US Financial Services AI Governance
The United States has no AI Act. What US banks, Farm Credit lenders, insurers, and advisers face instead is a layered mix of supervisory guidance, examination practice, and hard recordkeeping obligations attached to existing statutes. This page maps that landscape, as of August 2026, to shipped AxonFlow capabilities.
This page maps AxonFlow's technical controls to US supervisory expectations so that risk, compliance, and model governance teams can evaluate fit. It is not legal advice, and AxonFlow does not certify compliance with any instrument named here. Applicability of each instrument to your institution remains a determination for your legal and compliance teams.
The shape of US AI supervision
Three things distinguish the US from jurisdictions with codified AI frameworks (EU AI Act, RBI FREE-AI, MAS FEAT):
- Examiners ask AI questions without an AI rulebook. Federal banking examiners now routinely probe AI use in routine examinations: where AI is used across lending, KYC, and sanctions workflows; whether each AI-touched decision can be reconstructed; whether an AI system can be shut down; what data an AI system can access or infer beyond authorized limits; how AI vendors are governed and how the institution would disentangle from one; and where humans sit in the loop. Those questions are answered with evidence, not attestations.
- The binding obligations are mostly recordkeeping obligations. Adverse-action records (25 months, Regulation B), SAR supporting documentation (5 years, BSA), user-activity logging on systems holding customer information (GLBA Safeguards Rule), books and records that attach to AI outputs and agent actions (SEC/FINRA), and cybersecurity records under NYDFS Part 500 (23 NYCRR 500.06: 5 years for transaction-reconstruction records, 3 years for cybersecurity-event audit trails). These survive every shift in federal AI policy.
- Voluntary frameworks carry examination weight. The NIST AI Risk Management Framework and the Treasury-announced, industry-built Financial Services AI Risk Management Framework (230 control objectives with evidence-of-implementation guidance) are referenced by examiners and regulators in the absence of binding rules. The Farm Credit Administration names NIST AI RMF and its Generative AI Profile directly on its AI guidance page.
The standing examiner question set
| Examiner question | AxonFlow capability | Docs |
|---|---|---|
| Where is AI in use, and through what systems? | Governed agents, policies, and LLM providers are registered and observable on every path routed through AxonFlow. AxonFlow reports what it governs; it does not claim network-wide discovery of ungoverned AI | Architecture Overview |
| Can you reconstruct an individual AI decision? | Per-decision records with decision_id, evaluated policies, verdict, identity attribution, and timestamps across the agent, orchestrator, MCP, and workflow layers | Audit Logging |
| Who oversees high-risk actions, and can you prove it? | HITL approval gates (Professional tier and above) pause configured actions for human review; the approval record carries approver identity, justification, and timing. Below those tiers a require_approval policy holds the step but creates no queue entry | HITL Approval Gates |
| Can an AI system be shut down? | Circuit breaker halts governed paths on failure thresholds; kill-switch controls (Enterprise) disable AI systems; policy changes take effect at the enforcement point without redeploying agents | Choosing a Mode |
| What data can the AI reach, and what was denied? | Policy-scoped data access on governed paths; denials are recorded in the same audit surface as approvals, so denied-attempt evidence is producible | Policy Overview |
| How is customer information protected in prompts and tool calls? | PII detection with configurable block/redact/warn/log actions, including US patterns (SSN with format validation, US bank accounts) in the community runtime | PII Detection |
| How do you evidence any of the above to us? | Evidence export produces structured, time-bounded packages over audit logs, workflow steps, and HITL approvals (Evaluation tier with caps; Professional tier and above unlimited) | Evidence Export |
Banks and bank holding companies
Model risk management. On April 17, 2026 the Federal Reserve, OCC, and FDIC issued revised model risk management guidance (SR 26-2, OCC Bulletin 2026-13, FDIC FIL-15-2026), superseding SR 11-7 and OCC 2011-12. The revised guidance is stated to be most relevant to banking organizations above $30 billion in assets, and it retains the pillars examiners have applied for fifteen years: a model inventory covering vendor models, validation and effective challenge, ongoing monitoring against documented thresholds, and board reporting on aggregate model risk. One scope fact matters for AI teams: the revised guidance narrows the formal model definition and excludes generative and agentic AI from its scope, while the agencies indicate the underlying risk-management principles still apply. The standing examiner question set above is where those principles meet AI systems in practice.
