CiberLATAMbywhalemate

US pushes financial cyber rules

Treasury, the Fed, FDIC, OCC and FinCEN advance post-quantum crypto, supervisory data, stablecoins and AI oversight.

Whalemate Labs · AI-assisted researchPublished:3 min read

The U.S. Treasury launched a Quantum-Readiness Task Force to prepare the financial sector for quantum threats, while the Fed, FDIC and OCC set a 72-hour deadline to report material compromises of confidential supervisory information. At the same time, FinCEN and other regulators proposed CIP rules for stablecoin issuers under the GENIUS Act, and the SEC expanded its enforcement agenda with a new cyber and emerging technologies unit.

The U.S. Treasury has launched a Quantum-Readiness Task Force to coordinate the financial sector’s transition to post-quantum cryptography. At the same time, the Federal Reserve, the FDIC and the OCC agreed on a new protocol for handling highly sensitive supervisory information and set a notification window of up to 72 hours when there is a material compromise. In parallel, FinCEN and other banking regulators proposed Customer Identification Program rules for stablecoin issuers under the GENIUS Act, and the SEC strengthened its enforcement agenda with a unit focused on cybersecurity and emerging technologies.

What is the Treasury Task Force trying to do?

The Quantum-Readiness Task Force is aimed at banks, market infrastructure operators and technology providers that operate in, or with, the U.S. financial system. Its goal is to coordinate the shift to post-quantum cryptography and reduce risks to sensitive financial data. According to Nextgov’s analysis, its work is organized around three tracks: sector migration to post-quantum cryptography, assessment of the readiness of critical third parties and analysis of risks tied to digital assets and emerging technologies.

Another report linked that roadmap to a G7 document that points to 2035 as a general horizon for completing the transition across the international financial system, although that deadline is only indicative and not binding. Federal News Network added that the initiative aligns with a federal executive order requiring high-value assets and high-impact systems to move to post-quantum keys by December 31, 2030, and post-quantum digital signatures by December 31, 2031.

The task force’s practical focus includes improving cryptographic agility, meaning inventorying cryptography use, identifying the most sensitive systems and data, building migration plans and testing technologies resistant to quantum computing. Mallory.ai also said the initiative is meant to reduce risks from quantum threats to sensitive financial information.

What changed for bank exams?

On July 16, 2026, the Fed, the FDIC and the OCC issued a joint statement and official release on a coordinated approach to highly sensitive information during exams of supervised banks. The agencies committed to notify affected banks of material compromises of confidential supervisory information as soon as possible and, in general, no later than 72 hours after discovery. Debevoise & Plimpton said the obligation distinguishes between minor breaches and material compromises.

How is the stablecoin proposal moving forward?

FinCEN and other regulators proposed treating Permitted Payment Stablecoin Issuers as financial institutions for Bank Secrecy Act purposes. That would require them to maintain an AML/CFT program with an integrated Customer Identification Program. VitalLaw detailed that the framework would require customer identification to the extent reasonable and practicable, based on risk, and would require collecting a natural person’s name, date of birth, address and identification, plus the date of formation for legal entities.

The proposal also calls for verifying identity within a reasonable time, setting procedures to close or avoid opening accounts when the customer cannot be verified, and considering the filing of a Suspicious Activity Report. Issuers would also need reasonable procedures to check whether a customer appears on terrorist or terrorist organization lists issued by federal agencies and designated by the Treasury. The BPI and The Clearing House Association submitted comments on the proposal, while the Crypto Council for Innovation argued that the CIP should be limited to the issuer’s primary customer relationship and not extend to secondary users in secondary markets.

What is happening with model and AI supervision?

On April 17, 2026, the OCC, the Federal Reserve and the FDIC issued revised interagency guidance on model risk management, identified as OCC Bulletin 2026-13. It replaces the 2011 interagency framework, rescinds OCC guidance 2011-12 and also rescinds SR 11-7. The new issuance, referenced in other materials as SR 26-2 and FIL-15-2026, explicitly incorporates quantitative and machine learning models, but temporarily excludes generative and agentic AI, which remain under each institution’s general risk management programs.

Diligent said the framework is principles-based and that a lack of formal compliance alone should not lead to supervisory criticism, although it could still affect the overall assessment of a model risk profile. It also said the agencies expect the guidance to matter most for banking organizations with more than $30 billion in total assets, or smaller firms with significant model exposure. BankingNewsAI added that the Fed plans to publish an interagency request for information on AI and model risk, with a focus on machine learning and high-impact use cases.

What other regulatory pressure remains in place?

The FTC continues to enforce the Gramm-Leach-Bliley Act data protection framework, which requires financial institutions to explain their information-sharing practices to consumers and safeguard sensitive data. Its Safeguards Rule materials also require a comprehensive information security program with administrative, technical and physical safeguards, risk assessments, encryption and oversight of vendors that process customer information.

On the supervision and enforcement front, the SEC reported 456 actions in fiscal 2025 and recovered about $17.9 billion, according to SaltyCloud. The agency also launched a Cyber and Emerging Technologies Unit focused on AI-washing, insider hacking and cybersecurity disclosure fraud. Global Finance Magazine also warned that the limited liability protection under the Cybersecurity Information Sharing Act of 2015 will expire on September 30, 2026 if it is not renewed, which could expose companies that share cybersecurity information in the United States to greater scrutiny and penalties.

In parallel, Crypto.news noted that the U.S. crypto regulatory web involves FinCEN, the OCC, the Federal Reserve, the FDIC, OFAC and the IRS, with registration, sanctions, cybersecurity and transaction monitoring obligations for institutions operating in the U.S. financial system.

Sources

View all