AI Regulation · Compliance

OSFI E-23 vs SR 26-2 vs EU AI Act: Agentic AI Compliance Compared for 2026

Three regulators moved in three different directions between 2025 and 2026. Here is what each framework requires, where they conflict, and why liability stays with your institution regardless of which regime applies.

📅 July 29, 2026 ✍ AgentTrust OS ⏱ 9 min read 🏦 Banking · Insurance · Credit Unions
AgentTrust OS AGENTIC AI GOVERNANCE AI REGULATION · COMPLIANCE OSFI E-23 vs SR 26-2 vs EU AI Act: Agentic AI Compliance 2026 CANADA OSFI Guideline E-23 Sep 2025 UNITED STATES SR 26-2 / OCC 2026-13 Apr 2026 EUROPEAN UNION EU AI Act — Annex III In force 3 REGIMES · CONFLICTING OBLIGATIONS Sources: OSFI Guideline E-23 (Sep 2025) · SR 26-2/OCC 2026-13 (Apr 2026) · EU AI Act Annex III agent-trust.tech
Three simultaneous regulatory regimes create conflicting obligations for AI agent deployments — OSFI, SR 26-2, and EU AI Act
Key Facts — Citable Regulatory Summary
  • According to OSFI Guideline E-23 (published September 2025, effective May 1, 2027), all federally regulated financial institutions (FRFIs) must bring AI and machine learning models under their existing model risk management frameworks, with defined model ownership, validation, and risk appetite documentation.
  • SR 26-2 (Federal Reserve, April 2026) and companion OCC Bulletin 2026-13 (April 2026) explicitly exclude generative AI and agentic AI systems from the existing SR 11-7 model risk management guidance, acknowledging that non-deterministic systems require a different supervisory approach currently in development.
  • The EU AI Act Annex III classifies AI systems used for credit scoring, insurance pricing, and loan underwriting as high-risk AI applications. Conformity assessments and technical documentation for these systems must be completed before deployment; compliance deadlines for high-risk financial AI run to 2027–2028.
  • Per the EU AI Act Article 9, providers of high-risk AI systems bear primary conformity obligations, but deployers (i.e. financial institutions) carry independent obligations for monitoring, logging, and human oversight — regardless of whether the model was built in-house or purchased from a vendor.
  • According to OSFI E-23 Section 4.2, model inventory requirements extend to AI/ML models, including those procured from third parties, placing accountability squarely on the FRFI, not the technology vendor.
TL;DR
  • The EU AI Act flags agentic credit/insurance AI as high-risk with 2027–2028 deadlines; documentation work starts now.
  • SR 26-2 and OCC 2026-13 carve GenAI/agentic AI out of SR 11-7 MRM — but offer no replacement framework yet.
  • OSFI Guideline E-23 (effective May 1, 2027) explicitly folds AI/ML into model risk management for all Canadian FRFIs.
  • A Canadian bank with US and European operations faces all three regimes simultaneously — with no single compliance posture satisfying all three.
  • In every regime, institutional liability for AI agent failures stays with the deploying organization, not the technology vendor.
Keep reading → Full framework comparison, jurisdiction diagram, and compliance action checklist below.

In the span of eighteen months, three of the world's most important financial regulators made consequential moves on artificial intelligence — and they did not move in the same direction. The EU tightened. The US explicitly backed away from applying existing rules. Canada quietly folded AI into the framework it already had. The result is a regulatory divergence that compliance officers in globally active financial institutions must now navigate simultaneously.

The most dangerous assumption a CRO can make right now is "the rules aren't ready." They are ready. They just conflict. A Canadian bank running credit-decisioning agents that process European customers while reporting to US parent entity regulators now sits at the intersection of three distinct and partially contradictory compliance regimes. None of them accept "our AI vendor is responsible" as a valid compliance posture.

This article provides a practitioner-level comparison of the three frameworks, explains what each requires for agentic AI systems specifically, and identifies the action items that cannot wait for further regulatory clarity.

What is OSFI Guideline E-23 and why does it matter for AI-deploying Canadian banks?

OSFI Guideline E-23, published in September 2025 with an effective date of May 1, 2027, is the Office of the Superintendent of Financial Institutions' consolidated model risk management guidance for federally regulated financial institutions. It explicitly extends the definition of "model" to include AI and machine learning systems, requiring FRFIs to apply the same governance, validation, and risk appetite documentation to algorithmic models that they already apply to statistical risk models.

