On April 17 the Federal Reserve, OCC, and FDIC issued revised model risk management guidance (SR 26-2, OCC Bulletin 2026-13, FDIC FIL-15-2026). It supersedes SR 11-7, the 2011 document that governed bank model risk for fifteen years. The revision modernizes the framework for statistical and traditional AI models. Then it draws a line. Generative and agentic AI models are explicitly out of scope, described as too “novel and rapidly evolving” to govern in this document.
The agencies paired the carve-out with a promise. They said a request for information on model risk and banks’ use of AI, including generative and agentic AI, would come “in the near future.” As this edition went to press on August 8, no such RFI had been published. The result is a genuine vacuum. The fastest-moving model class in your institution is the one class your model-risk guidance now formally declines to cover.
The gap, precisely
| Model class | Governing framework |
|---|---|
| Traditional statistical & quantitative models | SR 26-2 (revised guidance) |
| Non-generative, non-agentic AI/ML | SR 26-2 (revised guidance) |
| Generative AI · agentic AI | Out of scope. RFI promised but not yet issued |
| AI vendors as third parties | Interagency TPRM guidance (unchanged since June 2023) |
A carve-out is not a safe harbor. The examiner who agrees your chatbot is outside SR 26-2 will still ask what does govern it, and “nothing” is the wrong answer.
Governing into the vacuum
Two anchors survive. The first is the third-party risk lens. The interagency guidance on third-party relationships has not changed since June 2023, and it still covers every GenAI vendor relationship. Inventory, diligence, and monitoring obligations stand regardless of the model-risk carve-out. The second is that nothing prevents you from applying SR 26-2’s own principles to GenAI voluntarily. That means an inventory entry, a documented validation approach sized to use-case risk, and defined ownership. Banks that do so now will have both a defensible exam answer and a ready-made RFI comment letter.
- State your GenAI governance position in writing. Say which framework you apply voluntarily, to which use cases, and who owns it.
- Keep GenAI tools in the model inventory even though SR 26-2 does not require it. The inventory is your exam answer.
- Pre-draft your RFI response now, while the pain points are fresh. The comment window will be short when it finally opens.
Zovos maintains your AI use-case inventory with each tool’s governance status, covering framework, validation state and owner. Your own documented policy fills the gap the guidance left.
This is for information only and is not legal advice. Confirm your obligations against the guidance text and counsel before acting.