Agentic AI in regulated industries lives or dies on oversight architecture, not model capability. Financial services and healthcare teams are already deploying agents that execute multi-step work — and between December 2025 and July 2026, FINRA, the Federal Reserve, the FCA, and the FDA each told those teams, in their own vocabulary, what deployable looks like. Read together, their guidance converges on five recurring patterns.
The stakes are concrete. According to a Cloud Security Alliance survey from June 2026, cited by Banking Dive, 62% of financial-services firms have deployed AI agents — and 93% of those firms have granted their agents some degree of autonomy. Autonomy at that scale is exactly what supervisory frameworks written for static software were never designed to absorb, which is why the regulatory response has been unusually fast and unusually consistent.
This framework distills that response into five oversight patterns: human-in-the-loop gates, audit trails a regulator can replay, scoped permissions, deterministic fallbacks, and model-risk documentation. For each, we pair the pattern with the regulator actually asking for it, then walk a named finserv implementation — Fenergo’s Fen-AI — and close with a sequencing guide for teams shipping agents into compliance review.
- 01Four regulators converged in under eight months.FINRA’s 2026 Regulatory Oversight Report (Dec 2025), the FDA’s CDS guidance (Jan 2026), the Fed’s SR 26-2 (Apr 2026), and the FCA’s Mills Review (Jul 2026) all address AI systems that act — and their asks rhyme.
- 02Human-in-the-loop is necessary but not sufficient.A Bank of England Deputy Governor has cautioned that human sign-off on every agent action is unlikely to be realistic. The workable version is tiered gates on consequential actions, not blanket approval.
- 03The audit trail regulators want is event-level.Every action, source, decision, and rationale, recorded as work happens — Fenergo’s stated implementation standard — is a fair proxy for what supervisory review will ask an agent operator to reconstruct.
- 04Model-risk scope is genuinely contested.SR 26-2 superseded SR 11-7 in April 2026, but whether agentic AI sits inside its formal scope is disputed across analyses. The defensible move is to document as if it does.
- 05Sequence patterns by regulator exposure, not by ease.Broker-dealers start with scoped permissions, banks with model-risk documentation, clinical teams with explainable fallbacks. The pattern-to-regulator map in section 08 is the sequencing tool.
01 — Why NowFour regulators converged in under eight months.
The regulatory moment is easy to miss because it arrived as four separate documents rather than one statute. FINRA’s 2026 Regulatory Oversight Report, published in December 2025, added a section flagging agentic AI — systems that autonomously execute multi-step tasks — as an emerging risk area, and tied deployment to supervisory controls under FINRA Rule 3110. In January 2026, the FDA issued updated guidance on clinical decision support software that extends enforcement discretion to AI features under explicit explainability conditions. On April 17, 2026, the Federal Reserve issued SR 26-2, superseding SR 11-7 — the model risk framework US banks had operated under for fifteen years. And on July 6, 2026, the FCA published the Mills Review, a forward-looking examination of how AI could transform UK retail financial services by 2030.
The EU’s timeline is its own story — most Annex III high-risk obligations began applying on August 2, 2026, subject to the Digital Omnibus proposal, and we cover the enforcement machinery separately in our EU AI Act enforcement guide. This post stays on the sector regulators, because that is where the agent-specific language lives.
FINRA’s supervision rule reaches agents
The 2026 Regulatory Oversight Report flags agentic AI as an emerging risk area. Firms deploying autonomous multi-step systems must maintain supervisory controls compliant with Rule 3110.
Mills Review autonomy spectrum
The FCA’s Mills Review proposes a five-level autonomy spectrum — Operator through Observer — for how far AI displaces human judgment, after surveying more than 5,000 UK adults.
Model-risk guidance turned over
SR 26-2 superseded SR 11-7 on April 17, 2026 — after a fifteen-year run. Whether generative and agentic AI sit inside its formal scope is contested across published analyses.
The demand side explains the urgency. Deployment has outrun governance: most financial firms in the CSA’s June 2026 survey sample already run agents, and nearly all of those grant the agents autonomy. Consumer appetite is moving the same direction — the Mills Review’s survey of more than 5,000 UK adults found one in five open to AI deciding for them on financial matters.
Autonomy is already deployed — oversight is catching up
Sources: Cloud Security Alliance survey (June 2026) via Banking Dive; FCA Mills Review (July 2026)"As AI moves from recommending to acting, and firms and consumers delegate more, risks shift from harm within a single firm towards system-wide harms."— Sheldon Mills, FCA, via Banking Dive (July 2026)
02 — Pattern 01Gates on consequential actions — not on everything.
