Three regulators moved in three different directions between 2025 and 2026. Here is what each framework requires, where they conflict, and why liability stays with your institution regardless of which regime applies.
In the span of eighteen months, three of the world's most important financial regulators made consequential moves on artificial intelligence — and they did not move in the same direction. The EU tightened. The US explicitly backed away from applying existing rules. Canada quietly folded AI into the framework it already had. The result is a regulatory divergence that compliance officers in globally active financial institutions must now navigate simultaneously.
The most dangerous assumption a CRO can make right now is "the rules aren't ready." They are ready. They just conflict. A Canadian bank running credit-decisioning agents that process European customers while reporting to US parent entity regulators now sits at the intersection of three distinct and partially contradictory compliance regimes. None of them accept "our AI vendor is responsible" as a valid compliance posture.
This article provides a practitioner-level comparison of the three frameworks, explains what each requires for agentic AI systems specifically, and identifies the action items that cannot wait for further regulatory clarity.
OSFI Guideline E-23, published in September 2025 with an effective date of May 1, 2027, is the Office of the Superintendent of Financial Institutions' consolidated model risk management guidance for federally regulated financial institutions. It explicitly extends the definition of "model" to include AI and machine learning systems, requiring FRFIs to apply the same governance, validation, and risk appetite documentation to algorithmic models that they already apply to statistical risk models.
The practical impact is significant for institutions that had been treating AI deployments as technology projects rather than model risk events. Under E-23, every AI model deployed in a risk-relevant function must have a named model owner, a documented model purpose and known limitations, an independent validation record, and a clear statement of the institution's appetite for the model's failure modes. This applies whether the model was built internally or procured from a third party.
For agentic AI systems — those that take autonomous actions, call external tools, or chain multi-step decisions — the E-23 inventory and validation requirements are particularly demanding. An agent that orchestrates credit limit adjustments, fraud disposition decisions, or insurance underwriting exceptions is unambiguously in scope. The May 1, 2027 effective date is closer than it appears when validation queues, governance documentation, and board-level risk appetite discussions are factored in.
OSFI Guideline E-23 is the Office of the Superintendent of Financial Institutions' consolidated model risk management standard, published September 2025 and effective May 1, 2027. It applies to all federally regulated financial institutions (FRFIs) in Canada and explicitly includes AI and ML models within its scope. Key requirements: model inventory with named ownership, independent validation, documented limitations, and board-level risk appetite alignment. Third-party AI models are in scope; vendor liability does not transfer institutional obligations.
In April 2026, the Federal Reserve issued SR 26-2 and the OCC issued companion Bulletin 2026-13, jointly declaring that existing SR 11-7 model risk management guidance does not apply to generative AI and agentic AI systems. At first glance, this sounds like regulatory relief. On closer inspection, it creates a governance vacuum that many institutions are misreading as permission to proceed without controls.
The carve-out was made because regulators acknowledged that SR 11-7's validation methodology — designed for deterministic statistical models that produce consistent outputs for identical inputs — does not map cleanly onto non-deterministic language model systems. This is a technically sound observation. But the withdrawal of SR 11-7 applicability was explicitly accompanied by language indicating that new guidance specific to GenAI/agentic systems is under development, and that institutions are expected to have their own internal risk management frameworks in place in the interim.
Critically, SR 26-2 does not create a compliance-free zone. Safety and soundness obligations, fair lending requirements, unfair or deceptive acts or practices (UDAAP) prohibitions, and operational risk capital requirements all continue to apply. US bank CROs who interpret SR 26-2 as "agentic AI doesn't need governance" are misreading the guidance and creating significant examination risk.
SR 26-2 (Federal Reserve, April 2026) and OCC Bulletin 2026-13 (April 2026) jointly exclude generative AI and agentic AI systems from the scope of SR 11-7 model risk management guidance, citing non-determinism as incompatible with SR 11-7's validation methodology. They do not create a compliance exemption — safety and soundness, UDAAP, fair lending, and operational risk obligations remain in full force. New purpose-built guidance for GenAI/agentic systems is in development. Institutions are expected to maintain internal controls in the interim.
The EU AI Act, through Annex III, classifies AI systems used in credit scoring, insurance risk assessment, and loan underwriting decisions as high-risk AI applications. For financial institutions deploying agents that touch these functions, the Act imposes a structured conformity assessment process that must be completed before the system can be deployed in the EU market. This includes technical documentation of the system's design and training methodology, logging and monitoring requirements, human oversight mechanisms, and registration in the EU's forthcoming AI database.
The compliance deadlines for high-risk AI systems in financial services run to 2027 and 2028, depending on when the relevant delegated acts come into force. However, these deadlines are frequently misunderstood as "we don't need to start yet." The documentation, risk classification, technical assessment, and governance infrastructure required by the Act takes substantial time to build. Institutions that begin in 2026 will be adequately prepared; those that wait until 2027 will face compressed timelines and examination risk.
Critically, the EU AI Act's deployer obligations are independent of provider obligations. A financial institution that deploys a third-party AI agent for credit decisioning cannot offload its Article 9 obligations to the model vendor. The deployer must independently ensure that the system operates within the risk management framework and that human override mechanisms are in place and functional.
