Home/ Compliance/ United States
United States

No AI Act. Examiners with standing questions, and records that have to answer them.

Orient banking, Farm Credit, insurance, and securities teams across supervisory guidance, examination practice, and the recordkeeping obligations that already attach to AI-assisted work.

Applies to: Banks and bank holding companies, Farm Credit System institutions, insurers, investment advisers, and broker-dealers Status: Mixed: supervisory guidance and examination practice rather than an AI statute, with binding recordkeeping obligations underneath Reviewed: 26 August 2026

Start with the supervised activity

The United States has no AI Act. What US financial institutions face instead is a layered mix of supervisory guidance, examination practice, and hard recordkeeping obligations attached to existing statutes. Four supervised populations answer to different agencies with different instruments, so start by identifying which one owns the workflow. This page describes the landscape as of August 2026 and maps it to shipped AxonFlow capabilities. It is not legal advice, and AxonFlow does not certify compliance with any instrument named here.

Federal banking agencies

Banks and bank holding companies

Model risk discipline under SR 26-2 and OCC Bulletin 2026-13, interagency third-party risk management, GLBA Safeguards activity logging, and FFIEC BSA/AML expectations for AI-assisted monitoring.

Read the banking mapping
Farm Credit Administration

Farm Credit System institutions

Examined by the FCA rather than the federal banking agencies: Exam Manual EM-31.1 model risk discipline, the 12 CFR Part 609 cyber rule, and NIST AI RMF as the named external framework.

Read the Farm Credit mapping
State insurance regulators

Insurers

The NAIC Model Bulletin on the use of AI systems, the AI Risk Evaluation Supplement questionnaire, NYDFS Circular Letter No. 7, Colorado Regulation 10-1-1, and Texas TDI Bulletin B-0003-26.

Read the insurance mapping
SEC and FINRA

Advisers and broker-dealers

No AI rule after the June 2025 withdrawal of the predictive data analytics proposal. Examination priorities, sweep letters, existing antifraud law, and books-and-records obligations that attach to AI outputs and agent actions.

Read the securities mapping

The standing examiner question set

Federal examiners probe AI use in routine examinations without an AI rulebook to cite. These are the questions that recur, and they are answered with evidence rather than attestations. The same set is a workable self-assessment for any of the four segments above.

Examiner questionWhat AxonFlow contributesWhat stays with you
Where is AI in use, and through what systems?Governed agents, policies, and LLM providers are registered and observable on every path routed through AxonFlow.The institution-wide AI inventory. AxonFlow reports what it governs and does not claim network-wide discovery of ungoverned AI.
Can you reconstruct an individual AI decision?Per-decision records carrying the decision identifier, evaluated policies, verdict, identity attribution, and timestamps across the agent, orchestrator, connector, and workflow layers.Correlation with the downstream core banking, policy administration, or order-management event.
Who oversees high-risk actions, and can you prove it?Human-in-the-loop approval gates pause configured actions for review, and the approval record carries approver identity, justification, and timing. Creating approval entries requires a paid licence (Professional or higher); below that, a require_approval policy still holds the step but creates no queue entry.Reviewer authority, escalation paths, separation of duties, and the risk appetite that decides which actions need a human.
Can an AI system be shut down?Circuit-breaker and kill-switch controls (Enterprise edition) halt governed paths on failure thresholds and disable AI systems, and policy changes take effect at the enforcement point without redeploying agents.Activation authority, recovery rehearsal, and business continuity.
What data can the AI reach, and what was denied?Policy-scoped data access on governed paths, with denials recorded in the same audit surface as approvals so denied-attempt evidence is producible.Data classification, lawful basis, and the access model outside governed paths.
How is customer information protected in prompts and tool calls?PII detection with configurable block, redact, warn, and log actions, including US patterns such as Social Security numbers with format validation and US bank routing and account numbers.The wider GLBA Safeguards program, including service-provider oversight and board reporting.
How do you evidence any of the above to us?Evidence Export (not included on Community) produces structured, time-bounded packages over audit logs, workflow steps, and approval records.Presenting that evidence inside your own examination and model risk processes.

US evidence is produced through the framework-agnostic Evidence Export and the audit APIs. The regulator-specific compliance report feature currently covers the EU AI Act, SEBI, RBI FREE-AI, MAS FEAT, and the Indonesian frameworks (OJK, Bank Indonesia, and UU PDP), and no US regulator is among them.

Banks and bank holding companies

On April 17, 2026 the Federal Reserve, OCC, and FDIC issued revised model risk management guidance (SR 26-2, OCC Bulletin 2026-13, and FDIC FIL-15-2026), superseding SR 11-7 and OCC 2011-12. The revised guidance is stated to be most relevant to banking organizations above $30 billion in assets, and it retains the pillars examiners have applied for fifteen years. One scope fact matters for AI teams: the revised guidance narrows the formal model definition and excludes generative and agentic AI from its scope, while the agencies indicate that the underlying risk-management principles still apply.

