Comment on OCC Stablecoin NPRM: GENIUS Act for National Banks
Box Commons · 30 N Gould St Ste N, Sheridan WY 82801
- SR 11-7 was built for periodic-validation statistical models, not continuously-adapting AI agents that make real-time compliance decisions autonomously.
- The most acute behavioral safety risk in BSA/AML AI is discriminatory false positives that automate and scale historically biased monitoring patterns.
- Third-party credentialing resolves the information asymmetry between banks and regulators — analogous to SOC 2 audits for AI systems.
+ Jump to Section
Executive Summary
The existing SR 11-7 model risk management framework was designed for traditional statistical models — periodic validation, human-interpretable outputs, bounded decision spaces. Autonomous AI agents making real-time compliance decisions in stablecoin operations operate outside these assumptions. OCC implementing regulations for the GENIUS Act should incorporate behavioral safety credentialing as a complementary framework.
I. The Supervisory Gap: SR 11-7 Was Not Built for This
SR 11-7 assumes models that are periodically validated, produce human-interpretable outputs, and operate within bounded decision spaces. AI agents in stablecoin compliance are continuously adapting, produce opaque outputs, and make real-time autonomous decisions. The framework cannot govern what it was not designed to evaluate.
II. The Discriminatory False-Positive Problem
The most acute behavioral safety risk in BSA/AML AI is discriminatory false positives — AI systems that automate and scale historically biased monitoring patterns. A system trained on historical SAR data inherits the biases embedded in human analysts' past flagging decisions, then applies those biases at machine speed and scale.
III. The Insurance Dimension
ISO CG 40 47 and CG 40 48 exclusions are creating coverage gaps for AI-related harms. Banks deploying AI in stablecoin compliance face increasing difficulty obtaining insurance coverage for AI behavioral failures. Third-party credentialing provides the independent verification that underwriters need to assess and price risk.
IV. Specific Recommendations
1. Supplement SR 11-7 with behavioral safety credentialing requirements for AI systems in stablecoin compliance.
2. Require independent evaluation of AI BSA/AML systems for discriminatory false-positive patterns.
3. Recognize third-party behavioral safety credentials as evidence of compliance in OCC examinations.
Contact:
Brice Love, Acting Executive Director
Box Commons
[email protected]
Content Integrity Notice: This comment was authored by the Box Commons Policy Working Group. Generative AI was used for research synthesis and drafting support. All policy positions, recommendations, and normative claims were formulated and reviewed by human authors.
Related Filings
Comment on FDIC GENIUS Act: Stablecoin PPSI Implementation
Urges FDIC to incorporate third-party behavioral safety credentialing into GENIUS Act implementing regulations for state-chartered banks. Addresses the unique dual supervision challenge, deposit insurance dimension, and community bank proportionality problem.
NCUAComment on NCUA GENIUS Act: Behavioral Safety Credentialing for Credit Unions
Urges NCUA to incorporate third-party behavioral safety credentialing into GENIUS Act regulations as a cost-effective mechanism for credit unions to verify vendor-provided AI system safety without requiring in-house model risk management.
Federal ReserveComment on Federal Reserve Reputation Risk Rule (R-1884)
Addresses AI-related reputation risk in banking supervision and the role of third-party credentialing in financial institution compliance. Argues that behavioral safety verification should be part of reputation risk management for AI-deploying banks.