Where generative AI sits
Footnote 3 is explicit: "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance." The same footnote adds that a banking organisation’s own risk management and governance practices should determine the controls for anything the document does not cover. For the systems most banks are deploying right now, there is therefore no prescribed control framework to point at. The bank is left to show its own work.
Receipt-field mapping
A receipt turns each model use into a signed, examinable record an independent validator can check against the published key. That matters more where the supervisor has declined to prescribe the controls, not less: the bank has to demonstrate that its own governance held, and a record that can be checked without trusting the party who produced it is harder to argue with. Aqta issues signed evidence, not a model validation or a compliance certification.
Read SR 26-2 on federalreserve.gov or read the full open spec at github.com/Aqta-ai/attestation-spec.