What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A bank cannot treat an AI agent as an accountable decision-maker. The bank needs named owners, bounded permissions, monitoring, escalation paths and a workable fallback for every process in which an agent can act. Who must compensate a harmed customer is a separate legal question: it depends on the jurisdiction, the bank and activity involved, the customer relationship, contracts and the facts. The available supervisory material does not establish a universal rule assigning liability to either a bank or its AI vendor.

What do current supervisors expect banks to do about AI agents?

There is no single agent-specific supervisory rulebook in the sources discussed here. U.S. and European materials instead point to governance, risk assessment, validation, monitoring, resilience and third-party oversight. Their scope and legal status differ, so banks should not mistake general risk-management themes for a bespoke set of legal requirements for agents.

United States: model-risk guidance excludes generative and agentic AI

On April 17, 2026, the OCC, Federal Reserve and FDIC issued revised interagency model-risk guidance. It describes risk-based practices for development and use, validation and monitoring, governance and controls, and third-party products within its scope. It expressly excludes generative and agentic AI; it is not an agent-specific rulebook. The bulletin says the guidance is not prescriptive or enforceable, and that failing to follow it will not itself result in supervisory criticism. It says the guidance is expected to be most relevant to banks with more than $30 billion in assets, while noting that it may also be relevant below that threshold in some cases. These qualifications matter: the document is neither a binding agent standard nor a blanket exemption from other applicable obligations. (OCC, “Model Risk Management: Revised Guidance,” April 17, 2026.)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On May 1, 2026, Federal Reserve Vice Chair for Supervision Michelle W. Bowman said generative and agentic AI fall outside that revised guidance and that other risk-management and governance practices are expected to support adoption. Her remarks describe the official’s supervisory perspective; they are not a new binding requirement. (Federal Reserve Board, “Speech by Vice Chair for Supervision Bowman on artificial intelligence in the financial system.”)

The U.S. Treasury’s financial-sector cybersecurity report identifies practical themes for AI-supported activities: risk assessment and due diligence before adoption; suitability for the intended purpose; adequate expertise and resources; testing and validation; ongoing monitoring; an AI inventory; issue and incident tracking; and information-security, cybersecurity, resilience, privacy, operational and fraud controls. These are themes in the report, not a bespoke legal checklist for agents. Its cited model-risk context should also be read with the later April 2026 revision. (U.S. Department of the Treasury, “Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector.”)

European Union: governance, oversight and resilience

The ECB’s 2026–28 supervisory priorities call for bank AI strategies that consider both opportunities and risks, supported by robust governance and risk controls. The ECB says it will monitor AI generally and take a more targeted approach to banks’ generative-AI applications, while cooperating with relevant authorities on implementation of the EU AI Act. Its supervisory material highlights explainability for decision-making, lifecycle monitoring and validation, change management, drift detection, escalation and remediation. It also flags generative-AI risks involving provider concentration, vendor lock-in, data confidentiality and security, resilience, exit strategies, and legal or reputational exposure. These priorities describe supervisory focus; they do not, by themselves, settle liability in a particular case. (ECB Banking Supervision, “Supervisory priorities 2026–28” and “Technology is neutral, governance is not: AI adoption in the banking sector,” February 24, 2026.)

Operational-resilience guidance has a defined scope

Federal Reserve SR 20-24 is an interagency paper on operational resilience for specified large and complex firms, not a standard that automatically applies to every bank. Revised June 2, 2026, it draws on operational-risk, continuity, third-party, cybersecurity and recovery or resolution disciplines. Its scope should be checked before treating it as directly applicable. (Federal Reserve Board, SR 20-24, “Interagency Paper on Sound Practices to Strengthen Operational Resilience.”)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How should a bank bound an agent’s authority?

Start with the bank process, not the model. An agent is one component in a workflow that also includes people, data, software, vendors and customer-facing decisions. For each proposed use, document what business purpose it serves, what actions it may take, what information it can access, what services it relies on and what could happen if it acts incorrectly. Then decide whether the institution has the expertise, staffing and resources to manage those risks. Treasury identifies these as pre-adoption considerations for emerging technology.

