US Financial Services AI Governance
The United States has no AI Act. What US banks, Farm Credit lenders, insurers, and advisers face instead is a layered mix of supervisory guidance, examination practice, and hard recordkeeping obligations attached to existing statutes. This page maps that landscape, as of August 2026, to shipped AxonFlow capabilities.
This page maps AxonFlow's technical controls to US supervisory expectations so that risk, compliance, and model governance teams can evaluate fit. It is not legal advice, and AxonFlow does not certify compliance with any instrument named here. Applicability of each instrument to your institution remains a determination for your legal and compliance teams.
The shape of US AI supervision
Three things distinguish the US from jurisdictions with codified AI frameworks (EU AI Act, RBI FREE-AI, MAS FEAT):
- Examiners ask AI questions without an AI rulebook. Federal banking examiners now routinely probe AI use in routine examinations: where AI is used across lending, KYC, and sanctions workflows; whether each AI-touched decision can be reconstructed; whether an AI system can be shut down; what data an AI system can access or infer beyond authorized limits; how AI vendors are governed and how the institution would disentangle from one; and where humans sit in the loop. Those questions are answered with evidence, not attestations.
- The binding obligations are mostly recordkeeping obligations. Adverse-action records (25 months, Regulation B), SAR supporting documentation (5 years, BSA), user-activity logging on systems holding customer information (GLBA Safeguards Rule), books and records that attach to AI outputs and agent actions (SEC/FINRA), and cybersecurity records under NYDFS Part 500 (23 NYCRR 500.06: 5 years for transaction-reconstruction records, 3 years for cybersecurity-event audit trails). These survive every shift in federal AI policy.
- Voluntary frameworks carry examination weight. The NIST AI Risk Management Framework and the Treasury-announced, industry-built Financial Services AI Risk Management Framework (230 control objectives with evidence-of-implementation guidance) are referenced by examiners and regulators in the absence of binding rules. The Farm Credit Administration names NIST AI RMF and its Generative AI Profile directly on its AI guidance page.
The standing examiner question set
| Examiner question | AxonFlow capability | Docs |
|---|---|---|
| Where is AI in use, and through what systems? | Governed agents, policies, and LLM providers are registered and observable on every path routed through AxonFlow. AxonFlow reports what it governs; it does not claim network-wide discovery of ungoverned AI | Architecture Overview |
| Can you reconstruct an individual AI decision? | Per-decision records with decision_id, evaluated policies, verdict, identity attribution, and timestamps across the agent, orchestrator, MCP, and workflow layers | Audit Logging |
| Who oversees high-risk actions, and can you prove it? | HITL approval gates (Professional tier and above) pause configured actions for human review; the approval record carries approver identity, justification, and timing. Below those tiers a require_approval policy holds the step but creates no queue entry | HITL Approval Gates |
| Can an AI system be shut down? | Circuit breaker halts governed paths on failure thresholds; kill-switch controls (Enterprise) disable AI systems; policy changes take effect at the enforcement point without redeploying agents | Choosing a Mode |
| What data can the AI reach, and what was denied? | Policy-scoped data access on governed paths; denials are recorded in the same audit surface as approvals, so denied-attempt evidence is producible | Policy Overview |
| How is customer information protected in prompts and tool calls? | PII detection with configurable block/redact/warn/log actions, including US patterns (SSN with format validation, US bank accounts) in the community runtime | PII Detection |
| How do you evidence any of the above to us? | Evidence export produces structured, time-bounded packages over audit logs, workflow steps, and HITL approvals (Evaluation and Enterprise tiers) | Evidence Export |
Banks and bank holding companies
Model risk management. On April 17, 2026 the Federal Reserve, OCC, and FDIC issued revised model risk management guidance (SR 26-2, OCC Bulletin 2026-13, FDIC FIL-15-2026), superseding SR 11-7 and OCC 2011-12. The revised guidance is stated to be most relevant to banking organizations above $30 billion in assets, and it retains the pillars examiners have applied for fifteen years: a model inventory covering vendor models, validation and effective challenge, ongoing monitoring against documented thresholds, and board reporting on aggregate model risk. One scope fact matters for AI teams: the revised guidance narrows the formal model definition and excludes generative and agentic AI from its scope, while the agencies indicate the underlying risk-management principles still apply. The standing examiner question set above is where those principles meet AI systems in practice.
Third-party risk. The Interagency Guidance on Third-Party Relationships (June 2023) is the operative hook for every LLM and foundation-model vendor relationship: planning, due diligence, contracts (including model-update notification and data-use terms), ongoing monitoring, and termination planning across the relationship life cycle.
