Skip to content
RiskTemplates · The Daily Brief Tuesday, September 15, 2026
Wire SEC's $64 Million Croft & Frost Offering Fraud Case: The Warning Email Compliance Teams Cannot Ignore SEP 14

Feature AI Risk

SR 26-2 Covers Your Models. It Doesn't Cover Your AI Agents.

The Fed, OCC, and FDIC rewrote model risk management in April 2026. SR 26-2 preserves the validation-first framework that's governed banking AI for 15 years — and explicitly carves out generative and agentic AI, leaving a governance gap at exactly the moment banks need it most.

By Rebecca Leung · September 12, 2026 ·
Table of Contents

You spent 15 years building a model risk management program to SR 11-7 specifications. Validation pipelines, model inventory, effective challenge, governance committees — the whole apparatus. In April 2026, the Fed, OCC, and FDIC replaced that framework with SR 26-2.

Here’s what they didn’t tell you loudly enough: your generative AI tools and AI agents aren’t covered by it.

SR 26-2 explicitly excludes generative AI and agentic AI from its formal scope. Not as an oversight — by name. The guidance acknowledges these technologies are “novel and rapidly evolving” and tells banks to rely on “broader risk management and governance practices” to govern them.

What counts as broader risk management practices? The guidance doesn’t say. Which means if you built your AI governance program around SR 26-2 and called it done, you have a gap — probably a large one — right at the edge of the regulation.

TL;DR

  • SR 26-2 (April 2026) replaces SR 11-7 with a materiality-sensitive model risk framework for large banks
  • Generative AI and agentic AI are explicitly excluded from SR 26-2’s formal scope
  • Banks are deploying GenAI fastest precisely where the guidance is silent
  • The FS AI RMF (Feb 2026) and NIST AI RMF are emerging as the de facto standards for filling the gap
  • Fed, OCC, FDIC, FINRA, and SEC examiners are all sharpening AI oversight expectations regardless

What SR 26-2 Actually Changed

SR 11-7 was issued in 2011. At the time, the dominant banking models were credit scorecards, stress-testing engines, and DFAST models. The guidance built a framework around those tools: independent validation, model inventory, challenger models, ongoing monitoring, and governance through a model risk committee.

That framework wasn’t wrong — it worked reasonably well for what it was designed to cover. But 15 years of AI development happened between SR 11-7 and the world banks actually operate in today.

SR 26-2 makes three substantive changes worth understanding.

Materiality replaces uniformity. Under SR 11-7, every model was subject to the same basic validation requirements regardless of its actual risk. SR 26-2 introduces a formal materiality framework that combines two factors: model exposure (the quantitative financial impact if the model fails or misbehaves) and model purpose (the qualitative, strategic, or regulatory importance of the model). The combination determines how rigorous your validation needs to be. A low-exposure, low-purpose model can get lighter treatment; a high-exposure model embedded in credit decisioning gets the full stack.

This is a practical improvement. It lets risk teams stop arguing about whether the model that ranks branch locations for drive-through upgrades needs the same validation burden as the CCAR stress-testing framework.

The definition of model got modernized — partly. SR 26-2 broadens the functional definition of a model to better capture complex systems that take inputs and produce outputs influencing financial decisions. It explicitly includes machine learning models used in credit underwriting, fraud detection, BSA/AML transaction monitoring, and algorithmic trading.

GenAI and agentic AI are carved out by name. This is the part that should be keeping chief model risk officers up at night. The guidance states directly that its model definition “does not capture all AI systems” and singles out generative AI and agentic AI as excluded because of their novel, rapidly-evolving nature. Banks are instructed to apply “broader risk management and governance practices” to determine appropriate controls.

That instruction is real. It is not permission to ignore those systems. But it leaves the entire design of AI agent governance to individual institutions, without a shared benchmark.

The Governance Gap in Practice

If you’re running SR 26-2-compliant model risk management, you have a validated, inventoried, and governed framework for your traditional models. Your credit models, your AML scoring, your fraud detection algorithms — all properly registered, validated, and monitored.

