Agentic AI in mid-market financial services: the 2026 governance playbook for banks, lenders, and broker-dealers
As of April 2026, US banking agencies’ model risk guidance, SR 26-2, places generative and agentic AI outside its scope, and FINRA has named AI agents as a new supervisory risk for broker-dealers. Until AI-specific guidance arrives, a mid-market institution governs agents itself: it scopes what each agent may do, holds consequential actions for a named approver, and records every action in a form an examiner can read.
This guide explains why the gap exists, which workflows are ready for agents now, the five controls that answer an examiner’s questions, and a 90-day plan for a first deployment. It is written for the Chief Risk Officer, Chief Compliance Officer, and COO at a community or regional bank, a specialty or commercial lender, an independent asset or wealth manager, or a FINRA member broker-dealer.
It is not legal advice. Whether a specific control satisfies a specific rule is a determination for your compliance team and counsel.
What changed between December 2025 and April 2026
Five developments, in date order, redrew the map for any institution that wants AI to act rather than only advise.
| Date | What happened | What it means for an agent deployment |
|---|---|---|
| June 2023 | The Federal Reserve, FDIC, and OCC issued joint interagency guidance on third-party relationships | A vendor’s agents are a third-party relationship. The institution manages that risk through planning, due diligence, contracting, monitoring, and termination |
| Dec 9, 2025 | FINRA published its 2026 Annual Regulatory Oversight Report, with a new GenAI section that addresses AI agents | Broker-dealers are asked to consider agent-specific supervision: access and data handling, human-in-the-loop oversight, tracking agent actions, and guardrails |
| Feb 13, 2026 | FinCEN granted exceptive relief (FIN-2026-R001) from re-verifying beneficial owners at every new account opening | Beneficial ownership is verified at first opening, when information is called into question, and under risk-based procedures. Catching the trigger becomes the hard part |
| Feb 19, 2026 | Treasury released the voluntary Financial Services AI Risk Management Framework, with 230 control objectives mapped to adoption stages | A sector-specific vocabulary for AI controls now exists, built to fit community institutions as well as large ones |
| Apr 17, 2026 | The agencies issued SR 26-2, superseding SR 11-7 and SR 21-8 | Generative and agentic AI are explicitly out of scope. The agencies plan a request for information on banks’ use of AI |
We break down what SR 26-2 changed for AI agents in a separate post. The pattern across all five is consistent: no new rule tells a mid-market institution how to govern an AI agent, and every existing obligation still applies to what the agent does.
Why the mid-market feels the gap first
Large institutions have model risk, AI platform, and integration teams that can write their own agent governance. Mid-market institutions face the same scrutiny with a fraction of the staff.
The sizing matters, so it is worth being precise. The Federal Reserve groups supervised institutions into portfolios by total assets: community banking organizations under $10 billion, regional banking organizations from $10 billion to $100 billion, and large institutions above that. FINRA’s By-Laws define member firms by registered persons: small firms have up to 150, mid-size firms 151 to 499, and large firms 500 or more.
Now set SR 26-2 against those bands. The guidance says it is expected to be most relevant to banking organizations with over $30 billion in total assets, and that models at institutions of $30 billion or less are generally subject to internal practices appropriate to their size. Then its scope footnote takes generative and agentic AI out entirely.
For a $3 billion community bank, that is two layers of distance from any model risk guidance written for agents. The same footnote says what fills the space: the institution’s own risk management and governance practices should guide the controls for any tool the guidance does not cover. The bank is expected to govern agents itself, and to be able to show how.
Assistants advise. Agents act. That is where exposure starts.
An AI system that drafts a summary for an analyst to read creates little exposure. An agent that writes to a loan file, contacts a customer, or changes a risk flag creates exposure at the moment it acts. FINRA’s 2026 report draws the same line. It describes agents as systems that can autonomously perform and complete tasks on behalf of a user, and lists the risks that follow:
- Autonomy: acting without human validation and approval.
- Scope and authority: acting beyond the user’s actual or intended scope.
- Auditability and transparency: multi-step reasoning that is hard to trace or explain.
