Federal regulators’ decision to exclude generative and agentic AI from updated guidance on testing automated models has created a dilemma for banks that still lack a clear roadmap for testing the tools in fraud investigations.
Azba Habib, chief compliance officer at Column, said banks should hold AI agents to the same standard as human investigators. The test would be whether the agent followed the right process and reached a defensible conclusion, rather than requiring the same result every time.
“I’m operating in a world in which the most consequential technology in my space is completely outside the framework that’s designed to govern that technology,” Habib said during a panel at the FinovateFall conference in New York last week.
The OCC, Federal Reserve and FDIC issued new guidance in April to help banks manage the risk that models produce flawed results. It covers how banks develop, test and validate traditional models. It excludes generative and agentic AI because the technologies are considered “novel and rapidly evolving.” The agencies plan to seek industry input on how those tools should be treated.
The traditional approach to testing models puts too much weight on reproducibility, Habib argued.
“It's really a focus not on explainability as this amorphous term that gets thrown around in the industry, but really around transparency of what we're building and defensibility of what we're building, because that's how we validate humans, and I don't think the framework's that different for agents,” she said.
Habib said a bank could give an AI agent the same checklist used by human investigators, then periodically review its work to ensure it followed the right process.
Fraudsters and Fraud Teams Are Both Using AI
Banks need to know whether AI fraud investigators can be trusted, especially as fraudsters use the same technology to create convincing fake identities.
Allison Watson, a product manager working on fraud and onboarding products at Plaid, said deepfakes (including synthetic selfies) and fraudulent identity documents are becoming more difficult to spot. She added that the industry also needs to distinguish AI agents acting on behalf of legitimate customers from malware controlled by fraudsters.
“How do I make sure that that’s actually an agent that’s authorized to do that, and not some malware or some fraudster?” Watson said. “I don’t know that the industry has really figured it out yet.”
Andrew Endicott, co-founder and general partner at Gilgamesh Ventures, said AI lets financial institutions respond to more fraud threats at once, but experienced people still need to direct the work.
“You still need someone really smart with a lot of domain expertise to play quarterback,” Endicott said.
(Disclosure: Plaid is the parent company of This Week in Fintech; it has no say in our editorial process.)


