Connect with us

BUSINESS

Bank Exams Now Hunt AI Kill Switches Banks Rarely Own

Examiners now demand AI kill switches in routine bank exams, even as April guidance left generative systems outside the official model playbook.

Published

on

U.S. bank examiners now ask who can shut an AI system down, and the answer often sits with a vendor. In routine exams that began surfacing by mid-June, the OCC and the Federal Reserve have made that question a standing topic, along with data access, human oversight, and the subcontractors behind the software.

The pressure is not a new statute. It is an exam file aimed at people who rarely built the model: vendor-risk officers, community-bank compliance desks, and contract lawyers who have to show a plug they do not own.

Examiners Want a Named Person at the Switch

Three people familiar with the reviews said OCC and Fed teams now ask banks to map how they use AI in higher-risk work such as lending, know-your-customer checks, and sanctions screening. The conversations happen on paper and in the room. Officials have treated them as fact-finding rather than a checklist of mandated designs.

The questions are specific. Who may step in if a system fails. Whether a documented backup exists. Whether the software can be shut off. Supervisors also want to see how client data is fenced, how vendors are watched, and whether those vendors’ own subcontractors meet the same bar the bank is held to.

That last ask is where the exam leaves the bank’s model shop. Many of the tools in credit files and identity checks are hosted outside the bank. An examiner can still ask the bank to prove a shutdown path. The person who can actually pull it often works for someone else.

WHAT EXAMINERS HAVE STARTED ASKING

  • Use map: Where AI sits in lending, identity checks, and sanctions screening, and who owns each use.
  • Kill switch: Whether the system can be shut down, and which named role has the authority to do it.
  • Data fence: How client data is kept from drifting into models that were never approved to see it.
  • Vendor stack: How the bank oversees AI suppliers and the subcontractors those suppliers use.
  • Backup plan: What runs if the model fails, and how that failover is documented.

Banks that have stood up autonomous agents, including systems that can run for hours without a person in the loop, sit in the hardest version of this conversation. The longer a tool acts without a human, the more an examiner wants a named stop and a paper trail.

The Kill Switch Lives in the Contract

A shutdown control on a cloud model is a commercial term before it is a safety feature. Banks can write the clause. They cannot always test it. Vendors guard weights, logs, and the live endpoint. Subcontractors add another layer the bank never hired directly.

If an examiner asked tomorrow for a complete record of which model touched which credit file, and with which artifacts, most shops would struggle to rebuild it. Reconstructing a six-month-old agent decision with no durable trail is the practical exam problem, not a missing slogan on a policy page.

That is why the overlooked party in this story is the vendor file. The bank still sits in the exam chair. The evidence examiners want, from kill-switch tests to data-use rights, has to come out of contracts, audit clauses, and incident notices the supplier agrees to send.

WHO HOLDS THE CONTROL EXAMINERS WANT

Exam ask Who typically holds it Where official model guidance sits
Named person who can stop the system Vendor operations, via contract Generative and agentic AI are out of scope
Client-data boundary Cloud and model supplier Left to broader bank governance
Subcontractor map The vendor’s vendors Third-party oversight, not model validation
Lending, KYC, sanctions uses Bank business line plus the tool vendor Traditional models in; generative systems out

Elaine Duffus, a senior specialized consultant at Wolters Kluwer, has told banks to push suppliers for kill switches and for notice when something breaks. She has also said banks need to see the models and the data those models are fed, including synthetic training sets that can be wrong or skewed.

April’s Guidance Left the Fast Models Out

On April 17, 2026, the OCC, the Federal Reserve, and the FDIC issued revised model risk management guidance. OCC Bulletin 2026-13 and the Fed’s SR 26-2 replace the 2011 playbook known as SR 11-7, a 15-year-old document examiners had stretched far past its original use.

The new text is principles-based and, the agencies said, does not set enforceable standards. Non-compliance with the guidance alone will not draw supervisory criticism. It is expected to matter most for banking organizations with more than $30 billion in total assets, though smaller firms with heavy model use can still fall under it.

Then comes the sentence that shapes every exam conversation about chatbots and agents. “Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance.” Banks are told to govern those tools through their wider risk programs. The agencies also said they planned a request for information on banks’ use of AI, including generative and agentic systems.

Rob Nichols, president and chief executive of the American Bankers Association, welcomed the carve-out. He said it would help banks of all sizes, “particularly community banks, continue to pursue responsible innovation by making it clear generative and agentic AI are outside the scope of the guidance.”

The carve-out is not a hall pass. Examiners can still ask about safety and soundness, consumer harm, and third-party control. What banks no longer have is a single official model-risk script that tells them how to validate an agent that writes, calls tools, and keeps going.

Most Banks Are Least Ready on the Plug

Two days before those exam questions became public, Wolters Kluwer published its U.S. Banking AI Risk and Governance Index for the first half of 2026. The survey of 230 banking professionals covered community, midsize, and large shops.

Asked where their bank was least prepared on AI risk, 72% chose model kill-switch protocols or regulatory reporting of AI failures. The split was 34% on kill switches and 38% on failure reporting. Wolters Kluwer called those two items the minimum needed to manage an AI incident in a regulated shop.

