Proposed OCC Fintech Charter Implications for Agentic Banking Vendors
OCC's fintech charter is redefining compliance rules for AI-driven banking vendors.

The OCC's fintech charter is back, following the version that died in litigation back in 2016. What's live now is the national trust bank pathway, and it's already changing what "compliant" means for any vendor whose AI agents touch actual money movement. That matters because charter review is turning into the place where the real rules get written, months before any formal rule shows up.
The 2016 charter attempt got buried under lawsuits from state regulators who argued the OCC had no business chartering non-depository fintechs. That fight never really got resolved; it just got shelved. The national trust bank route, NTB for short, sidesteps deposit-taking entirely, which means it doesn't trigger Bank Holding Company Act treatment. That's structurally attractive to fintechs and AI-native firms that want a federal charter without becoming, in effect, a bank holding company overnight.
The OCC's April 2026 rule clarification on national trust bank authority made that path a lot cleaner. It spelled out how fintechs can combine trust operations with non-fiduciary banking activities, and that clarity matters more than it sounds like it should. Ambiguity was the deterrent before: firms didn't know if combining those activities would draw a denial or a multi-year review, so a lot of them just didn't try. Now there's a cluster of conditional approvals from late 2025 through mid-2026, spanning digital asset custody, AI-driven lending, and payments infrastructure. Read through that sequence and it's hard not to conclude a regulator is recalibrating on purpose.
Part of what's driving this: a growing number of fintechs are exiting or diversifying away from sponsor-bank arrangements. Those arrangements came under heavy regulatory pressure in 2023 and 2024, with enforcement actions hitting financial crime compliance, third-party risk management, and board governance at sponsor banks across the board. A charter looks a lot more appealing once your sponsor-bank relationship is the exact thing regulators keep flagging.
Still, none of this is settled law. Legal challenges echoing the 2016 fight will likely show up again, so the charter door is open with a fight brewing on the other side of it. That framing matters for everything below: the compliance expectations built into charter review aren't polite suggestions. They're gateway conditions, and the OCC has already shown, in writing, what happens when a firm doesn't meet them.
What the OCC's denial decisions reveal about the actual compliance floor
Approvals tell you what's allowed. Denials tell you where the floor actually sits, and the OCC's decision on Wise US is the clearest floor-marking event so far.
Wise walked into its charter application already carrying acknowledged AML/CFT problems, including a multistate consent order tied to delayed suspicious activity report filings and gaps in transaction monitoring integrity. The OCC didn't soften the conclusion. It said, plainly, that it couldn't find the proposed trust bank would run an effective anti-money-laundering program, and that the people organizing the new entity were part of the same organization carrying those long-standing deficiencies.
That's a direct line from an existing compliance record to a charter denial. There was no quarantine, no fresh start, no benefit of the doubt for a "new" entity built out of an old problem.
Here's the part vendors keep getting backwards: they assume governance is something you clean up once the product proves itself, then bolt on before the audit. Wise shows that ordering fails in practice. Transaction monitoring quality and audit trail completeness get checked before the door opens, not patched in after approval. And the denial makes something else clear: regulators look through corporate structure to the entity actually doing the work. A new charter application can't wall off a parent company's history just by filing under a new name.
So the vendor market is splitting, whether vendors admit it yet or not. Firms that already built real transaction monitoring and explainable controls into their core system have a head start over firms that treated compliance as an afterthought. Bolting it on later isn't just slower, it's the kind of mistake that shows up in a denial letter years down the line. The Wise case is, right now, the best signal available for where that bar actually sits.
How the charter shift redefines what "operating on banking rails" means for agentic vendors
Agentic AI in banking isn't the same animal as the automation that came before it. Earlier systems flagged a transaction or suggested a next step and left a person to act on it. Agentic systems execute: they initiate payments, move funds, and touch multiple systems in sequence, often with almost no human check at each individual step.
That execution behavior is exactly what pulls these systems onto the same compliance surface as the rails underneath them. When an agent initiates a transfer or picks a route across FedNow, RTP, or ACH, that transaction carries the same AML/CFT obligations, fraud monitoring requirements, and record-keeping duties as if a person had typed it in by hand. The agent's autonomy doesn't buy anyone an exemption.