The practical impact is significant for institutions that had been treating AI deployments as technology projects rather than model risk events. Under E-23, every AI model deployed in a risk-relevant function must have a named model owner, a documented model purpose and known limitations, an independent validation record, and a clear statement of the institution's appetite for the model's failure modes. This applies whether the model was built internally or procured from a third party.

For agentic AI systems — those that take autonomous actions, call external tools, or chain multi-step decisions — the E-23 inventory and validation requirements are particularly demanding. An agent that orchestrates credit limit adjustments, fraud disposition decisions, or insurance underwriting exceptions is unambiguously in scope. The May 1, 2027 effective date is closer than it appears when validation queues, governance documentation, and board-level risk appetite discussions are factored in.

Definition · OSFI Guideline E-23

OSFI Guideline E-23 is the Office of the Superintendent of Financial Institutions' consolidated model risk management standard, published September 2025 and effective May 1, 2027. It applies to all federally regulated financial institutions (FRFIs) in Canada and explicitly includes AI and ML models within its scope. Key requirements: model inventory with named ownership, independent validation, documented limitations, and board-level risk appetite alignment. Third-party AI models are in scope; vendor liability does not transfer institutional obligations.

What did SR 26-2 and OCC Bulletin 2026-13 actually change for US bank AI governance?

In April 2026, the Federal Reserve issued SR 26-2 and the OCC issued companion Bulletin 2026-13, jointly declaring that existing SR 11-7 model risk management guidance does not apply to generative AI and agentic AI systems. At first glance, this sounds like regulatory relief. On closer inspection, it creates a governance vacuum that many institutions are misreading as permission to proceed without controls.

The carve-out was made because regulators acknowledged that SR 11-7's validation methodology — designed for deterministic statistical models that produce consistent outputs for identical inputs — does not map cleanly onto non-deterministic language model systems. This is a technically sound observation. But the withdrawal of SR 11-7 applicability was explicitly accompanied by language indicating that new guidance specific to GenAI/agentic systems is under development, and that institutions are expected to have their own internal risk management frameworks in place in the interim.

Critically, SR 26-2 does not create a compliance-free zone. Safety and soundness obligations, fair lending requirements, unfair or deceptive acts or practices (UDAAP) prohibitions, and operational risk capital requirements all continue to apply. US bank CROs who interpret SR 26-2 as "agentic AI doesn't need governance" are misreading the guidance and creating significant examination risk.

Definition · SR 26-2 / OCC Bulletin 2026-13

SR 26-2 (Federal Reserve, April 2026) and OCC Bulletin 2026-13 (April 2026) jointly exclude generative AI and agentic AI systems from the scope of SR 11-7 model risk management guidance, citing non-determinism as incompatible with SR 11-7's validation methodology. They do not create a compliance exemption — safety and soundness, UDAAP, fair lending, and operational risk obligations remain in full force. New purpose-built guidance for GenAI/agentic systems is in development. Institutions are expected to maintain internal controls in the interim.

2025–2026 Regulatory Divergence: AI Agents in Financial Services 🇨🇦 OSFI E-23 🇺🇸 SR 26-2 / OCC 2026-13 🇪🇺 EU AI Act Annex III DIRECTION FOLDS IN AI/ML added to MRM scope CARVES OUT GenAI/Agentic ≠ SR 11-7 CLASSIFIES Credit/insurance AI = High-Risk EFFECTIVE DATE May 1, 2027 April 2026 (in effect) 2027–2028 (high-risk) VENDOR EXEMPTION? NO — FRFI liable NO — Bank liable NO — Deployer liable All three regimes: institutional liability stays with the deploying organization, not the AI vendor.
Figure 1: Regulatory directions for agentic AI in financial services — OSFI E-23, SR 26-2/OCC 2026-13, and EU AI Act Annex III compared across three key dimensions.

What does the EU AI Act require for agentic AI in credit and insurance?

The EU AI Act, through Annex III, classifies AI systems used in credit scoring, insurance risk assessment, and loan underwriting decisions as high-risk AI applications. For financial institutions deploying agents that touch these functions, the Act imposes a structured conformity assessment process that must be completed before the system can be deployed in the EU market. This includes technical documentation of the system's design and training methodology, logging and monitoring requirements, human oversight mechanisms, and registration in the EU's forthcoming AI database.

The compliance deadlines for high-risk AI systems in financial services run to 2027 and 2028, depending on when the relevant delegated acts come into force. However, these deadlines are frequently misunderstood as "we don't need to start yet." The documentation, risk classification, technical assessment, and governance infrastructure required by the Act takes substantial time to build. Institutions that begin in 2026 will be adequately prepared; those that wait until 2027 will face compressed timelines and examination risk.

