Feature AI Risk
SR 26-2 Covers Your Models. It Doesn't Cover Your AI Agents.
The Fed, OCC, and FDIC rewrote model risk management in April 2026. SR 26-2 preserves the validation-first framework that's governed banking AI for 15 years — and explicitly carves out generative and agentic AI, leaving a governance gap at exactly the moment banks need it most.
Table of Contents
You spent 15 years building a model risk management program to SR 11-7 specifications. Validation pipelines, model inventory, effective challenge, governance committees — the whole apparatus. In April 2026, the Fed, OCC, and FDIC replaced that framework with SR 26-2.
Here’s what they didn’t tell you loudly enough: your generative AI tools and AI agents aren’t covered by it.
SR 26-2 explicitly excludes generative AI and agentic AI from its formal scope. Not as an oversight — by name. The guidance acknowledges these technologies are “novel and rapidly evolving” and tells banks to rely on “broader risk management and governance practices” to govern them.
What counts as broader risk management practices? The guidance doesn’t say. Which means if you built your AI governance program around SR 26-2 and called it done, you have a gap — probably a large one — right at the edge of the regulation.
TL;DR
- SR 26-2 (April 2026) replaces SR 11-7 with a materiality-sensitive model risk framework for large banks
- Generative AI and agentic AI are explicitly excluded from SR 26-2’s formal scope
- Banks are deploying GenAI fastest precisely where the guidance is silent
- The FS AI RMF (Feb 2026) and NIST AI RMF are emerging as the de facto standards for filling the gap
- Fed, OCC, FDIC, FINRA, and SEC examiners are all sharpening AI oversight expectations regardless
What SR 26-2 Actually Changed
SR 11-7 was issued in 2011. At the time, the dominant banking models were credit scorecards, stress-testing engines, and DFAST models. The guidance built a framework around those tools: independent validation, model inventory, challenger models, ongoing monitoring, and governance through a model risk committee.
That framework wasn’t wrong — it worked reasonably well for what it was designed to cover. But 15 years of AI development happened between SR 11-7 and the world banks actually operate in today.
SR 26-2 makes three substantive changes worth understanding.
Materiality replaces uniformity. Under SR 11-7, every model was subject to the same basic validation requirements regardless of its actual risk. SR 26-2 introduces a formal materiality framework that combines two factors: model exposure (the quantitative financial impact if the model fails or misbehaves) and model purpose (the qualitative, strategic, or regulatory importance of the model). The combination determines how rigorous your validation needs to be. A low-exposure, low-purpose model can get lighter treatment; a high-exposure model embedded in credit decisioning gets the full stack.
This is a practical improvement. It lets risk teams stop arguing about whether the model that ranks branch locations for drive-through upgrades needs the same validation burden as the CCAR stress-testing framework.
The definition of model got modernized — partly. SR 26-2 broadens the functional definition of a model to better capture complex systems that take inputs and produce outputs influencing financial decisions. It explicitly includes machine learning models used in credit underwriting, fraud detection, BSA/AML transaction monitoring, and algorithmic trading.
GenAI and agentic AI are carved out by name. This is the part that should be keeping chief model risk officers up at night. The guidance states directly that its model definition “does not capture all AI systems” and singles out generative AI and agentic AI as excluded because of their novel, rapidly-evolving nature. Banks are instructed to apply “broader risk management and governance practices” to determine appropriate controls.
That instruction is real. It is not permission to ignore those systems. But it leaves the entire design of AI agent governance to individual institutions, without a shared benchmark.
The Governance Gap in Practice
If you’re running SR 26-2-compliant model risk management, you have a validated, inventoried, and governed framework for your traditional models. Your credit models, your AML scoring, your fraud detection algorithms — all properly registered, validated, and monitored.
