Skip to content
JL

No Single Framework Owns Your AI Risk

7 min readJeff Lemieux
AI governancemodel risk managementfinancial regulationEU AI ActNIST AI RMF
Table of Contents
  1. The regulatory picture is deliberately incomplete
  2. Where Europe raises the stakes
  3. The through-line: seven gates, not one committee
  4. Closing

If you are waiting for the one rulebook that governs artificial intelligence at a large financial institution, stop waiting. It does not exist, and the developments of the past eighteen months make that plainer, not less so. What a mature institution actually runs is a control system assembled from several regimes: model-risk supervisory guidance, a voluntary AI-risk taxonomy, existing third-party and fair-lending law, and — for anyone with European exposure — the EU AI Act. None of these owns the whole problem. The work of governance is stitching them into a single lifecycle that every AI system passes through, from intake to retirement.

The most useful way to think about that lifecycle is as seven gates: Inventory, Classify, Approve, Validate, Monitor, Evidence, Retire. Treat those as the spine of the program and the fragmented regulatory picture starts to organize itself.

The regulatory picture is deliberately incomplete

Start with what changed. For roughly fifteen years, US model-risk management ran on SR 11-7, the interagency guidance issued in April 2011 that gave the industry its enduring vocabulary — the model lifecycle, a comprehensive model inventory, materiality-based tiering, and "effective challenge." That guidance is no longer the operative standard. On April 17, 2026, the Federal Reserve, OCC, and FDIC issued Revised Guidance on Model Risk Management (Federal Reserve SR 26-2; OCC Bulletin 2026-13), which expressly supersedes and replaces SR 11-7 and rescinds OCC Bulletin 2011-12. The revised guidance keeps the core architecture but reframes it as a risk-based approach tailored to a firm's model-risk profile, size, and complexity. The agencies note it is most relevant to banking organizations with over $30 billion in total assets, and it states plainly that it "does not set forth enforceable standards or prescriptive requirements." Non-compliance with the guidance will not, by itself, draw supervisory criticism — though the guidance is clear that violations of law or unsafe or unsound practices still can.

Here is the part that should shape every AI program. SR 26-2 places generative AI and agentic AI outside its scope, calling them "novel and rapidly evolving." The guidance's principles apply to traditional statistical and quantitative models, and to non-generative, non-agentic AI models — but for GenAI and agentic systems, it directs that a firm's own risk-management and governance practices should determine appropriate controls. Read that carefully: regulators updated model-risk guidance and, in the same breath, declined to bring the fastest-moving category of AI under it. That is not an oversight. It is a deliberate gap, and filling it falls to the institution.

The voluntary layer helps. The NIST AI Risk Management Framework (AI RMF 1.0, released January 2023) organizes AI risk around four functions — Govern, Map, Measure, Manage — and remains the most widely referenced taxonomy institutions map their AI controls to. Its companion, the Generative AI Profile (NIST AI 600-1, July 2024), names twelve GenAI-specific risk categories, including what it calls Confabulation (the framework's term for confidently stated but false output) and Data Privacy. Both documents were developed pursuant to an executive order that has since been revoked, which means the federal-policy tailwind behind them is gone. The documents themselves remain published and voluntary — reference frameworks an institution chooses to adopt, not mandates, and never law.

Two more anchors matter. The Interagency Guidance on Third-Party Relationships (final June 2023) governs externally sourced and vendor AI across a planning-to-termination lifecycle and expressly contemplates machine learning and AI providers. And beneath all of it sits existing law that never mentions AI by name but plainly applies to it: fair lending under ECOA and Regulation B, prohibitions on unfair or deceptive practices, safety-and-soundness, and BSA/AML. Under ECOA and Regulation B, a lender must generally provide an accurate adverse-action reason regardless of the technique that produced the credit decision.

Where Europe raises the stakes

For institutions with EU exposure, the AI Act (Regulation (EU) 2024/1689) adds a binding layer with real teeth. Its four-tier structure — prohibited, high-risk, limited-risk, minimal-risk — plus a separate track for general-purpose AI, is now partly in force. Prohibited practices and AI-literacy obligations have applied since February 2, 2025. GPAI obligations have applied since August 2, 2025, though GPAI models already on the market before that date carry a transitional period to come into compliance.

For financial services, most exposure sits in the high-risk tier. AI used to evaluate creditworthiness or set a credit score is high-risk under Annex III, with a narrow carve-out for fraud detection — narrow being the operative word, since a fraud tool that interacts with individuals can still carry transparency duties. Risk assessment and pricing in life and health insurance are separately high-risk.

The timeline moved, and citing the old dates is an easy way to be wrong on a live compliance deadline. The Digital Omnibus on AI, formally adopted by the Council of the EU on June 29, 2026, postponed the application date for standalone high-risk systems (Annex III, including credit scoring) from August 2, 2026 to December 2, 2027, and embedded-product high-risk (Annex I) from August 2, 2027 to August 2, 2028. Critically, the Omnibus moved the deadline, not the classification — credit scoring is still high-risk. As of this writing, formal Official Journal publication was being finalized, so treat the exact entry-into-force date as the residual detail while planning to the settled deadlines.

The through-line: seven gates, not one committee

None of this is governed by a committee that convenes to bless finished models. By the time a model is built, most of the risk decisions have already been made. Governance has to be a control system the AI moves through.

Inventory. The systems most likely to escape governance are the ones no one sees — embedded features and vendor-supplied tools bought as products, not built as models. A current, enterprise-wide inventory of AI systems, including those, is the precondition for everything else. Both the revised US guidance and OSFI's Guideline E-23 in Canada center the inventory for good reason.

Classify. Tier by inherent risk and materiality — exposure and use — and let that rating drive how much scrutiny follows. This is also where jurisdiction attaches: a system touching EU credit decisions inherits Annex III obligations a US-only tool does not.

Approve. Gate first use behind a decision that matches the tier. The revised US guidance expects validation to normally precede first use, with compensating controls — usage limits, heightened monitoring — where a model must run before validation completes.

Validate. Effective challenge survives intact: objective, competent, independent review of conceptual soundness, outcomes, and ongoing performance. For GenAI and agentic systems the model-risk track does not reach, mature institutions extend the same discipline into a parallel track — grounded in NIST's taxonomy and application-security references such as the OWASP Top 10 for LLM Applications, which catalogs prompt injection and sensitive-information disclosure.

Monitor. Watch for performance drift and trigger overlays, recalibration, or redevelopment. For agentic systems, mature practice converges on bounded autonomy — narrow scope, human checkpoints before high-impact or irreversible actions, and immutable logging — though this remains a principles-and-commentary space, not a settled rulebook.

Evidence. Every gate produces an artifact an examiner or auditor can inspect. Internal audit assesses whether the program works rather than re-running validation itself.

Retire. Decommissioning is a governed step, not neglect. OSFI's E-23 — finalized September 11, 2025, applicable May 1, 2027, and explicitly extended to AI/ML — names decommission as part of the lifecycle. Models that linger past their usefulness are their own risk.

Closing

The institutions that will handle AI well are not the ones holding out for a single framework to tell them what to do. They are the ones who accept that no framework owns the whole problem and build the connective tissue themselves — an inventory that sees everything, tiering that routes attention, gates that hold, and evidence at each step. Regulators drew a deliberate line around generative and agentic AI. The mature response is not to wait for them to redraw it, but to govern to the edge of that line and past it.

This reflects publicly available regulatory information as of July 2026, is general in nature, is not legal or compliance advice, and describes how mature institutions generally approach model governance; specifics continue to evolve, including pending Official Journal publication of the EU Digital Omnibus.