- Data sensitivity: storing, exposing, or misusing sensitive information.
- Domain knowledge: general-purpose agents lacking industry-specific expertise.
- Rewards and reinforcement: misaligned objectives that optimize the wrong outcome.
Nearly every item is about what the agent does and whether anyone can prove what it did. Few are about the model. That is why governing agents is an architecture problem before it is a validation problem. We set out the attribution, explanation, and boundary questions that follow in how financial firms govern internal AI.
Four workflows ready for agents now, and who owns the decision in each
The workflows that suit agents first share three traits: the work is bounded by hours rather than judgment, the inputs are documents and records the institution already holds, and the decision stays with a named person.
| Workflow | What the agent does | What the person decides | Evidence it leaves |
|---|---|---|---|
| Commercial credit memo assembly | Pulls borrower financial statements, filings, and internal data into a draft memo with every source attached | The underwriter approves, edits, or rejects the memo, and makes the credit decision | Draft version, sources consulted, approver, timestamp |
| KYB and beneficial ownership mapping | Cross-references corporate filings and disclosures into a draft ownership and entity map, flagging gaps and conflicts | A compliance analyst reviews every map and every flag | Map version, filings used, flags raised and resolved |
| Portfolio exposure monitoring | Surfaces concentration and pricing anomalies, each linked to its source data | A risk officer decides what, if anything, to act on | Observation, data snapshot, disposition |
| Capital markets and advisory research | Compiles market, company, and comparable-transaction research into draft materials | Bankers and analysts own the final work | Sources, draft, reviewer |
| Communications supervision (broker-dealers) | Holds high-risk messages before they reach a client and routes them to a compliance officer | The compliance officer grants an exception or confirms the violation | Message, rule triggered, decision, decider |
The last row is the model behind Compliance Shield, which sits in front of the send rather than behind it in an archive. The first four are the workflows PrescientIQ supports for banks, lenders, and asset managers. Notice what is absent: credit decisions, suspicious activity determinations, and investment advice. Those remain with people.
Five controls that answer the examiner’s questions
An examiner reviewing an agent deployment is likely to ask five questions, whichever framework they start from. Who acted? On whose authority? On what input? Could it have been stopped? Can you prove all of that from a record made at the time, rather than one reconstructed afterward? Five controls answer them.
| Control | What it does | Question it answers | Where the question comes from |
|---|---|---|---|
| 1. Scoped identity per agent | Each agent runs under its own least-privilege identity, never a shared service account or a borrowed human login | Who acted, and what could it reach? | FINRA: monitor agent system access and data handling; least privilege for human and non-human accounts |
| 2. Approval gate | Consequential actions wait for a named person. Missing approval or missing data halts the workflow | On whose authority? Could it have been stopped? | FINRA: where to place human-in-the-loop oversight |
| 3. Pre-dispatch policy screening | The proposed action is checked against your written rules before it executes, and a block returns the rule that triggered it | Were guardrails in place before the action? | FINRA: guardrails that limit agent behaviors, actions, or decisions |
| 4. Immutable action ledger | Actor, identity, inputs, rationale, approver, and before-and-after state are appended at the moment of action | Can you prove it from a contemporaneous record? | FINRA: track agent actions and decisions |
| 5. Re-testing on rule change | When a rule changes, previously approved records are re-evaluated against it | Did exposure accumulate after the rules moved? | Treasury FS AI RMF: its monitoring control objectives |
Two notes on that table. FINRA’s report says plainly that it creates no new legal requirements; it shares effective practices for firms to consider. The controls answer questions an examiner is likely to ask, not a mandated checklist. And the Treasury framework’s 230 control objectives are organized by adoption stage, so a first pilot should use its adoption-stage questionnaire to find the subset that fits, rather than try to address all of them.
The ledger does the most work, because it turns the other four into evidence. We describe the eight fields a complete entry carries in the audit ledger as the system of record for agent actions, and why the evidence has to exist before anyone asks for it in the evidence production gap.
Two governance modes, chosen per action class
Human-in-the-loop (HITL). The action is drafted and held. It does not execute until a named person on your team approves it.
