Platform Platform
System
ConceptsEnginePolicy as codeDeclarationsSafe changeGatewaysIntegrationsObservabilityAdministrationSecurityHuman reviewAudit and evidenceData retentionSecrets and data classification
Controls
Registries and documentationAuthentication and authorizationInjection detectionData redactionCode fingerprintingRole and judge checksContent classificationSpend and loop limitsBusiness rules
Solutions Solutions
By what you do
Sell into the enterpriseControl the AI you run
By industry
Financial servicesDigital assetsInsuranceHealthcareLegalUser-generated content
By discipline
AI governanceTrust and safetyRisk and compliance
Cases Cases Embedded control planeSource-code leakTrading agents over MCPLive firehoseRefund assistant
Compare Compare LiteLLMNVIDIA NeMo GuardrailsOPAROOSTAgent Governance Toolkit
Resources Resources
Guides
Enterprise review questionsPrompt injectionAgent and control layerAgent architecturesDecision system mapAI control maturity model
Standards
Standards OWASP Agent Control StandardEU AI ActPMI AI standardNIST AI RMFERC-8004
Book a demo
Resources · Guides

Agent layer vs control layer

SR 26-2, the revised model-risk guidance the Federal Reserve issued on April 17, 2026, supersedes SR 11-7 and SR 21-8 and puts generative and agentic AI out of scope. It calls them "novel and rapidly evolving" and states in footnote 3 that they "are not within the scope of this guidance".

The same footnote hands the problem back: a bank's own practices "should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document."

The regulator paused. The expectation did not.

This page reads SR 26-2 the way a builder does, not a compliance expert: it shows how its expectations apply to AI agents. Source: Federal Reserve SR 26-2 (the gen-AI exclusion is in the attached guidance).

One set of expectations, two layers

SR 26-2's expectations group into roughly four areas: model development and use, validation and monitoring, governance and controls, and vendor products. For a statistical model they apply in one place. For an AI agent that takes actions, the same expectations split across two layers that have to stay separate.

The two layers

Agent layer
what the agent is and does
  • Versioned model, prompt, tools, and memory
  • Pre-deployment evaluation and red-teaming
  • Drift and behavior monitoring
  • Documentation of model behavior and limits
  • Owned by the ML / AI platform team
Control layer Swiftward
what the agent is allowed to do
  • Action grants: which tools, which data, which value thresholds
  • Versioned policies with controlled rollout, and rollback by naming the previous version
  • A decision record naming the policy version and the inputs it read
  • Materiality-based human escalation
  • Owned by risk and policy, with rollback authority

Why they have to be separate

The two layers change at different times, have different owners and use different tools. Mix them, and you cannot change a policy without redeploying the agent, you cannot say from the record which policy version produced a disputed decision, and you cannot give the risk team controls it owns separately from the platform team.

Where Swiftward sits

Most banks already have the agent layer through a cloud model platform or an in-house stack. The control layer usually exists only in pieces: rules buried in application code, action limits hardcoded, audit logs that reference no policy version. Swiftward is that control layer, built as one product: action grants, versioned policy with rollback, a decision record per event, and escalation to a person when the stakes are high enough, on infrastructure you run. Risk and compliance.

Book a demo