State Bank Examiners Wrote the Kill-Switch Rule Federal AI Guidance Skipped · Enterprise Agentic AI Insights
CSBS published an AI examination framework covering 79 percent of FDIC-insured banks on Sept 16, 2026, requiring agentic AI kill-switch documentation that federal guidance (SR 26-2) left out of scope.
One week ago, federal bank regulators told examiners not to look yet. On September 16, state examiners looked anyway. Here is what actually happened. On April 17, 2026, the OCC, the Federal Reserve, and the FDIC jointly issued SR 26-2, revised model risk management guidance. One line inside it excluded generative and agentic AI, calling both "novel and rapidly evolving" and, as a result, "not within the scope of this guidance." No enforceable federal standard for autonomous AI systems in banking existed as of that date. Nine days into Dreamforce week, with Salesforce spending three days at Moscone Center building a case for agent governance as infrastructure, the Conference of State Bank Supervisors published something federal guidance had not: an actual examination requirement for autonomous AI, on September 16, 2026, the middle day of that same event. State regulators supervise 3,355 of the 4,233 FDIC-insured banks in the United States, 79 percent of the total, spanning $360 million community banks up to Goldman Sachs Bank USA's $758.8 billion in assets. CSBS published five documents: a core examiner guide, a 28-page work program, a nonbank supplement, a risk-tiering worksheet, and source materials documentation. Examiners start with eight questions: does the bank use AI, where, does it touch customers or shape decisions, do vendors supply it, is generative AI in use, how are risks categorized, and where does sensitive data flow. For autonomous systems specifically, the framework requires banks to document five things: permissible actions the system may take, human intervention checkpoints, system logging, action reversibility, and the ability to restrict or halt operations. That last item is the one federal guidance left unaddressed five months earlier. Each AI use case gets a risk tier from one to three based on consumer impact, oversight, potential harm, and data sensitivity. Tier three, the highest, requires independent model validation and an AI-specific incident response plan. A Wolters Kluwer survey of 230 bankers found 72 percent report being least prepared for exactly this: kill-switch protocols and regulatory AI failure reporting. The requirement landed on the group least ready to meet it. Meanwhile at Moscone Center, the pre-event materials for Dreamforce's "Agentic Enterprise" push carried no customer-reported ROI figures, no adoption numbers, and no published production cost data for Agentforce, a gap one trade outlet covering the event summarized this way: if the keynote cannot explain the audit trail, the rollout stays in pilot purgatory. Two facts, both true at the same time. Federal examiners are not yet grading agentic AI. State examiners, covering four out of five FDIC-insured banks, started grading it nine days ago, on a rubric with a named kill-switch requirement most banks admit they cannot yet meet. Which leaves the same question this column asked a week ago, now with a deadline attached. Not whether your vendor published a trust boundary or an agent governance framework. Whether you can name the person who halts your own autonomous system, show the logging that proves it works, and produce that answer for a state examiner who may already be asking.