Summary
MAS SAFR is the first framework specifically designed for AI agents that can take action (not just recommend). It differs fundamentally from the EU AI Act (prescriptive, risk-tiered, applies to all sectors) and OCC SR 11-7 (model risk management for statistical models, excludes GenAI/agentic AI). SAFR focuses on runtime governance — checking identity, authority, controls, and risk thresholds before each action executes. The EU AI Act's high-risk obligations take effect August 2, 2026; OCC updated SR 11-7 in April 2026 but explicitly excluded GenAI and agentic AI.
Key Points
- SAFR: runtime governance for AI agents — checks identity, authority, controls, risk thresholds before execution
- Four components: agent identity, controls repository, disposition engine, audit log (tamper-evident)
- Disposition: approve, reject, human review, or flag for monitoring
- EU AI Act: prescriptive four-tier system (Prohibited/High/Limited/Minimal risk); high-risk AI in finance faces conformity assessments, technical documentation, human oversight
- EU AI Act penalties: up to €35M or 7% of global turnover (prohibited AI)
- OCC SR 11-7 (updated April 2026): explicitly excluded GenAI and agentic AI from scope — separate RFI planned
- MAS AIRG: principles-based, proportionate to materiality — board-level accountability, explainability of material outputs
- Key gap: EU AI Act covers ~80% of what mature SR 11-7 programs already do; remaining 20% (FRIA, EU database registration, transparency obligations) is new
- Banks with mature MRM programs have structural advantage — extending existing governance rather than building parallel structures