Comment on FDIC GENIUS Act: Stablecoin PPSI Implementation
Box Commons · 30 N Gould St Ste N, Sheridan WY 82801
- AI systems will make consequential, autonomous BSA/AML and reserve management decisions for stablecoin operations — behavioral safety is a safety-and-soundness issue.
- Dual supervision (FDIC + state) creates coordination challenges as state AI governance frameworks diverge; credentialing provides a common standard.
- Third-party credentialing resolves the community bank proportionality problem the same way SOC 2 resolved information security.
+ Jump to Section
Executive Summary
AI systems will make consequential, autonomous decisions in BSA/AML transaction monitoring and reserve management for stablecoin operations. These are safety-and-soundness issues, not merely technology management concerns. The FDIC should incorporate third-party behavioral safety credentialing into GENIUS Act implementing regulations.
I. The AI Compliance Imperative
Stablecoin operations require real-time BSA/AML transaction monitoring at volumes and speeds that preclude human review. AI systems will make autonomous decisions to flag, block, or escalate transactions — decisions with direct consequences for consumers and regulatory compliance.
Reserve management under stress scenarios (redemption waves, market volatility) will increasingly rely on AI-driven decision-making. The behavioral safety of these systems — not just their cybersecurity posture — determines whether they maintain compliance under pressure.
II. The Dual Supervision Challenge
State-chartered banks issuing stablecoins face dual supervision from the FDIC and their state chartering authority. As state AI governance frameworks diverge — Colorado's SB 21-169, New York's DFS AI guidance, Connecticut's AI framework — third-party credentialing provides a common standard that satisfies both federal and state requirements without requiring regulatory harmonization.
III. The Community Bank Proportionality Problem
Community banks lack the resources for in-house AI model risk management teams. Third-party credentialing resolves this proportionality problem the same way SOC 2 resolved information security: the standard is applied to the AI system, not the deploying institution. A community bank can rely on a vendor's behavioral safety credential rather than building its own evaluation capability.
IV. Specific Recommendations
1. Recognize third-party behavioral safety credentialing as a mechanism for satisfying AI governance requirements in GENIUS Act implementing regulations.
2. Establish a proportionality framework that allows community banks to rely on vendor credentials rather than requiring in-house AI evaluation capabilities.
3. Coordinate with state regulators on mutual recognition of behavioral safety credentials to address the dual supervision challenge.
Contact:
Brice Love, Acting Executive Director
Box Commons
[email protected]
Content Integrity Notice: This comment was authored by the Box Commons Policy Working Group. Generative AI was used for research synthesis and drafting support. All policy positions, recommendations, and normative claims were formulated and reviewed by human authors.
Related Filings
Comment on OCC Stablecoin NPRM: GENIUS Act for National Banks
Proposes that OCC incorporate behavioral safety credentialing into GENIUS Act implementing regulations for national banks, arguing that the existing SR 11-7 model risk management framework was designed for traditional statistical models and cannot govern autonomous AI agents.
NCUAComment on NCUA GENIUS Act: Behavioral Safety Credentialing for Credit Unions
Urges NCUA to incorporate third-party behavioral safety credentialing into GENIUS Act regulations as a cost-effective mechanism for credit unions to verify vendor-provided AI system safety without requiring in-house model risk management.
Federal ReserveComment on Federal Reserve Reputation Risk Rule (R-1884)
Addresses AI-related reputation risk in banking supervision and the role of third-party credentialing in financial institution compliance. Argues that behavioral safety verification should be part of reputation risk management for AI-deploying banks.