A bank compliance officer asked a good question in July. Her firm had three agentic workflows in production, a fourth in pilot, and a supervisory examination on the calendar. She wanted to know which document she was supposed to be governing them against.
The honest answer is that there is not one, and that the reason there is not one is more interesting than the absence itself.
On 17 April 2026 the Federal Reserve, the FDIC and the Office of the Comptroller of the Currency issued revised interagency guidance on model risk management. The OCC carries it as Bulletin 2026-13; the Federal Reserve designates the same shared text SR 26-2. It supersedes the 2011 and 2021 supervisory letters and rescinds the corresponding OCC issuances, including the model-risk booklet of the Comptroller's Handbook. Two sentences in that shared text are the ones that matter here. Generative and agentic AI models are described as novel and rapidly evolving and placed expressly outside the guidance's scope, with separate AI guidance promised. And the guidance states that it does not set forth enforceable standards or prescriptive requirements.
Alongside it, the agencies said they intended to issue a request for information — on model risk management generally, and on banks' use of artificial intelligence including generative and agentic systems — in the near future, ahead of that separate guidance.
Four months have passed. The request for information has not been issued.
That sentence is the piece. Everything below is either the work of establishing it properly, or the work of deciding what follows from it — and the first of those has to come first, because a claim of absence made without a method is not a finding. It is a person saying they have not heard anything.
Establishing a negative
There is a specific failure mode in writing about regulation, and it is not getting a rule wrong. It is asserting that no rule exists on the strength of having not encountered one. The assertion feels like reporting and behaves like an assumption, and it is wrong in exactly the cases where it matters most — because the thing you have not encountered is disproportionately likely to be the thing you did not know to look for.
So the claim above was made against three named registers, each with a query someone else can re-run.
The Federal Register, queried through its API. The query asked for the newest AI-related documents from the Office of the Comptroller of the Currency. It returned nothing later than the April 2026 anti-money-laundering and counter-financing-of-terrorism proposed rule. This establishes that no request for information has been published in the Federal Register, which is the venue such a request would be published in.
The Federal Reserve's own 2026 press-release index, read for August. It carries enforcement actions and applications. The 13 August item is unrelated to this subject. This establishes that no announcement was made on the Board's own newsroom in the window — and a newsroom is a publication, not a plan, which is a limit rather than a quibble.
The Comptroller's news-issuances index, read forward from 17 April 2026. Nothing addressing artificial intelligence appears after the bulletin itself. This establishes that the agency has issued no follow-on bulletin on the subject.
Three registers, one consistent answer. Figure 1 lays out all three, and it carries a fourth column that most such tables omit.
The right-hand column is the honest part. None of these checks establishes that nothing has been drafted. None establishes that nothing has been circulated between the agencies. None establishes that nothing has been scheduled, or that an announcement is not imminent. Interagency documents are negotiated privately and appear without warning; the absence of a publication is evidence about publication and about nothing else.
The method matters more than the finding, for a reason that is easy to miss: a verified negative expires. The moment the request for information is published, every sentence in this section becomes false, publicly and checkably, and that is a property of the claim rather than a weakness in it. Any reader can re-run all three checks in under an hour. Anyone relying on this piece for a decision should.
The silence is confined to one lane
Read only the prudential banking lane and the reasonable conclusion is that supervision has gone quiet on agentic AI. Read one lane over and the conclusion inverts.
Conduct and sector supervision has been productive, and what it has produced is examination-shaped. FINRA's annual regulatory oversight report, published in December 2025, carries a generative-AI section addressing supervisory expectations for member firms. In January 2026 FINRA published observations on AI agents, listed with its other artificial-intelligence material — and the characterisation matters, because that document is observational material rather than a rule and carries its own disclaimer of new obligations. Separately, the National Association of Insurance Commissioners has an AI Systems Evaluation Tool at version 4.0, running through a twelve-state examiner pilot across 2026. That last one is the most interesting object in the lane, because it is not a principle or an expectation. It is a structured instrument that examiners will use to examine.
