: what data can it read, what tools can it call, what actions can it take without a human, and where does the record of its reasoning live. If you cannot answer those four questions, the agent is not ready for a compliance decision.
Strip the frameworks down and a governable agent has five properties. Miss one and you have an exam finding waiting to happen:
Almost all agentic capability now reaches compliance teams through vendors: an operating system for banking agents here, a financial-crimes agent there. That is efficient, and it is fine, but it does not outsource the accountability. The vendor’s governance becomes part of yours, which means the contract, not just the demo, has to deliver the five properties. Insist on testability, evidence access, and the right to intervene. If a vendor cannot let you observe, explain, and interrupt their agent, they are not selling you a governable system. They are selling you an accountability you cannot discharge.
The institutions making real progress did not start with the agent and bolt governance on afterward. They started with the architecture. Five moves put you there:
Every one of those properties depends on what sits beneath the agent. An agent is only as explainable as the data it reasoned over, and only as defensible as the evidence it can show. Govern the agent all you like; if it is reasoning over a black-box data layer, you cannot explain its decisions, because you cannot explain its inputs.