Rank #3
100 Pockets Currency Album with Password Lock Top Grade PU Leather Banknote Collection Book Binder World Paper Money Holders Sleeves for Collector Dollar Bill Cash Storage Collecting Supplies, Black
  • 【LARGE CAPACITY】This currency album Includes 50 double-sided pockets (100 slots total), neatly storing up to 100 banknotes, tickets, cards, stamps, bills, documents, invoices—keeping your collection tidy and easily accessible.
  • 【UNIVERSAL SIZE】Each pocket measures 16 x 8.3 cm (approx. 6.3" x 3.3"), designed to fit most international currencies, protects world paper money from dust, wear, and damage.
  • 【EXCELLENT QUALITY】Features a high-quality waterproof black PU leather cover. Eco-friendly transparent PP pages offer clear visibility and long-lasting protection.
  • 【PASSWORD LOCK FOR ADDED SECURITY】Equipped with a 3-digit combination lock. Set your own code to prevent accidental opening and keep contents safe from children, pets, or mishandling.
  • 【PERFECT GIFT IDEA】An ideal present for currency collectors, hobbyists and travelers. Great for birthdays, holidays, or special occasions.

A useful design review asks how much authority the agent needs and how reversible its actions are. A system that drafts a recommendation for review presents a different control problem from one that can execute a payment, change an account or communicate a final decision. Where an action can cause customer harm or is difficult to reverse, the bank should decide explicitly whether to require approval, restrict the action, or reserve it to a person. These are design questions for the bank’s process, not source-quoted regulatory mandates.

  • Purpose and scope: Define the process and actions the agent is allowed to perform, as well as actions it must not take.
  • Data and tools: Identify information access, permissions, connected applications, APIs and downstream services.
  • Decision points: Determine where a person must approve, review or take over, and how an exception reaches that person.
  • Evidence: Keep records sufficient to reconstruct the relevant inputs, system version, actions, approvals and outcome.
  • Readiness: Confirm that owners and control teams have the expertise and resources to supervise the use.

What controls belong before and during deployment?

Before deployment: assess, test and prepare

  1. Assess the use case and dependencies. Record the intended purpose, possible harms, data involved, agent permissions, external providers and the people responsible for the process. Treasury calls for risk assessment and due diligence before adopting emerging technology.
  2. Check suitability and capability. Establish whether the system is suitable for the intended task and whether the bank has the skills and resources to manage it. If those conditions are not met, narrow the use or do not deploy it.
  3. Test the full workflow. Test not only the agent but also its tools, approval steps, handoffs, failure handling and fallback. Validate what matters for the intended use; testing a model in isolation does not show that the complete banking process is controlled.
  4. Set change controls and records. Track versions and material changes, maintain an inventory of AI use cases, and establish how issues and incidents will be recorded and reviewed. Treasury identifies inventories, change management, ongoing validation and incident tracking among relevant practices.
  5. Plan for disruption and exit. Identify how the process will continue if a provider or connected service fails, and how the bank could move away from a dependency. ECB supervisory material highlights resilience, concentration, lock-in and exit planning.

In operation: monitor and intervene

Define what the bank will monitor, who reviews the results and what conditions trigger escalation, suspension, rollback or human review. The thresholds should reflect the process’s consequences; the sources do not provide universal numerical trigger values for bank agents. Monitor behavior and outcomes over time, watch for drift or unintended effects, and assign owners to remediate issues. ECB supervisory material specifically emphasizes lifecycle monitoring, drift detection, escalation and remediation.

The bank should be able to explain an agent’s behavior in terms meaningful to the decisions it supports. An ECB supervisory speaker put the control issue plainly: “If a bank cannot explain why an AI model behaves the way it does, in terms that are meaningful for decision-making, then it cannot truly control that model.” (ECB Banking Supervision, “Technology is neutral, governance is not: AI adoption in the banking sector,” February 24, 2026.)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How can an AI agent fail, and what should the bank plan for?

