Federal Reserve Supervisory Expectations for AI in Payment Systems
Banks must build their own AI oversight rules before regulators do.

For fifteen years, model risk management in banking ran on a single document: SR 11-7. On April 17, 2026, the Fed, OCC, and FDIC replaced it with SR 26-2, and the replacement doesn't so much settle the question of AI oversight as move it somewhere the agencies haven't fully mapped yet. Banks now have a new set of core principles to satisfy and a carveout for agentic AI that hands them the job of building governance rules regulators declined to write themselves.
That timing matters. A recent Wolters Kluwer survey found 44% of finance teams expect to use agentic AI in 2026, a sharp jump from the year before. Banks are walking into this gap right now, with live payment systems, real customer funds, and examiners who are already asking questions.
The carveout in Footnote 3 and what it actually obligates banks to do
Buried in SR 26-2 is Footnote 3, and it's doing more work than a footnote usually does. It says generative AI and agentic AI models are "novel and rapidly evolving" and, for that reason, sit outside the scope of the guidance. Read quickly, that sounds like a pass, but read carefully, the details tell a more complicated story.
The same footnote turns around and says a bank's own risk management and governance practices "should guide the determination of appropriate governance and controls" for these out-of-scope tools. The regulators are declining to set the specific rule, while still expecting banks to have one and to be able to show it.
That's a real shift in where accountability sits. Under the old model, a regulator wrote the standard and a bank met it, but here, the bank writes the standard and then has to defend it. Fed Vice Chair for Supervision Michelle Bowman said as much in May 2026, acknowledging that fast-moving technology "may require a different approach" and that other risk management practices should support adoption as it happens. Reading between the lines, the message is: build ahead of us, because we're not ready to hand you the answer key.
What examiners are actually asking about when they review AI payment systems
SR 26-2 doesn't create a standalone AI exam. Officials from the FDIC, Fed, and OCC told the GAO that when AI use is significant enough to matter, it gets folded into the existing safety-and-soundness, IT, and compliance exam tracks. OCC officials added that how deep examiners go depends on how much AI an institution is running and how risky that use looks. More deployment simply means more ground for an examiner to cover.
What are they actually looking for, once they're in the door? A few things keep showing up: Can the bank shut an AI agent down mid-transaction, and does it actually work when tested, not just on paper? What data can the agent touch, and is that access scoped, logged, and reviewable? How is the bank managing the vendors behind these tools? Is there a complete, current list of every generative AI tool and agent running in production? Is monitoring built for how these systems actually break, things like hallucinated outputs or adversarial prompting, rather than the old model-drift checks built for traditional statistical models? Can every decision be traced back to its source, with documentation ready for an audit? And is there a human in the loop at every point where the decision actually matters?
The OCC's Fall 2025 Semiannual Risk Perspective added a new section on innovation in the federal banking system, treating AI, payments modernization, and digital assets as strategic issues rather than side experiments. It went further, noting that under-investing in technology can itself become a long-term risk management problem. For payment AI specifically, that risk surface is wide: an agent executing payments touches fraud detection, AML compliance, and customer funds all at once, and each of those is its own line of examination.
How the three-lines-of-defense model applies to an AI agent that executes payments
Three lines of defense is the governance skeleton regulators already recognize. Bolting an AI agent onto it takes real redesign, not just a relabeling of existing roles.
Line one lives inside the agent itself: transaction limits, velocity thresholds that catch unusual bursts of activity, escalation rules that kick a decision up to a human when it crosses a certain threshold, and confidence scores low enough that the agent pauses instead of acting. Every transaction the agent touches needs a log entry that can't be altered after the fact.
Line two is the independent risk function sitting above it, watching model performance in an ongoing way rather than checking in once a quarter, digging into escalated cases to spot patterns across them, and holding the actual authority to pull the plug. That authority is the kill-switch examiners keep asking about, and it only counts if line two, not the technology team, holds it.
Line three is internal audit, confirming line one's controls work the way they're supposed to and that line two hasn't quietly lost its independence from the people who built the system.
Here's the failure mode examiners watch for: all three lines reporting up through the same technology team. That collapses the independence the whole model depends on, and it's a flag in any banking AI review. For payment AI, the baseline expectation is a named executive accountable for every AI-driven payment outcome, with documentation clear enough to show how the agent reached its decision. Auditability functions as a governance requirement here, not a dashboard feature: every automated action needs a permanent record an examiner can pull up and review.
Third-party AI vendors and what the 2023 TPRM guidance requires banks to prove
Most banks running agentic payment AI aren't building the model in-house. They're buying it, or integrating someone else's, and that choice carries its own compliance weight. The OCC, Fed, and FDIC's 2023 Third-Party Risk Management guidance sets the federal expectations here, and it applies to AI vendors the same way it applies to any other outside relationship.
