Open Questions — Global Aggregator
Last refreshed: 2026-08-15 (monthly Open Brain sync; previous refresh 2026-05-17 seed — the weekly refresh rule in wiki-schema §6 had not run in the interim) Next refresh: weekly
This page aggregates ## Open Questions from every Topic page in the wiki. One section per topic, with a wikilink back. Refreshed weekly per wiki-schema §6.
Refresh note (2026-08-15). Questions from the 2026-05-17 seed are retained below with dated status notes where topic pages have since resolved or reframed them — nothing is deleted. Sections were added for topics created after the seed. For full question lists see each topic page; this aggregator carries the material items.
From EU AI Act
Will the EU Digital Omnibus delay the high-risk obligations beyond 2 August 2026?Resolved 2026-07-24: the Digital Omnibus received final Council adoption 29 June 2026 — high-risk obligations now 2 Dec 2027 (stand-alone Annex III) / 2 Aug 2028 (product-embedded); enforcement + Article 50 transparency commenced 2 Aug 2026 [S-2026-06-29-council-ai-omnibus-final-adoption][S-2026-07-31-ec-ai-act-enforcement-begins]. (Seed wording retained above per no-delete.)When will the overdue Article 6 high-risk classification guidelines publish?Updated: draft published 19 May 2026; consultation closed 23 July 2026; final guidelines due “by end-2026” — timing of the final text still open [S-2026-07-01-ec-highrisk-consultation-extension-confirmed].- What evidence will firms be expected to retain for Article 50 transparency/labelling now the obligations are live (2 Aug 2026) and the final Guidelines are published (20 Jul 2026)? Narrower than the seed question but still open — including whether signing the voluntary content-transparency Code counts as Article 50 evidence for FS firms.
Will JTC 21 harmonised standards publish before enforcement begins 2 Aug 2026?Overtaken: enforcement began without them; standards timing remains open (see AI and Data Assurance Pathway).- New since seed: how the financial-institutions competence carve-out (national authorities, not the AI Office, over same-provider GPAI systems) will interact with EBA/NCA supervision; effect of the 2 Dec 2026 transparency-solutions deadline (grace cut 6→3 months).
From FCA approach to AI
- What specific examples the FCA will publish as “good vs poor practice” on AI — still pending “later in the year”; note the 10 Aug 2026 “High-growth firms” review is explicitly not this publication.
Whether the 2026 SM&CR recalibration will introduce AI-specific prescribed responsibilities.Updated: PS26/6 phase 1 is staged through 2026 (most changes 24 Apr; reporting 10 Jul; Directory 30 Jul; non-financial-misconduct 1 Sep); the Mills Review (published 6 Jul 2026) recommends comprehensive practical guidance by end-2026 including “the accountability and level of assurance expected from senior managers under SM&CR for harm caused through AI” — how that assurance is evidenced remains open.Whether existing frameworks will be judged sufficient for agentic AI by the Mills Review.Partially resolved: Mills Review published 6 July 2026; it recommends guidance rather than a new rulebook — whether existing frameworks are sufficient for agentic AI remains open on the topic page.- How the FCA’s four de-facto AI test criteria — explainability, fairness, resilience, accountability — will be evidenced in practice. (Unchanged.)
From BCBS AI Governance Framework
What benchmark the BCBS 2026 range-of-practices report on ICT risk will set.Updated: d611 published 2 June 2026; what benchmark it sets in supervision is still being assessed.- Whether traditional MRM frameworks can scale to generative and agentic AI without structural change. Reframed since seed: the US anchor is now SR 26-2 (17 Apr 2026, superseding SR 11-7), which excludes GenAI/agentic AI from scope (RFI promised) — sharpening rather than resolving the question (see Model Risk Management and Agentic AI).
From Model Risk Management and Agentic AI
- Where AI model governance accountability should sit — CISO, CDO, CRO under 3LoD, or a cross-functional committee. Sources disagree — see Tensions on the topic page; still unresolved.
- What “human-in-the-loop” oversight means operationally as autonomy grows. (Unchanged; MAS SAFR v1.0 (Jul 2026) and Santander’s harness doctrine are new reference points.)
- How 2LoD/3LoD catch up — EBA’s “inadequate at most firms” finding stands. (Unchanged.)