Third-party risk. The Interagency Guidance on Third-Party Relationships (June 2023) is the operative hook for every LLM and foundation-model vendor relationship: planning, due diligence, contracts (including model-update notification and data-use terms), ongoing monitoring, and termination planning across the relationship life cycle.
Information security. The GLBA Safeguards framework (the Interagency Guidelines for banking organizations, the FTC Safeguards Rule for non-bank financial institutions) requires monitoring and logging the activity of authorized users on systems that hold customer information, access controls, service-provider oversight, and an annual written report to the board. A 36-hour computer-security incident notification rule applies to banking organizations. An LLM agent that touches customer information is such a system.
BSA/AML. The FFIEC BSA/AML Examination Manual sets expectations for governance of monitoring systems, including AI-assisted ones: independent validation, scenario and threshold documentation, and alert-disposition records. SARs and all supporting documentation must be retained five years, which for AI-assisted monitoring includes the records of what triggered or suppressed an alert.
| Requirement | Regulation | AxonFlow Capability | Docs |
|---|---|---|---|
| Model risk discipline for AI systems: inventory support, monitoring evidence, documentation a knowledgeable third party can follow | SR 26-2 / OCC 2026-13 (successors to SR 11-7) | Per-decision audit records, HITL history, and monitoring evidence that a model risk team folds into its own MRM documentation. AxonFlow does not perform model validation | Audit Logging |
| Life-cycle governance of third-party AI relationships | Interagency TPRM Guidance (2023) | LLM provider inventory and routing controls, per-provider usage and decision records, self-hosted deployment inside the institution's own environment | Community vs Enterprise |
| Monitor and log activity on systems holding customer information | GLBA Safeguards / Interagency Guidelines | Identity-attributed records of every governed model and tool call; PII detection and configurable redaction before model or connector access | Evidence Export |
| Governance of AI-assisted financial crime monitoring | FFIEC BSA/AML Examination Manual, FinCEN guidance | The FinCrime Policy Pack rules are authored from public FFIEC examination guidance, FinCEN advisories, OFAC sanctions programs, and 31 CFR 1010.311 thresholds; detections land in the standard audit surface | Fraud & Risk Add-on |
| Support for specific adverse-action reasons where AI touches credit | ECOA / Regulation B 12 CFR 1002.9 | Per-decision records identify the policies evaluated and actions gated, supporting the institution's own adverse-action process. AxonFlow does not generate adverse-action notices or perform fair-lending testing | Audit Logging |
Farm Credit System institutions
Farm Credit System lenders are supervised by the Farm Credit Administration, not the federal banking agencies, and the FCA's expectations for AI are concrete:
- Model risk management under Exam Manual EM-31.1, which applies SR 11-7 grade discipline to material models: a risk-tiered inventory including vendor and System-shared models, independent validation and effective challenge, a change-control log recording when, what, who, and approver, and board reporting. Model risk itself is not outsourced. Where it is unclear whether a tool is a model, EM-31.1's direction is to treat it as one, which pulls AI tools into scope.
- 12 CFR Part 609 (cyber risk management), effective January 2025, which FCA states has particular relevance to AI: a board-approved written program reviewed annually, risk assessment of all vendors, independent control testing, incident notification to FCA within 36 hours, and quarterly board reporting.
- NIST AI RMF and the Generative AI Profile, which the FCA names as the operative external frameworks.
- The FCA's FY2026 oversight plan includes evaluating a sample of institutions on their use of AI in risk management and operations.
The capability mapping for banks above applies, with three FCA-specific notes: the change-approval evidence AxonFlow's HITL and policy-versioning records produce matches EM-31.1's when/what/who/approver form; the audit and evidence surfaces support the quarterly (not annual) board reporting cadence Part 609 requires; and the governance evidence maps onto NIST AI RMF's Govern, Map, Measure, and Manage functions, which is the framework FCA examiners are pointed to.
Insurers
- NAIC Model Bulletin on the Use of AI Systems by Insurers, adopted in 25 jurisdictions as of August 2026: a written AI systems program with board accountability, an AI system inventory with risk classification, testing and drift monitoring, third-party AI accountability, and lifecycle documentation producible to regulators.
