Regulatory brief · CFPB / OCC / Fed / FDIC

Who examines what, after April 2026.

No US banking regulator has issued a framework for agentic AI. They examine it anyway — through existing supervisory frameworks for safety and soundness, consumer compliance, and third-party risk. This is who asks what.

The 2026 reset

On 17 April 2026 the Federal Reserve, OCC and FDIC jointly issued SR 26-2, superseding SR 11-7 and SR 21-8 and placing generative and agentic AI outside model-risk guidance.

Material published before April 2026 needs re-reading

Guidance, vendor collateral and internal policy that cites SR 11-7 as the operative model-risk framework is out of date. That includes a good deal of AI governance marketing still in circulation. Where earlier supervisory statements concern adverse action, disparate impact and fair lending, they remain current — those rest on statute, not on model-risk guidance.

Who examines what

RegulatorWhat they look at
CFPBConsumer protection. Circular 2022-03 holds that adverse-action requirements apply equally regardless of the technology used, and that not understanding your own methods is not a defence. Circular 2023-03 extends it to non-traditional data. See the fair lending brief.
OCCSafety and soundness plus consumer compliance, through the existing supervisory framework. Examiners look for documentation, validation, governance, bias testing and performance monitoring, and expect credit decisioning AI to produce explainable output for adverse-action notices. Community banks may tailor to size and complexity but cannot opt out.
Federal ReserveModel risk under SR 26-2, now materiality-based rather than fixed-cadence, plus third-party relationships. Governors have publicly raised AI concentration and the need for human oversight of AI-driven decisions.
FDICJoint issuer of SR 26-2. Its Risk Review has flagged AI-related risk in supervised institutions.

What an examiner asks that a registry cannot answer

  • “Show me this decision.” Not a dashboard aggregate — the individual decision, the rules that produced it, and proof it has not been altered since.
  • “What stopped it?” Whether a control actually prevented an action, or merely recorded that it happened.
  • “Who approved this change, and when?” Policy and mode changes with a named accountable owner on an append-only record.
  • “How do you know it still works?” Ongoing monitoring and sampled human review, not a validation performed once at deployment.

Sentinel is built around those four questions. The evidence bundle answers the first, and you can verify one yourself before believing us about the rest.

Sources

Check every claim above. We would rather you did.

If we have characterised any of this incorrectly, tell us and we will correct the page.

Design partners

Examiner-readable, before the examiner asks.

Run in shadow mode and produce a walkthrough of one evidence bundle. That is the artefact worth testing internally before it is requested externally.