None of this binds a bank. A FINRA notice reaches member firms of FINRA. An NAIC tool reaches insurers in adopting states through their own state regulators. A national bank running an agentic workflow is not governed by either, and no amount of thematic similarity changes that. This piece is not arguing a transfer, and the figure states the non-transfer in its own frame rather than leaving it to be inferred.
What the populated lane provides is different and more useful than a binding obligation. It provides the shape of the question. Two supervisors in adjacent domains, writing independently, have converged on a similar set of things they want to be shown: an inventory of what is running, a named owner for each, a description of what each touches, evidence of oversight by someone senior enough for it to mean something, and the ability to stop one thing without stopping everything. When two supervisors who do not coordinate arrive at the same list, the list is telling you something about the problem rather than about either supervisor.
Both lanes are described here at document-class level deliberately. The distinction between a rule, a notice, an annual examination report, an observational publication and a pilot tool is not pedantry — it determines who is bound, what a finding can be written against, and how much weight a firm should put on it. A piece that flattened all five into "the regulator says" would be easier to read and worse to act on.
Reading one: this is a deferral, not an exemption
The most common misreading of April 2026 is the cheerful one. Agentic AI is out of scope, the guidance sets no enforceable standards, therefore the exposure has gone away until somebody writes something new.
What went out of scope is a framework for managing model risk. What did not go anywhere is the obligation attached to the action the model participates in. A bank that declines a credit application still owes the applicant the protections that attach to declining a credit application, and the answer to how the decision was reached does not become optional because the tool that reached it sits outside a guidance document. Safety and soundness survives. Consumer protection and fair lending survive. Third-party risk management survives, and the April text's own third-party passage is explicit that its principles remain applicable even where a vendor's code, data and methodology are proprietary. Sectoral duties survive. Every one of those attaches to the effect, and the effect is unchanged by the provenance of the thing that produced it.
What was withdrawn was the specification, not the duty. That is a genuinely unusual position to be in, and it is worth naming precisely rather than mourning. Ordinarily a supervisor tells an institution both that something must be controlled and roughly what controlling it looks like. Here the first half stands and the second half was deliberately removed on the stated grounds that the technology is moving too fast to specify. The institution still owes the outcome. Nobody is currently telling it what the control looks like.
There is a second withdrawal inside the first, and it is the one that will cost firms the most. The 2011 text carried an inventory schema — purpose, scope, provenance of inputs, a responsible person, a validity expiry — and a documentation standard written against a specific reader: someone unfamiliar with the model, who should be able to work out what it does and why. The April 2026 revision simplified both away. Neither was replaced with something stricter. So the most concretely useful pair of requirements in the old text, and the pair that mapped most cleanly onto an agentic system, is exactly what is now absent.
Reading two: this is an interval, and it is open now
The separate AI guidance will be written. When it is, it will be written by people who spent the preceding period looking at what institutions actually built.
That is not a hopeful reading of how supervision works; it is a description of it. Supervisory expectations are, in large part, the codification of observed practice — the agencies look across a population, identify what the better-run institutions do, and write it down as what everyone should do. A consultation is the formal version of the same mechanism. It asks the industry what it does and what it can evidence, and the answers become the raw material.
The interval also has an ending that is not under anyone's control, which is what makes it an interval rather than an opportunity. It closes when the request for information is published. From that point the conversation is about responding to a document rather than shaping one, and the material a firm can put in front of a supervisor is whatever it happens to have by then. Building starts producing evidence on a lag; a control stood up the week after the consultation opens has no history behind it.
Reading three: a vacuum is not a neutral space
The third reading is the least comfortable, and the reason to include it is that the first two are both, in their way, encouraging. An unspecified control surface does not stay empty. It fills.
What fills it is vendor vocabulary. In the absence of a supervisory definition of what an agent-governance control is, the definitions in circulation are the ones written by people selling agent-governance controls — and those definitions are, quite reasonably from the seller's point of view, shaped around what the seller's product does. A firm that adopts a vendor's taxonomy during the interval does not merely buy a product. It inherits a description of its own control environment, and that description is what it will be defending later, in front of someone who did not write it and has no reason to accept it.
