Artificial intelligence is moving from experimentation to infrastructure.
Financial institutions are no longer asking only whether they should use AI. They are deciding where AI will operate, what decisions it may influence, how much autonomy it should have, which third parties may provide it, and who remains accountable when technology acts at a speed and scale that traditional governance models were not designed to manage.
The regulatory framework, meanwhile, is still taking shape. That gap creates one of the most important governance challenges facing financial services leaders today: organizations cannot wait for the rulebook to be finished before building the capabilities needed to govern what comes next.
Recent banking developments make the point directly.
In July and August 2026, the Office of the Comptroller of the Currency denied charter applications from Wise National Trust and bunq US Bank. The circumstances differed, but both decisions rested on familiar fundamentals: capable management and boards, sufficient regulatory knowledge, effective compliance, credible business assumptions, adequate capital, and the ability to operate safely and soundly. For bunq, the OCC concluded that the application presented significant supervisory and compliance concerns, including an unclear capitalization plan and a management team without direct experience in unsecured credit cards, the bank's core proposed product.
Wise offered a related lesson. The OCC pointed to Wise US's existing Bank Secrecy Act and AML/CFT deficiencies, identified in a 2025 multistate consent order, and found that the application had not demonstrated the compliance capability, regulatory familiarity, or management and board experience needed for the activities the proposed trust bank intended to conduct.
Meanwhile, the OCC granted preliminary conditional approval to Augustus National Bank, a proposed branchless clearing platform built to serve digital asset firms, AI and technology companies, and institutional clients. That approval was not authorization to open. Preopening conditions, FDIC deposit insurance, and Federal Reserve approval remained necessary before the bank could begin operating.
The broader message is not that regulators oppose innovation. It is that innovation must be supported by an institution capable of governing it.
Artificial intelligence presents the same challenge.
The Rulebook Is Still Being Written
On April 17, 2026, the OCC, Federal Reserve, and FDIC issued revised interagency model risk management guidance, replacing the framework that had anchored bank model governance since 2011. One detail deserves particular attention from AI governance leaders: generative AI and agentic AI were expressly excluded from the guidance's scope because the agencies view the technologies as novel and rapidly evolving.
That exclusion does not mean these tools are outside governance. The agencies were explicit that an organization's broader risk management and governance practices should determine appropriate controls for tools and processes outside the guidance, and they signaled that additional work, including a forthcoming request for information, would address banks' use of generative and agentic AI.
For financial institutions, that creates an important distinction:
The absence of prescriptive AI guidance does not mean the absence of governance expectations.
Organizations already carry obligations involving consumer protection, privacy, information security, third-party risk, fair lending, model risk, data governance, operational resilience, record retention, regulatory compliance, and board oversight. AI does not erase those obligations; it changes how they need to be applied, often faster and across more of the institution than existing programs were built to handle.
That is why waiting for comprehensive AI regulation before establishing governance is risky. By the time detailed requirements arrive, AI may already be embedded across customer service, underwriting, fraud detection, compliance monitoring, software development, marketing, operations, and decision support. The governance architecture needs to be ready before that happens.
From AI Tools to AI Ecosystems
Many organizations began their AI journey by governing individual use cases. A business unit wanted a chatbot. A compliance team experimented with document review. Technology deployed a coding assistant. Marketing explored generative content. Those use cases could often be inventoried, assessed, and approved individually.
The next stage looks different. Financial institutions are increasingly connecting AI within broader ecosystems, where models, data, APIs, third-party platforms, and automated workflows operate together rather than in isolation. An AI-enabled process may retrieve customer information, interpret it, call another system, generate a recommendation, initiate an action, and document the result.
With traditional automation, governance often focused on whether the system performed the programmed task correctly. With increasingly autonomous systems, the questions get broader: what authority has the system been given, what data may it access, what systems may it interact with, and when must a human intervene. Perhaps most importantly, who is accountable for the outcome.
These are not merely technology questions. They are enterprise governance questions.
Agentic AI Changes the Oversight Equation
Generative AI produces content. Agentic AI can be designed to take action, and that distinction will become increasingly important. An AI agent may gather information, reason across multiple sources, select among available actions, and execute a workflow with limited human intervention.