Take intelligent rail selection, the ability to choose between payment networks in real time based on cost, speed, liquidity, or fraud exposure. Sit with that capability for a moment: its value comes precisely from forcing compliance logic into the routing decision itself, rather than checking the transaction after the fact. The system has to know the rules while it's deciding, not after the money's already moved.
Vendor accountability doesn't transfer, and that's the part banks can't get around. The FFIEC framework is explicit that outsourcing execution to an AI vendor doesn't move the compliance responsibility off the bank's books. The bank stays accountable for the vendor's controls, its data handling, and what happens when something breaks.
Here's where it gets genuinely uncomfortable for vendors trying to plan ahead: the April 2026 interagency model risk guidance, SR 26-2, put generative and agentic AI outside its current scope, calling them novel. So vendors can't point to existing model risk frameworks and call that a ceiling; that ceiling doesn't exist yet for these systems. The obligations are real and immediate, even while the guidance meant to cover them stays unfinished. Vendors building to the highest defensible standard right now aren't just protecting themselves. They're setting the reference point everyone else gets measured against later.
The specific governance requirements that agentic vendors can no longer treat as aspirational
A handful of rules, once treated as directional, have turned into hard requirements with dates attached to them.
NYDFS Part 500, amended in 2023, requires that AI systems processing customer data sit inside a covered institution's cybersecurity program. Risk assessments, access controls, audit trails: these are mandatory, layered into the product from the outset rather than added once it ships.
ECOA and Regulation B require an adverse-action explanation no matter how the decision got made. Model opacity isn't a defense here. The CFPB confirmed in 2022 that this duty applies even to complex algorithms, which means an agentic system influencing a credit or account decision has to be explainable down to specific reasons, not general categories like "risk score too low."
The Bank of Thailand's 2025 AI risk-management policy is worth watching even for firms with no Thai operations, because it points to where global mandates are heading. It requires human oversight anywhere AI touches strategic functions: credit approval, account opening, approving deposits, withdrawals, or transfers. The same logic is showing up in different jurisdictions, wearing different words.
For vendors with EU-connected operations, DORA requires ICT risk management that covers AI systems specifically, and GDPR Article 22 adds lawful basis, transparency, and a right to human review for automated decisions. Colorado's AI Act, effective June 30, 2026, reaches past the deploying bank straight to the developer: high-risk AI systems that materially affect financial services trigger public disclosures, consumer notification, and impact assessments from the vendor itself.
Boards are named, specifically, as the accountability layer. Regulators are explicit that AI-driven decisions have to be transparent, auditable, and aligned with conduct obligations, and that board-level accountability doesn't get delegated away just because execution did.
Add it up: the compliance surface for agentic vendors spans multiple jurisdictions, touches cybersecurity, explainability, human oversight, and audit completeness all at once, and lands on the vendor layer directly, not just on the bank that happens to be using the vendor.
Where the guardrails gap sits today and why it compounds vendor risk
A lot of financial firms will tell you, publicly, that they use AI. Far fewer have built internal controls that match the claim. Disclosure isn't governance, and regulators are starting to treat that gap as a finding on its own, not a footnote buried in an exam report.
The scale of the gap shows up in broader industry research: only a small fraction of companies across sectors had real AI guardrails in place as of 2025, and most respondents in one major study already reported at least one AI incident. In a charter-application context, that incident history is exactly what an examiner goes looking for. The Wise denial already showed what happens when past deficiencies show up in a fresh application: they don't get forgiven, they get inherited.
SR 26-2's exclusion of agentic AI from the interagency model risk guidance doesn't lower the risk for vendors. It removes the safe harbor. Banks and their vendor partners are operating in a space where examination standards get built, in real time, out of enforcement actions and denial decisions rather than out of finished rules.
Liability makes this worse. When an agent executes a wrong or fraudulent payment, existing legal frameworks don't cleanly sort out who's responsible among the user, the AI developer, the deploying bank, and the network carrying the transaction. That ambiguity isn't an academic problem sitting in a law review somewhere. It's a governance risk sitting on top of any vendor whose agents touch live rails right now.
Cybersecurity exposure gets specific here too. Account takeover attacks aimed at agentic payment systems can try to reconfigure what the agent is actually trying to do: change a payment destination, inflate a transfer amount, redirect a purchase mid-flow. That makes the integrity of the agent's own instruction set a compliance surface and a security surface at the same time.