Now walk through your actual AI deployment inventory:
- Your underwriting team is using a GenAI assistant to draft adverse action notices
- Your BSA team has deployed an AI agent that reviews SAR drafts before analyst sign-off
- Your customer service function runs an LLM-powered chatbot handling account inquiries and dispute intake
- Your treasury desk uses an AI system to surface market data patterns and suggest hedging strategies
Which of those are in your model inventory? Which have been validated? Which have documented failure modes, fallback procedures, and monitoring thresholds?
If you’re being honest, the answer for most large banks is: some are, some aren’t, and the governance is inconsistent. That’s the gap SR 26-2 doesn’t fill.
FINRA’s 2026 Regulatory Oversight Report makes the same point from the broker-dealer side — examiners are asking firms to account for AI agent decision-making in their supervisory frameworks, with or without specific written guidance. The expectation is there even when the rule isn’t.
What Examiners Are Actually Looking For
SR 26-2 is non-binding guidance, not a rule. That matters legally. It matters much less in practice.
Examiners from the Federal Reserve, OCC, and FDIC routinely cite non-binding guidance in examination findings when institutions deviate from it. “SR 26-2 expects” is a phrase that will appear in examination reports for large banks that fail to maintain adequate model governance — including, almost certainly, governance of AI systems that technically fall outside the guidance’s scope.
The SEC’s FY 2026 Examination Priorities explicitly sharpen expectations around AI use, governance documentation, and disclosure accuracy. FINRA’s 2026 Oversight Report elevates GenAI risk as an examination focus for broker-dealers. Texas TRAIGA has been in effect since January 2026 for financial services companies operating in Texas.
The regulatory expectation is converging even as the written guidance lags behind deployment reality.
For most large banks, the examination risk for inadequate GenAI governance isn’t theoretical. It’s a matter of when, not whether.
The FS AI RMF: Filling the Gap
The Cyber Risk Institute released its Financial Services AI Risk Management Framework (FS AI RMF) on February 12, 2026. The document adapts NIST’s AI Risk Management Framework into 230 control objectives specifically calibrated for banking and financial services.
The FS AI RMF spans four domains: governance, model development, third-party risk, and consumer protection. Unlike the NIST AI RMF (which is generic across industries), the FS AI RMF maps directly to banking regulatory concepts — so a control objective around AI model monitoring speaks the language of model risk management rather than abstract AI safety principles.
For institutions trying to fill the SR 26-2 gap for GenAI and agentic AI, the FS AI RMF is currently the most practically actionable framework available. It’s not the only option — NIST’s draft Cyber AI Profile is also shaping what “secure AI” looks like in practice — but the FS AI RMF has the advantage of being built by and for banking practitioners.
A handful of larger institutions have begun mapping their GenAI programs to FS AI RMF control objectives explicitly in model risk committee documentation, treating it as a documented methodology that responds to the “broader risk management practices” instruction in SR 26-2. That approach has the virtue of being auditable and explainable to examiners.
Building the GenAI Governance Layer
If you haven’t already, the work is straightforward to define — harder to execute, but straightforward to scope.
Step one is inventory. You cannot govern what you haven’t catalogued. Every AI system in production that takes financial-services-relevant inputs and produces outputs influencing any decision — credit, compliance, operations, customer service — should be on a list. GenAI assistants, LLM-powered tools, AI agents, automated scoring systems not covered under SR 26-2 proper. All of them.
Step two is risk tiering. Not every GenAI system carries the same risk. An AI tool that drafts internal memos has different consequences from an AI agent that routes SAR filings or scores credit applications. Apply a simplified version of SR 26-2’s materiality concept: exposure and purpose. High-exposure, high-purpose systems get more governance. Low-exposure systems get lighter treatment and periodic review.
Step three is governance documentation. For each tier, define: who approved deployment, what the system does, what inputs it uses, what outputs it produces, what failure modes exist, how you detect drift or misbehavior, and who is accountable. This is not a validation in the SR 26-2 sense — but it’s auditable documentation that demonstrates intentional, deliberate governance rather than unmanaged proliferation.
