The agentic AI regulatory map is mostly blank — and one set of supervisors said so
Across healthcare, banking, ecommerce and platforms, only two bodies have published anything agent-specific: FINRA's 2026 oversight report names agents acting beyond delegated scope, and the FSB's June 2026 consultation carries a seven-category agentic risk taxonomy that names memory poisoning outright. US federal banking supervisors went the other way, expressly excluding generative and agentic AI from April 2026 model risk guidance. Healthcare rules cover AI but never mention agents. If you are building agentic systems in a regulated sector, you are deriving your controls from first principles, and you should know that rather than assume a framework exists.
I set out to map how the agentic threat model changes across regulated sectors — healthcare, banking, ecommerce, platforms — expecting to find four sets of constraints and write them up.
The map is nearly empty. Two bodies have published anything agent-specific. One set of supervisors looked at agentic AI and explicitly wrote it out of scope.
That absence is more useful to know than a tidy compliance table would have been, because it tells you what you are actually standing on when you ship an agent into a regulated environment.
What exists, and what doesn’t
FINRA: excessive agency, in regulator language
FINRA’s 2026 Annual Regulatory Oversight Report defines the thing directly:
AI agents are systems or programs that are capable of autonomously performing and completing tasks on behalf of a user. An AI agent can interact within an environment, plan, make decisions and take action to achieve specific goals without predefined rules or logic programming.
A subsection headed Emerging Trends in GenAI: Agents then carries risks that only exist because of autonomy. The first one should be familiar to anyone who has read OWASP’s taxonomy:
Agents may act beyond the user’s actual or intended scope and authority.
That is excessive agency, written by a securities regulator. It sits alongside agents “acting autonomously without human validation and approval”, and the observation that “complicated, multi-step agent reasoning tasks can make outcomes difficult to trace or explain, complicating auditability.”
The supervisory considerations read like a control list: human-in-the-loop protocols, tracking agent actions and decisions, guardrails limiting agent behaviours, monitoring agent system access and data handling.
Two things to be precise about. The Annual Regulatory Oversight Report is an observations and effective practices document, not a rule — FINRA states its existing rules are technology-neutral and continue to apply, so this creates no new obligations. And agents appear as a subsection inside the GenAI section, not as a standalone category. It is the clearest regulatory articulation of agent risk currently available, and it is still guidance about how existing rules land.
FSB: autonomy as the risk generator
The Financial Stability Board’s June 2026 consultation report is the only structured agentic taxonomy found. The section heading is simply Agentic AI risks, and the lead-in is the thesis:
The high levels of autonomy that AI agents may have can create or amplify certain risks, which can materialise at great speed, including:
Seven categories follow: unauthorised actions, erroneous actions, data breaches, disruption to connected systems, additional risks from inadequate human oversight, additional data security and privacy risks, and additional cyber and ICT risks that challenge traditional controls.
Two passages are worth reading closely. On unauthorised actions:
They can also dynamically set or modify their objectives based on what they learn from interacting with their external environments… Overriding, redressing, or remediating these actions can be difficult or impossible for humans.
And under cyber risk, the FSB names the attack directly: threat actors can manipulate AI agents by injecting malicious data into their knowledge base — memory poisoning, in a financial stability document.
That is the same failure mode OWASP files as T1 and ATLAS covers under context poisoning. When a standards body, an adversary knowledge base and a financial regulator independently converge on the same mechanism, it has stopped being a research topic.
Banking: the gap is on the record
The most striking finding is an absence that was deliberately created.
The April 2026 revised interagency model risk management guidance expressly places generative and agentic AI outside its scope, committing only to a future request for information.
Read that as a practitioner rather than a compliance reader. Model risk management is the framework US banking supervision would naturally reach for to govern an agentic system. The supervisors looked at it, decided the existing framework did not fit, and said so — leaving an acknowledged, currently unfilled gap.
If you are deploying agents in a US bank, there is no supervisory framework purpose-built for what you are doing, and the regulators have put that in writing. That is useful to know before someone assures a risk committee that model risk management covers it.
