Canada’s federal banking regulator has published an unusually concrete control list for generative and agentic AI, moving the conversation from broad principles to the mechanics of identity, permissions, data, software changes and incident response.
The Office of the Superintendent of Financial Institutions bulletin, dated July 2026 and modified July 13, says AI can increase the speed, scale and automation of cyber and operational risks. It also warns that autonomous systems may turn an inaccurate model output into an unvalidated downstream action.
Reuters reported July 13 that OSFI had separately warned major Canadian banks and insurers that frontier models may accelerate attacks and shrink the time available to find and patch weaknesses in legacy systems.
A control list, not a new rule
OSFI describes its technology bulletins as sound practices, not regulatory expectations. The document applies to Canada’s federally regulated financial institutions and aligns its recommendations with existing Canadian guidance on technology, operational resilience and third-party risk.
That distinction matters for U.S. credit unions: this is not a new NCUA requirement. But the controls are specific enough to serve as a practical benchmark for boards, technology teams and vendor managers already deciding where agents may act.
OSFI says institutions should assign each agent a unique non-human identity, apply least privilege, scope permissions and use just-in-time access with short-lived credentials. It also recommends tool allow-lists, API gateways and approval checkpoints for high-impact actions, plus logging and periodic access recertification.
Those measures extend the identity model already familiar to cybersecurity teams. A credit union should be able to answer who owns an agent, which systems and data it can reach, which actions require a person, and how its access can be suspended without disabling an entire workflow.
The vendor questions become operational
The bulletin also tells institutions to map internal and external AI dependencies to critical operations, test outage scenarios, maintain manual fallbacks, assess portability and require third parties to disclose how they use AI in service delivery.
For credit unions, that turns AI oversight into contract work. Core, digital-banking, contact-center, lending and fraud vendors should identify embedded models, subprocessors, APIs and agent permissions. Contracts should cover material model or tool changes, incident notification, audit evidence, continuity procedures and data handling in prompts, outputs and logs. Our AI vendor due-diligence checklist provides a starting structure.
OSFI also recommends treating AI output as an input to a decision rather than a definitive outcome. Material or high-impact decisions should retain accountable human oversight and auditable documentation. That is especially relevant when agents support lending, disputes, fraud holds or member communications, where a plausible but wrong output can quickly become a member-impacting action.
What credit unions should do now
A useful first step is to select one live or planned AI workflow and document five things: its named business owner, non-human identity, approved tools and data, human approval boundary, and manual fallback. Then run an incident exercise covering prompt injection, sensitive-data leakage or an unavailable third-party model.
Security teams should also feed agent activity into existing monitoring, while change-management teams review model, prompt, data-source and tool updates as controlled technology changes. AI-generated code should pass the same vulnerability checks and production approvals as human-written code.
OSFI’s message complements the broader shift described in our coverage of banks moving AI agents into daily operations. The competitive question is no longer only whether to deploy agents. It is whether the institution can identify, constrain, monitor and recover from them as reliably as any other privileged operator.