Three regulators, three jurisdictions, one governance mandate for boards on AI risk

The Governance Mandate Extends to AI: The Deadline Moved. The Expectation Did Not.

August 29, 2026•10 min read

TL;DR

In July 2026, the EU's Digital Omnibus moved the AI Act's high-risk obligations for credit scoring and insurance pricing from August 2026 to 2 December 2027. The governance expectation did not move. The Financial Stability Board's June 2026 Sound Practices consultation places AI direction and oversight with the board and senior management, and US regulators, including the OCC and Treasury, expect AI risk to sit inside existing risk frameworks rather than beside them. The extra time is a window to build governance evidence, not permission to wait.

AI governance is now judged on documented evidence, not stated intent.

Regulators who spent three years telling boards to own climate risk have now told them, almost verbatim, to own AI risk too. And something happened this summer that most boards have not yet fully absorbed: Brussels moved the deadline, and the expectation stayed exactly where it was.

In July 2026, the EU's Digital Omnibus on AI moved the AI Act's high-risk obligations for stand-alone systems, including creditworthiness assessment and life and health insurance pricing, from 2 August 2026 to 2 December 2027. A few weeks earlier, the Financial Stability Board consulted on Sound Practices for Responsible AI Adoption, which places responsibility for the direction and oversight of AI adoption with the board and senior management. In the United States, the OCC's May 2026 Semiannual Risk Perspective flagged explainability, data integrity, and validation gaps as live supervisory concerns, and the Treasury has since published coordinated guidance instructing institutions to fold AI risk into existing risk and compliance frameworks, not treat it as a technology side-project.

None of these bodies coordinated with each other. All of them arrived, within months, at the same conclusion. That is not a coincidence. It is what happens when a risk moves from experimental to structural faster than governance models can absorb it.

Who this is really about

When I refer to mid-tier firms, I mean institutions below the largest global banks but well above community-bank scale: Category III and IV banks and the larger regionals in the US, and Less Significant Institutions and mid-cap and challenger banks in Europe. Comparable insurers and asset managers sit in the same position.

These institutions are large enough to use AI meaningfully in credit, underwriting, claims, and customer-facing decisions, and large enough to attract real supervisory and investor scrutiny, but rarely resourced like a G-SIB or a Big Tech platform. That is precisely the population now caught in the most awkward position on AI governance.

What moved, and what did not

The EU AI Act's timeline has been running since 2024, and 2 August 2026 was meant to be the date that mattered for financial institutions. The Digital Omnibus, in force since 27 July 2026, moved the high-risk obligations to 2 December 2027. What did not move: the AI literacy duty that has applied since February 2025, the prohibited practices, the transparency obligations, and the classification itself. By December 2027, firms must be able to identify where AI is in use across the enterprise, classify each system against the Act's risk tiers, and apply governance controls proportionate to that classification. Sixteen extra months is not relief. It is roughly the time a mid-tier institution needs to build an evidence set it cannot assemble in a single quarter.

AI systems used in creditworthiness assessment and credit scoring remain explicitly designated high-risk. High-risk status is not a ban. It is a requirement to produce a specific evidence set: a system inventory, documented risk classifications, assigned ownership, technical and functional documentation, decision traceability, human oversight arrangements, robustness testing, and continuous monitoring.

The Act does not ask whether a firm has good intentions about AI. It asks whether a firm can produce the paperwork proving control.

The FSB's Sound Practices are nonbinding, but they distill what leading supervisors are already converging on. Boards approve the AI strategy and set risk appetite. Institutions allocate clear accountability across business, technology, legal, compliance, risk, and audit, not a single technology function. AI risk is folded into the existing ERM framework through a centralized inventory, formal approval gates, and lifecycle tracking. Human oversight, including override and kill-switch capability, is calibrated to how material, autonomous, and explainable a given AI use case actually is.

The US picture diverges sharply from the climate story. On climate, Washington stepped back. On AI, Washington has stepped in. The OCC, FDIC, and Federal Reserve have signaled a forthcoming request for information on AI model risk management. Treasury's six coordinated deliverables, covering AI risk taxonomy, identity protection, explainability, data quality, and fraud prevention, all point in the same direction: AI risk gets embedded into existing frameworks, with documented, tested, provable oversight.

Three regulatory bodies. Three jurisdictions. No coordination. One governance mandate.

Governance evidence, not governance language

Most institutions using AI in credit, underwriting, claims triage, or customer service can describe what they are doing. Fewer can produce the governance evidence a supervisor or investor will actually ask for. AI has been discussed at committee level, piloted in a few business units, and wrapped in a policy document. It has not always been built into the place where the institution actually governs risk.

A model inventory is not governance. A responsible-AI policy is not governance. A statement that "the AI Committee reviewed this" is not governance unless it comes with a record of what was reviewed, what was challenged, and what changed. Naming a committee is not the same discipline as proving, on demand, that the committee's decisions hold up.

The timeline compounds the problem. A climate governance gap can sit unaddressed for a supervisory cycle before it surfaces. An AI governance gap does not get that grace period: new model capabilities, new supervisory guidance, and new attack techniques move on a scale of months, and an institution that treats its AI governance the way it once treated a slow-moving policy update will find the gap has widened by the time anyone checks on it again.

A lending model, walked through

Consider a mid-tier bank using a third-party AI model to support unsecured consumer lending decisions, layered on top of its existing credit scorecard. The vendor's marketing is confident. The pilot results look strong. Approval rates improve, and the credit team is pleased with the lift.