Healthcare: in scope by inheritance, not by design
HIPAA’s position is coverage without recognition.
The proposed Security Rule update brings AI squarely inside scope — ePHI in AI training data, prediction models and algorithm data maintained for covered functions is protected, and AI software touching or trained on ePHI must appear in the proposed written technology asset inventory.
But the proposal never mentions agentic systems, tool invocation or agent memory. Not once.
Coverage is inherited through a definition rather than designed for the architecture. The AI definition HHS recites — from the FY2019 NDAA — is textually broad enough to catch agents:
an intelligent software agent… that achieves goals using perception, planning, reasoning, learning, communicating, decision making, and acting
along with systems performing tasks “without significant human oversight”. Your agent is regulated. The regulation was not written with it in mind.
The FDA position is narrower still. Jurisdiction is scoped by function, not autonomy — the trigger is an AI-enabled device software function meeting the FD&C Act 201(h) device definition, so an agentic clinical system is regulated only where a specific function qualifies. The January 2025 draft guidance enumerates a genuine AI threat taxonomy — data poisoning, model inversion and stealing, evasion, data leakage, deliberate overfitting, training-time backdoors, performance drift — tied to section 524B cyber device obligations.
All of it is model-level. A full-text search of the 67-page draft returns zero occurrences of agentic, generative, large language model, memory, prompt, retrieval or foundation model.
One tempting bridge does not hold up. It would be elegant if HIPAA’s minimum necessary standard applied to agent retrieval scope, or if business associate status functioned as a runtime check on tool invocation. No primary-source evidence supports either. Those are good architectural ideas; they are not current regulatory positions, and presenting them as such would be inventing authority.
The four blanks
For ecommerce and payments, social media and platforms, the cross-cutting instruments, and documented real-world incidents, this research surfaced no primary-source evidence at all.
Not thin evidence. None that survived verification.
There is abundant secondary material asserting that PCI DSS, the DSA or the EU AI Act change your agentic threat model. What is missing is any primary instrument establishing how — agent-specific scoping for cardholder data, card scheme rules for delegated checkout, platform policy on automated agent accounts, or an AI Act classification analysis that turns on autonomy.
Treat confident claims in those areas as derived rather than cited, including mine.
What to do with an empty map
If you build agentic systems in a regulated sector, three things follow.
Stop waiting for the framework. For most sectors it does not exist, and in US banking the supervisors have said it does not exist. Your controls come from the architecture, not the rulebook — the six trust boundaries are a better starting point than a compliance matrix.
Borrow across sectors. The FSB’s seven categories and FINRA’s failure modes are not jurisdiction-bound observations about securities and stability — they are observations about autonomy. A healthcare agent exhibits the same scope-and-authority failure FINRA describes. Nothing stops you using the clearest available articulation regardless of which regulator wrote it.
Write down what you derived. When the guidance arrives — and the promised RFI says it will — the organisations that can show a reasoned threat model will be in a much better position than those who waited. Documented first-principles reasoning is defensible. Silence is not.
The regulatory map being blank is not a reprieve. It means the burden of defining adequate control sits with you, and that the written record of how you reasoned is doing the work a framework would otherwise do.
Method and limits. This surveys primary sources — regulators, supervisory authorities and standards bodies — and reports absence as absence rather than substituting vendor or consultancy material. Claims were verified adversarially; several plausible-sounding ones did not survive and are excluded, including a specific attribution of the model-risk exclusion to named agencies, a books-and-records obligation inferred from FINRA's traceability discussion, and specific FSB supervisory expectations such as value thresholds for human approval. The FSB taxonomy is in the consultation PDF, not the landing page. FINRA's report is observations and effective practices, not a rule. The HHS Security Rule update was a proposal at the time of writing. "No evidence found" means this survey did not surface it, not that it cannot exist — if you have primary sources for the four blank areas, I would genuinely like to see them.