- NAIC AI Systems Evaluation Tool, formally "Artificial Intelligence Systems Evaluation: Optional Supplemental Exhibits for State Regulators", from the NAIC Big Data and Artificial Intelligence (H) Working Group: an examination information request that supplements existing market conduct, financial analysis and financial examination review procedures. Four optional exhibits, using the form's own titles: Exhibit A "Quantify Regulated Entity's Use of AI Systems", Exhibit B "AI Systems Governance Risk Assessment Framework" (narrative or checklist variant), Exhibit C "High Risk AI Systems Details", Exhibit D "AI Systems Model Data Details". The current revision is version 4.0, every page of it is marked DRAFT, and a multi-state pilot is running. It is not an annual-statement filing. Note that the Working Group also has a separate AI Risk Evaluation Supplement in progress; that is a different instrument, and the four exhibits above belong to the AI Systems Evaluation Tool.
- NYDFS Insurance Circular Letter No. 7 (2024) for New York licensed insurers: an AI system inventory including retired models with change tracking and approvals, vendor accountability (a proprietary vendor algorithm is no excuse for non-specific adverse-action reasons), disclosure of all information an adverse decision relied on plus its source, and quantitative fairness analysis before deployment and at least annually.
- Colorado Regulation 10-1-1 (life insurers since 2023, expanded to private-passenger auto and health insurers effective October 2025): governance and risk management frameworks for external consumer data and information sources, with annual compliance reports naming accountable individuals.
- Texas TDI Bulletin B-0003-26 (June 2026): decisions made or supported by AI must comply with unfair-discrimination law, governance extends to third parties, and TDI examinations may probe AI governance and human oversight.
| Requirement | Instrument | AxonFlow Capability | Docs |
|---|---|---|---|
| AI system inventory with change tracking and approvals | NAIC Model Bulletin, NYDFS CL7 | Policy versioning and HITL approval records with approver identity and timestamps | HITL Approval Gates |
| Lifecycle documentation producible to a regulator | NAIC Model Bulletin | Per-decision audit records and time-bounded evidence export packages | Evidence Export |
| Disclosure of information an adverse decision relied on | NYDFS CL7 | Decision records enumerate the policies evaluated and data categories acted on for governed paths | Audit Logging |
| Examination information request evidence (usage, governance, per-system detail, data inputs) | NAIC AI Systems Evaluation Tool | The usinsurance compliance report renders the Tool's exhibit structure over governed activity: Exhibit A "Quantify Regulated Entity's Use of AI Systems", Exhibit B "AI Systems Governance Risk Assessment Framework", Exhibit C "High Risk AI Systems Details" with exceptions and overrides, Exhibit D "AI Systems Model Data Details". AxonFlow supplies the governed-decision evidence behind the exhibits; the risk classifications, the line-of-business mapping, and the ECDIS register remain yours | Compliance Reports |
| Annual compliance report naming accountable individuals | Colorado Regulation 10-1-1 | A Colorado 10-1-1 annex over the governance records AxonFlow holds, alongside a NYDFS CL7 annex. Naming the accountable individuals and attesting to the framework remain the carrier's own | Compliance Reports |
| Quantitative fairness testing | NYDFS CL7, Colorado 10-1-1 | Not an AxonFlow capability. Fairness and bias testing remains the insurer's own actuarial and data-science work; AxonFlow records complement that evidence, they do not produce it | n/a |
The usinsurance report's fairness section is a pointer, never a result: it names the instrument and the AxonFlow records that support it, and states on the artifact that AxonFlow performs no statistical fairness or bias testing. The NAIC Tool is at version 4.0, every page of it is marked DRAFT, and a multi-state pilot is running, so the artifact names the NAIC form revision it renders against and the adopted form may differ from it. AxonFlow does not classify a system as high risk, does not discover AI outside the paths routed through it, and does not compute the share of adverse decisions. Because the exhibits are an examination information request rather than a filing, the report is source evidence for your response to a regulator, not a submission in its own right.
Advisers and broker-dealers
The SEC withdrew its predictive data analytics proposal in June 2025; there is no AI rule. What operates instead: the FY2026 examination priorities (accuracy of AI representations, supervision of AI use, alignment of AI outputs with client profiles), examination sweep letters requesting AI inventories, policies, and model documentation, and enforcement under existing antifraud law against firms whose AI claims exceed their AI reality. Books-and-records obligations (Rule 204-2 for advisers; 17a-3/17a-4 for broker-dealers, satisfied by WORM storage or the 2022 amendments' audit-trail alternative) attach to AI outputs, and FINRA's 2026 Regulatory Oversight Report states that once an AI agent takes actions, supervision and recordkeeping obligations attach to those actions. The amended Regulation S-P (fully in force June 2026) adds incident-response and service-provider oversight requirements.