Information security. The GLBA Safeguards framework (the Interagency Guidelines for banking organizations, the FTC Safeguards Rule for non-bank financial institutions) requires monitoring and logging the activity of authorized users on systems that hold customer information, access controls, service-provider oversight, and an annual written report to the board. A 36-hour computer-security incident notification rule applies to banking organizations. An LLM agent that touches customer information is such a system.
BSA/AML. The FFIEC BSA/AML Examination Manual sets expectations for governance of monitoring systems, including AI-assisted ones: independent validation, scenario and threshold documentation, and alert-disposition records. SARs and all supporting documentation must be retained five years, which for AI-assisted monitoring includes the records of what triggered or suppressed an alert.
| Requirement | Regulation | AxonFlow Capability | Docs |
|---|---|---|---|
| Model risk discipline for AI systems: inventory support, monitoring evidence, documentation a knowledgeable third party can follow | SR 26-2 / OCC 2026-13 (successors to SR 11-7) | Per-decision audit records, HITL history, and monitoring evidence that a model risk team folds into its own MRM documentation. AxonFlow does not perform model validation | Audit Logging |
| Life-cycle governance of third-party AI relationships | Interagency TPRM Guidance (2023) | LLM provider inventory and routing controls, per-provider usage and decision records, self-hosted deployment inside the institution's own environment | Community vs Enterprise |
| Monitor and log activity on systems holding customer information | GLBA Safeguards / Interagency Guidelines | Identity-attributed records of every governed model and tool call; PII detection and configurable redaction before model or connector access | Evidence Export |
| Governance of AI-assisted financial crime monitoring | FFIEC BSA/AML Examination Manual, FinCEN guidance | The FinCrime Policy Pack rules are authored from public FFIEC examination guidance, FinCEN advisories, OFAC sanctions programs, and 31 CFR 1010.311 thresholds; detections land in the standard audit surface | Fraud & Risk Add-on |
| Support for specific adverse-action reasons where AI touches credit | ECOA / Regulation B 12 CFR 1002.9 | Per-decision records identify the policies evaluated and actions gated, supporting the institution's own adverse-action process. AxonFlow does not generate adverse-action notices or perform fair-lending testing | Audit Logging |
Farm Credit System institutions
Farm Credit System lenders are supervised by the Farm Credit Administration, not the federal banking agencies, and the FCA's expectations for AI are concrete:
- Model risk management under Exam Manual EM-31.1, which applies SR 11-7 grade discipline to material models: a risk-tiered inventory including vendor and System-shared models, independent validation and effective challenge, a change-control log recording when, what, who, and approver, and board reporting. Model risk itself is not outsourced. Where it is unclear whether a tool is a model, EM-31.1's direction is to treat it as one, which pulls AI tools into scope.
- 12 CFR Part 609 (cyber risk management), effective January 2025, which FCA states has particular relevance to AI: a board-approved written program reviewed annually, risk assessment of all vendors, independent control testing, incident notification to FCA within 36 hours, and quarterly board reporting.
- NIST AI RMF and the Generative AI Profile, which the FCA names as the operative external frameworks.
- The FCA's FY2026 oversight plan includes evaluating a sample of institutions on their use of AI in risk management and operations.
The capability mapping for banks above applies, with three FCA-specific notes: the change-approval evidence AxonFlow's HITL and policy-versioning records produce matches EM-31.1's when/what/who/approver form; the audit and evidence surfaces support the quarterly (not annual) board reporting cadence Part 609 requires; and the governance evidence maps onto NIST AI RMF's Govern, Map, Measure, and Manage functions, which is the framework FCA examiners are pointed to.
Insurers
- NAIC Model Bulletin on the Use of AI Systems by Insurers, adopted in 25 jurisdictions as of August 2026: a written AI systems program with board accountability, an AI system inventory with risk classification, testing and drift monitoring, third-party AI accountability, and lifecycle documentation producible to regulators.
- NAIC AI Risk Evaluation Supplement: a standardized examiner questionnaire (quantified AI usage; governance framework; per-high-risk-system detail; data inputs and sources), piloting in 12 states through September 2026 with adoption targeted for late 2026.
- NYDFS Insurance Circular Letter No. 7 (2024) for New York licensed insurers: an AI system inventory including retired models with change tracking and approvals, vendor accountability (a proprietary vendor algorithm is no excuse for non-specific adverse-action reasons), disclosure of all information an adverse decision relied on plus its source, and quantitative fairness analysis before deployment and at least annually.