Critically, the EU AI Act's deployer obligations are independent of provider obligations. A financial institution that deploys a third-party AI agent for credit decisioning cannot offload its Article 9 obligations to the model vendor. The deployer must independently ensure that the system operates within the risk management framework and that human override mechanisms are in place and functional.

Definition · EU AI Act Annex III High-Risk AI

The EU AI Act designates AI systems in credit scoring, insurance pricing, and loan underwriting as high-risk AI under Annex III. High-risk systems require: conformity assessment before deployment, technical documentation per Article 11, accuracy/robustness/cybersecurity standards per Article 15, human oversight per Article 14, and post-market monitoring. Deployers carry independent obligations separate from the AI provider/developer. Deadline for compliance: 2027–2028 for Annex III financial services systems.

3
Overlapping regimes for Canadian banks with EU/US exposure
2027
OSFI E-23 effective date — May 1, 2027
0
Regimes that accept "our vendor handles it" as compliance
100%
Deployer liability retained under all three frameworks

Where do SR 26-2 and OSFI E-23 directly conflict for a Canadian bank?

The most acute conflict for Canadian banks with US subsidiary operations arises from the directly opposed regulatory postures of OSFI E-23 and SR 26-2. OSFI explicitly folds AI/ML into MRM scope; SR 26-2 explicitly excludes GenAI/agentic AI from MRM scope. A Canadian bank running US banking operations faces a scenario where its OSFI compliance program requires formal MRM treatment of its agentic systems while its Fed/OCC examiners are operating under guidance that says traditional MRM doesn't apply.

The practical resolution is not to pick one regime and ignore the other. Instead, the most defensible approach is to build a governance framework that satisfies the more demanding of the two requirements — in this case, OSFI E-23 — while documenting the rationale for how that framework addresses SR 26-2's safety and soundness expectations. This is a common multi-jurisdiction compliance pattern: establish a global baseline at the highest common denominator and document jurisdiction-specific exceptions.

What institutions should not do is interpret SR 26-2's MRM carve-out as an invitation to defer all governance work. The Fed's 2025 and 2026 examination findings on operational risk at large banks with AI deployments have consistently noted inadequate change management, insufficient model inventory coverage, and absent human escalation paths — all issues that pre-date SR 26-2 but are now squarely in the safety and soundness examination framework.

What specific documentation does OSFI Guideline E-23 require for agentic AI systems?

OSFI Guideline E-23 requires FRFIs to maintain a comprehensive model inventory that includes all AI and ML models, with each entry containing: the model's intended use and known limitations; the name and role of the model owner; a summary of the validation methodology applied; a statement of the board-approved risk appetite for the model's failure modes; and a record of material changes, re-validations, and incidents.

For agentic AI systems specifically, several E-23 requirements become particularly demanding. The "known limitations" requirement necessitates formal red-teaming or adversarial testing to identify failure modes such as hallucination, prompt injection, and tool misuse — categories that don't exist in traditional MRM vocabulary. The "validation methodology" requirement must address non-deterministic outputs, meaning validation cannot simply compare model predictions to a holdout dataset but must assess behavioral policies across a distribution of inputs. And the "human escalation" requirements become governance questions about which agent decisions require human review before execution.

Does the EU AI Act apply to AI agents deployed by non-EU financial institutions?

Yes — the EU AI Act has explicit extraterritorial reach. Article 2(1)(c) applies the Act to providers and deployers located outside the EU when the output of the AI system is used in the EU. For a Canadian or US bank that deploys agents processing loan applications or insurance quotes from EU-resident customers, the Act's high-risk provisions apply regardless of where the deploying institution is headquartered or where the AI system is hosted.

The practical implication is that global banks cannot treat EU AI Act compliance as a European subsidiary problem. If the agent's output affects EU customers, the group-level governance must satisfy the Act. This is especially relevant for AI agents that operate across customer geographies by design — a credit limit adjustment agent for a multi-national card portfolio, for example, likely touches EU customers in the normal course of operation.

What is the minimum viable governance framework that satisfies all three regimes?

Given the three-regime landscape, the minimum viable governance framework for a globally active bank must include seven capabilities. First, a living model inventory with AI/ML scope coverage that satisfies E-23's documentation requirements. Second, behavioral policy documentation (what the agent is and is not authorized to do) that satisfies the EU AI Act's Article 9 risk management requirements. Third, a validation methodology that addresses non-determinism — either through distribution-based eval, policy-as-code testing, or red-teaming. Fourth, logging and audit trail infrastructure that produces the human-readable explanations required under both E-23 and the EU AI Act's transparency requirements. Fifth, a human escalation framework that defines which agent decision categories require pre-approval versus post-review. Sixth, a third-party AI vendor management process that establishes contractual liability, obtains technical documentation, and integrates vendor AI into the institution's model inventory. And seventh, a board-level AI risk appetite statement that covers agentic systems specifically.