Human-on-the-loop (HOTL). The action executes under a standing policy your team sets. A named person supervises and keeps intervention, override, and revocation authority.
Your team chooses the mode for each action class, based on its risk tolerance, and can change it at any time.
Every action, in either mode, is recorded to the audit ledger with its rationale, before-and-after state, and the approver or policy behind it.
Every action class starts in human-in-the-loop until your team changes it.
Most institutions will use both modes. How to decide which action classes get which is covered in setting the autonomy ceiling for each action.
Governing the vendor, not only the agent
Most mid-market institutions will buy agents rather than build them. That makes the agent vendor a third-party relationship under the 2023 interagency guidance, which applies across the full life cycle: planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination.
FINRA’s report says much the same for broker-dealers. Its third-party section lists effective practices that include assessing a vendor’s use of GenAI in its products, contract language that keeps firm and customer data out of a vendor’s open-source GenAI tools, and procedures to return or destroy data when a contract ends.
Five questions belong in every agent vendor’s due diligence file:
- Where does the workload run, and whose attestations apply? If the infrastructure provider holds the attestation and the vendor’s own is in progress, the file should say so in those words.
- What identity does each agent use, and what can it write? Ask for the write list by agent.
- Is the approval gate the default, or an option someone can switch off? Ask the vendor to try to skip it in the demo.
- What does an audit record contain, and can you export it without the vendor’s help?
- What happens to your data, prompts, and logs at termination? Get it in the contract, not on a web page.
A broader version is in seven governance questions to ask an AI agent vendor, and what an AI agent security review actually checks covers the security side. For MatrixLabX, the answer to the first question is this:
PrescientIQ is hosted and operated by MatrixLabX on Google Cloud. SOC 2, ISO 27001, and PCI DSS attestations are held by Google Cloud, which operates the underlying infrastructure. They are not MatrixLabX certifications. MatrixLabX application-layer SOC 2 is in progress.
Readiness self-score: twelve statements, ten minutes
Two statements for each of the six dimensions the Agentic Readiness Audit assesses. Score each 0 (no), 1 (partly), or 2 (yes). Nothing you select is stored or sent anywhere. Your total appears when all twelve are answered.
Answered 0 of 12
0 / 24
- 18–24:
- Ready to pilot one workflow
- 10–17:
- Close specific gaps first
- 0–9:
- Start with inventory and governance
Decision tree: which workflow first
Choose the first workflow by two tests, in this order.
- Where is the data closest to ready? An agent on imperfect data is survivable only if a bad record is caught before anything leaves the building. Start where it would be. We make the case in deploying agents on the data you actually have.
- Where does an error land? Prefer workflows whose output goes to an internal approver, such as a draft credit memo or an ownership map, over workflows that reach a customer or a regulator directly.
For most banks and lenders, those tests point to credit memo assembly or KYB mapping first. For broker-dealers, they usually point to pre-send communications review, because the exposure is already in the send path.
A 90-day plan for a first deployment
Weeks 1 to 2: inventory and assess. List every AI capability already active in your stack, including default-on features in tools you already license. Run the Agentic Readiness Audit, which returns a written assessment within 48 hours of the intake session.
Weeks 3 to 6: one workflow, held for approval. Deploy agents on one workflow with every consequential action held for a named approver and the ledger recording from the first action. Add it to your third-party inventory and your AI inventory on day one.
Weeks 7 to 12: review the evidence, then decide. Export the ledger. Review rejection reasons, approval turnaround, and any action the gate stopped. Decide, with evidence, whether to expand the workflow, move a low-risk action class to standing policy, or stop. Bring that record to the board.
See which of your workflows are ready, before any commitment
The free Agentic Readiness Audit assesses governance, non-human identity, shadow AI, data readiness, workflow suitability, and evidence, and returns a written assessment within 48 hours of the intake session.
Get the readiness auditWhat we will not tell you
That the platform makes your institution compliant. Compliance is a property of your program. The platform enforces the governance mode you set and records what happened.
That an agent makes credit, suspicious-activity, or investment decisions. It does not. Agents prepare and surface. People decide.