- New since seed: timing/scope of the promised US RFI on GenAI/agentic MRM; who owns guardrail policy after the OpenAI→Hugging Face autonomous-agent intrusion (Jul 2026).
From EBA Supervisory Direction on AI and Governance
- What practical control expectations EBA will publish beyond the Nov 2025 factsheet — the 2026–2027 supervisory convergence programme remains the vehicle. (Unchanged.)
- Whether “CRR/CRD as technology-neutral baseline” holds now AI Act enforcement has begun (2 Aug 2026). (Sharpened by events; still open.)
From EBA Pillar 3 Data Hub (topic created 2026-06-10, after seed)
- Listed-SNCI publication date (end-April vs end-June); the sign-off model once qualitative/ESG data are added; how institutions evidence the integrity of EBA-side mapping/calculation.
From EBA Simplification and Efficiency Programme (topic created 2026-06-17, after seed)
- Whether the September 2027 supervisory-reporting application date holds; which TFE recommendations reach CRR/CRD/BRRD; buffer/MDA interactions from the stacking-orders review.
From BCBS 239 and Data Lineage
- Whether lineage remains flagged through 2026–27 supervision; how the H2 2026 SREP Business Glossaries deliverable is assessed; defensibility of AI-generated DQ rules and vendor auto-assessments; post-EOL Collibra CLI evidence-continuity verification (EOL effective 31 Jul 2026).
From Operational Resilience and Third Party Risk
- Scope of DORA Article 30 contractual clauses for AI vendor contracts. (Unchanged.)
- How FCA PS26/2 (effective 18 Mar 2027) interacts with DORA’s parallel obligations. (Unchanged.)
- New since seed: how the ESAs’ frontier-AI statements (7 Jul and 31 Jul 2026, JC 2026 25) translate into CTPP oversight; whether ISO/IEC 42001 certification becomes a de facto procurement requirement (three consecutive scope-unstated certification announcements).
From AI Governance Maturity Gap
- Whether the survey signal (~12–18% confident on independent AI-controls review) reflects real maturity or under-confidence in self-reporting. (Unchanged; the topic page now also tracks the stated-confidence vs measured-maturity tension.)
From Agentic Data Access Governance (topic created 2026-06-21, after seed)
- Whether session roles / runtime lineage satisfy DORA/GDPR/AI-Act Art 12 evidence expectations; EU residency of agent-governance control planes; the standing absence of any named EU/UK regulated-FS production reference.
From AI Governance Platforms (topic created 2026-06-26, after seed)
- Top items of ~25 on the topic page: EU/UK FS production deployments and independent assessment of vendor control mappings; which function owns the agent inventory of record; retention/immutability of “enforcement evidence” (no vendor discloses); managed-service governance (Rimini) vs firm-held obligations.
From CLM Transformation Programme and sub-projects
- SI vs LSI status of the Irish Tier-1 client bank (affects IRB obligations).
- Current IRB scope at the client (PD/LGD coverage by portfolio).
- Materiality threshold parameters under CDR 2018/171.
- Model-owner mapping at the client.
- Use-test evidence retention policy.
- Pillar 3 cadence and template-population responsibility.
- JST engagement protocol.
- Historical default-flag back-fill scope.
- Whether the 2026 SREP Business Glossaries deliverable (H2 2026) will be met on time.
- New since seed (project pages): CLMP DG&DQ engagement window ended 31 Jul 2026 with no closeout/handover captured — status unconfirmed; CLM Dashboard v4 Edge smoke test gating first client publish; Taxonomy Knowledge Tool environment provisioning is that project’s binding constraint.
From AI and Data Assurance Pathway
- Agent assurance best practice — no FS-supervisor formal expectations yet. (Unchanged.)
- GPAI systemic-risk evaluation methodology from the AI Office still being published. (Unchanged.)
- CSSF and other NCA specifics need local supplementation when client jurisdiction is known. (Unchanged.)
High-risk consultation deadline (23 June vs 23 July).Resolved 2026-07-01: extension to 23 July 2026 confirmed on the Commission’s consultation page (this resolution was already recorded on EU AI Act; the pathway page still lists it open — cross-page staleness noted in the 2026-08-15 sync report).