Now ask the governance questions. Was the model classified against the EU AI Act's risk tiers before deployment? Who, by name, owns the model at executive and board level, and is that ownership recorded anywhere a supervisor could find it? Was there a documented fair-lending and disparate-impact review, or only a vendor assurance that the model was "tested for bias"? Can the bank explain, to an individual declined applicant and to a regulator, why the model reached its decision? Is there a human in the loop with real authority to override the model, or only a nominal review step that never actually overturns an output?

In many mid-tier firms, the honest answer to most of these questions is no. Not because anyone was careless, but because the model was governed as a technology deployment rather than as a credit decision. That is not an IT failure. It is a credit governance failure wearing an AI label.

And it is exactly the kind of failure that surfaces in a fair-lending exam, an EU AI Act conformity assessment, or a plaintiff's discovery request, months or years after the model went live.

The ARCHITECT™ Governance System, applied to AI

I developed the ARCHITECT™ Governance System to assess governance maturity on climate and sustainability risk. The same six pillars apply to AI risk with almost no translation required, because the underlying discipline, not the subject matter, is what regulators are actually testing. Naming that discipline is the easy part. It only means something once each pillar is translated on its own terms, not asserted in a single sentence.

Accountability: named executive and board-level owners for each AI system, with clear roles and escalation routes across the Three Lines of Defense.

Risk Integration: AI risk embedded in the principal risk taxonomy and ERM framework, with formal approval gates and lifecycle tracking, not a parallel technology process.

Capital Exposure: clear translation of AI-driven decisions and AI failure modes into financial effect: credit loss, conduct risk, litigation exposure, regulatory penalty.

Horizon Scanning: a disciplined process for tracking fast-moving risks: new model capabilities, new supervisory guidance, new attack techniques, new peer findings.

Information and Reporting: board reporting that enables real challenge: a live system inventory, risk classifications, oversight evidence, not narrative updates that create the appearance of control.

Transparency and Defensibility: documented decision traceability, human oversight, and evidence that would hold up under an EU AI Act conformity review, a fair-lending exam, or investor due diligence.

The aim is the same as it is on climate: move the risk out of the margins of a technology function and into the operating core of the institution, where it can actually be governed.

Mid-tier firms cannot outsource this to the vendor

Proportionality is real. A mid-tier bank does not need the AI governance infrastructure of a G-SIB. But proportionality is not a reason to treat a vendor's AI model as someone else's governance problem.

Under the EU AI Act, under the FSB's Sound Practices, and under emerging US supervisory expectations, the deploying institution owns the governance obligation regardless of who built the model. Vendor assurance is an input. It is not an outcome.

This is the same mistake mid-tier firms made on climate when they assumed a strong disclosure report satisfied a governance expectation it was never designed to meet. The lesson is worth applying here, before the same gap is discovered the expensive way.

Before the next Risk Committee meeting

  1. Do we have a single, current inventory of every AI system in production, including vendor models, with a documented risk classification for each?

  2. Who, by name, owns each of those systems at executive and board level?

  3. Is AI risk inside our principal risk taxonomy and ERM framework, or is it still reported through a separate technology or innovation committee?

  4. Could we produce documented evidence of human oversight and challenge on a specific AI-driven decision?

  5. If a supervisor, an EU AI Act assessor, or an investor asked for our AI governance evidence tomorrow, would we be proud of what we handed over?

If those questions produce hesitation, the governance gap is already there.

Closing

Governance does not distinguish neatly between risk categories. A board that has spent the last several years building the discipline to govern climate and sustainability risk already has most of the muscle it needs for AI: named accountability, integration into core risk frameworks, defensible documentation, real challenge.

What changes with AI is the clock speed. The institutions that recognize early that this is the same governance question, arriving faster and with less patience for delay, will handle this cycle from a position of strength. The ones that wait for a supervisor, a plaintiff, or an investor to ask first will be doing the same work later, under pressure, in front of an audience.

Not sure how your AI governance would stand up under an EU AI Act conformity review, a supervisory exam, or investor due diligence? The ARCHITECT™ AI Governance Maturity Assessment gives mid-tier financial institutions a practical starting point. Over two to three weeks, it shows where AI governance is strong, where it is exposed, and what needs to change.

Start the AI Governance Maturity Assessment →

Sources

  1. Regulation (EU) 2026/1744, Digital Omnibus on AI (Official Journal, July 2026)

  2. Regulation (EU) 2024/1689, the EU AI Act

  3. Financial Stability Board, Sound Practices for Responsible Adoption of AI, consultation report (June 2026)

  4. OCC, Semiannual Risk Perspective, Spring 2026

  5. Grant Thornton, Treasury guidance brings urgency to AI governance (2026)

Author bio

Brendan Walsh is the founder of Walsh SRA and creator of the ARCHITECT™ Governance System. He brings more than 30 years of global executive leadership at American Express across the US, Europe and Asia, including as Chairman of American Express Services Europe and American Express Bank Russia. He has served as a Board Advisor to OFGEM, the UK energy regulator, and as a Board Member of the ECB's Euro Retail Payments Board. He holds a Master's in Sustainability from Harvard and GARP certifications in Sustainability & Climate Risk and AI Risk. Walsh SRA advises mid-tier banks, insurers, asset managers and private equity firms on governance for climate, sustainability and AI risk.

Back to Blog