Box Commons

Comment on OCC Stablecoin NPRM: GENIUS Act for National Banks

Date March 11, 2026
Submitted to Office of the Comptroller of the Currency
Docket OCC-2025-0372 / RIN 1557-AF41
Type Formal Comment (US Federal)

Box Commons · 30 N Gould St Ste N, Sheridan WY 82801

Key Takeaways
  • SR 11-7 was built for periodic-validation statistical models, not continuously-adapting AI agents that make real-time compliance decisions autonomously.
  • The most acute behavioral safety risk in BSA/AML AI is discriminatory false positives that automate and scale historically biased monitoring patterns.
  • Third-party credentialing resolves the information asymmetry between banks and regulators — analogous to SOC 2 audits for AI systems.
+ Jump to Section

Executive Summary

The existing SR 11-7 model risk management framework was designed for traditional statistical models — periodic validation, human-interpretable outputs, bounded decision spaces. Autonomous AI agents making real-time compliance decisions in stablecoin operations operate outside these assumptions. OCC implementing regulations for the GENIUS Act should incorporate behavioral safety credentialing as a complementary framework.

I. The Supervisory Gap: SR 11-7 Was Not Built for This

SR 11-7 assumes models that are periodically validated, produce human-interpretable outputs, and operate within bounded decision spaces. AI agents in stablecoin compliance are continuously adapting, produce opaque outputs, and make real-time autonomous decisions. The framework cannot govern what it was not designed to evaluate.

II. The Discriminatory False-Positive Problem

The most acute behavioral safety risk in BSA/AML AI is discriminatory false positives — AI systems that automate and scale historically biased monitoring patterns. A system trained on historical SAR data inherits the biases embedded in human analysts' past flagging decisions, then applies those biases at machine speed and scale.

III. The Insurance Dimension

ISO CG 40 47 and CG 40 48 exclusions are creating coverage gaps for AI-related harms. Banks deploying AI in stablecoin compliance face increasing difficulty obtaining insurance coverage for AI behavioral failures. Third-party credentialing provides the independent verification that underwriters need to assess and price risk.

IV. Specific Recommendations

1. Supplement SR 11-7 with behavioral safety credentialing requirements for AI systems in stablecoin compliance.

2. Require independent evaluation of AI BSA/AML systems for discriminatory false-positive patterns.

3. Recognize third-party behavioral safety credentials as evidence of compliance in OCC examinations.


Contact:
Brice Love, Acting Executive Director
Box Commons
[email protected]

Content Integrity Notice: This comment was authored by the Box Commons Policy Working Group. Generative AI was used for research synthesis and drafting support. All policy positions, recommendations, and normative claims were formulated and reviewed by human authors.