The first pattern is the one everyone names and most teams implement badly: a human approval step between what an agent proposes and what it executes. The design question regulators are now surfacing is not whether to gate, but where. Gate nothing and you fail FINRA’s supervisory expectations; gate everything and you rebuild the manual process you deployed the agent to replace.
The most useful regulatory statement on this trade-off came from the Bank of England. In remarks covered by law firm Burges Salmon on July 1, 2026, a Deputy Governor put it plainly: “our frameworks were not built to contemplate autonomous agents, and relying on a human in the loop for all agent actions is unlikely to be realistic. More sophisticated governance and accountability frameworks may be needed.” That is a central bank explicitly cautioning against the naive version of this pattern — a blanket per-action approval queue that drowns reviewers and trains them to rubber-stamp.
The workable design gates by consequence class. Actions that touch a regulated outcome — moving money, filing a report, communicating with a customer about a financial decision — route through an explicit approval; reversible internal actions proceed with logging only. The FCA’s leadership has framed the underlying principle the same way: accountability for regulated activities and outcomes must remain clear, with the right human oversight designed in, and boards and leadership teams must understand the risks. How the escalation handoff itself should behave — queue design, reviewer context, fatigue — is a UX problem we cover in our human-in-the-loop escalation design guide, so we will not restate it here.
03 — Pattern 02An audit trail a regulator can replay.
The second pattern is event-level logging of everything the agent did and why. The regulated-industry bar is higher than ordinary observability: the SR 11-7 lineage of model governance assumed decision paths that could be reconstructed on request. An agent whose actions cannot be replayed step by step is, from a supervisory standpoint, an unsupervised employee.
What does event-level mean in practice? The clearest published articulation currently comes from a vendor rather than a regulator. Fenergo, which launched its governed agentic platform in late July 2026, states that its agents run on a Legal Entity System of Record where “every action, source, decision and rationale is recorded as work takes place.” Vendor language, yes — but it is a fair proxy for what a supervisory review will ask an agent operator to produce: not just outputs, but inputs, intermediate decisions, and the rationale chain connecting them.
The implementation details — event schemas, retention, immutable storage, correlating agent steps to business records — are covered in our agent audit-trail design guide. The regulated-vertical delta is the audience: design the log for an examiner who was not in the room, not for the engineer who was. If a periodic review, a screening decision, or a clinical recommendation cannot be reconstructed from the trail alone, the trail is not done.
04 — Pattern 03Permissions scoped to the action, not the agent.
The third pattern is the one FINRA’s 2026 report describes most concretely. Per legal analyses of the report, the risk focus is AI agents that can take actions — placing orders, executing transactions, sending communications, making compliance filings — without explicit human approval for each individual action. That is a permissions statement: the concern is not that an agent exists, but that its execution surface includes regulated actions it can reach ungated.
FINRA’s framing of its own jurisdiction makes the design implication clear. Its AI topic page states that “FINRA’s rules—which are intended to be technology neutral—and the securities laws more generally, continue to apply” — regardless of whether AI built or operates the tool. The firm remains accountable for every action the agent takes, which means the deployable architecture grants each agent the narrowest permission set its task needs: read access where reading suffices, propose-only access to regulated actions, and execution rights only behind the gates from Pattern 01. FINRA’s standing notices — Regulatory Notice 24-09 (June 2024) on generative AI and Notice 21-29 (August 2021) on third-party vendor oversight — remain the cited baseline on its AI topic page at the time of writing.
The UK is converging on the same idea from a different angle. The Mills Review’s five-level autonomy spectrum — Operator through Observer — is a regulator formalizing the notion that autonomy is a dial, not a switch, set per activity rather than per system. Teams that already model permissions as autonomy tiers will find that regulatory conversations map cleanly onto their architecture. The mechanics of building the approval layer itself are in our approval-gate framework guide.
05 — Pattern 04Deterministic fallbacks and explainable outputs.
The fourth pattern answers the question every compliance officer asks first: what happens when the model is wrong, unavailable, or un-explainable? A regulated workflow cannot degrade into nothing. It needs a deterministic path — rules-based processing, queued human handling, or a safe halt state — that the organization has actually tested, not merely documented. One industry analysis of European banking deployments (Neontri, 2026) makes the point that human override has to be exercised under real operating conditions to count; an override that has never fired is a diagram, not a control.
Healthcare gives this pattern its sharpest regulatory edge. The FDA’s January 2026 guidance expanded enforcement discretion for certain clinical decision support software functions — including AI and generative-AI features — but only so long as the software provides a single, clinically appropriate recommendation and clinicians can independently review and understand the basis for it. Law firm Covington & Burling’s reading of the guidance captures the operating rule: the more the software behaves as a black box to healthcare professionals, the greater the risk the FDA treats it as a regulated medical device. Explainability is not a nice-to-have there — it is the line between enforcement discretion and full device regulation.