That we have published customer outcomes. MatrixLabX is in a founding pilot program and does not publish measured customer results. The readiness audit works from your own data before any commitment.
That the regulatory picture is settled. The agencies have said a request for information on AI is coming. Build controls you would keep whatever it says.
Frequently Asked Questions
- Does SR 26-2 apply to AI agents?
- No. SR 26-2, the April 2026 interagency model risk guidance, states that generative AI and agentic AI models are novel and rapidly evolving and are not within its scope. It directs banking organizations to rely on their own risk management and governance practices for tools it does not cover, and the agencies plan a request for information on AI.
- Is the Treasury Financial Services AI Risk Management Framework mandatory?
- No. Treasury released the Financial Services AI Risk Management Framework in February 2026 as a voluntary resource. It adapts the NIST AI Risk Management Framework to financial services, with 230 control objectives organized by stage of AI adoption, and it was designed to fit institutions of every size, including community banks and credit unions.
- What did FINRA say about AI agents in its 2026 report?
- FINRA’s 2026 Annual Regulatory Oversight Report addressed AI agents for the first time. It listed risks including autonomy without human validation, agents acting beyond their intended scope, and reasoning that is hard to trace, and suggested firms consider monitoring agent access, human-in-the-loop oversight, tracking agent actions, and guardrails on agent behavior.
- Can an AI agent make a credit decision at a bank?
- Under a governed model, no. An AI agent can assemble borrower financial statements, filings, and internal data into a draft credit memo with every source attached, but the underwriter approves the memo and makes the credit decision. The agent’s output is an input to that decision, never a substitute for the person accountable for it.
- Who is accountable when a vendor’s AI agent acts?
- The financial institution remains accountable. Under the 2023 interagency guidance on third-party relationships, using a vendor does not transfer responsibility for managing the risk. Planning, due diligence, contract terms, ongoing monitoring, and termination all apply to an AI agent vendor, the same as they do to any other third party supporting a critical activity.
- What should an audit record for an AI agent contain?
- An audit record for an AI agent should show which agent acted and under which identity, the inputs it relied on, its rationale, the person who approved the action or the standing policy that covered it, the time, and the record’s state before and after. It should be written when the action happens, not reconstructed later.
- Is a community bank too small to deploy AI agents?
- Not if the deployment fits the bank’s governance capacity. A community bank can start with one workflow where an agent assembles work and an existing approver decides, with every action recorded. Treasury designed its financial services AI framework for institutions of every size, and a narrow first workflow keeps the control set manageable.
- How does a financial institution get started with MatrixLabX?
- A financial institution starts with the free MatrixLabX Agentic Readiness Audit. It assesses governance, non-human identity, shadow AI, data readiness, workflow suitability, and evidence, then returns a written assessment within 48 hours of the intake session, including which workflows are ready now and which should stay with people.
Broker-dealer and fintech compliance teams evaluating pre-send communications supervision can talk to us about Compliance Shield early access. Closed beta is targeted for December 2026.
Related Reading
Sources
- Board of Governors of the Federal Reserve System, SR 26-2: Revised Guidance on Model Risk Management, April 17, 2026, and the guidance text (PDF)
- Office of the Comptroller of the Currency, News Release 2026-29, April 17, 2026
- FINRA, 2026 Annual Regulatory Oversight Report, December 2025
- Board of Governors of the Federal Reserve System, SR 23-4: Interagency Guidance on Third-Party Relationships, June 7, 2023
- FinCEN, Customer Due Diligence Final Rule and FIN-2026-R001
- ExecutiveGov, Treasury Issues AI Lexicon, Risk Framework for Financial Sector, February 23, 2026
- Board of Governors of the Federal Reserve System, 2024 Annual Report: Supervision and Regulation
- FINRA, By-Laws of FINRA Regulation, Article I: Definitions
This guide describes how governed AI agents are designed to operate and summarizes public regulatory documents. It is not legal, regulatory, or investment advice. Whether any control satisfies a specific supervisory or recordkeeping requirement is a determination for your compliance team and counsel.