
Answering for the Machine — Part 1: Who Is Authorised to Pull It?
In the first half of 2026, Wolters Kluwer surveyed 230 banking professionals across community, midsize and large institutions and asked a plain question: where is your bank least prepared to manage AI risk? Seventy-two percent named one of two things: the ability to shut down a malfunctioning AI model, or the ability to report an AI failure to regulators. The report's authors called these the minimum viable requirements for managing an AI incident in a regulated environment. Nearly three in four banks could not confirm they had them.
These are not exotic capabilities. They are the regulatory equivalent of a fire exit, the controls a bank reaches for on the worst day, when a system that has been running quietly for a year does something it should not and someone has to stop it and account for what happened. Most of the banks surveyed have already deployed AI into lending, fraud detection, collections and customer service. Most of them, on their own admission, cannot confidently say who would stop it or how they would explain it afterward. The pipeline to run a model got built. The protocol to halt one did not.
That gap is organisational, not technical. A kill switch is not hard to build. The hard part is the question of who is authorised to pull it, on what authority, with what record to show for it afterward, and that question is about to stop being optional, because regulators on more than one continent have started asking it directly.
The switch is the easy part
The control that protects customers is not, in the end, software. It is authority: a named person with the standing to act, vendor contracts that grant that authority, and a defensible way to answer a regulator when they ask what happened. A kill switch with no one authorised to pull it is not a control. It is a button.
This is where most AI governance conversations go wrong. They treat the problem as a capability the bank is missing, a monitoring tool or a logging system or a shut-off mechanism, and assume that acquiring the capability closes the gap. But the survey respondents were not reporting a shortage of software. They were reporting that no one had settled who decides, who acts, and who answers for it. Those are things a bank assigns, before the system goes live, to people who know they hold them.
What actually has to be true for a bank to stop a malfunctioning AI model in production is a chain of assigned responsibility. Someone has to notice it is malfunctioning, which means someone owns watching it. Someone has to have the authority to halt it, which may mean overriding a business line that depends on it and a vendor whose contract may not grant the bank that right. Someone has to decide whether the failure is reportable, which means knowing what the regulator expects and holding the record to support the account. Each link is a person with a defined responsibility, and the technology is the last and easiest link. The chain is mostly made of authority.
This is why the institutions that handle AI well and the ones that handle it badly are rarely separated by the quality of their models. They are separated by whether anyone can answer a simple question about any given AI-influenced decision: who was allowed to act on this, and who owns the outcome if it was wrong. An earlier series of articles on this site argued that AI deployments fail not because the technology is inadequate but because organisations bolt it onto existing workflows without ever deciding who is authorised to act on the output. The survey is that argument arriving as a supervisory problem rather than an operational one. The banks that never assigned the authority did not just build fragile deployments. They built deployments they cannot answer for.
Why the regulator now cares
For most of the last two years, the pressure on banks was to adopt, to show they were not falling behind, to get something into production. The question in the room was whether the model worked. Supervisors have now replaced it with the one the survey exposed: whether the institution can govern the model, control it, and account for it when it does not.
The shift is visible across jurisdictions at once, which is what makes it hard to dismiss as a local quirk. In the United States, the Federal Reserve, the OCC and the FDIC have, according to reporting on supervisory practice, begun embedding AI governance questions into routine examinations, with kill-switch protocols and failure reporting among the standard lines of questioning. India's reserve bank has circulated a draft framework requiring documented AI controls and board-level accountability. In Singapore, the Monetary Authority has consulted on guidelines whose central move is to place the board and senior management at the centre of AI risk governance, explicitly reaching generative AI and autonomous agents. The mechanisms differ across jurisdictions, but the direction is uniform. Regulatory responsibility for AI is settling on the institution that deploys it, and it is settling on the parts that were always the hard parts: who governs the system, who is accountable for its outputs, who decided what it was allowed to do.
What Article 50 actually reaches
The most concrete instance arrived in Europe, written into enforceable law rather than left as supervisory expectation. Most of the attention over the past month went to a narrower story. On the second of August 2026, Anthropic said it would begin embedding an invisible watermark into the text its newer AI models produce, a compliance measure, the company said, to satisfy a transparency obligation under the European Union's AI Act, applied worldwide rather than only in Europe. The company was careful about the limits. A detected mark shows only that content may have been processed by the model, and its absence proves nothing, since older-model output or heavily edited text may carry no mark at all.
