VICI Insights • AI Track • Week 07
What Banking Taught Me About AI Risk
The model-risk rulebook I trained on in banking was just rewritten in 2026.
And it deliberately leaves out the AI everyone is actually deploying.
That is the part most leaders are missing.
Banking has spent years building discipline around model risk: validation, effective challenge, governance, documentation, monitoring. Those instincts matter. But the 2026 US model-risk guidance from the Federal Reserve and OCC treats generative and agentic AI as novel enough to sit outside the revised framework, while the promised interagency AI RFI still has not landed.
So the useful banking lesson is not, "we already have the rules."
It is: build defensible controls in the gap before the rules arrive.
That is especially relevant right now. India's banking regulator has a 2026 draft model-risk framework in live consultation through July 24 that explicitly pulls AI and machine-learning models into governance and calls for human oversight, override, suspension, and deactivation mechanisms. In plain language: an off-switch.
That is not fear of AI.
That is risk discipline.
Here is the operating model I would use with any regulated AI program:
- Tier the decision, not the tool.
Start with the business decision and its blast radius. A customer-facing credit decision is not in the same risk tier as an internal meeting-notes copilot. Governance should scale with impact, not with how impressive the demo looks. The CFPB has already made clear that "the algorithm is too complex" is not a defense when a consumer is owed an adverse-action explanation.
- Name an owner and an off-switch.
Every model or agent needs a human owner, an approval path, and a way to override, suspend, or deactivate it before launch. Accountability cannot be delegated to software. If an AI agent can take an action, someone has to own the authority behind that action.
- Validate with effective challenge, then monitor.
The banking concept that transfers cleanly is effective challenge: independent review with enough authority to question the output, not simply admire the system. For GenAI and agentic workflows, that also means post-launch monitoring for drift, over-reliance, automation bias, and exception handling.
This is where banking's old discipline becomes useful again. Not because it solves AI risk by default, but because it teaches leaders to ask the right questions before scale:
What decision is this AI influencing? Who is accountable when it is wrong? How do we stop it? Who can challenge it? What do we monitor after launch?
The winners in regulated AI will not be the companies that choose speed over control. They will be the ones that learn how to make control part of speed.
Where are you seeing this show up in your organization: experimentation, governance, data readiness, or scaling?
Prefer LinkedIn? Join the discussion on the original post.