A few obligations sit at the center of it. The bank needs governance structures with clear ownership; it can't hand accountability off to the vendor just because the vendor built the model. It needs to validate the model's accuracy and reliability itself, regardless of who wrote the code. And it needs documentation covering the model's full lifecycle, procurement through configuration, deployment, and every change made after that.
A joint Bank of England and FCA survey found that roughly half of responding firms had only a partial grasp of the AI technologies they were actually running, mostly because they leaned on third-party models without digging into how those models worked. Regulators on both sides of the Atlantic treat that as a governance failure. The same survey found a large majority of firms had a named person accountable for their AI framework, which marks a starting point rather than a finished job.
SR 26-2 and Bowman both flag the same open question: how third-party risk rules should apply to vendor-supplied agentic tools is still being worked out. Banks should be writing their own vendor oversight process now, before an examiner hands them one. For payment AI vendors specifically, the bank has to show it can validate the vendor's agent, monitor it continuously, and cut it off if needed, rather than take the vendor's word for it. A SOC 2 certification is a useful floor, and the bank's own oversight paperwork still has to sit on top of it.
How credit unions sit differently under this framework than large banks do
SR 26-2 is written for institutions with more than roughly $30 billion in assets under Federal Reserve supervision. Most credit unions fall well under that line, which means the new guidance doesn't reach them directly.
There's no equivalent model-risk rule built specifically for credit unions. The GAO recommended in May 2025 that NCUA put together AI model-risk guidance of its own, but NCUA staff concluded a model-risk-only approach wouldn't cover the range of ways credit unions actually use AI, and that anything more formal would need full rulemaking to get there.
The oversight that does apply runs through examiner judgment and board accountability layered on top of rules that already exist: BSA/AML, fair lending, consumer protection, all of which an agentic payment tool touches at once. A credit union running an AI agent on its payment rails is governed by how its examiner reads the risk and how seriously its board takes oversight, which makes internal documentation more important, precisely because there's no external checklist to fall back on.
The pressure to deploy is real regardless. Credit unions face staffing constraints and rising member expectations for digital service, and agentic AI is a direct answer to both. Examiners will still evaluate AI use through the safety-and-soundness and compliance lens they already have, dedicated rule or not.
Where state law creates obligations federal guidance has not yet addressed
Federal guidance doesn't override state law, and SR 26-2 is no exception. Institutions have to satisfy both at the same time, which is harder than it sounds when the two frameworks aren't built to line up.
Colorado's AI Act, signed in 2024 and effective June 30, 2026, puts requirements on developers of high-risk AI systems, defined to include systems with a material effect on financial services. Agentic payment AI fits that description without much argument. California's CCPA rules on automated decision-making go further still: pre-use notice, the right to opt out, the right to appeal a decision, and the right to see what information the system used to make it. Every one of those has a direct bearing on AI-driven payment or credit decisions touching a California resident.
The hard part is that federal examiner expectations are still forming through practice, case by case, while state law is already enforceable today. A bank has to operate under both, often without a clean way to reconcile them. The Financial Stability Board's 2026 consultation on responsible AI adoption adds a global layer on top, asking directly whether its proposed sound practices can stretch to cover generative and agentic AI. International expectations are converging with domestic ones, even if the timing doesn't line up neatly.
The practical move: the same governance work that satisfies the spirit of SR 26-2, traceability, human oversight at the moments that matter, clear explanations of how a decision got made, also builds the foundation for state-law compliance. Each institution still needs to map its specific state obligations on its own.
Building the governance posture the Fed expects but hasn't fully specified
Because SR 26-2's carveout makes the bank's own framework the main evidence of whether governance is adequate, documenting the decisions matters almost as much as making them well in the first place.
A few things belong on any list of minimums for a bank running agentic payment AI. A full, current inventory of every AI agent and generative AI tool in production, the kind examiners ask for and expect to already exist. A named executive on the hook for AI outcomes in payment operations. A kill-switch that's been tested, not just built, with an escalation path written down somewhere real. Monitoring designed around how these systems actually fail, not just the drift checks built for older statistical models. A permanent audit trail for every transaction an agent touches, one an examiner can review without having to reconstruct it after the fact. And oversight documentation for vendors that shows the bank, not the vendor, is the one holding governance.
Running these systems on existing banking rails rather than building new infrastructure from scratch cuts down on integration risk and gets a bank to a working audit trail faster, since much of the control environment is already in place.
The Wolters Kluwer Q1 2026 survey also found that only a small share of institutions describe their AI or machine learning strategy as well-defined and properly resourced. Read that as an opening: institutions that put this governance work in place now are ahead of most of the field, and likely ahead of wherever examiners eventually draw the line. The OCC's own framing backs that up, warning that under-investing in technology can become its own long-term risk problem. Standing still isn't neutral under the standards regulators are applying today.
Bowman's May 2026 remarks read like an agency still reviewing, weighing options rather than settling on a fixed rule, and no one has said when more specific agentic AI guidance will land. Banks and credit unions have a window open right now to define what good practice looks like on their own terms, rather than wait for someone else to define it for them.


