Audit & compliance for agentic finance.
Autonomous systems do not enter a regulatory vacuum — they enter a dense existing regime. The working question for any deployment is not "is this allowed?" but "which of our standing obligations does this system now carry, and where is the evidence?" This page maps the major anchors.
SR 26-2: the revised discipline, and the door it left open
On 17 April 2026 the Federal Reserve, OCC and FDIC issued SR 26-2, superseding SR 11-7 (2011) and SR 21-8 (2021). It carries forward the disciplines that mattered — sound development and documentation, independent validation with effective challenge, ongoing monitoring — but replaces fixed-cycle validation with materiality-based scaling: rigor is set by a model's exposure and purpose rather than by the calendar. It also narrows the definition of "model" to complex quantitative methods, explicitly excluding simple arithmetic and deterministic rule-based processes, and judges validation independence by the rigor of the review rather than by reporting lines.
For autonomous systems, the operative text is footnote 3. Generative and agentic AI models are described as novel and rapidly evolving, and are placed outside the scope of the guidance — with the note that an organization's own risk management and governance practices should determine appropriate controls for anything not covered.
The primary US model-risk framework now expressly declines to govern the systems this platform is about. That is not an oversight; it is a scoping decision, and it hands the question back to the institution.
An agent is a model that acts. Validation must cover behavior and constraint-adherence, not predictive accuracy alone — and after April 2026 there is no supervisory document telling a US bank how. MARQUE exists to state the questions that gap leaves unanswered, and the jurisdictional map shows who else has answered them.
The EU AI Act: the extraterritorial layer
The EU AI Act entered into force in August 2024 with obligations phasing in through 2026–27. AI systems used in certain financial contexts face requirements that read like a regulatory restatement of the oversight framework: risk-management systems, data governance, technical documentation, automatic event logging, human oversight, and demonstrated accuracy and robustness. Any institution serving EU clients or markets should assume the documentation bar it sets becomes the de facto global baseline — as GDPR's did.
Recordkeeping: the oldest obligation is the sharpest
Books-and-records regimes (SEC 17a-3/4, CFTC equivalents, MiFID II) already require reconstructing how orders came to be. When an agent originates the order, the record must include what the agent knew, which constraints it evaluated, and which version of it acted — the tamper-evident evidence trail of Control 5. The practical standard: append-only, integrity-protected, and reconstructable by someone who did not build the system.
What an audit-ready deployment produces
- A validation dossier: rationale, testing record (including failed variants), boundary-scenario results, and sign-off by an independent reviewer with authority to say no.
- A constraint register: every runtime limit, where it is enforced, and proof it binds outside the agent's own process.
- The kill book: criteria, owners, response times, and dated drill records.
- Drift dashboards with threshold history and every graduated response taken.
- Hash-chained decision logs mapping each action to code, config, and data versions.
References: Federal Reserve SR 26-2 (17 April 2026), superseding SR 11-7 (2011) and SR 21-8 (2021); Regulation (EU) 2024/1689 (AI Act) public texts and Commission implementation timeline; SEC Rules 17a-3/17a-4; MiFID II recordkeeping provisions. Editorial reference only — not legal or compliance advice.