AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →
VoluntaryGuidelineGlobalHigh risk

Financial Stability Board Recommendations on Agentic AI Controls in Financial Services

Issued by

Financial Stability Board

liveFSB-AgentAIVerified August 2026

The Financial Stability Board issued recommendations calling on corporate boards at financial institutions to establish safeguards for agentic AI systems that can plan, reason, and act with minimal human oversight. The guidance applies to banks, asset managers, insurers, and other regulated financial entities deploying or considering autonomous AI. It identifies board-level governance, defined usage limits, and protective controls as expected baseline practices for agentic AI deployments.

Applies To

Large enterprisePublic sectorAI deployer

Overview

The Financial Stability Board, a global body coordinating financial regulation across G20 jurisdictions, issued guidance in June 2026 addressing the growing use of agentic AI in financial services. Agentic AI refers to systems capable of autonomous decision-making, multi-step reasoning, and executing actions across systems with limited human intervention. The FSB identified this category of AI as presenting heightened systemic and operational risks compared to conventional machine learning tools. Key provisions call for boards to formally consider and document agentic AI risks, establish usage boundaries, and implement technical and procedural controls proportionate to the autonomy level of deployed systems. As an FSB recommendation, the guidance does not carry direct legal force but is expected to inform national supervisory expectations across member jurisdictions. Financial institutions operating in FSB member countries should anticipate that domestic regulators will reference this guidance in examination frameworks and supervisory communications.

Key Requirements

  • Corporate boards must formally consider and document risks arising from agentic AI systems in use or under evaluation
  • Financial institutions must define and enforce usage limits that constrain autonomous AI actions within approved operational boundaries
  • Protective controls must be implemented proportionate to the autonomy and decision-making scope of each agentic AI deployment
  • Governance frameworks must address the specific characteristics of agentic AI, including multi-step reasoning, tool use, and reduced human supervision
  • Institutions should establish oversight mechanisms capable of monitoring, auditing, and intervening in autonomous AI operations in near real time
  • No binding penalty regime is attached to the FSB recommendation, but non-compliance creates supervisory examination risk in member jurisdictions

What Your Organization Must Do

  • Inventory all AI systems currently in production and flag any that operate with autonomous planning, chained actions, or reduced human checkpoints for priority review
  • Present a formal agentic AI risk assessment to the board or relevant board committee, with documented conclusions and approved risk appetite statements
  • Define and codify operational usage limits for each agentic AI deployment, specifying which actions the system may take autonomously and which require human authorization
  • Implement technical guardrails such as action logging, rate limits, and kill-switch capabilities to support real-time oversight of autonomous systems
  • Update internal AI governance policies to distinguish agentic AI from conventional predictive models, with separate approval and monitoring workflows
  • Brief legal and compliance teams on FSB member jurisdictions where domestic supervisors are likely to adopt or reference this guidance in upcoming examination cycles

Playbook Guidance

Step-by-step implementation guidance for compliance teams.

Frequently Asked Questions

Does the FSB agentic AI recommendation create binding legal obligations for banks and asset managers?
No, FSB recommendations do not carry direct legal force. However, financial institutions in G20 member jurisdictions should expect domestic regulators to incorporate this guidance into examination frameworks and supervisory communications, making non-compliance a material examination risk in practice.
Which financial institutions are in scope for the FSB agentic AI controls guidance?
The guidance applies to banks, asset managers, insurers, and other regulated financial entities that are deploying or evaluating agentic AI systems. Scope is determined by the nature of the AI technology in use, not institution size, though proportionality principles apply to control implementation.
What specifically distinguishes agentic AI from conventional machine learning under this FSB guidance?
The FSB defines agentic AI as systems capable of autonomous decision-making, multi-step reasoning, and executing actions across systems with limited human intervention. Conventional predictive models used for credit scoring or fraud detection would not typically meet this threshold.
What board-level actions does the FSB recommendation require financial institutions to take on agentic AI?
Boards must formally consider and document risks from agentic AI systems currently in use or under evaluation, approve risk appetite statements, and establish defined usage boundaries. This expectation elevates agentic AI governance from a technology function to a fiduciary responsibility.
What is the effective date and current status of the FSB agentic AI recommendation?
As of the available entry, the guidance was issued in June 2026 and remains in draft review status with no confirmed effective date. Institutions should monitor domestic regulatory communications in FSB member jurisdictions for adoption timelines and supervisory expectations.
How should compliance teams differentiate oversight requirements for agentic AI versus standard AI models under FSB-AgentAI?
The guidance calls for separate governance workflows specifically addressing agentic AI characteristics such as tool use, chained actions, and reduced human checkpoints. Compliance teams should inventory deployed systems, flag those meeting the agentic definition, and apply distinct approval and monitoring processes to that subset.