Free executive playbook.
Your bank runs a model-risk framework it trusts — and it has a hole in it. That framework was built for models that are stable, inspectable, backtestable and bank-owned; generative and agentic AI are none of those. In April twenty twenty-six the Federal Reserve, the Office of the Comptroller of the Currency and the Federal Deposit Insurance Corporation issued SR 26-2, superseding SR 11-7 and SR 21-8, and placed generative and agentic AI outside the scope of that guidance — while leaving them squarely inside your obligation to govern. Out of scope is not out of governance, and you do not close the gap by validating harder. You close it by assuring the system around a model you cannot open: inventory, tiering, orchestration, evaluation, and vendor challenge. This playbook lays those five control rings out for a risk committee and names the one ring that is weakest for the system in front of you — so you fix that ring instead of writing a validation report on a core you are not allowed to inspect.
What's inside
- The assurance gap, in four assumptions — stable, inspectable, backtestable, passive: what each one becomes under a closed third-party model, and the specific control every break costs you, from "no single ground truth to validate" to "no identity or entitlement control for a synthetic employee"; plus the honest concession that most of the fix is information-technology, cyber and third-party discipline rather than classical validation, which is what tells you where the control belongs
- The five control rings, in build order with a return arc — 1 Inventory, the AI System Registry and the baseline · 2 Tier, materiality × autonomy × entitlements · 3 Orchestrate, the load-bearing ring · 4 Evaluate, continuous and in production · 5 Challenge vendors, accountability without access — each with its role, its failure mode, and the one diagnostic question that tells you whether it holds
- The control mechanic — AI proposes. The orchestration layer disposes. The model produces a proposal; a separate control plane decides whether the action is allowed to reach the customer or the ledger, keeping intelligence and authority apart on purpose
- The materiality-tiering matrix and the Assurance-Gap Read — four tiers, Prohibited through High and Medium to Low, each with its trigger, evaluate depth, challenge route and oversight mode, plus one question per ring: see it, sized right, contained, watched, owned. Classical validation is supplemented here, never discarded, and the evaluation tooling is treated as emerging practice rather than a settled standard
- The ninety-day sequence, the proof and the dated clock — days zero to thirty see it and gate it, thirty-one to sixty size it and watch it, sixty-one to ninety entitle it and own the vendor; the Apple Card with Goldman Sachs, where regulators found no intentional bias yet a Consumer Financial Protection Bureau order of more than eighty-nine million dollars followed because the dispute-handling workflow failed; EU AI Act Article 50 transparency duties from the second of August twenty twenty-six; and Vietnam's AI Law 134/2025 and PDPL in force, with the finance-sector grace window and every penalty figure reported and pending primary-source confirmation
Five pages · free with a member sign-in · PDF.
Want the weekly version? Subscribe to The AI Architect Letter · Read the latest insights.