In financial services, consider the difference between an AI system that summarizes a customer complaint and one that analyzes the complaint, determines the likely regulatory category, retrieves the customer's history, recommends remediation, initiates correspondence, and updates internal systems. The second environment carries a materially different risk profile. Traditional controls generally assume a person is the actor; agentic systems challenge that assumption, and organizations need governance that addresses authority, not just functionality.
A useful question for leaders: what is this AI permitted to decide or do without a human? That question belongs in AI risk assessments, approval processes, and ongoing monitoring. Organizations may eventually need defined levels of AI authority, similar to financial approval limits or delegated lending authorities: lower-risk systems operating with greater autonomy, higher-impact decisions requiring human confirmation or prohibiting autonomous action altogether.
The exact design will vary by institution. The governing principle should not: AI autonomy should be intentional, documented, and proportionate to risk.
AI Governance Cannot Become Another Silo
As AI programs mature, organizations face another risk: creating an entirely separate governance structure around AI. That may feel efficient at first, but over time it produces overlapping policies, duplicate committees, competing inventories, and unclear accountability.
The strongest AI governance programs are not built beside enterprise governance; they are built within it. AI risk should connect to existing structures for enterprise risk, compliance, privacy, cybersecurity, model risk, data governance, third-party risk, legal review, and operational risk. The objective is not to force every AI use case through every control function. It is to create a coordinated governance pathway where the level of review increases with the potential impact: a low-risk productivity tool should not require the same scrutiny as an AI system influencing credit decisions, and an internally developed model should not automatically receive the same review as a third-party generative AI platform with access to sensitive data.
Governance should be risk-based, but risk-based does not mean informal. The organization still needs clear criteria for which risks matter, which functions must participate, who can approve a use case, what documentation must exist, and when an issue must be escalated. AI governance should become another enterprise capability, not another organizational silo.
Third-Party AI Will Test Existing Risk Programs
Many financial institutions will not build their most important AI capabilities themselves. They will buy them. AI is increasingly embedded into software platforms, customer-service tools, fraud systems, compliance technology, analytics products, and cloud services that institutions already use, which means an organization may adopt AI without ever purchasing a product labeled "AI."
That creates a significant third-party governance challenge. Traditional vendor due diligence asks whether a provider protects data, maintains business continuity, uses subcontractors, and complies with contractual obligations. AI requires additional questions: what models are being used, whether the provider can change those models without notifying the institution, whether customer or institutional data is used to train them, what information is retained, whether the organization can explain or challenge an output, how the vendor tests for performance degradation or bias, what happens when the underlying model changes, and who monitors the fourth parties supporting the service.
Vendor management needs to evolve from assessing the provider to understanding the AI supply chain. That does not require a completely new third-party risk program. It requires expanding the existing one.
Boards Will Need More Than AI Awareness
During the early stages of AI adoption, board education may appropriately focus on terminology and opportunity: what generative AI is, how it differs from traditional models, and where the organization is using it. Those questions remain useful, but board oversight now needs to mature.
Directors should increasingly understand the institution's AI risk profile, major use cases, governance structure, risk appetite, significant incidents, third-party exposures, and the areas where AI is influencing customers or important business decisions. The expectation should not be that directors become data scientists; it should be that they can provide meaningful oversight. There is an important difference. A board does not need to understand every technical feature of an underwriting model to ask whether management understands its performance, limitations, and compliance risk. AI should be treated the same way.
Useful board questions may include:
- Where are our highest-risk AI applications?
- Which AI systems can influence customer outcomes?
- What activities can AI perform autonomously?
- How do we identify unapproved AI use?
- Where are we most dependent on third-party AI providers?
- What AI-related incidents or control weaknesses have been identified?
- How do management and the board know that our governance is keeping pace with adoption?
These are governance questions, not engineering questions.
Compliance Must Move Earlier
AI also creates an opportunity for compliance leaders to reconsider where the function enters the innovation lifecycle. For years, compliance has often been brought into technology initiatives after the business model was largely designed. That approach becomes increasingly difficult with AI, because compliance issues are embedded in the choice of data, the way a system is trained, the prompt architecture, the design of human review, the records retained, the customer disclosures provided, and the authority given to an automated system. By the time a product is ready for final approval, some of the most important risk decisions may already have been made.