AxonFlow's fit here is the same evidence spine: identity-attributed records of what AI produced and did, HITL dispositions for outputs that constitute recommendations or actions, and export packages in reviewable formats. As of platform v10.1.0 the ussecurities compliance report renders that evidence as the SEC/FINRA examination package: eight sections in the order the published AI sweep letters ask for them, with the supervised population (adviser or broker-dealer) derived from the chosen framework (SEC_EXAM / FINRA_SUPERVISION / REG_SP), and a jsonl format for the line-oriented systems that ingest into a 17a-4 recordkeeping pipeline. The compliant archival system (WORM or the audit-trail alternative) remains the firm's own; the package is an export and preserves nothing.
Retention obligations worth designing for
| Records | Instrument | Retention |
|---|---|---|
| Adverse-action records | Regulation B, 12 CFR 1002.12(b) | 25 months |
| SARs and supporting documentation | BSA, 31 CFR 1020.320(d) | 5 years |
| Books and records | SEC 17a-4 / 204-2 | 5 to 6 years; WORM or the 2022 amendments' audit-trail alternative for broker-dealers |
| Cybersecurity records | NYDFS 23 NYCRR 500.06 | 5 years (transaction-reconstruction records); 3 years (cybersecurity-event audit trails) |
| AI system documentation and AIS/ECDIS complaint records for NY-licensed insurers | NYDFS Circular Letter No. 7 (2024), which cross-references 11 NYCRR 243 | As set by the 11 NYCRR 243 schedule. Part 500 is the cybersecurity regulation and does not set this; CL7 points at Part 243 |
| ADMT records | Colorado SB 26-189 (effective January 2027) | 3 years |
Audit retention in AxonFlow is configurable by tier; align your retention configuration with the strictest instrument that applies to the workflow.
What AxonFlow does not do
Consistent with every compliance page in these docs, the boundaries are explicit:
- No model validation, effective challenge, or statistical fairness and bias testing. Those remain your model risk and actuarial functions' work.
- No adverse-action notice generation and no fair-lending determinations.
- No legal applicability analysis and no compliance certification.
- No claim of discovering AI systems that are not routed through AxonFlow's governed paths.
- The compliance report feature packages evidence; it does not certify anything. Its output is source evidence for your own response to a regulator, never a compliance determination. Banking and Farm Credit are served by the
usbankingregulator, insurance byusinsurance, and advisers and broker-dealers by theussecuritiesregulator (SEC_EXAM/FINRA_SUPERVISION/REG_SP, with the supervised population derived from the framework), all shipped in platform v10.1.0; a deployment on v10.0.0 or earlier refuses all three with400 UNKNOWN_REGULATOR. The framework-agnostic Evidence Export and the audit APIs remain available for anything the packages do not cover. - The US banking and US securities packages are scoped to the requesting tenancy, and each reports how many records in the period carry no organization attribution rather than omitting them silently.
Where to start
- Route one AI workflow through AxonFlow in your own environment (self-hosted; the data and the governance records stay inside your boundary).
- Turn on the policies the workflow needs: PII detection with US patterns, approval gates on the actions your risk appetite says a human must see (approval queues require a Professional or higher tier licence), and data-access scoping.
- Generate a compliance report for a bounded period, choosing the framework that matches the instrument in scope (
FCA_EM31for a Farm Credit institution, which renders the EM-31.1 change-log form and a quarterly board pack;SEC_EXAM,FINRA_SUPERVISIONorREG_SPfor an adviser or broker-dealer). Walk it through your model risk or compliance function against the examiner question set above. The framework-agnostic Evidence Export remains available for anything the package does not cover. (requires platform v10.1.0 or later; a v10.0.0 or earlier deployment refuses the US regulators with400 UNKNOWN_REGULATOR)
Related: Compliance Reports, Evidence Export, Audit Logging, HITL Approval Gates, PII Detection, FinCrime Policy Pack, Security Control Matrix.