The Financial Stability Board has proposed twelve sound practices for responsible AI adoption in finance, and its toolkit says plainly that autonomous agents "pose a distinct challenge for human oversight." The practices are non-binding. The FSB "strongly encourages the board and senior management" of financial institutions to reference them. A board that reads that sentence as optional has decided something, and it has decided it without a vote.
Governing Evidence
The FSB published its consultation report, Sound Practices for the Responsible Adoption of Artificial Intelligence, on June 10, 2026. Comments closed on July 22, 2026, and the FSB has said the final report is due in October 2026, with Michelle Bowman, Chair of its Standing Committee on Supervisory and Regulatory Cooperation, describing it as a deliverable that can be issued later this year for the U.S. G20 presidency. The twelve practices cover governance, the AI lifecycle, cyber and ICT risk, and third-party risk. Skadden's August 2026 analysis quotes the strategy practice as "Adopt a board-approved AI strategy and define AI risk appetite," and the human oversight practice as "Define mandatory review and override points for material decisions." As reported by TechInformed, the FSB treats agents as "synthetic employees" for identity, access, and responsibility, proposes a documented identifier for every agent, calls for human or dual approval above set thresholds, and suggests limits on direct access to payment systems. The Cambridge Centre for Alternative Finance's 2026 Global AI in Financial Services Report, also cited by TechInformed, found 52 percent of surveyed firms actively adopting agentic AI and 23 percent at the scaling or transforming stage.
The Document Is Non-Binding. The Exposure Is Not.
The FSB is explicit that these practices are not an international standard and not a prescriptive rule. They are a toolkit. That is exactly why they matter to a director.
A binding rule tells a board what it must do. A toolkit published by the body that coordinates the world's financial supervisors tells a board what a prudent peer will have done by the time something goes wrong. When an agent moves money, approves a credit exception, or changes a fraud rule, the first question from a supervisor, a plaintiff, or a successor will be whether the institution measured itself against the most credible description of good practice available. The FSB has now written that description.
Half the Industry Is Already Past the Pilot Question
Fifty-two percent of surveyed firms are actively adopting agentic AI. Nearly one in four has reached scaling. At that point the practice list stops being a reading assignment and becomes a comparison against what is already running.
Real-time human oversight, the FSB observes, becomes impractical as agents multiply, because a single agent can take hundreds of intermediate steps toward a goal and any one of them can be the error. That sentence should change how a board asks its questions. "Is a human in the loop?" is no longer an answer. The answer is which actions an agent may never take, which require a second approval, and who is named when an agent acts inside its permissions and still gets it wrong.
The Governance Boundary Principle Applies Line by Line
Touch Stone's Governance Boundary Principle holds that a board owns the standard and management executes against it. A board that keeps oversight only because an outside body requires it has not yet owned the standard.
The FSB has done the outside part. It has named the categories: prohibited actions, approval thresholds, agent identity, audit trails, vendor accountability. What it cannot do is decide where the line sits at this institution. The risk appetite for an autonomous agent is a judgment about how much unsupervised action the board is willing to defend. Management can propose a number. Only the board can adopt it as its own.
The same applies to the "synthetic employee" idea. An employee has a manager, a limit, and a record. If agents are to be treated that way, someone must be the manager of record for each one, and that assignment is a governance decision, not an IT ticket.
What a Board or Risk Committee Does Before the Final Report
Three actions follow, and each can be completed in one cycle.
Ask management for a complete register of every AI agent now acting inside the institution, including agents embedded in vendor products, with the action each is permitted to take and the person accountable for it. A practice cannot be applied to a population nobody has counted.
Adopt, in a recorded session, the list of actions no agent may take without approval, and the dollar or customer-impact threshold above which a second approver is required. Do not delegate the first draft of that list to the team that benefits from fewer limits.
Decide which of the twelve practices the board is adopting as its own standard, which it is deferring and why, and which it rejects. A documented rejection with a reason is a defensible position. Silence is not.
A board that waits for the final report to begin has made the report its standard. One that does this work in the weeks before it lands will read the final text as a comparison against its own conviction, and will leave its successors a standard they inherit and can build on. That is what governance looks like when it is not built in response to a supervisor's finding or the first failure.