If you’ve been tracking AI regulation in banking one headline at a time, this year has been genuinely difficult to keep straight – a Federal Reserve guidance update, a European deferral that has been widely misread, and a CFPB circular that closes a door some institutions were hoping stayed open. Taken individually, each looks like a discrete compliance update. Taken together, they describe one consistent direction: regulators everywhere are moving from asking whether a bank uses AI to asking whether the bank can prove, on demand, that it is controlled.
Here is what actually changed, and what each change requires of your governance programme specifically.
SR 26-2 Supersedes SR 11-7 – and That Matters More Than It Sounds
The Federal Reserve’s SR 26-2, issued in April 2026, now supersedes SR 11-7 and SR 21-8 as the interagency model risk management guidance banks are examined against. SR 11-7 was written for a generation of models that were validated once, at deployment, and reviewed periodically thereafter – a static documentation exercise. If your model risk framework was built purely to that standard, it is, by the Fed’s own action, no longer sufficient on its own.
The practical implication: examiners are now looking for continuous validation and production monitoring as a standing capability, not a periodic exercise. A framework built around an annual model validation calendar will not satisfy an examiner asking to see this quarter’s drift monitoring evidence.
The EU AI Act’s Deferral Is Real – But It Is Not the Relief It Looks Like
The May 2026 Digital Omnibus agreement deferred the EU AI Act’s Annex III high-risk compliance deadline – covering credit scoring and AML monitoring – from 2 August 2026 to 2 December 2027. That is a genuine sixteen-month extension, and it has understandably been read by some institutions as breathing room.
The extension bought time to meet a bar that has not been lowered – it did not lower the bar.
The deferral exists because the technical conformity-assessment standards the Act depends on were not ready by the original deadline – not because the underlying obligation softened. Two things did not move: the prohibited-practice provisions have applied since February 2025, and the European AI Office gains direct enforcement power over general-purpose AI model providers from August 2026 regardless of the Annex III deferral. A bank that reads the sixteen-month extension as licence to pause its governance build will find itself starting the same work in eighteen months, on a shorter runway, against a deadline that has not actually moved for the parts of the Act that matter most immediately.
CFPB Circular 2026-03 Closes the “The Model Is Too Complex to Explain” Argument
The CFPB’s Circular 2026-03, issued May 2026, confirms something that has been a live argument in lending circles for several years: lenders using machine-learning underwriting models remain fully responsible under ECOA and Regulation B for providing specific, accurate reasons for adverse action. Model complexity, proprietary architecture, or a vendor relationship are explicitly not a defence. If your institution cannot trace a specific credit decision back to the specific factors that drove it, in language a customer can understand, that is now a compliance gap – not a technical limitation the regulator is expected to make allowances for.
This is the circular that makes decision-level explainability infrastructure a requirement rather than a best practice. Institutions relying on high-performing but genuinely opaque underwriting models now need an explainability layer sitting alongside the model, reconstructing the specific reasoning for each decision, regardless of how the model itself was built.
Meanwhile: the UK and APAC Are on the Same Trajectory, Just Earlier in It
The UK’s PRA has named AI adoption a 2026 supervisory priority under its existing SS1/23 model risk principles, and a House of Commons Treasury Committee report has explicitly called on the PRA and FCA to publish AI-specific guidance and clarify senior-manager accountability for AI decisions by the end of 2026. Singapore’s MAS FEAT Principles remain the reference standard across APAC supervisory conversations, with Hong Kong’s HKMA and India’s RBI following a similar principles-based-first pattern. None of these jurisdictions have finished tightening. All of them are moving in the same direction the US and EU have already travelled further along.
What This Means for Your 2026–2027 Governance Roadmap

- Audit your current model risk framework against SR 26-2 specifically – not SR 11-7 – and identify where periodic validation needs to become continuous monitoring.
- Treat the EU AI Act’s Annex III deferral as a construction timeline, not a deprioritisation signal – December 2027 will arrive faster than the sixteen months suggests once conformity assessment infrastructure is actually being built.
- Build decision-level explainability for any underwriting model now, regardless of jurisdiction – CFPB Circular 2026-03 has made this a US requirement, and every other regulator in this list is heading toward the same expectation.
- If you operate across multiple jurisdictions, look for the four capabilities that satisfy all of them at once – explainability, auditability, human accountability, and lifecycle monitoring – rather than building a separate compliance response to each instrument.
The instruments are different. The direction is not. Every one of these updates is asking the same underlying question: can you produce the evidence, not just the policy.
This is the full regulatory landscape mapped, jurisdiction by jurisdiction, in Paper 5 of Maveric’s CIO Mandate Series:
AI Compliance and Regulatory Governance: A CIO & CRO Mandate for Global Banks