RequirementInstrumentAxonFlow contribution
Model risk discipline for AI systems: inventory support, monitoring evidence, and documentation a knowledgeable third party can followSR 26-2 and OCC 2026-13, successors to SR 11-7Per-decision audit records, approval history, and monitoring evidence that a model risk team folds into its own documentation. AxonFlow does not perform model validation or effective challenge.
Life-cycle governance of third-party AI relationshipsInteragency Guidance on Third-Party Relationships (2023)LLM provider inventory and routing controls, per-provider usage and decision records, and self-hosted deployment inside the institution's own environment.
Monitor and log the activity of authorized users on systems holding customer informationGLBA Safeguards and the Interagency GuidelinesIdentity-attributed records of every governed model and tool call, with PII detection and configurable redaction before model or connector access.
Governance of AI-assisted financial crime monitoring, with the records that show what triggered or suppressed an alertFFIEC BSA/AML Examination Manual and FinCEN guidanceThe FinCrime Policy Pack rules, part of the Fraud and Risk Add-on, are authored from public FFIEC examination guidance, FinCEN advisories, OFAC sanctions programs, and 31 CFR 1010.311 thresholds, and detections land in the standard audit surface.
Support for specific adverse-action reasons where AI touches creditECOA and Regulation B, 12 CFR 1002.9Per-decision records identify the policies evaluated and the actions gated, supporting the institution's own adverse-action process. AxonFlow does not generate adverse-action notices and does not perform fair-lending or statistical fairness testing.
Map AI governance evidence to the voluntary frameworks examiners referenceNIST AI RMF and the Treasury-announced, industry-built Financial Services AI Risk Management FrameworkPolicy enforcement, approval, and audit evidence align with the Govern, Map, Measure, and Manage functions. The final mapping remains with the institution's risk team.

Farm Credit System institutions

Farm Credit System lenders are supervised by the Farm Credit Administration, not the federal banking agencies, and the FCA's expectations for AI are concrete. The banking mapping above applies, with the differences below.

Exam Manual EM-31.1 keeps SR 11-7 grade discipline

A risk-tiered inventory including vendor and System-shared models, independent validation and effective challenge, a change-control log recording when, what, who, and approver, and board reporting. Model risk itself is not outsourced. Where it is unclear whether a tool is a model, EM-31.1's direction is to treat it as one, which pulls AI tools into scope. The change-approval evidence that AxonFlow's approval and policy-versioning records produce matches that when, what, who, and approver form.

12 CFR Part 609 applies to AI-based technologies

Effective January 2025: a board-approved written cyber risk program reviewed annually, risk assessment of all vendors, independent control testing, incident notification to the FCA within 36 hours, and quarterly board reporting. Audit and evidence surfaces support the quarterly rather than annual reporting cadence.

NIST AI RMF is the named external framework

The FCA names the NIST AI Risk Management Framework and its Generative AI Profile directly on its AI guidance page, so governance evidence organized around the Govern, Map, Measure, and Manage functions is what examiners are pointed to.

AI is on the FY2026 oversight plan

The FCA's FY2026 oversight plan includes evaluating a sample of institutions on their use of AI in risk management and operations, which makes the standing examiner question set above an immediate self-assessment rather than a future one.

Insurers

Insurance AI governance is set by state regulators working from NAIC instruments, with several states adding their own. The instruments converge on an AI systems program with board accountability, an inventory with risk classification, third-party accountability, and lifecycle documentation producible to a regulator.

RequirementInstrumentAxonFlow contribution
AI system inventory with change tracking and approvals, including retired modelsNAIC Model Bulletin on the Use of AI Systems by Insurers, adopted in 25 jurisdictions as of August 2026; NYDFS Insurance Circular Letter No. 7 (2024)Policy versioning and approval records carrying approver identity and timestamps.
Lifecycle documentation producible to a regulatorNAIC Model BulletinPer-decision audit records and time-bounded Evidence Export packages.
Disclosure of the information an adverse decision relied on, and its sourceNYDFS Circular Letter No. 7Decision records enumerate the policies evaluated and the data categories acted on for governed paths. A proprietary vendor algorithm is not an excuse under CL7, so vendor-side reasoning remains the insurer's to obtain.
Examiner questionnaire evidence: quantified AI usage, governance framework, per-high-risk-system detail, data inputs and sourcesNAIC AI Risk Evaluation Supplement, piloting in 12 states as of August 2026, running through September 2026, with adoption targeted for late 2026Decision volumes, governance policies, per-system audit history, and override records provide source evidence for the supplement's exhibits.
Governance and risk management frameworks for external consumer data and information sources, with annual compliance reports naming accountable individualsColorado Regulation 10-1-1, life insurers since 2023 and expanded to private-passenger auto and health insurers effective October 2025Governed connector and data-access records support the framework's evidence, and approval records name the humans who authorized changes. AxonFlow does not perform the quantitative fairness testing these frameworks also require.
Quantitative fairness analysis before deployment and at least annuallyNYDFS Circular Letter No. 7 and Colorado Regulation 10-1-1Not an AxonFlow capability. Fairness and bias testing remains the insurer's own actuarial and data-science work. AxonFlow records complement that evidence, they do not produce it.

