Hi there,
On April 17, federal banking regulators rewrote the model risk management rulebook — and deliberately left out generative AI and agentic AI. For banks running LLMs in credit, fraud, and compliance workflows, that's not a reprieve. It's a mandate to build your own governance framework before examiners come knocking.
🔥 Featured Post
SR 26-2 Blew a Hole in Bank AI Governance. Now Every Model Risk Team Has to Fill It.
- SR 26-2 replaced SR 11-7 on April 17 and explicitly excluded generative and agentic AI from its scope
- The governance vacuum is real: banks must build parallel AI governance frameworks without regulatory blueprints
- Traditional model validation — train/test splits, champion-challenger, annual review — doesn't map to LLM behavior
- Agentic AI introduces runtime authorization problems that pre-deployment validation was never designed to catch
- The RFI on generative AI governance is coming, and banks that build now will have the playbook when it does
📚 In Case You Missed It
CommBank's Fraud Agent Now Writes Its Own Detection Rules — The Architecture Shift Behind a 20% Drop in Fraud Losses — CommBank's agentic fraud AI now writes 75% of its own card detection rules — and delivered a 20%+ reduction in fraud losses — but the architecture behind human-in-the-loop rule generation at 80M daily signals is what every fraud AI team should be studying.
Five AI Vendors Shipped Agent Registries in One Quarter — That's Not Competition, It's a Production Crisis Signal — Microsoft Agent 365 went GA on May 1 with cross-cloud registry sync across AWS Bedrock and Google Cloud — and it's just one of five major vendors shipping agent governance layers in the same quarter, signaling that agent sprawl has crossed from engineering inconvenience to compliance crisis.
When RAG Breaks at Agent Scale: Pinecone Nexus and the Context Compilation Turn in Enterprise AI — Pinecone launched Nexus this week — a context compiler that pre-processes knowledge into agent-optimized artifacts at build time, not query time — which signals that the RAG architecture most enterprises built in 2024–2025 has a structural ceiling at agentic scale.
More posts dropping every day. Stay curious.
— Bhanu @ superml.dev
