VICI Insights • AI Track • Week 02
Why Regulated Industries Can't Move Fast and Break Things With AI
In April, the Fed issued its flagship 2026 model-risk guidance — SR 26-2 — and deliberately left generative AI and agentic AI out of scope.
"Novel and rapidly evolving," the agencies said. A Request for Information is coming.
That means the most consequential AI systems banks deployed in the last two years — the ones generating content, summarizing documents, powering chatbots, and starting to execute decisions — are operating in a gap. No formal regulatory template. No SR 11-7 equivalent. Leadership owns the bridge until the rules arrive.
That's what "regulated industries can't move fast and break things with AI" actually means in 2026. It's not that regulators have hemmed you in. It's that they haven't yet — and you're accountable anyway.
The cliché is wrong. The constraint isn't slowness — it's survivable speed.
In banking, insurance, fintech, and payments, a bad AI answer isn't an embarrassing hallucination on a demo. It's a credit decision with a disparate-impact exposure. It's a claims denial a regulator will reconstruct. It's a customer interaction a class-action attorney will subpoena.
The question isn't whether you can move fast. It's whether the speed survives an exam, an audit, or a failure.
Right now, it largely doesn't. A Wolters Kluwer survey of 230 U.S. banking professionals found nearly three in four couldn't confidently operate a kill switch on a malfunctioning AI model or report a failure to supervisors. Examiners from the Fed, OCC, and FDIC are pressing on exactly these capabilities in every exam cycle — even as their April guidance declines to define them.
The three things a regulated AI program needs that most don't have:
1. Make it auditable before you make it fast. Every regulated AI decision needs a traceable owner, input, and rationale. Not because a regulator will definitely look — because when they do, and they will, the decision needs to be reconstructable. Speed is fine. Speed without a paper trail is a liability.
2. Build the bridge framework where regulators left a gap. SR 26-2 excludes GenAI and agentic AI. That's not a green light — it's a governance gap you now own. The working framework is NIST AI RMF + EU AI Act (high-risk FSI use cases, including credit scoring, carry penalties up to €15M or 3% of global turnover; the August 2, 2026 deadline is active) + applicable state law. Build the lane now. Retrofitting it after an incident costs orders of magnitude more.
3. Prove you can stop it. Kill switch. Failure reporting path. Vendor-chain and data-boundary documentation. These aren't theoretical — examiners are asking in active cycles. Nearly 3 in 4 banks can't answer confidently. That's the gap.
The institutions that build these controls first don't move slower. They move faster afterward, because they're not re-litigating every model with risk and compliance each time. The audit trail is the speed advantage.
"Move fast and break things" was built for a world where the things you break are yours to fix. In regulated AI, the things you break belong to your customers, your regulators, and your charter.
If you're working through AI governance, workflow design, or production-readiness in financial services, fintech, or insurance, feel free to reach out on LinkedIn or visit www.consultvici.com.
Where are you seeing this show up in your organization — experimentation, governance, data readiness, or scaling?