Now walk through your actual AI deployment inventory:

  • Your underwriting team is using a GenAI assistant to draft adverse action notices
  • Your BSA team has deployed an AI agent that reviews SAR drafts before analyst sign-off
  • Your customer service function runs an LLM-powered chatbot handling account inquiries and dispute intake
  • Your treasury desk uses an AI system to surface market data patterns and suggest hedging strategies

Which of those are in your model inventory? Which have been validated? Which have documented failure modes, fallback procedures, and monitoring thresholds?

If you’re being honest, the answer for most large banks is: some are, some aren’t, and the governance is inconsistent. That’s the gap SR 26-2 doesn’t fill.

FINRA’s 2026 Regulatory Oversight Report makes the same point from the broker-dealer side — examiners are asking firms to account for AI agent decision-making in their supervisory frameworks, with or without specific written guidance. The expectation is there even when the rule isn’t.

What Examiners Are Actually Looking For

SR 26-2 is non-binding guidance, not a rule. That matters legally. It matters much less in practice.

Examiners from the Federal Reserve, OCC, and FDIC routinely cite non-binding guidance in examination findings when institutions deviate from it. “SR 26-2 expects” is a phrase that will appear in examination reports for large banks that fail to maintain adequate model governance — including, almost certainly, governance of AI systems that technically fall outside the guidance’s scope.

The SEC’s FY 2026 Examination Priorities explicitly sharpen expectations around AI use, governance documentation, and disclosure accuracy. FINRA’s 2026 Oversight Report elevates GenAI risk as an examination focus for broker-dealers. Texas TRAIGA has been in effect since January 2026 for financial services companies operating in Texas.

The regulatory expectation is converging even as the written guidance lags behind deployment reality.

For most large banks, the examination risk for inadequate GenAI governance isn’t theoretical. It’s a matter of when, not whether.

The FS AI RMF: Filling the Gap

The Cyber Risk Institute released its Financial Services AI Risk Management Framework (FS AI RMF) on February 12, 2026. The document adapts NIST’s AI Risk Management Framework into 230 control objectives specifically calibrated for banking and financial services.

The FS AI RMF spans four domains: governance, model development, third-party risk, and consumer protection. Unlike the NIST AI RMF (which is generic across industries), the FS AI RMF maps directly to banking regulatory concepts — so a control objective around AI model monitoring speaks the language of model risk management rather than abstract AI safety principles.

For institutions trying to fill the SR 26-2 gap for GenAI and agentic AI, the FS AI RMF is currently the most practically actionable framework available. It’s not the only option — NIST’s draft Cyber AI Profile is also shaping what “secure AI” looks like in practice — but the FS AI RMF has the advantage of being built by and for banking practitioners.

A handful of larger institutions have begun mapping their GenAI programs to FS AI RMF control objectives explicitly in model risk committee documentation, treating it as a documented methodology that responds to the “broader risk management practices” instruction in SR 26-2. That approach has the virtue of being auditable and explainable to examiners.

Building the GenAI Governance Layer

If you haven’t already, the work is straightforward to define — harder to execute, but straightforward to scope.

Step one is inventory. You cannot govern what you haven’t catalogued. Every AI system in production that takes financial-services-relevant inputs and produces outputs influencing any decision — credit, compliance, operations, customer service — should be on a list. GenAI assistants, LLM-powered tools, AI agents, automated scoring systems not covered under SR 26-2 proper. All of them.

Step two is risk tiering. Not every GenAI system carries the same risk. An AI tool that drafts internal memos has different consequences from an AI agent that routes SAR filings or scores credit applications. Apply a simplified version of SR 26-2’s materiality concept: exposure and purpose. High-exposure, high-purpose systems get more governance. Low-exposure systems get lighter treatment and periodic review.