Institutions that build this framework satisfy E-23's explicit requirements, provide the internal control infrastructure that SR 26-2 implicitly requires pending new guidance, and address the EU AI Act's Article 9 risk management obligations for high-risk AI.

Governance Platform Approach

Regulated institutions navigating this three-regime landscape are increasingly looking for governance platforms that can operationalize model inventory, behavioral policy enforcement, and audit trail generation across their agentic AI deployments. The requirements map cleanly onto three governance functions: pre-production certification (does this agent behave within its documented policy?), runtime validation (is this specific decision within the agent's authorized scope?), and post-execution audit (can we explain this decision to a regulator in plain language?).

Agent Code + Policy Docs Trust Certify Pre-Prod Gate · E-23 Validation Approved Certified for Prod Live Request Agent Decision Trust Runtime Contract · Scope · EU Art.9 Trust Audit Trace · Explain · Report
Figure 2: A governance platform that operationalizes OSFI E-23 validation (pre-prod), EU AI Act Article 9 runtime oversight, and audit trail generation for all three regimes.

The key insight is that the three regulatory requirements map to three distinct points in the agent lifecycle — certification at build time, validation at runtime, and explanation at audit time. A governance platform that instruments all three points can produce the documentation artifacts required by OSFI E-23, the EU AI Act, and the safety-and-soundness expectations of US regulators from a single telemetry stream.

Frequently Asked Questions

Does SR 26-2 mean US banks don't need to govern their AI agents?
No. SR 26-2 removes agentic AI from the scope of SR 11-7 model risk management guidance — it does not remove safety and soundness obligations, UDAAP requirements, or operational risk expectations. Banks are explicitly expected to maintain internal control frameworks for GenAI/agentic systems while new purpose-built guidance is developed. Examination findings have consistently cited inadequate AI governance as a safety and soundness concern independent of SR 11-7 applicability.
When does OSFI Guideline E-23 come into effect for AI systems?
OSFI Guideline E-23 was published in September 2025 and comes into full effect on May 1, 2027, for all federally regulated financial institutions. The effective date applies to the full scope of the guideline including AI and ML model provisions. FRFIs are expected to begin gap assessments and remediation work well before the effective date; OSFI has indicated that examination activities will assess readiness in the 2026–2027 period.
Which AI systems does the EU AI Act classify as high-risk in financial services?
Under EU AI Act Annex III, AI systems used for creditworthiness assessment, credit scoring, loan underwriting, and insurance risk assessment and pricing are classified as high-risk. This includes AI agents that make or influence these decisions autonomously. High-risk classification requires conformity assessment, technical documentation, human oversight mechanisms, and post-market monitoring before deployment in the EU market.
Can a financial institution delegate EU AI Act compliance to its AI vendor?
No. The EU AI Act creates independent obligations for providers (those who develop or make available the AI system) and deployers (those who use it in a professional context). As a deployer, a financial institution must independently ensure human oversight, conduct its own monitoring, and maintain records — regardless of what the vendor provides. Vendor contracts that purport to transfer these obligations are legally ineffective under the Act.
What is the first practical step for a bank that hasn't started AI governance yet?
Build a model inventory. This is the foundational requirement under OSFI E-23 and the most common gap identified in regulatory examinations. The inventory should enumerate all AI and ML models in production, including those embedded in third-party software, with named model owners. From the inventory, risk tier each model (using the EU AI Act's high-risk classification as a starting framework), then prioritize validation and documentation work by tier. Inventory alone will not achieve compliance, but no compliance program can proceed without it.
How does this regulatory picture apply to credit unions and smaller FRFIs?
OSFI Guideline E-23 applies to all federally regulated financial institutions, including federal credit unions. Proportionality is built into the framework — smaller institutions with simpler AI deployments face a lower absolute documentation burden. However, the core requirements (model inventory, ownership, validation, and risk appetite documentation) apply regardless of size. The May 1, 2027 effective date is the same for all FRFIs.
AgentTrust OS

Ready to Govern Your Agents?

Map your AI agents to the tier your home regulator expects — OSFI E-23, EU AI Act, or SR 26-2 framework. AgentTrust OS operationalizes pre-production certification, runtime validation, and audit-ready reporting in one platform.

Start Free →