The EU AI Act designates AI systems in credit scoring, insurance pricing, and loan underwriting as high-risk AI under Annex III. High-risk systems require: conformity assessment before deployment, technical documentation per Article 11, accuracy/robustness/cybersecurity standards per Article 15, human oversight per Article 14, and post-market monitoring. Deployers carry independent obligations separate from the AI provider/developer. Deadline for compliance: 2027–2028 for Annex III financial services systems.
The most acute conflict for Canadian banks with US subsidiary operations arises from the directly opposed regulatory postures of OSFI E-23 and SR 26-2. OSFI explicitly folds AI/ML into MRM scope; SR 26-2 explicitly excludes GenAI/agentic AI from MRM scope. A Canadian bank running US banking operations faces a scenario where its OSFI compliance program requires formal MRM treatment of its agentic systems while its Fed/OCC examiners are operating under guidance that says traditional MRM doesn't apply.
The practical resolution is not to pick one regime and ignore the other. Instead, the most defensible approach is to build a governance framework that satisfies the more demanding of the two requirements — in this case, OSFI E-23 — while documenting the rationale for how that framework addresses SR 26-2's safety and soundness expectations. This is a common multi-jurisdiction compliance pattern: establish a global baseline at the highest common denominator and document jurisdiction-specific exceptions.
What institutions should not do is interpret SR 26-2's MRM carve-out as an invitation to defer all governance work. The Fed's 2025 and 2026 examination findings on operational risk at large banks with AI deployments have consistently noted inadequate change management, insufficient model inventory coverage, and absent human escalation paths — all issues that pre-date SR 26-2 but are now squarely in the safety and soundness examination framework.
OSFI Guideline E-23 requires FRFIs to maintain a comprehensive model inventory that includes all AI and ML models, with each entry containing: the model's intended use and known limitations; the name and role of the model owner; a summary of the validation methodology applied; a statement of the board-approved risk appetite for the model's failure modes; and a record of material changes, re-validations, and incidents.
For agentic AI systems specifically, several E-23 requirements become particularly demanding. The "known limitations" requirement necessitates formal red-teaming or adversarial testing to identify failure modes such as hallucination, prompt injection, and tool misuse — categories that don't exist in traditional MRM vocabulary. The "validation methodology" requirement must address non-deterministic outputs, meaning validation cannot simply compare model predictions to a holdout dataset but must assess behavioral policies across a distribution of inputs. And the "human escalation" requirements become governance questions about which agent decisions require human review before execution.
Yes — the EU AI Act has explicit extraterritorial reach. Article 2(1)(c) applies the Act to providers and deployers located outside the EU when the output of the AI system is used in the EU. For a Canadian or US bank that deploys agents processing loan applications or insurance quotes from EU-resident customers, the Act's high-risk provisions apply regardless of where the deploying institution is headquartered or where the AI system is hosted.
The practical implication is that global banks cannot treat EU AI Act compliance as a European subsidiary problem. If the agent's output affects EU customers, the group-level governance must satisfy the Act. This is especially relevant for AI agents that operate across customer geographies by design — a credit limit adjustment agent for a multi-national card portfolio, for example, likely touches EU customers in the normal course of operation.
Given the three-regime landscape, the minimum viable governance framework for a globally active bank must include seven capabilities. First, a living model inventory with AI/ML scope coverage that satisfies E-23's documentation requirements. Second, behavioral policy documentation (what the agent is and is not authorized to do) that satisfies the EU AI Act's Article 9 risk management requirements. Third, a validation methodology that addresses non-determinism — either through distribution-based eval, policy-as-code testing, or red-teaming. Fourth, logging and audit trail infrastructure that produces the human-readable explanations required under both E-23 and the EU AI Act's transparency requirements. Fifth, a human escalation framework that defines which agent decision categories require pre-approval versus post-review. Sixth, a third-party AI vendor management process that establishes contractual liability, obtains technical documentation, and integrates vendor AI into the institution's model inventory. And seventh, a board-level AI risk appetite statement that covers agentic systems specifically.
Institutions that build this framework satisfy E-23's explicit requirements, provide the internal control infrastructure that SR 26-2 implicitly requires pending new guidance, and address the EU AI Act's Article 9 risk management obligations for high-risk AI.
Regulated institutions navigating this three-regime landscape are increasingly looking for governance platforms that can operationalize model inventory, behavioral policy enforcement, and audit trail generation across their agentic AI deployments. The requirements map cleanly onto three governance functions: pre-production certification (does this agent behave within its documented policy?), runtime validation (is this specific decision within the agent's authorized scope?), and post-execution audit (can we explain this decision to a regulator in plain language?).
The key insight is that the three regulatory requirements map to three distinct points in the agent lifecycle — certification at build time, validation at runtime, and explanation at audit time. A governance platform that instruments all three points can produce the documentation artifacts required by OSFI E-23, the EU AI Act, and the safety-and-soundness expectations of US regulators from a single telemetry stream.
Map your AI agents to the tier your home regulator expects — OSFI E-23, EU AI Act, or SR 26-2 framework. AgentTrust OS operationalizes pre-production certification, runtime validation, and audit-ready reporting in one platform.
Start Free →