Step three is governance documentation. For each tier, define: who approved deployment, what the system does, what inputs it uses, what outputs it produces, what failure modes exist, how you detect drift or misbehavior, and who is accountable. This is not a validation in the SR 26-2 sense — but it’s auditable documentation that demonstrates intentional, deliberate governance rather than unmanaged proliferation.

Step four is ongoing monitoring. AI systems change. The underlying models get updated. Prompts drift. Usage expands beyond original scope. Establish review triggers: when does a GenAI tool get re-evaluated? Quarterly? On model updates? On significant use-case expansion?

None of this requires creating a parallel MRM apparatus. It requires extending your existing governance instincts to cover the tools SR 26-2 left on the table.

The Real Risk of Waiting

There is a version of this problem that becomes dramatically more expensive over time. Banks that let GenAI governance drift — no inventory, no documentation, no accountability structure — accumulate exposure that’s hard to address retroactively.

The pattern from traditional model risk applies here. Early in the deployment cycle, governance documentation is cheap. You’re deploying a few systems, the scope is manageable, the institutional memory is fresh. Three years in, when you’re trying to reconstruct the governance rationale for 40 AI systems deployed without consistent methodology, the remediation is painful and expensive.

SR 26-2 gave large banks a modernized framework for the models they built over the last 15 years. For the AI they’re deploying right now, the framework hasn’t arrived yet. The prudent move is to build the governance layer before examiners start asking why it doesn’t exist.

So What?

SR 26-2 is genuinely useful. The materiality framework is a practical improvement over SR 11-7’s one-size-fits-all approach, and the updated model definition covers a wider range of ML systems than the 2011 guidance.

But if you’re deploying generative AI or AI agents in any banking function — and you almost certainly are — SR 26-2 doesn’t govern those systems. It says so explicitly.

The gap is real. The examiner expectations are also real, and they’re growing. The FS AI RMF provides a workable methodology for filling the gap. The time to build that layer is now, while deployment is still manageable and before an examination finding forces the conversation.

Your model inventory is in good shape. Your AI agent inventory probably isn’t. That’s the actual problem.


Building your AI risk governance program? The AI Risk Assessment Template gives you a pre-built framework for inventorying, tiering, and documenting AI systems across your organization — designed for banking and financial services practitioners.

External sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is SR 26-2?
SR 26-2 is the joint supervisory guidance on model risk management issued by the Federal Reserve, OCC, and FDIC in April 2026. It replaces SR 11-7 (from 2011) and applies primarily to banking organizations with more than $30 billion in total assets.
Does SR 26-2 cover generative AI and AI agents?
No. SR 26-2 explicitly excludes generative AI and agentic AI from its formal model definition, citing their novel and rapidly evolving nature. Banks must apply 'broader risk management and governance practices' to these tools — but the guidance doesn't define what that means.
Who does SR 26-2 apply to?
It is primarily targeted at banking organizations with more than $30 billion in total assets regulated by the Federal Reserve, OCC, or FDIC. Community banks face the same sound practice expectations but are not the primary audience.
What's the key difference between SR 26-2 and SR 11-7?
SR 26-2 introduces a formal materiality framework combining model exposure (quantitative financial impact) and model purpose (strategic or regulatory importance). This lets banks calibrate validation rigor to actual risk rather than treating every model identically.
What framework should banks use for GenAI governance since SR 26-2 doesn't cover it?
The Cyber Risk Institute's Financial Services AI Risk Management Framework (FS AI RMF), released February 2026, adapts NIST's AI RMF into 230 control objectives spanning governance, model development, third-party risk, and consumer protection — it's become the de facto standard for filling the GenAI governance gap.
Will examiners hold banks accountable for GenAI even though SR 26-2 excludes it?
Yes. SR 26-2 explicitly tells banks to apply broader governance to excluded tools. FINRA's 2026 Oversight Report and the SEC's FY 2026 Examination Priorities both sharpen expectations around AI — regulators are watching even where written guidance doesn't yet exist.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.