US Treasury — AI Risk Framework for Financial Services

Tag: S-2026-03-17-us-treasury-ai-risk Type: report Author(s): US Department of the Treasury Date of source: 2026-03-17 Date ingested: 2026-05-17 Authority weight: medium-high — US Treasury issuance; not directly binding on EU/UK firms but materially shapes practitioner expectations and Big-4 frameworks. Raw file: Open Brain corpus snapshot at /_raw_sources/open-brain-2026-05-17-corpus.md. Practitioner coverage: resultsense.com, Grant Thornton “Treasury guidance brings urgency to AI governance”.

What it claims

The US Treasury published an AI Risk Framework for Financial Services on 17 March 2026 setting out:

  • ~230 control objectives across four governance functions.
  • Four AI maturity stages for benchmarking.

Grant Thornton and other practitioner coverage frame the publication as raising the urgency on AI governance in US institutions and creating de-facto benchmark control objectives that European firms operating in the US will need to evidence. The framework is cited alongside BCBS othp90 — Governance of AI adoption as one of the two most explicit supervisory-style AI governance anchors available in early 2026.

Notable quotes

None captured verbatim — ingestion relied on practitioner summaries.

What’s speculative vs. asserted

  • Asserted: the 230 control objectives figure and four-function / four-stage structure (Grant Thornton summary).
  • Speculative: the practical applicability to EU/UK firms — Paul’s framing is that it informs but does not directly bind.

Topics this feeds

Open questions raised

  • Whether and how non-US firms with US operations should map their existing AI governance arrangements to the Treasury framework.
  • Whether the Federal Reserve will publish parallel guidance via SR-letter route.

Ingestion note

Single Open Brain thought dated 3/20/2026 references the framework; corroborating practitioner coverage in thoughts dated 5/7, 4/26.