Set Agentic AI Autonomy Boundaries Before Financial Regulators Do

Access this content by contacting one of our representatives for assistance.

Author(s): Mitchell Fong

More than half of financial institutions are already running agentic AI in production, and SR 26-2 (April 2026) excludes these systems from formal model-risk oversight, directing institutions to govern them through their own risk-management practices instead. The result is that every institution deploying agentic AI already has an autonomy boundary in place, whether by deliberate design or by default, and financial regulators are increasingly testing that boundary during examinations using a three-part standard: what did the agent do, why did it do it, and should it have been permitted to. This research presents a thought model that converts an implicit, inherited autonomy boundary into an explicit, evidenced decision, and recommends initiating a cross-functional review, closing four defining questions (permitted action, boundary, escalation ownership, and evidence), and documenting the outputs as artifacts an examiner could request at any time.