AI Regulation Tracker / Banking and finance
US Bank Regulators Revise Model Risk Guidance and Leave AI Outside the Formal Scope
Effective April 17, 2026, SR 26-2 supersedes SR 11-7 and SR 21-8. It modernizes model risk management but places generative and agentic AI outside the formal framework, while saying existing risk expectations still apply. That gap is now yours to fill.
For fifteen years, SR 11-7 was the model risk bible. If your bank built a model, SR 11-7 told you how to govern it, from development and validation through ongoing monitoring, and examiners cited it constantly. SR 26-2 retires it. Issued on April 17, 2026 and effective the same day, the revised guidance reflects, in the agencies' words, "supervisory experience and industry feedback accumulated over the past fifteen years, as well as significant advancements in modeling practices." That alone would be worth reading. The part that finance and model risk teams need to sit up for is what the agencies decided to leave out.
What did SR 26-2 do with AI?
It carved the newest AI out of the formal framework. The agencies characterized generative AI and agentic AI as novel and rapidly evolving and placed them outside the scope of the revised model risk management guidance. Traditional statistical and quantitative models remain fully in scope. Non-generative, non-agentic machine learning models remain in scope. It is specifically the generative and agentic layer, the large language models and the autonomous AI agents, that the agencies decided not to fold into the formal model risk process yet. They also signaled a separate Request for Information on AI, generative AI, and agentic AI model risk, which as of mid-2026 had not been published.
Does the carveout mean generative AI is unregulated?
No, and this is the trap. Excluded from the formal model risk framework is not the same as exempt from oversight. The guidance is explicit that "existing risk management expectations still apply." Your operational risk, third-party risk, compliance, and consumer protection obligations do not switch off because a tool happens to be a large language model. What changed is that you no longer have the tidy SR 11-7 playbook to apply to these systems by default. The agencies pulled generative and agentic AI out of the one framework that would have told you exactly how to govern them, and left the general expectation that you govern them anyway. That is a gap, and gaps in supervisory expectations tend to get filled at the worst possible moment, during an exam or after a loss.
What should CPAs and finance teams do about the gap?
Fill it deliberately, in writing, before anyone asks. The practical program looks a lot like model risk management even though the formal guidance no longer requires it here. Assign clear ownership for every generative or agentic AI tool in production, so there is a named accountable person. Run a documented pre-deployment review before an AI tool goes live in a finance or reporting workflow. Put post-deployment monitoring in place for the things that actually go wrong with these systems, such as hallucination rates, error and complaint tracking, and the accuracy of anything that feeds a customer decision. Assess your third-party AI vendors under the existing 2023 interagency third-party risk guidance. And where you want a recognized control set, the Treasury financial services AI risk management framework gives you a voluntary one to lean on. The point is not to wait for the promised RFI. It is to have documented governance in place now, because in a carveout the burden shifts to you.
One more note on status, because precision matters here. SR guidance is supervisory guidance, not a regulation, and the agencies have said as much about guidance generally in the past. It does not create binding legal obligations the way a rule does. But treating that as permission to relax would be a mistake. This is the framework examiners will use, it is what your board and audit committee will be measured against, and it is what a plaintiff will point to when a generative AI tool produces a bad financial outcome. Govern to it as if it matters, because in practice it does.
Questions professionals are asking
What is SR 26-2 and what did it replace?
SR 26-2 is the federal banking agencies' revised guidance on model risk management, issued and effective April 17, 2026. It supersedes SR 11-7 from 2011 and SR 21-8 from 2021, modernizing supervisory expectations after fifteen years of change in modeling practice.
Are generative AI and agentic AI covered by SR 26-2?
No. The agencies treated generative AI and agentic AI as novel and rapidly evolving and placed them outside the formal model risk management scope. Traditional statistical models and non-generative machine learning models stay in scope. A separate Request for Information on AI model risk was signaled but not yet published as of mid-2026.
If AI is carved out, do we still have to govern it?
Yes. The guidance says existing risk management expectations still apply. The carveout means the formal model risk playbook does not automatically cover generative and agentic AI, not that those tools are exempt. Your operational, third-party, compliance, and consumer protection obligations remain.
What should finance and model risk teams do now?
Build documented governance for every generative and agentic AI tool in production: assign ownership, run pre-deployment review, monitor post-deployment for issues like hallucinations and error rates, and assess vendors under the 2023 third-party risk guidance. The Treasury financial services AI risk framework offers a voluntary control set to lean on.
RELATED BRIEFINGS
- Browse the full AI Regulation Tracker
- Federal Reserve SR 26-2, Revised Guidance on Model Risk Management (primary source)
- Canada OSFI Guideline E-23 on model risk for AI and ML
- Treasury financial services AI risk management framework and lexicon
- RBI draft model risk management and the AI kill switch
Browse the full AI Regulation News tracker
Informational analysis for working professionals, not legal advice. Confirm how any guidance or requirement applies to your institution with qualified counsel and your primary regulator.