This is the hazard I would put highest, and I will name my own exposure to it: the system I am building is exactly the kind of thing that would benefit from a firm adopting its vocabulary early. The defence I have adopted against my own incentive is to make every claim the system makes declare, in the artefact itself, what deployment conditions entitle it to that claim — so that a claim which has not been earned is visibly unearned rather than merely unchallenged. It is a partial defence. It is better than asserting good intentions.
The practical form of the hazard is a category error about what a tool proves. A tool that observes an agent's actions and writes them down produces evidence and attribution. It does not produce containment, and the two are routinely sold under the same word. Containment is a property of where the decision sits relative to the execution path — whether the effect is reachable without passing through the control — and it is a property of a deployment rather than of a piece of software. A firm that acquires the first and reports the second has not lied. It has adopted a vocabulary in which the distinction does not exist, and it will discover the distinction at the worst possible moment.
The three readings are not alternatives. They are a sequence. The duty survives the deferral, which creates the interval, and the interval is where the vocabulary gets set.
The questions, and where they are already being asked
If the interval is worth using, the useful thing to know is what to build toward. Nobody can answer that from the American prudential material, because the American prudential material is the thing that is silent. It can be answered from two other places: what the April revision took out, and what supervisors elsewhere already ask for.
The label across the top of that figure is load-bearing and I want to restate it in the text rather than leaving it inside an image. This is a construction. It is not a draft of the request for information, it is not a leak, and it is not a regulatory statement of any kind. It is five questions assembled from published material by someone who has read the published material, and a reader who took it for a document would be badly misled.
Two of the five come straight out of the withdrawal. The inventory question — which systems are running, who owns each, what does each touch — is the 2011 schema, restated for a population of agents rather than models. The reconstruction question — could someone unfamiliar with this system work out why it did what it did — is the 2011 documentation standard almost verbatim, and its successor passage no longer contains it. Both were removed in a simplification rather than rejected on the merits, and both are the questions an examiner asks first when something has gone wrong.
Two more come from supervisors outside the United States who have written down what they want. India's draft model-risk guidance proposes a board-approved framework over an enterprise-wide inventory, and proposes model override and kill-switch capability. The Central Bank of the UAE's guidance note places accountability for AI outcomes with the board and enumerates a comparable stopping control. Neither binds an American institution and neither is described here as doing so; both are draft or guidance-note status and are named as such. What they demonstrate is convergence. Two supervisors, in different jurisdictions, with different legal traditions, independently concluding that the ability to stop one system without stopping the estate is a thing a board should be able to evidence.
The fifth comes from the April text itself. Its third-party passage is the part of the revision that did not soften: the principles remain applicable even where the vendor's code, data and methodology are proprietary. That sentence is a supervisory expectation with an unresolved practical problem inside it, and every firm running a vendor agent has that problem now.
What I would not claim
Three limits, stated because a piece built on a verified negative has an obligation to bound itself.
The first is the one already in Figure 1's fourth column: nothing here establishes that the request for information is not imminent. It could be published the week this is read. The claim is about publication and about nothing else.
The second is that convergence between the Indian and Emirati positions is a weaker signal than it looks if you squint at it. Both are recent, both are influenced by the same international discussion, and independence of drafting is not the same as independence of intellectual origin. I have described it as convergence because that is what the record supports, and I would not describe it as confirmation.
The third is about my own position. I build in this space, which means I have a commercial interest in firms concluding that the gap is real and worth closing. The correct response to that is not to pretend otherwise but to make the argument checkable: three named registers with re-runnable queries, document classes stated rather than blurred, the non-transfer between lanes said out loud, and the question set labelled as a construction in the figure and in the text. A reader who checks all four and finds them sound has a reason to accept the conclusion that does not depend on trusting me.
What would falsify this piece is simple and public. The request for information gets issued. When it does, the negative expires — and the interval it describes closes with it.