WHERE THE JUNE SURVEY FOUND THE GAP

  • 72% least prepared: Kill-switch protocols or reporting of AI failures, the two items now in the exam script.
  • 34% on the switch: Share that named shutdown protocols as the weakest area.
  • 38% on reporting: Share that named failure reporting as the weakest area.
  • Agentic hot spots: 33% put lending and underwriting first for automation without enough human control; 30% put collections and recovery second.

Duffus said the results showed banks scaling AI faster than they are building the governance, incident response, and consumer protections they need to defend it. Collections, she noted, carries fewer consumer-protection rails than credit underwriting, which is why a weak human loop there is a different kind of problem.

What a Community Bank Can Show

The April guidance tells smaller lenders they are not the main audience unless model risk is heavy. That does not stop an examiner from asking how a community bank uses a vendor’s “AI underwriting” screen, who can turn it off, and what customer data leaves the building.

A shop under $30 billion rarely has a model-risk department that can re-validate a foundation model. What it can show is thinner and more contractual: an owner inside the bank, a classification of the tool, tests on the bank’s own files, and a record of when a person overrode the output.

On Sept. 10, 2026, the OCC, Fed, and FDIC separately raised the asset line for an 18-month on-site exam cycle from $3 billion to $6 billion for qualifying well-rated, well-capitalized firms. The OCC said about 50 more of its banks become eligible. That change cuts how often some small banks sit for a full exam. It does not erase AI questions when the exam does arrive.

The two policies pull in different directions. One says generative systems sit outside the model-risk booklet. The other still lets examiners ask, on a longer or shorter cycle, who holds the plug.

Bowman Asked If Old Tools Still Fit

Federal Reserve Vice Chair for Supervision Michelle W. Bowman put the tension on the record on May 1, 2026, in remarks delivered April 27 at an FSOC roundtable on AI, cybersecurity, and risk management. She said supervisors have talked with banks about AI for nearly a decade, and that smaller banks still need a path to the same tools as their larger peers.

Today, banks are relying on existing risk-management frameworks to guide their use of AI. While these supervisory tools are intended to support banks in applying sound governance and risk management, we should assess whether our supervisory guidance is fit for the future.

Michelle W. Bowman, Vice Chair for Supervision, Federal Reserve, FSOC AI roundtable

In the same speech she noted the agencies had amended model-risk guidance to make clear it does not apply to generative or agentic AI. She asked, without answering, how third-party expectations should work for vendor-provided AI, and said the Fed is working to update and simplify that third-party guidance because it has been vague for too long.

She also pointed to Anthropic’s Mythos model, which finds cyber holes faster than older tools. Treasury Secretary Scott Bessent and Fed Chair Jerome Powell had already pulled in the largest banks to discuss it. Banks of all sizes, Bowman said, have worried about access to the same model. Used in-house, it can patch weaknesses. Used by an attacker, it can find them.

The FSB Listed Practices Without a U.S. Rule

On June 10, 2026, the same day as the Wolters Kluwer index, the Financial Stability Board published a consultation on 12 sound practices for AI adoption by financial firms. Comments ran through July 22. Bowman, who chairs the FSB committee behind the work, said the aim was a final report later in the year as a U.S. G20 deliverable.

The menu covers board oversight, data, explainability, human control, cyber, and third-party AI risk. It is not a U.S. rule. It is the closest public list of what “responsible adoption” looks like while Washington still treats generative systems as too fast to freeze into model-risk text.

HOW THE 2026 AI SUPERVISION CALENDAR UNFOLDED

  1. April 17, 2026: OCC, Fed, and FDIC issue the revised model-risk guidance and carve generative and agentic AI out of its scope.
  2. May 1, 2026: Bowman asks whether existing guidance is fit for vendor AI and points to Mythos as a reason the old cycle cannot keep up.
  3. June 10, 2026: Wolters Kluwer finds 72% of surveyed bankers least prepared on kill switches or failure reporting; the FSB opens its 12-practice consultation.
  4. June 12, 2026: People familiar with OCC and Fed exams say AI maps, vendor stacks, and kill switches are now routine questions.
  5. July 22, 2026: Comment window closes on the FSB sound-practices paper.
  6. Sept. 10, 2026: Agencies raise the 18-month exam-cycle line from $3 billion to $6 billion for qualifying community banks.

Until a dedicated U.S. request for information turns into something banks can cite, the working rule is the exam question. Lenders can still build. They have to show, often through a vendor’s paperwork, that someone can stop the system and that customer data did not creep where it was never meant to go.

Harry runs THUNDER TIGER as its editor, owning the title outright and writing across every section on it. Ten years in journalism sit behind that, a reporter's stretch followed by an editor's, and the habits show in what he reads before he writes: the filing rather than the results announcement, the judgment rather than a summary of it, the electoral authority's own count, the safety notice as the regulator issued it, the paper with its sample size and its stated limitations, the governing body's official record, the specification sheet, the release notes. Figures get checked against whatever produced them, then checked again for the base they were calculated from. He treats the corrections policy as part of the reporting rather than an apology for it: an error is repaired inside the article with a dated note saying what changed, and anything still unconfirmed is labelled unverified instead of being smoothed into fact. His readers are international and his sections run from news, business, technology and science through sports, entertainment, lifestyle, travel, auto and gaming. Readers can reach him at support@thundertiger-europe.com.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending