Radar

What actually moved, and what it changes

Supervisory movement on AI agents across the regimes this practice works in. Every entry carries the primary source, a plain account of what it says, and a separate reading of what it changes — kept separate so you can take the first and argue with the second.

14 instruments · 9 in force · 2 phasing · 2 with a future date · 1 superseded and kept.

Oldest entry review: 2026-07-24 — the oldest, not the newest, because quoting the most recently checked item would describe the best-maintained corner rather than the register. 5 of 14 are marked reported rather than verified: credible secondary reporting not yet confirmed at source. They are labelled inline so you can discount them.
Dates ahead

The ones with a date on them

A concern with a date behaves differently from a general anxiety — it can be planned against, budgeted for, and taken to a committee. These are the dated obligations not yet landed, as at 10 August 2026.

Fall 2026 National MeetingNational Association of Insurance Commissioners

NAIC AI evaluation tool

The practical effect of a shared evaluation tool is that examination questions converge across states, which removes the variance insurers have been managing around. Whatever it asks for becomes the de facto minimum in every adopting jurisdiction at once.

12 May 2027Ministry of Electronics and IT, India

DPDP Act — significant data fiduciary audit obligation

The date that should be in a planning cycle now rather than in 2027. An agent that retrieves context aggressively to answer narrowly is in direct tension with purpose limitation, and that is an architectural property — not something a policy document resolves in the quarter before an audit.

The register

Everything, newest first

Showing 14 of 14

Expected12 May 2027Ministry of Electronics and IT, India

DPDP Act — significant data fiduciary audit obligation

Organisations designated as significant data fiduciaries face audit and data-protection-impact-assessment obligations on the published commencement timetable.

What it changes. The date that should be in a planning cycle now rather than in 2027. An agent that retrieves context aggressively to answer narrowly is in direct tension with purpose limitation, and that is an architectural property — not something a policy document resolves in the quarter before an audit.

MeitY — DPDP Act and rules · reported, not yet confirmed at source · reviewed 2026-08-10 · India

ExpectedFall 2026 National MeetingNational Association of Insurance Commissioners

NAIC AI evaluation tool

An evaluation instrument for insurer AI use, piloted across a number of states and expected to progress at the Fall 2026 National Meeting.

What it changes. The practical effect of a shared evaluation tool is that examination questions converge across states, which removes the variance insurers have been managing around. Whatever it asks for becomes the de facto minimum in every adopting jurisdiction at once.

NAIC — Big Data and Artificial Intelligence Working Group · reported, not yet confirmed at source · reviewed 2026-08-10 · Insurance

Phasing in20 March 2026 and June 2026Nacha

Nacha fraud-monitoring rules, phases 1 and 2

Phased fraud-monitoring obligations requiring detection of payments authorised under false pretenses. Phase 2 carries no volume threshold, so it reaches participants the first phase did not.

What it changes. The connection almost nobody is making: a manipulated agent produces exactly an authorisation that was technically valid and substantively induced. That is the definition being written about. If an agent in your payment flow can be steered by its inputs, prompt injection stopped being a security curiosity and became an unauthorised transaction with a real counterparty and a real settlement. Both phases are already live.

Nacha rules and operating guidelines · checked against the source · reviewed 2026-08-10 · Payments

In force5 May 2026Securities and Exchange Board of India

Cybersecurity circular and Cyber Suraksha AI task force

Cybersecurity requirements for market intermediaries, establishing a task force with an explicit AI remit.

What it changes. Worth watching rather than acting on immediately. The significance is institutional: a standing body with an AI mandate is how specific expectations get written, and it is easier to shape a position before those exist than to retrofit against them.

SEBI — legal circulars · reported, not yet confirmed at source · reviewed 2026-08-10 · India

In force17 April 2026Federal Reserve, FDIC, OCC

Model Risk Management: Revised Guidance (OCC Bulletin 2026-13 / Fed SR 26-2)

Replaces fifteen years of interagency model risk guidance, superseding SR 11-7 and SR 21-8 and rescinding OCC 2011-12, OCC 2021-19 and OCC 1997-24. It states that generative and agentic AI models are novel and rapidly evolving and are therefore not within the scope of this guidance, with separate AI guidance promised. It also states it does not set forth enforceable standards.

What it changes. Read as a deferral, not an exemption — and the single most misread instrument in this space. Every obligation attached to the underlying action survives untouched: safety and soundness, consumer protection and fair lending, sectoral duties, third-party risk. What was withdrawn is the framework that would have specified the controls. So nobody is going to hand you an agent-control spec, and the separate guidance will be written against whatever the industry has already built. That is a stronger argument for building the governance layer now, not a weaker one.

OCC Bulletin 2026-13 · checked against the source · reviewed 2026-08-02 · US banking

In force14 January 2026FDA and EMA

Joint principles on AI in medicines regulation

Shared principles for AI used across the medicinal product lifecycle, organised around context of use and a risk-based credibility assessment.

What it changes. Context of use is the useful phrase, because it is a permissions question wearing regulatory clothing: what is this system allowed to be relied on for, and what evidence supports that reliance. Entry here should be explicitly non-clinical — pharmacovigilance intake, quality events, deviations, regulatory document generation — where the purchase category already exists.