The watermark was widely read as a story about AI providers and their obligations, which it is. But the provision behind it, Article 50 of the AI Act, does something easy to miss if you read the headlines rather than the text. It splits the transparency obligation in two. One duty falls on the provider, the company that builds and supplies the AI system, to mark generated content so it can be detected as artificially generated. This is the duty the watermark addresses. The second duty falls on the deployer, the party that uses the system under its own authority. And the definition of deployer is broad in a way that matters. It reaches any organisation using an AI system under its authority, where authority means assuming responsibility over the decision to deploy the system and the manner of its use. Technical control is not required. A bank does not have to build, host, or understand the model to be a deployer. It only has to decide to use it and to direct how it is used.
Most institutions have yet to internalise this division. The provider meeting its obligation does nothing to settle the deployer's. When a model vendor watermarks its output, it has satisfied its own duty and left the bank exactly where it was. The bank that reasons "our vendor handles the compliance" has misread which obligation sits where, and it is the same misreading as assuming the kill switch is the control. The vendor's mark, like the switch, is a mechanism. The obligation attached to the deploying institution is a matter of authority and accountability, and it does not transfer.
Article 50's carve-out for human oversight effectively defines operational good practice. For the specific case the provision covers directly, AI-generated text published to inform the public on matters of public interest, the duty to disclose falls away where the content has undergone genuine human review or editorial control and a natural or legal person holds editorial responsibility for it. The carve-out is narrow, but the principle it encodes matters. The regulation treats real human oversight, exercised by a person who carries responsibility, as the thing that changes the content's status. Editorial control is the substantive condition the regulation cares about.
Compliance and operational rigour turn out to be the same discipline here. An organisation with a real human in the loop, someone who genuinely reviews the output, exercises judgment, and holds accountability for what goes out, has both a better deployment and a cleaner regulatory position. An organisation with a nominal review step, the kind that decayed months ago into a person clicking approve on output they no longer read, has neither. The review that satisfies an examiner as genuine oversight is the review that was actually doing something. A rubber stamp does not qualify, because there is no editorial control in a signature, and no accountability in a name that was never told it held the responsibility.
The question in advance
If regulatory responsibility sits with the deployer, and the thing being demanded is the ability to govern, control, and account for an AI system, then the deployment has to be built to carry that from the start. It is an architectural matter, decided before anything ships, and it cannot be retrofitted onto decisions already made and not recorded, or onto authority that was never assigned. To stop a system that has gone wrong, the bank needs someone who owns watching it and someone with the standing authority to halt it. To account for what it did, it needs to reconstruct the decision: the input, the output, whether a person reviewed it, the authority under which it was acted on, and the named individual who held that authority. To report a failure, it needs a record complete enough to satisfy an examiner who was not in the room. A system that produced good outputs but kept no defensible record of who reviewed them and on what authority cannot be answered for, however good the outputs were.
So a bank can settle in advance what the 72% had not: for every AI-influenced decision its systems make, who is authorised to act on it, who is watching it, who can stop it, and whether the record exists to show all three. The one that can answer will not need rescuing by its vendor's watermark or by a switch no one is named to pull, because the obligation the regulator cares about belongs to the institution that decided to deploy, from the day the decision was made. The only open question is whether anyone was assigned to hold it before the regulator asks who was.
Sources
Wolters Kluwer, US Banking AI Risk and Governance Index, H1 2026, published 10 June 2026 (survey of 230 US banking professionals; 72% least prepared on kill-switch protocols or regulatory reporting of AI failures). Reported in American Banker, "72% of banks lack AI model 'kill switches,' failure reporting," 10 June 2026.
Elaine F. Duffus and Aoife May, Wolters Kluwer, "Who Is Authorized to Shut Off the Bank's AI?", Corporate Compliance Insights (named accountability, vendor contracts, and answering regulators).
Reporting on US supervisory practice (Fed/OCC/FDIC embedding AI governance questions into routine examinations) and SR 26-2, revised model risk management guidance issued 17 April 2026.
Reserve Bank of India, draft framework on AI governance for regulated entities (June 2026); Monetary Authority of Singapore, Consultation Paper on Proposed Guidelines on Artificial Intelligence Risk Management (consultation closed 31 January 2026), covering generative AI and AI agents.
EU AI Act, Article 50, transparency obligations for providers and deployers; European Commission Guidelines on Article 50 (20 July 2026). Obligations applicable from 2 August 2026; grace period to 2 December 2026 for the Article 50(2) marking obligation on systems already on the market.
Anthropic support documentation on content marking (text watermarking and signed file provenance), reported August 2026 (TechCrunch, Euronews, The Register); framed as compliance with EU AI Act Article 50(2).