Gartner's projection that AI-on-AI governance, sometimes called guardian agents, will make up a meaningful share of the agentic AI market by 2030 says something on its own. Weighed against everything above, it reads less like a forecast and more like an admission: the industry already knows autonomous systems need autonomous oversight watching them. Vendors building that layer now aren't speculating. They're ahead of where the requirements are going to land.
What a charter-ready governance architecture looks like in practice for agentic vendors
Start with the rails themselves. A vendor built on existing, established banking infrastructure reads as more credible to examiners than one built on novel architecture nobody's figured out how to supervise yet. Charter applicants get more traction integrating with systems examiners already know how to check.
Audit trails come next, and they carry weight of their own. Every agent-initiated action, every payment, transfer, or account interaction, has to be reconstructable after the fact. An examiner reviewing a charter application, or a bank's own third-party risk review, will expect to walk back through any transaction the agent touched, step by step, with no gaps.
Configurable controls matter for a related reason: they keep the institution in charge of the agent's decision space. Transaction limits, approval thresholds, escalation rules: the agent executes inside boundaries a human set, not the other way around.
Human oversight needs to sit at defined points in the workflow, built into the design rather than added after something goes wrong. That's the direction regulators in multiple countries are already pushing for strategic banking functions.
Explainability has to work at the transaction level. Any decision an agent influences that touches a customer account needs to trace back to specific inputs and logic, which is what ECOA and Reg B already require for adverse actions and what's fast becoming the general expectation for any customer-facing outcome.
SOC 2 certification gives all of this an outside check. It's independent verification that a vendor's security, availability, and confidentiality controls meet a defined bar, and in a charter or third-party-risk context, that's evidence a bank can point to, alongside whatever the vendor says about itself in a pitch deck.
AML/CFT automation has to be built into transaction monitoring from the start, with reporting as one output among several rather than the whole job. That's the exact capability the OCC was scrutinizing when it denied Wise. Vendors whose agents produce clean, complete transaction records with monitoring running in real time, built into execution itself, start from a stronger position than vendors treating compliance as paperwork generated after the fact.
Voice and text interfaces add one more requirement people sometimes miss: the interaction record itself, the instruction given, the action taken, the confirmation sent back, needs to be just as complete and retrievable as any other transaction record. The interface doesn't earn an exemption just because it's conversational.
How the charter landscape sorts the vendor market and what it means for banks choosing partners
Formal rules for agentic AI in banking haven't been written yet, yet the OCC's charter activity is already sorting the vendor market ahead of that, and it's doing it in public. Vendors whose governance could survive charter-level scrutiny are pulling away from vendors still treating compliance as something on next year's roadmap.
That gap matters for banks and credit unions evaluating agentic vendors right now, even ones with no interest in a charter themselves. The questions the OCC asks charter applicants, about AML/CFT program quality, audit completeness, explainability, third-party accountability, are the same questions bank examiners ask about vendor relationships. Community banks and credit unions aren't going to pursue charters of their own, but their vendor choices decide whether they're operating to an examination-ready standard or quietly stacking up third-party risk that surfaces in the next exam cycle.
Adoption data underlines the urgency. Agentic AI use across banking is broad already and still climbing, with most financial services firms engaged at some level. Institutions still on the sidelines aren't choosing into a blank market. They're choosing into one where governance differences between vendors are already visible to anyone looking closely.
So what should a bank actually check before signing? Certification on file, audit records that hold up under review, a control architecture built for scrutiny rather than described for a pitch, weigh more than anything in a sales deck.
Vendors that started from a compliance-first build, treating auditability, configurability, and human oversight as design constraints rather than features bolted on later, are the ones best positioned here. The charter environment rewards a demonstrated governance history over a promise about future compliance, no matter how sincere that promise sounds.
This doesn't close the regulatory gap around agentic AI, and SR 26-2's carve-out makes sure that gap sticks around for a while longer. Even so, the charter wave has raised the reference standard anyway. What a charter applicant has to prove is visible now, in writing, in the Wise denial and the approvals sitting around it. Banks choosing vendors against that standard today are building relationships that hold up once the formal guidance finally catches up to where the practice already stands.