Failure mode What can go wrong Control focus
Unintended action or tool misuse The agent may act beyond its intended business purpose or authority. Set permissions and approval points; test the surrounding workflow; monitor actions; track incidents. Treasury supports these control themes but does not provide validated agent-specific failure rates.
Drift or changed behavior Changes in data or connected systems can affect behavior or outcomes. Monitor and validate over the lifecycle; manage changes; detect drift; escalate and remediate unintended effects.
Opaque decision-making The bank may be unable to explain behavior in a way that supports meaningful review. Require evidence and explanations that decision-makers can use; set a review or stop point if the bank cannot understand the behavior it is relying on.
Third-party disruption or dependency A provider, cloud platform, external data source, API or downstream service may fail, create security or confidentiality exposure, or leave the bank with weak alternatives. Assess dependencies and concentration; protect information; plan for resilience, exit and recovery.
Control-system lag Deployment may get ahead of governance’s understanding of concentrated decision-making or resilience teams’ fallback design. Make governance and fallback readiness part of deployment decisions, rather than treating them as later operational work.

The control-system lag risk was described by New York Fed Chief Risk Officer and Head of the Risk Group Mihaela Nistor in a September 24, 2026 speech, delivered in a personal capacity: “A process can become dependent on AI before resilience teams have designed a credible fallback.” She also observed that “A function can deploy autonomous agents before governance fully understands the resulting concentration of decision-making.” These are the speaker’s analysis, not requirements issued by the New York Fed or Federal Reserve System. (Federal Reserve Bank of New York, “Forging A Resilient Path,” September 24, 2026.)

Best Value
100 Pockets Currency Album with Password Lock Top Grade PU Leather Banknote Collection Book Binder World Paper Money Holders Sleeves for Collector Dollar Bill Cash Storage Collecting Supplies, Blue
  • 【LARGE CAPACITY】This currency album Includes 50 double-sided pockets (100 slots total), neatly storing up to 100 banknotes, tickets, cards, stamps, bills, documents, invoices—keeping your collection tidy and easily accessible.
  • 【UNIVERSAL SIZE】Each pocket measures 16 x 8.3 cm (approx. 6.3" x 3.3"), designed to fit most international currencies, protects world paper money from dust, wear, and damage.
  • 【EXCELLENT QUALITY】Features a high-quality waterproof blue PU leather cover. Eco-friendly transparent PP pages offer clear visibility and long-lasting protection.
  • 【PASSWORD LOCK FOR ADDED SECURITY】Equipped with a 3-digit combination lock. Set your own code to prevent accidental opening and keep contents safe from children, pets, or mishandling.
  • 【PERFECT GIFT IDEA】An ideal present for currency collectors, hobbyists and travelers. Great for birthdays, holidays, or special occasions.

Who is liable if an agent harms a customer?

The sources do not establish a universal answer. It would be inaccurate to say, on this evidence, that the bank is always liable, that the AI vendor is always liable, or that the agent itself is liable. Legal allocation depends on the jurisdiction, the bank’s charter and activity, the customer relationship, applicable consumer, privacy, prudential and financial-services rules, contract terms, agency principles and the facts of the harmful action. Supervisory guidance about sound controls does not resolve that case-specific legal analysis.

The OECD’s 2024 comparative report describes one jurisdiction-specific example: in Israel, the licensed institution is liable to its client for damages following deployment of digital tools, including AI-related innovation, and cannot redirect the client to claim against a service provider. That example does not establish the rule for banks elsewhere or for an unspecified bank, activity or dispute. (OECD, “Regulatory approaches to Artificial Intelligence in finance,” 2024.)

For a real incident, the bank should preserve the records needed to understand what happened and have qualified counsel assess the applicable law and contracts. Operationally, the bank still needs to identify the responsible internal owners, contain the harm, escalate the incident and restore a safe process; assigning contractual responsibility to a vendor does not itself provide a functioning customer or business recovery plan.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.