Step four is ongoing monitoring. AI systems change. The underlying models get updated. Prompts drift. Usage expands beyond original scope. Establish review triggers: when does a GenAI tool get re-evaluated? Quarterly? On model updates? On significant use-case expansion?
None of this requires creating a parallel MRM apparatus. It requires extending your existing governance instincts to cover the tools SR 26-2 left on the table.
The Real Risk of Waiting
There is a version of this problem that becomes dramatically more expensive over time. Banks that let GenAI governance drift — no inventory, no documentation, no accountability structure — accumulate exposure that’s hard to address retroactively.
The pattern from traditional model risk applies here. Early in the deployment cycle, governance documentation is cheap. You’re deploying a few systems, the scope is manageable, the institutional memory is fresh. Three years in, when you’re trying to reconstruct the governance rationale for 40 AI systems deployed without consistent methodology, the remediation is painful and expensive.
SR 26-2 gave large banks a modernized framework for the models they built over the last 15 years. For the AI they’re deploying right now, the framework hasn’t arrived yet. The prudent move is to build the governance layer before examiners start asking why it doesn’t exist.
So What?
SR 26-2 is genuinely useful. The materiality framework is a practical improvement over SR 11-7’s one-size-fits-all approach, and the updated model definition covers a wider range of ML systems than the 2011 guidance.
But if you’re deploying generative AI or AI agents in any banking function — and you almost certainly are — SR 26-2 doesn’t govern those systems. It says so explicitly.
The gap is real. The examiner expectations are also real, and they’re growing. The FS AI RMF provides a workable methodology for filling the gap. The time to build that layer is now, while deployment is still manageable and before an examination finding forces the conversation.
Your model inventory is in good shape. Your AI agent inventory probably isn’t. That’s the actual problem.
Building your AI risk governance program? The AI Risk Assessment Template gives you a pre-built framework for inventorying, tiering, and documenting AI systems across your organization — designed for banking and financial services practitioners.
External sources:
- What Changes with SR 26-2: Model Risk Management Guidance — Domino.ai
- SR 26-2: Model Risk Management Guidance Explained — Domino.ai
- SR 26-2 Regulates Your Models, Not Your AI Agents — CIMCON Software
- SR 26-2: What Every Bank Needs to Know — ValidMind
- Governing Generative AI: An SR 26-2-Compatible Framework — arXiv
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is SR 26-2?
Does SR 26-2 cover generative AI and AI agents?
Who does SR 26-2 apply to?
What's the key difference between SR 26-2 and SR 11-7?
What framework should banks use for GenAI governance since SR 26-2 doesn't cover it?
Will examiners hold banks accountable for GenAI even though SR 26-2 excludes it?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
AI Risk
Texas's TRAIGA Has Been in Effect for Eight Months. If Your AI Touches Financial Decisions for Texas Residents, Here's What's Actually Required.
The Texas Responsible AI Governance Act (TRAIGA) took effect January 1, 2026. The final law is narrower than feared — but financial services firms using AI in credit, insurance, or banking decisions have real obligations. Here's what they are.
Sep 11, 2026
AI Risk
FINRA's 2026 Oversight Report Moved Agentic AI to Active Examination Priority. Examiners Are Now Asking About It. Here's What Broker-Dealers Need in Place.
FINRA's 2026 Annual Regulatory Oversight Report formally classified agentic AI as an active supervisory priority, with examinations targeting broker-dealer governance in Q2-Q3 2026. Here is what examiners are asking about and what your program needs to have documented.
Sep 10, 2026
AI Risk
Cox Media Group's 'Active Listening' Fallout: What the FTC Settlement Means for AI Vendor Due Diligence
The FTC finalized consent orders against Cox Media Group and two smaller firms on August 27, 2026, over deceptive 'active listening' AI claims — marketing that phones were capturing voice data to target ads. They weren't. The $930,000 in penalties and 20-year oversight period signal what the FTC will do with vendors who overclaim AI capabilities. Here's what your AI vendor due diligence program needs to cover.
Sep 6, 2026