Finance has an unresolved version of the same problem. The Bank of England commentary covered by Burges Salmon flags an open question directly relevant here: how disputes are settled and liability assigned for erroneous or fraudulent transactions initiated by an agent. Until that is settled, the pragmatic posture is to make the fallback path — and the record of who or what acted — deterministic enough that liability can at least be traced. The runtime safety layers that catch bad outputs before they execute are cataloged in our LLM guardrails reference.
06 — Pattern 05Model-risk documentation, with contested scope.
The fifth pattern is the least glamorous and the most load-bearing: documenting agents inside a model-risk-management framework. For US banking, that framework was SR 11-7 — the interagency guidance from 2011 built on governance, independent validation, and effective challenge. As risk association GARP’s analysis notes, SR 11-7 assumed models are “simplified, relatively static representations of real-world relationships” — bounded scope, stable parameters, reconstructible decision paths. Agentic systems violate those assumptions by design, and GARP’s analysis identifies exactly where the framework strains:
- Dynamic behavior. Agents that recalibrate autonomously produce material behavioral change without a formal redevelopment event — so nothing triggers re-validation.
- Probabilistic outputs. The guidance’s validation logic presumes deterministic systems; agents are probabilistic at every step.
- Definition mismatch. SR 11-7’s “model” — something that processes input data into quantitative estimates — may be too narrow for systems that continuously learn, adapt, and initiate actions in real time.
- Third-party concentration. Reliance on a small set of external AI vendors creates concentration risk that sits outside the traditional regulatory perimeter.
On April 17, 2026, the Federal Reserve issued SR 26-2, superseding SR 11-7. Here honesty matters more than tidiness: published analyses disagree on whether SR 26-2 brings agentic AI into formal scope. One reading holds that it explicitly leaves generative and agentic AI out, pending a future interagency request for information on AI model-risk management. Treat the question as open — and notice that the ambiguity does not reduce the documentation burden. It increases it, because the firm that documented as if in scope is prepared under either resolution.
GARP’s recommended path forward is adaptation, not abandonment: dynamic and continuous validation approaches, explicit treatment of third-party concentration risk, and clearer explainability standards. That maps one-to-one onto this pattern — an inventory of agents, their intended scope, validation evidence, monitoring thresholds, and re-validation triggers tied to behavioral change rather than release dates.
07 — Worked ExampleFenergo: a governed agentic stack in production finserv.
One named implementation makes the five patterns concrete. On July 29, 2026, Fenergo — a client-lifecycle-management vendor that says it serves more than 40% of the world’s top 50 banks and over 110 financial institutions (a company-stated market claim) — launched Fen-AI, a governed agentic-AI orchestration platform for KYC and AML operations. It is one example, not the subject of this post; what makes it useful is how visibly the oversight patterns show up in its published architecture.
Fen-AI + KYRA
Coordinates AI-driven activity across client onboarding, periodic reviews, ongoing monitoring, and material client changes — built on Fen-X, Fenergo’s Legal Entity System of Record, so the event log is the substrate rather than an add-on.
Six specialized agents
Narrow agents with narrow mandates, observed through role-based dashboards where users “observe all agent activity and maintain complete governance and control.” Early adopters named: Citco Group and Northern Trust.
The agent roster in Fenergo’s related FinCrime Operating System reads like a scoped-permissions diagram: a Data Sourcing Agent that retrieves third-party data, a Screening Agent that executes and auto-resolves screening hits, a Document Agent that extracts, classifies, and links documents, a Significance Agent that evaluates data changes for compliance relevance, an Autocompletion Agent that completes tasks per predefined rules, and an Insights Agent serving as a natural-language co-pilot for operational analytics. Each agent’s mandate is narrow enough that its permission surface is legible — Pattern 03 expressed as product architecture.
Two more patterns are visible in the launch materials. The platform’s Agent-to-Agent Interoperability Framework lets firms link Fenergo agents with approved client or third-party agents through a single governed interface, using Model Context Protocol alongside A2A interoperability to authenticate requests and maintain context across handoffs — scoping applied at the boundary between organizations, not just inside one. And the logging standard quoted in Pattern 02 is the audit-trail pattern as a first-class product feature. All of this is vendor-stated rather than independently audited — but as a worked example of what “deployable under compliance” looks like in 2026 finserv, it is the clearest one publicly documented.
"This is where agentic AI will be a game changer, allowing for faster onboarding, fewer manual errors and lower compliance risks."— Keith Redmond, Chief Product Officer, Fenergo (vendor-stated)
08 — The MapThe pattern-to-regulator map.