Texas TDI Bulletin B-0003-26 (June 2026) adds that decisions made or supported by AI must comply with unfair-discrimination law, that governance extends to third parties, and that TDI examinations may probe AI governance and human oversight.

Advisers and broker-dealers

The SEC withdrew its predictive data analytics proposal in June 2025, so there is no AI rule. What operates instead is examination practice and existing law.

  • FY2026 examination priorities cover the accuracy of AI representations, supervision of AI use, and alignment of AI outputs with client profiles.
  • Examination sweep letters request AI inventories, policies, and model documentation.
  • Enforcement proceeds under existing antifraud law against firms whose AI claims exceed their AI reality.
  • Books-and-records obligations attach to AI outputs: Rule 204-2 for advisers, and 17a-3 and 17a-4 for broker-dealers, satisfied by WORM storage or the audit-trail alternative introduced by the 2022 amendments.
  • FINRA's 2026 Regulatory Oversight Report states that once an AI agent takes actions, supervision and recordkeeping obligations attach to those actions.
  • The amended Regulation S-P, fully in force June 2026, adds incident-response and service-provider oversight requirements.

AxonFlow's fit here is the same evidence spine: identity-attributed records of what AI produced and did, approval dispositions for outputs that constitute recommendations or actions, and export packages in reviewable formats. The compliant archival system, whether WORM or the audit-trail alternative, remains the firm's own.

Retention obligations worth designing for

The binding US obligations that reach AI work are mostly recordkeeping obligations. They survive shifts in federal AI policy, which makes them the safest thing to design a retention configuration against.

RecordsInstrumentRetention
Adverse-action recordsRegulation B, 12 CFR 1002.12(b)25 months
Suspicious activity reports and supporting documentationBSA, 31 CFR 1020.320(d)5 years
Books and recordsSEC Rule 17a-4 and Rule 204-25 to 6 years; WORM or the 2022 amendments' audit-trail alternative for broker-dealers
Cybersecurity recordsNYDFS, 23 NYCRR 500.065 years for transaction-reconstruction records; 3 years for cybersecurity-event audit trails
Automated decision-making technology recordsColorado SB 26-189, effective January 20273 years

Audit retention is fixed on Community (3 days) and Evaluation (14 days), and is configurable up to 10 years on the paid tiers. Neither Community nor Evaluation can meet any obligation in the table above, so plan on a paid-tier retention configuration or an archive outside AxonFlow, aligned with the strictest instrument that applies to the workflow.

Be precise about the boundary

AxonFlow can support

  • Per-decision records with identity attribution across governed agent, orchestrator, connector, and workflow paths
  • Human review gates whose records carry approver identity, justification, and timing
  • PII detection with US patterns, including Social Security numbers with format validation and US bank routing and account numbers
  • Circuit-breaker and kill-switch controls (Enterprise edition) that answer the shutdown question
  • Time-bounded Evidence Export packages over audit logs, workflow steps, and approval records (not included on Community)
  • Self-hosted deployment, so the governed data and the governance records stay inside your own boundary

AxonFlow does not do

  • Model validation, effective challenge, or statistical fairness and bias testing
  • Adverse-action notice generation or fair-lending determinations
  • Legal applicability analysis or compliance certification for any instrument named on this page
  • Discovery of AI systems that are not routed through AxonFlow's governed paths
  • Regulator-specific compliance reports for US regulators; US evidence comes from Evidence Export and the audit APIs

AxonFlow is source-available under BSL 1.1, so a model risk or security team can inspect the enforcement, detection, and audit implementations directly rather than relying on a vendor attestation. Legal and compliance teams must still validate the complete system against current law, supervisory guidance, contractual obligations, and deployment facts.

A sensible assessment sequence

  1. Identify which supervised population owns each AI-assisted workflow, since the instruments differ by agency rather than by technology.
  2. Route one workflow through AxonFlow in your own environment, so the data and the governance records stay inside your boundary.
  3. Turn on the policies that workflow needs: PII detection with US patterns, approval gates on the actions your risk appetite says a human must see (approval queues require a paid licence, Professional or higher), and data-access scoping.
  4. Generate an Evidence Export for a bounded period and walk it through your model risk or compliance function against the standing examiner question set above.
  5. Correlate the AxonFlow decision records with the downstream core banking, policy administration, or order-management event, and confirm the combined record answers the questions an examiner would ask.

Test the control path against a real workflow.

Use the Evaluation license to assess policy enforcement, human review, evidence records, and deployment boundaries before a regulated rollout.