Open Questions — Global Aggregator

Last refreshed: 2026-08-15 (monthly Open Brain sync; previous refresh 2026-05-17 seed — the weekly refresh rule in wiki-schema §6 had not run in the interim) Next refresh: weekly

This page aggregates ## Open Questions from every Topic page in the wiki. One section per topic, with a wikilink back. Refreshed weekly per wiki-schema §6.

Refresh note (2026-08-15). Questions from the 2026-05-17 seed are retained below with dated status notes where topic pages have since resolved or reframed them — nothing is deleted. Sections were added for topics created after the seed. For full question lists see each topic page; this aggregator carries the material items.

From EU AI Act

  • Will the EU Digital Omnibus delay the high-risk obligations beyond 2 August 2026? Resolved 2026-07-24: the Digital Omnibus received final Council adoption 29 June 2026 — high-risk obligations now 2 Dec 2027 (stand-alone Annex III) / 2 Aug 2028 (product-embedded); enforcement + Article 50 transparency commenced 2 Aug 2026 [S-2026-06-29-council-ai-omnibus-final-adoption][S-2026-07-31-ec-ai-act-enforcement-begins]. (Seed wording retained above per no-delete.)
  • When will the overdue Article 6 high-risk classification guidelines publish? Updated: draft published 19 May 2026; consultation closed 23 July 2026; final guidelines due “by end-2026” — timing of the final text still open [S-2026-07-01-ec-highrisk-consultation-extension-confirmed].
  • What evidence will firms be expected to retain for Article 50 transparency/labelling now the obligations are live (2 Aug 2026) and the final Guidelines are published (20 Jul 2026)? Narrower than the seed question but still open — including whether signing the voluntary content-transparency Code counts as Article 50 evidence for FS firms.
  • Will JTC 21 harmonised standards publish before enforcement begins 2 Aug 2026? Overtaken: enforcement began without them; standards timing remains open (see AI and Data Assurance Pathway).
  • New since seed: how the financial-institutions competence carve-out (national authorities, not the AI Office, over same-provider GPAI systems) will interact with EBA/NCA supervision; effect of the 2 Dec 2026 transparency-solutions deadline (grace cut 6→3 months).

From FCA approach to AI

  • What specific examples the FCA will publish as “good vs poor practice” on AI — still pending “later in the year”; note the 10 Aug 2026 “High-growth firms” review is explicitly not this publication.
  • Whether the 2026 SM&CR recalibration will introduce AI-specific prescribed responsibilities. Updated: PS26/6 phase 1 is staged through 2026 (most changes 24 Apr; reporting 10 Jul; Directory 30 Jul; non-financial-misconduct 1 Sep); the Mills Review (published 6 Jul 2026) recommends comprehensive practical guidance by end-2026 including “the accountability and level of assurance expected from senior managers under SM&CR for harm caused through AI” — how that assurance is evidenced remains open.
  • Whether existing frameworks will be judged sufficient for agentic AI by the Mills Review. Partially resolved: Mills Review published 6 July 2026; it recommends guidance rather than a new rulebook — whether existing frameworks are sufficient for agentic AI remains open on the topic page.
  • How the FCA’s four de-facto AI test criteria — explainability, fairness, resilience, accountability — will be evidenced in practice. (Unchanged.)

From BCBS AI Governance Framework

  • What benchmark the BCBS 2026 range-of-practices report on ICT risk will set. Updated: d611 published 2 June 2026; what benchmark it sets in supervision is still being assessed.
  • Whether traditional MRM frameworks can scale to generative and agentic AI without structural change. Reframed since seed: the US anchor is now SR 26-2 (17 Apr 2026, superseding SR 11-7), which excludes GenAI/agentic AI from scope (RFI promised) — sharpening rather than resolving the question (see Model Risk Management and Agentic AI).

From Model Risk Management and Agentic AI

  • Where AI model governance accountability should sit — CISO, CDO, CRO under 3LoD, or a cross-functional committee. Sources disagree — see Tensions on the topic page; still unresolved.
  • What “human-in-the-loop” oversight means operationally as autonomy grows. (Unchanged; MAS SAFR v1.0 (Jul 2026) and Santander’s harness doctrine are new reference points.)
  • How 2LoD/3LoD catch up — EBA’s “inadequate at most firms” finding stands. (Unchanged.)
  • New since seed: timing/scope of the promised US RFI on GenAI/agentic MRM; who owns guardrail policy after the OpenAI→Hugging Face autonomous-agent intrusion (Jul 2026).

