Most US banks cannot produce this document.
By the time a human reviews the agent's final output, dozens of autonomous decisions have already executed. Your controls are reviewing ancient history.
Regulation (EU) 2026/1744 is now in force. High-risk AI deadlines move to December 2027 and August 2028, and agentic AI enters the AI Act text for the first time as conformity assessment code AIH 0401.
Answer five quick yes/no indicators
Signals from the supervisory horizon
FINRA lists autonomy, scope, and auditability among agentic AI risks to member firms.
Translation: FINRA has moved from watching agentic AI to naming its risks.
Read the Guidance ↗"Generative AI and agentic AI models are novel and rapidly evolving... not within the scope of this guidance."
Translation: The model rules regulators just refreshed deliberately skip the AI you are actually deploying.
Read the Bulletin ↗IMF maps where agentic AI meets payment authorization, settlement, and compliance.
Translation: The payment rails were built for deterministic instructions, not autonomous agents.
Read the IMF Note ↗UK authorities tell firms to treat frontier AI as a live cyber threat to operational resilience.
Translation: Britain's regulators are already writing the agentic-risk playbook US supervisors are still drafting.
Read the Statement ↗Identifying internal exposure sectors
Foundational controls for agentic deployments
Every agent in production requires a verifiable, non-human identity — not a shared service account, not a developer's personal token.
Agents operate within defined boundaries. Every external call, every approval chain, every data access is mediated by policy — not trust.
When something happens, you know which agent did it, when, and under what authority. Ambiguity in the audit trail is a regulatory liability.