- Colorado Regulation 10-1-1 (life insurers since 2023, expanded to private-passenger auto and health insurers effective October 2025): governance and risk management frameworks for external consumer data and information sources, with annual compliance reports naming accountable individuals.
- Texas TDI Bulletin B-0003-26 (June 2026): decisions made or supported by AI must comply with unfair-discrimination law, governance extends to third parties, and TDI examinations may probe AI governance and human oversight.
| Requirement | Instrument | AxonFlow Capability | Docs |
|---|---|---|---|
| AI system inventory with change tracking and approvals | NAIC Model Bulletin, NYDFS CL7 | Policy versioning and HITL approval records with approver identity and timestamps | HITL Approval Gates |
| Lifecycle documentation producible to a regulator | NAIC Model Bulletin | Per-decision audit records and time-bounded evidence export packages | Evidence Export |
| Disclosure of information an adverse decision relied on | NYDFS CL7 | Decision records enumerate the policies evaluated and data categories acted on for governed paths | Audit Logging |
| Examiner questionnaire evidence (usage, governance, per-system detail, data inputs) | NAIC AI Risk Evaluation Supplement | Decision volumes, governance policies, per-system audit history, and override records provide source evidence for the supplement's exhibits | Evidence Export |
| Quantitative fairness testing | NYDFS CL7, Colorado 10-1-1 | Not an AxonFlow capability. Fairness and bias testing remains the insurer's own actuarial and data-science work; AxonFlow records complement that evidence, they do not produce it | n/a |
Advisers and broker-dealers
The SEC withdrew its predictive data analytics proposal in June 2025; there is no AI rule. What operates instead: the FY2026 examination priorities (accuracy of AI representations, supervision of AI use, alignment of AI outputs with client profiles), examination sweep letters requesting AI inventories, policies, and model documentation, and enforcement under existing antifraud law against firms whose AI claims exceed their AI reality. Books-and-records obligations (Rule 204-2 for advisers; 17a-3/17a-4 for broker-dealers, satisfied by WORM storage or the 2022 amendments' audit-trail alternative) attach to AI outputs, and FINRA's 2026 Regulatory Oversight Report states that once an AI agent takes actions, supervision and recordkeeping obligations attach to those actions. The amended Regulation S-P (fully in force June 2026) adds incident-response and service-provider oversight requirements.
AxonFlow's fit here is the same evidence spine: identity-attributed records of what AI produced and did, HITL dispositions for outputs that constitute recommendations or actions, and export packages in reviewable formats. The compliant archival system (WORM or the audit-trail alternative) remains the firm's own.
Retention obligations worth designing for
| Records | Instrument | Retention |
|---|---|---|
| Adverse-action records | Regulation B, 12 CFR 1002.12(b) | 25 months |
| SARs and supporting documentation | BSA, 31 CFR 1020.320(d) | 5 years |
| Books and records | SEC 17a-4 / 204-2 | 5 to 6 years; WORM or the 2022 amendments' audit-trail alternative for broker-dealers |
| Cybersecurity records | NYDFS 23 NYCRR 500.06 | 5 years (transaction-reconstruction records); 3 years (cybersecurity-event audit trails) |
| ADMT records | Colorado SB 26-189 (effective January 2027) | 3 years |
Audit retention in AxonFlow is configurable by tier; align your retention configuration with the strictest instrument that applies to the workflow.
What AxonFlow does not do
Consistent with every compliance page in these docs, the boundaries are explicit:
- No model validation, effective challenge, or statistical fairness and bias testing. Those remain your model risk and actuarial functions' work.
- No adverse-action notice generation and no fair-lending determinations.
- No legal applicability analysis and no compliance certification.
- No claim of discovering AI systems that are not routed through AxonFlow's governed paths.
- The compliance report feature currently supports the EU AI Act, SEBI, RBI FREE-AI, MAS FEAT, and OJK/BI/UU PDP regulators. US evidence today is produced through the framework-agnostic Evidence Export and the audit APIs.
Where to start
- Route one AI workflow through AxonFlow in your own environment (self-hosted; the data and the governance records stay inside your boundary).
- Turn on the policies the workflow needs: PII detection with US patterns, approval gates on the actions your risk appetite says a human must see (approval queues require a Professional or higher tier licence), and data-access scoping.
- Generate an evidence export for a bounded period and walk it through your model risk or compliance function against the examiner question set above.
Related: Evidence Export, Audit Logging, HITL Approval Gates, PII Detection, FinCrime Policy Pack, Security Control Matrix.