This table is ours — no regulator publishes the five patterns side by side, and no single source maps them against regulator language this way. Each row pairs one oversight pattern with the body asking for it, what that body has actually said (dated), and where the ask applies. Use it to brief a compliance counterpart in one page, or to decide which pattern your next sprint should harden.
| Pattern | Who is asking | What they have said | Applies to |
|---|---|---|---|
| Human-in-the-loop gates | FCA · Bank of England | Mills Review (Jul 6, 2026) proposes a five-level autonomy spectrum rather than binary approval; BoE remarks (covered Jul 2026) caution that human sign-off on every agent action is unlikely to be realistic | UK financial services; any consequential agent action |
| Audit trails / event logs | FINRA · SR 11-7 lineage | 2026 Regulatory Oversight Report (Dec 2025) ties agentic AI to Rule 3110 supervisory controls; the SR 11-7 lineage assumes reconstructible decision paths | US broker-dealers; bank model governance |
| Scoped permissions | FINRA | The report’s stated focus (Dec 2025): agents placing orders, executing transactions, sending communications, or making compliance filings without explicit human approval per action | US broker-dealers; any agent reaching regulated actions |
| Deterministic fallbacks | FDA | Jan 2026 CDS guidance: enforcement discretion where software gives a single, clinically appropriate recommendation whose basis clinicians can independently review — opacity invites device regulation | Clinical decision support; healthcare agent workflows |
| Model-risk documentation | Federal Reserve | SR 26-2 (Apr 17, 2026) supersedes SR 11-7; whether agentic AI is in formal scope is contested — document as if it is | US banks; any firm running a model-risk framework |
09 — ImplicationsSequencing the five patterns on a real roadmap.
Here is our reading of the trend, rather than any single regulator’s: the convergence is the story. Four bodies with different mandates, jurisdictions, and vocabularies arrived at the same short list — evidence of what happened, limits on what an agent can reach, a human at the consequential moments, a tested path when the model fails, and paperwork that survives an examiner. When independent regulators converge that fast, the patterns stop being compliance overhead and become the de facto reference architecture for agents in any high-accountability environment — including ones no regulator has visited yet. Where you start, though, should depend on which regulator can hurt you first.
FINRA exposure first
Rule 3110 supervision plus the report’s per-action concern makes ungated execution your fastest way to fail an exam. Inventory every regulated action an agent can reach; gate or de-scope each one.
SR 26-2 ambiguity
Scope is contested, so documentation is the hedge. Extend the model inventory to agents, define re-validation triggers on behavioral change, and address third-party concentration explicitly.
FDA classification risk
The black-box test decides whether you face enforcement discretion or device regulation. Single reviewable recommendation, independently understandable basis, deterministic clinical fallback.
Regulated-adjacent automation
Agents updating customer records, sending communications, or driving onboarding in a regulated firm inherit the same expectations. Event-level audit trail first; it makes every later pattern cheaper.
Looking forward, two developments seem likely from where things stand at the time of writing. First, supervision itself is going agentic: the Mills Review explicitly recommends the FCA build an AI-enabled supervisory model — continuous, system-wide, and risk-based rather than episodic and document-driven. When the examiner is an agent, an event-level audit trail stops being a differentiator and becomes the interface. Second, the SR 26-2 scope question will eventually be resolved through the interagency request-for-information process, and firms that documented as-if-in-scope will convert that ambiguity into a head start rather than a remediation project. Teams weighing whether to build this oversight layer themselves or buy it should start with our agentic CRM buy-vs-build framework and the vertical context in our fintech and banking agentic AI guide.
For most mid-size firms, the five patterns land first in the CRM and workflow layer — the systems where agents touch customer records, communications, and onboarding. That is where we build: our CRM automation engagements wire gates, logs, and scoped permissions into agent workflows from day one, and our AI transformation practice handles the governance layer — agent inventories, autonomy tiers, and the documentation an examiner will actually ask for.
10 — ConclusionOversight is the deployment architecture.
The five patterns are not compliance overhead — they are what deployable means.
Between December 2025 and July 2026, FINRA, the FDA, the Federal Reserve, and the FCA each published their answer to the same question: what does it take to let software that acts — not just recommends — operate inside a regulated business? Their answers converge on the five patterns in this framework: gates, trails, scope, fallbacks, and documentation.
None of it requires waiting for regulatory certainty — which is fortunate, because certainty is not on offer. SR 26-2’s agentic scope is contested, the UK’s framework is a review rather than a rulebook, and liability for agent-initiated transactions remains an open question at a central-bank level. The firms deploying successfully are not the ones that resolved that ambiguity; they are the ones whose architecture is defensible under any resolution of it.
The practical move is to pick your first pattern by regulator exposure, implement it at event level rather than as documentation theater, and let the remaining four follow. An agent your compliance team can replay, bound, interrupt, and explain is an agent that ships — and stays shipped.