
A bank evaluating an AI employee for KYC, sanctions screening, or chargeback handling is not asking a product question. It is asking a supervisory one: what happens the first time an examiner asks who approved this decision, and how do you show your work. That question separates AI employees that can run inside a regulated bank from the ones that can only run in a demo.
This guide covers the US rules that actually govern AI employees in banking and financial services: the federal banking agencies' 2026 overhaul of model risk management guidance, the Bank Secrecy Act and FinCEN's Customer Due Diligence Rule, the Gramm-Leach-Bliley Act's data safeguards, third-party risk management expectations, and how sanctions screening, trade finance, and chargeback decisioning fit into all of it. It also covers what to check for when a vendor's AI employee is going to sit inside your bank's regulated processes.
Most companies adopting AI worry about accuracy and cost. Banks worry about those too, but they also answer to examiners who can require a bank to unwind a program, file a corrective action plan, or hold more capital against a process they consider poorly controlled. A chargeback decision, a sanctions match disposition, or a customer risk rating is not just an operational output. It is evidence in an exam file, and it stays evidence for as long as regulators can ask about it.
That changes what good AI means in a bank. A model that is 95% accurate but cannot explain the other 5% is a liability, not a win, because the bank still has to answer for every one of those cases individually if a regulator asks. The requirement is not just performance. It is explainability, a record of who approved what and when, and a designated human who owns the outcome. A vendor pitching raw accuracy numbers without addressing any of that is pitching the wrong bank.
For fifteen years, model risk in US banking meant one document: the Federal Reserve, OCC, and FDIC's 2011 Supervisory Guidance on Model Risk Management, known industry-wide as SR 11-7. It set the rules for how banks validate, monitor, and govern any model used in a business decision, and examiners have graded banks against it ever since.
That changed on April 17, 2026. The three federal banking agencies replaced most of SR 11-7 with new interagency guidance: Federal Reserve SR 26-2, OCC Bulletin 2026-13, and FDIC FIL-15-2026. The new guidance keeps the core disciplines banks already know: independent validation, ongoing monitoring, governance, and effective challenge. What changed is the boundary around what counts as a model in the first place. SR 26-2 takes a more risk-based, materiality-sensitive approach, so a bank spends its formal validation effort on the things that actually carry risk rather than treating every spreadsheet the same way it treats a credit scoring engine.
The detail that matters most for an AI employee doing KYC or sanctions work is this: SR 26-2 explicitly excludes generative AI and agentic AI from its formal scope. The agencies consider both categories too new and too fast-moving to fit inside a validation framework built around static, versioned models. A joint interagency Request for Information on generative and agentic AI is already planned, which signals formal rules are coming, just not yet.
That exclusion is not the same as an exemption. An agentic system that chains several steps together, where one agent's output becomes the next agent's input, carries a real risk of compounding errors that a single-step model never had. Examiners are watching that risk closely even without a formal rule requiring them to. In practice, a bank deploying an AI employee for a regulated process sits in an in-between zone right now: not yet bound by SR 26-2's formal validation requirements, but still expected to show the governance discipline the guidance was written to enforce. The safer assumption is that formal coverage is a matter of when, not if, and building the audit trail now costs far less than retrofitting one after the rule lands.
This is where deployment architecture becomes a compliance decision, not just a technical one. An AI employee built around an Agent Operating Procedure, a documented set of tolerances, approval thresholds, and escalation rules that a compliance officer can read and adjust directly, gives a bank something concrete to hand an examiner today, ahead of any formal requirement to do so. A black-box agent whose logic lives only inside a prompt has nothing to show once the RFI turns into a rule, and by then the gap is expensive to close.
The Bank Secrecy Act and FinCEN's Customer Due Diligence Rule do not care whether a human or an AI agent performs the work. A bank still has to verify customer identity, identify beneficial owners of legal-entity customers, understand the nature of the customer relationship, and monitor for suspicious activity closely enough to file a Suspicious Activity Report when the facts call for it. None of those obligations shift to a vendor because the vendor's software did the underlying work.
What automation changes is throughput and consistency, not the underlying legal duty. An AI employee handling onboarding can pull identity documents, cross-reference beneficial ownership structures, and flag inconsistencies faster than a manual analyst working through a queue. It can also apply the same risk-rating logic to every applicant instead of the variance that creeps in when different analysts interpret the same policy differently on a busy Friday. See our KYC automation guide for how that onboarding workflow runs end to end.
