KYE Governed Research Rail™ · Bulletin · Edition 2026-06
AI Legal Brief: the FSB asks for engineered controls, not well-worded prompts — June 2026
Ed25519-sealed · fingerprint ef27fb4ecf7bfcd4 · verify it yourself ↓
KYE Protocol™ governs actions and authorities, not outcomes, diagnoses, or results. This report synthesises public sources under the evidence / no-hallucination gate — every claim below is pinned to a cited source.
Executive tear-sheet
A financial-stability regulator has, in effect, told the market that a paragraph of instructions is not a control — reporting based on publicly available sources, not legal or compliance advice. On 10 June 2026 the Financial Stability Board (FSB) published a consultation, Sound Practices for Responsible Adoption of Artificial Intelligence: a deliberately non-binding, proportionate menu of sound practices for financial institutions, open for comment until 22 July 2026 with a final report due in October 2026. This brief relays what the consultation asks for and, separately and clearly labelled, what KYE Protocol™ reads into it for agentic-AI accountability. It does not advise on the law, on supervisory expectations, or on any institution's compliance position.
Key findings
- What was published, as reported: the FSB consultation sets out sound practices spanning firm-wide governance, AI-lifecycle risk management, and cyber / third-party risk, and is explicitly proportionate — more is expected where AI sits in material, high-risk or critical functions (Financial Stability Board, 10 June 2026).
- It is principles, re-engineered — not a break from model risk management. The expectations echo long-standing SR 11-7 principles: control proportionate to risk, independent effective challenge, lifecycle governance, and a named owner of the outcome.
- The bar is engineered controls, not prompts. Commentary has named the failure pattern — instruction + an LLM-as-judge review + a human sign-off + a green dashboard — "prompt and pray", and argued it converges to a longer prompt over the same unfixed bottleneck.
- Transparency is not explainability. A self-generated rationale is another model output — fluent, plausible, and under no obligation to faithfully report its own basis. Publishing a model card or a chain-of-thought log is transparency; it is not an understanding of how inputs became the action.
- Oversight must be exercisable. Meaningful oversight requires that a reviewer can inspect what the agent did not retrieve, replay the tool calls, and test the policy claim — not tick a box on a compliance assertion.
What the consultation asks for, as reported
TL;DR According to the FSB consultation published on 10 June 2026, responsible adoption is assessed against engineered expectations rather than declarations: what an AI system is permitted to see, decide, call, change, approve and explain; whether oversight is meaningful rather than nominal; and — for systems that act — whether the actions taken to reach an outcome were appropriate, not merely whether the outcome was correct.
According to the FSB consultation published on 10 June 2026, responsible adoption is assessed against engineered expectations rather than declarations: what an AI system is permitted to see, decide, call, change, approve and explain; whether oversight is meaningful rather than nominal; and — for systems that act — whether the actions taken to reach an outcome were appropriate, not merely whether the outcome was correct. This brief relays the consultation as a public document; it does not independently characterise supervisory intent beyond what the cited source states, and the consultation is itself a non-binding menu open for comment.
Why "be extra careful" hits a ceiling
TL;DR The dispute is concrete in a way much of the AI-governance debate is not.
The dispute is concrete in a way much of the AI-governance debate is not. If an agent cannot see omitted evidence, no instruction conjures it; if its tool permissions let it close a case it should have escalated, no adjective revokes that permission; if a reviewer cannot replay what the agent did, no "be careful" makes the review real. The bottleneck is set by things prompts cannot touch — whether the system had the right evidence, whether the tool call was authorised, whether policy was actually checked, and whether the record can be independently replayed.
What KYE Protocol™ reads into it (interpretation, not advice)
TL;DR This section is KYE Protocol™'s interpretation, clearly separated from the reported facts above, and is not legal or compliance advice.
This section is KYE Protocol™'s interpretation, clearly separated from the reported facts above, and is not legal or compliance advice. The consultation's questions are answerable with artefacts, not assertions — and that is an authority-and-evidence problem, which is the problem KYE Protocol™ exists to solve:
- What physically prevents an agent asserting a compliance it never performed? — <a href="/knowledge-graph.html">Action Admissibility™</a> checks each consequential action at the moment it happens.
- Are we reading the actual basis, or a story written after the fact? — the sealed <a href="/evidence-pack.html">Decision Map™</a> records inputs, the rules they hit, and the outcome — not a narrated rationale.
- Can reviewers see what the agent did not retrieve or do? — the <a href="/evidence-pack.html">Evidence Pack™</a> captures the basis, and <a href="/authority-sourcing.html">Authority Sourcing™</a> renders the timeline and authority graph behind the action.
- Could we reconstruct it from independent logs, surviving an exam? — Replay-Proof™: anyone verifies the record offline from published keys alone.
One boundary KYE Protocol™ states plainly, because the consultation is right about it: KYE Protocol™ does not claim to explain a model's internal mapping, and a self-generated rationale is not explainability. KYE Protocol™ proves what happened, on whose authority, and on what cited basis — accountability, the soundness of the control, and a replayable record — not why the weights produced a given token. It does not make any AI output correct. Whether and how the consultation applies to any given institution is a matter for that institution's own legal and compliance advisers.
Claims → sources — every claim mapped to a pinned source
This is the claims→source map: no claim ships without a cited, pinned public source (evidence gate). Each numbered claim below is pinned into this edition's sealed evidence pack kye:evidence-pack:research:ai-legal-brief-fsb-prompt-and-pray:2026-06.
- On 10 June 2026 the Financial Stability Board published a consultation, 'Sound Practices for Responsible Adoption of Artificial Intelligence', a deliberately non-binding and proportionate menu of sound practices for financial institutions, open for comment until 22 July 2026 with a final report due October 2026. https://www.fsb.org/ — Financial Stability Board (consultation report). Publisher-level citation; deep-link to be pinned. (retrieved 2026-06-13T00:00:00Z)
- US model risk management guidance (SR 11-7) sets out principles — control proportionate to risk, independent effective challenge by parties with the incentive, competence and access to find what is wrong, governance across the model lifecycle, and a named owner of the outcome. https://www.federalreserve.gov/supervisionreg/srletters/sr1107.htm — Board of Governors of the Federal Reserve System / OCC (SR 11-7) (retrieved 2026-06-13T00:00:00Z)
- Commentary has named the pattern of treating a paragraph of instructions as a control — instruction plus an LLM-as-judge review plus a human sign-off plus a green dashboard — 'prompt and pray', and argued that strengthening the prompt converges to a longer prompt over the same unfixed bottleneck. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6932339 — Agus Sudjianto, 'Unified Prompt and Pray Framework' (SSRN). Cited as commentary, not as a statement of law. (retrieved 2026-06-13T00:00:00Z)
Replay-verifiable
This edition is sealed and Ed25519-signed over the published keys. Any reader can confirm the seal offline — no KYE™ service required.
- Signature algorithm
EdDSA- Key id
kye:key:self-audit-fixture-2026-06- Seal fingerprint
ef27fb4ecf7bfcd4(sha256 of the signature, first 16 hex)- Published keys (JWKS)
/trust/self-audit-jwks.json- Report envelope
kye:research-report:ai-legal-brief-fsb-prompt-and-pray-2026-06· schemakye.research_report.v1
Verify it yourself: fetch the published JWKS, recompute the Ed25519 signature over this edition's canonicalised envelope (minus seal) bound to the body hash, and confirm it matches the key id above — from public keys alone, no KYE™ service in the loop.