From EBA Supervisory Direction on AI and Governance

  • What practical control expectations EBA will publish beyond the Nov 2025 factsheet — the 2026–2027 supervisory convergence programme remains the vehicle. (Unchanged.)
  • Whether “CRR/CRD as technology-neutral baseline” holds now AI Act enforcement has begun (2 Aug 2026). (Sharpened by events; still open.)

From EBA Pillar 3 Data Hub (topic created 2026-06-10, after seed)

  • Listed-SNCI publication date (end-April vs end-June); the sign-off model once qualitative/ESG data are added; how institutions evidence the integrity of EBA-side mapping/calculation.

From EBA Simplification and Efficiency Programme (topic created 2026-06-17, after seed)

  • Whether the September 2027 supervisory-reporting application date holds; which TFE recommendations reach CRR/CRD/BRRD; buffer/MDA interactions from the stacking-orders review.

From BCBS 239 and Data Lineage

  • Whether lineage remains flagged through 2026–27 supervision; how the H2 2026 SREP Business Glossaries deliverable is assessed; defensibility of AI-generated DQ rules and vendor auto-assessments; post-EOL Collibra CLI evidence-continuity verification (EOL effective 31 Jul 2026).

From Operational Resilience and Third Party Risk

  • Scope of DORA Article 30 contractual clauses for AI vendor contracts. (Unchanged.)
  • How FCA PS26/2 (effective 18 Mar 2027) interacts with DORA’s parallel obligations. (Unchanged.)
  • New since seed: how the ESAs’ frontier-AI statements (7 Jul and 31 Jul 2026, JC 2026 25) translate into CTPP oversight; whether ISO/IEC 42001 certification becomes a de facto procurement requirement (three consecutive scope-unstated certification announcements).

From AI Governance Maturity Gap

  • Whether the survey signal (~12–18% confident on independent AI-controls review) reflects real maturity or under-confidence in self-reporting. (Unchanged; the topic page now also tracks the stated-confidence vs measured-maturity tension.)

From Agentic Data Access Governance (topic created 2026-06-21, after seed)

  • Whether session roles / runtime lineage satisfy DORA/GDPR/AI-Act Art 12 evidence expectations; EU residency of agent-governance control planes; the standing absence of any named EU/UK regulated-FS production reference.

From AI Governance Platforms (topic created 2026-06-26, after seed)

  • Top items of ~25 on the topic page: EU/UK FS production deployments and independent assessment of vendor control mappings; which function owns the agent inventory of record; retention/immutability of “enforcement evidence” (no vendor discloses); managed-service governance (Rimini) vs firm-held obligations.

From CLM Transformation Programme and sub-projects

  • SI vs LSI status of the Irish Tier-1 client bank (affects IRB obligations).
  • Current IRB scope at the client (PD/LGD coverage by portfolio).
  • Materiality threshold parameters under CDR 2018/171.
  • Model-owner mapping at the client.
  • Use-test evidence retention policy.
  • Pillar 3 cadence and template-population responsibility.
  • JST engagement protocol.
  • Historical default-flag back-fill scope.
  • Whether the 2026 SREP Business Glossaries deliverable (H2 2026) will be met on time.
  • New since seed (project pages): CLMP DG&DQ engagement window ended 31 Jul 2026 with no closeout/handover captured — status unconfirmed; CLM Dashboard v4 Edge smoke test gating first client publish; Taxonomy Knowledge Tool environment provisioning is that project’s binding constraint.

From AI and Data Assurance Pathway

  • Agent assurance best practice — no FS-supervisor formal expectations yet. (Unchanged.)
  • GPAI systemic-risk evaluation methodology from the AI Office still being published. (Unchanged.)
  • CSSF and other NCA specifics need local supplementation when client jurisdiction is known. (Unchanged.)
  • High-risk consultation deadline (23 June vs 23 July). Resolved 2026-07-01: extension to 23 July 2026 confirmed on the Commission’s consultation page (this resolution was already recorded on EU AI Act; the pathway page still lists it open — cross-page staleness noted in the 2026-08-15 sync report).