Four months in 2026 when the world disagreed about agents.
Between January and May 2026, four instruments took a position on whether autonomous AI agents fall inside financial governance. Three said yes. The one with supervisory authority over US banks said no. That divergence is not a technicality — it determines who has to answer for an agent that commits capital, and in one major jurisdiction the answer is currently nobody in particular.
The sequence.
Read it in date order. The interesting thing is not any single position but the direction of travel — and the fact that the outlier is also the most consequential.
| Date | Jurisdiction | Instrument | Agentic AI | Note |
|---|---|---|---|---|
| 2026-01-22 | Singapore | IMDA MGF for Agentic AI | In scope | World's first framework built specifically for agentic AI. Four dimensions, voluntary. |
| 2026-02 | United States | AIEOG Shared AI Lexicon | Defines only | Treasury-convened body defines 'Agentic AI' and 'AI Agent' for the financial sector. |
| 2026-02-09 | United States | FS AI RMF v1.0 | Partial | 230 control objectives for AI risk in financial services. Not agent-specific. |
| 2026-04-17 | United States | SR 26-2 | Excluded | Footnote 3 places generative and agentic AI outside the scope of model risk management. |
| 2026-05-20 | Singapore | IMDA MGF v1.5 | In scope | Extended to multi-agent systems, third-party agents and automation bias. |
| 2026-05-25 | Global | IOSCO FR/02/2026 | In scope | Supervisory toolkit explicitly covers emerging agentic AI techniques. |
What SR 26-2 actually did.
The revised US model-risk guidance is a genuine improvement. Materiality-based scaling is better than annual validation cycles. Judging independence by the rigour of review rather than by reporting lines is better than an org-chart test. Narrowing "model" to complex quantitative methods removes a decade of arguments about spreadsheets.
And in footnote 3 it describes generative and agentic AI as novel and rapidly evolving, places them outside the scope of the guidance, and directs that an organisation's own risk management and governance practices should determine appropriate controls for anything not covered.
That is a deliberate scoping decision, not an omission — and it is defensible. Writing durable supervisory guidance for a technology moving this fast is genuinely hard, and premature rules would have aged worse than silence. But the consequence is precise:
A US banking organisation deploying an autonomous agent that commits capital is not outside regulation. It is outside the framework that would have told it what adequate looks like. The obligation did not disappear; the specification did.
Two months earlier, a Treasury-convened public-private group had already defined an AI Agent as a system that autonomously perceives its environment, decides what to do, and takes actions to achieve its goals. The vocabulary existed. The scope decision was made anyway.
What the others agreed on.
More interesting than the divergence is what the in-scope instruments independently converged on. Singapore's framework, IOSCO's toolkit and the financial services control matrix were written by different bodies for different audiences, and all three arrive at the same three requirements:
- Bound the autonomy before deployment. Declare what the system may do, to what limit, and what it must escalate. Bounded autonomy is the shared primitive.
- Keep accountability with a named human. None of the three permits responsibility to distribute into the system. Singapore's phrasing — meaningful human accountability — is the sharpest.
- Make the shutdown real and tested. The control matrix requires technical mechanisms for shutdown and disconnection that are regularly tested, which is kill criteria written as an auditable line item.
Convergent evolution across independent drafting bodies usually means the underlying constraint is real. These three are the closest thing to settled ground in agentic governance, and they map directly onto the first three MARQUE questions.
If you operate in more than one of these.
The practical position for an institution with US and international exposure is straightforward and slightly uncomfortable: the most demanding published expectation is the operative one, regardless of where it was written.
An agent governed to Singapore's four dimensions and documented against the IOSCO supervisory indicators will satisfy a US examiner asking what your own risk management determined, because you will have an answer. The reverse does not hold. Building to the US floor means building to an absence.
That is the entire argument for adopting a framework before one is required. MARQUE states the eight questions; the control objective crosswalk shows which of them the existing 230 financial-services control objectives already answer, and which they do not.
Every instrument above is linked to its primary source on its register page, and every assertion on this page is recorded in the verification register with a review date. Where we have characterised a document, read the document.