The part banks tend to get wrong is treating the AI's output as the final answer instead of as a recommendation with evidence attached. A defensible setup keeps a named compliance officer as the approver of record for anything above a low-risk threshold, with the AI employee assembling the file rather than closing the case. That distinction, recommend versus decide, is often what separates a program an examiner accepts from one they flag.
Sanctions screening against OFAC lists and transaction monitoring for suspicious patterns sit at the highest-consequence end of bank compliance work, because a missed true positive can mean a bank processed a payment for a sanctioned party. An AI employee working this queue has to do two things at once: reduce the false-positive rate that buries analysts in irrelevant alerts, and never quietly suppress a genuine hit to hit that goal.
The design pattern that works is the same one as KYC: the agent triages, scores, and assembles evidence, but escalation to a human reviewer happens automatically once confidence drops below a set threshold, and every disposition, cleared or escalated, gets logged with the reasoning behind it. That log is what turns a sanctions program from a black box into something a bank can defend during an exam. Our guide to AI agents in financial crime investigations goes deeper into how that evidence-gathering works case by case.
The Gramm-Leach-Bliley Act's Safeguards Rule requires financial institutions to protect customer financial data with a written information security program, and that requirement extends to any vendor or system that touches the data, AI included. An AI employee that reads account records, transaction history, or identity documents to do its job is processing exactly the data GLBA is written to protect.
Separately, the federal banking agencies' interagency guidance on third-party relationships applies to any AI vendor the same way it applies to a core banking processor: due diligence before onboarding, contract terms that preserve the bank's ability to audit and terminate, and ongoing monitoring for the life of the relationship. An AI vendor that cannot answer basic third-party risk questions, where data lives, who can access it, what happens on termination, is going to stall in procurement regardless of how good the model is.
For a bank vetting an AI vendor, both of these rules turn into the same practical question: where does the model run, where is the data stored, and who else can see it. That is why deployment model matters as much as accuracy. An AI employee that can run on-prem, inside a dedicated multi-tenant environment, or fully inside the bank's own cloud under the bank's own security controls gives a compliance team an answer to the GLBA and third-party risk questions that a single fixed SaaS deployment cannot.
Chargeback and dispute handling looks like an operational workflow, but for consumer accounts it runs inside a regulatory framework too, governed by card network rules and, depending on the payment type, consumer protection regulations that set specific timelines and documentation standards for how a dispute gets investigated and resolved. Missing a deadline or mishandling documentation is not just a lost dispute. It can be a compliance finding.
An AI employee working chargebacks has to hit the same procedural requirements a human analyst does: gather the transaction evidence, apply the right dispute reason code, meet the response window, and produce a record showing why a case was resolved the way it was. See our chargeback automation guide for the mechanics of that evidence assembly and representment process.
Trade finance operations, letter-of-credit review, document checking against UCP 600 standards, sanctions screening on counterparties and vessels, run on a different rhythm than KYC or chargebacks, but they carry the same governance requirements. A discrepancy in a bill of lading or a screening miss on a shipping counterparty has the same regulatory weight as a missed sanctions hit anywhere else in the bank. An AI employee handling trade document review needs the same audit trail and human escalation path as one handling onboarding, even though the documents look completely different.
Most vendor demos look similar. The differences that matter to an examiner show up when you ask about governance, not features. A short list worth working through before signing anything:
This is the model Zamp builds to. Every AI employee runs against an Agent Operating Procedure that a process owner controls directly, carries a full decision audit trail on every action, and deploys on-prem, multi-tenant, or inside your own cloud depending on what your compliance function requires. That combination is what lets a bank put an AI employee into a regulated process today, ahead of whatever formal rule eventually comes out of the pending interagency review of agentic AI. Our guide to AI employees in banking and financial services covers how KYC, sanctions screening, chargebacks, and trade finance fit together as a single connected back office rather than four separate point tools.
The rules covered here govern how AI employees handle regulated financial decisions specifically. If your bank is also using AI in hiring or other HR decisions, a separate set of US employment law requirements applies, state hiring-disclosure laws and federal anti-discrimination rules chief among them. Our guide to AI employee laws across the US covers that ground.