The better model is earlier involvement. Compliance should help identify regulatory boundaries and design requirements while there is still time to influence the solution. That does not mean compliance owns AI; it means compliance becomes one of the architects of responsible implementation.
There is a meaningful difference between saying, "You cannot do this," and saying, "Here is what must be true for us to do this responsibly." The second approach protects the institution while helping the business move forward. That is where the compliance function can create enormous value in the next generation of AI governance.
What Leaders Should Be Building Now
Organizations do not need to predict every future AI regulation. They need the capability to respond as AI and regulatory expectations evolve. The most important investments now are therefore foundational.
A reliable AI inventory. An organization cannot govern what it cannot identify. The inventory should increasingly capture not only internally developed models, but embedded and third-party AI capabilities.
Risk-tiering methodology. AI review should reflect potential impact. Customer-facing, decision-making, and autonomous applications generally warrant more scrutiny than low-risk productivity tools.
Defined decision rights. Organizations should know who owns the use case, who accepts the risk, who may approve deployment, and what circumstances require escalation.
AI authority boundaries. For systems capable of taking action, organizations should define what may be done autonomously and where human intervention is required.
Integrated control functions. Compliance, legal, privacy, information security, data, model risk, third-party risk, and business management should understand how and when they participate.
Ongoing monitoring. Approval cannot be the end of governance. AI systems, vendors, data, and business uses change. Monitoring must account for that change.
Board and executive reporting. Leadership needs visibility into AI adoption, material risks, incidents, control weaknesses, and emerging issues, not simply a count of approved use cases.
These capabilities are durable. Specific regulations will evolve, and so will the technology. A strong governance infrastructure allows the organization to adapt to both.
Governance Is Becoming a Competitive Capability
There is a tendency to frame governance as the counterweight to innovation. That framing is increasingly outdated. Weak governance can slow innovation because every new use case becomes a custom negotiation: responsibilities are unclear, approvals take too long, risk concerns surface late, and business teams do not know what standards they are expected to meet.
Strong governance creates the opposite environment. The organization knows the boundaries, business teams understand the process, and control functions know when they need to participate. Higher-risk uses receive greater scrutiny while lower-risk innovation can move more efficiently. Governance, in other words, can create speed.
The organizations most prepared for the next generation of AI may not be the ones that deploy the most AI. They may be the ones that become best at deciding where AI belongs, how much authority it should have, what risks are acceptable, and when humans must remain accountable.
Preparing for What Comes Next
The AI governance conversation began with principles. It quickly moved to frameworks, inventories, policies, and committees. The next stage is more difficult, because it requires organizations to make governance operational while the technology continues changing underneath them: generative AI will keep evolving, agentic AI will expand, third-party AI will become less visible as it is embedded throughout enterprise technology, and regulatory expectations will keep developing. Organizations will be forced to make decisions before every question has a regulatory answer.
That is why the objective should not be an AI governance program that perfectly reflects today's technology. It should be an organization capable of governing tomorrow's technology. The next generation of AI governance will not be defined by who has the longest AI policy or the largest oversight committee. It will be defined by whether business strategy, technology, risk management, compliance, and executive accountability operate as one system.
AI governance is not about preparing for the technology of today. It is about preparing the organization to govern the decisions, risks, and responsibilities that will emerge from the use of AI tomorrow.
Sources
- Office of the Comptroller of the Currency – Corporate Decision #1384, bunq US Bank, N.A., August 4, 2026: occ.gov
- Office of the Comptroller of the Currency – Corporate Decision #1381, Wise National Trust, July 21, 2026: occ.gov
- Office of the Comptroller of the Currency – Corporate Decision #1374, Augustus National Bank, May 8, 2026: occ.gov
- Office of the Comptroller of the Currency – Model Risk Management: Revised Guidance, April 17, 2026: occ.gov
Companion Resources
Continue exploring AI governance through the companion resources developed alongside the AI Governance Summer Series.
Executive AI Governance Maturity Assessment
Evaluate your organization's AI governance maturity across eleven core governance domains.
Download the AssessmentAI Governance White Paper
Explore additional executive insights that complement this article and the AI Governance Summer Series.
Download the White PaperGuidebook
Building an AI Governance Program: A Practical Guide for Financial Institutions. Expand beyond the concepts introduced in this series with a practical framework for designing, implementing, and maturing an enterprise AI governance program.
Coming Soon