EMA — artificial intelligence workplan and guidance · reported, not yet confirmed at source · reviewed 2026-08-10 · Life sciences

In force9 December 2025FINRA

2026 FINRA Regulatory Oversight Report

Defines AI agents and sets out risks specific to them, including the difficulty of reconstructing multi-step agent reasoning for audit purposes. Points firms toward agent-specific supervisory processes covering permission limits, access monitoring and where a human must remain in the loop.

What it changes. The most useful document in this register, because the supervisor has already written down the question most firms cannot answer. It is addressed to roughly 3,184 member firms, most of them small, each with a named compliance officer who is personally exposed — a very different buyer from a G-SIB, and one that can actually purchase. If you are in capital markets, this is the paragraph to take to your risk committee.

FINRA 2026 Regulatory Oversight Report · checked against the source · reviewed 2026-08-10 · US capital markets

In force13 August 2025Reserve Bank of India

FREE-AI committee framework

A framework for responsible and ethical enablement of AI in the financial sector: seven principles, six pillars and twenty-six recommendations.

What it changes. India's supervisory direction on AI is now written down rather than inferred, which changes what a board can reasonably say it did not know. Note the framing — enablement, not restriction. That matters for how a programme is positioned internally: the regulator is not asking whether to build, it is asking how the build is governed.

IndiaAI — RBI FREE-AI committee report · checked against the source · reviewed 2026-08-10 · India

In force10 February 2025Securities and Exchange Board of India

SEBI Regulation 16C

Places responsibility on regulated market intermediaries for the AI and ML tools they deploy, including for outputs and for the protection of investor data handled by those tools.

What it changes. Cross-listed against US capital markets deliberately: SEBI's direction mirrors FINRA and the SEC closely enough that one body of agent-governance work usually serves an Indian and a US entity together. For a group with both, that is the cheapest coverage available anywhere in this register.

SEBI — legal circulars and regulations · checked against the source · reviewed 2026-08-10 · India · US capital markets

In forceNovember 2024Central Bank of the UAE

Guidance on the use of artificial intelligence

Supervisory expectations for licensed financial institutions deploying AI, covering governance, risk management and third-party dependency.

What it changes. Gulf supervision tends to arrive as expectation before it arrives as rule, and expectation is examined. The distinctive local factor is sovereignty: where an agent's inference physically executes is a supervisory question here in a way it is not everywhere, and provider routing makes that answer non-obvious in most architectures.

CBUAE — regulations and standards · reported, not yet confirmed at source · reviewed 2026-08-10 · Gulf

Phasing inPhasing from 1 August 2024European Union

EU AI Act

Risk-tiered obligations for AI systems, phasing in across several dates by tier.

What it changes. Listed for completeness and applies where a client's footprint reaches Europe. It is not the anchor for most programmes in this practice's markets, and treating it as the default frame usually imports obligations a US, Indian or Gulf deployment does not have while missing the ones it does.

EUR-Lex — Regulation (EU) 2024/1689 · checked against the source · reviewed 2026-07-24 · Europe

In force11 July 2024New York Department of Financial Services

Circular guidance on AI in underwriting and pricing

Expects insurers using AI and external data in underwriting and pricing to demonstrate independent review and effective challenge, alongside testing for unfair discrimination.

What it changes. Effective challenge assumes a reviewer who can reconstruct the decision and question it. Once an agent orchestrates quote to bind, the harder question is not whether the model was validated but whether anyone validated its authority — because bind is contract-forming, and that converts a model question into an authority question.

NYDFS — insurance circular letters · checked against the source · reviewed 2026-08-10 · Insurance · US banking

In forceStandingHHS Office for Civil Rights

HIPAA Security Rule — audit controls and minimum necessary

Requires records of access to electronic protected health information and limits use and disclosure to the minimum necessary for the purpose.

What it changes. Included because it is the clearest case of an old rule biting a new architecture. Agents retrieve context aggressively by design, which is in structural tension with minimum necessary — and an agent generates orders of magnitude more access events than a clinician, which most logging designs were never sized for. Neither problem is solved by policy.

HHS — HIPAA Security Rule · checked against the source · reviewed 2026-08-10 · US health

SupersededSuperseded 17 April 2026Federal Reserve, OCC

SR 11-7 — Guidance on Model Risk Management

The interagency model risk management guidance that governed validation, effective challenge and ongoing monitoring for fifteen years.

What it changes. Kept in this register precisely because it is superseded. It is still cited as current in vendor material, consultancy decks and job descriptions — and citing it in front of a board in 2026 is the fastest way to signal that the advice predates the regime. If you see it in your own documentation, that documentation has not been reviewed since April.

OCC Bulletin 2026-13 (rescinding instrument) · checked against the source · reviewed 2026-08-02 · US banking

How this is maintained

Every entry names a primary source — the instrument or the supervisor’s own publication of it, never a consultancy summary. Several widely-repeated claims about 2026 AI supervision trace back to nothing, and this register is the place that must not propagate them.

Superseded instruments stay, marked. Removing them would hide the most useful thing here: that something practitioners still cite has moved. SR 11-7 is the live example — still quoted as current in vendor material and job descriptions four months after it was replaced.

If a date here applies to you

The useful question is not what the instrument says — it is whether you could evidence compliance if asked next quarter. That is a shorter conversation than it sounds, and usually a surprising one.

Corrections welcome and credited — if an entry here is wrong or stale, tell me and it will be fixed with the change recorded on the corrections log.