The model-risk rewrite left GenAI ungoverned, and the RFI hasn’t come

April’s SR 26-2 superseded fifteen years of SR 11-7 and explicitly carved generative and agentic AI out of scope, promising an RFI “in the near future.” Four months on, it has not arrived, and the models keep shipping.

Apr 17
SR 26-2 issued
15 yrs
SR 11-7 era ended
Down: Out
GenAI / agentic · of scope
Down: None
RFI issued as of Aug 8

On April 17 the Federal Reserve, OCC, and FDIC issued revised model risk management guidance (SR 26-2, OCC Bulletin 2026-13, FDIC FIL-15-2026). It supersedes SR 11-7, the 2011 document that governed bank model risk for fifteen years. The revision modernizes the framework for statistical and traditional AI models. Then it draws a line. Generative and agentic AI models are explicitly out of scope, described as too “novel and rapidly evolving” to govern in this document.

The agencies paired the carve-out with a promise. They said a request for information on model risk and banks’ use of AI, including generative and agentic AI, would come “in the near future.” As this edition went to press on August 8, no such RFI had been published. The result is a genuine vacuum. The fastest-moving model class in your institution is the one class your model-risk guidance now formally declines to cover.

The gap, precisely

What governs what, as of August 2026
Model classGoverning framework
Traditional statistical & quantitative modelsSR 26-2 (revised guidance)
Non-generative, non-agentic AI/MLSR 26-2 (revised guidance)
Generative AI · agentic AIOut of scope. RFI promised but not yet issued
AI vendors as third partiesInteragency TPRM guidance (unchanged since June 2023)
SR 26-2 · OCC 2026-13 · FIL-15-2026 · April 17, 2026
A carve-out is not a safe harbor. The examiner who agrees your chatbot is outside SR 26-2 will still ask what does govern it, and “nothing” is the wrong answer.

Governing into the vacuum

Two anchors survive. The first is the third-party risk lens. The interagency guidance on third-party relationships has not changed since June 2023, and it still covers every GenAI vendor relationship. Inventory, diligence, and monitoring obligations stand regardless of the model-risk carve-out. The second is that nothing prevents you from applying SR 26-2’s own principles to GenAI voluntarily. That means an inventory entry, a documented validation approach sized to use-case risk, and defined ownership. Banks that do so now will have both a defensible exam answer and a ready-made RFI comment letter.

What this means for your bank
  • State your GenAI governance position in writing. Say which framework you apply voluntarily, to which use cases, and who owns it.
  • Keep GenAI tools in the model inventory even though SR 26-2 does not require it. The inventory is your exam answer.
  • Pre-draft your RFI response now, while the pain points are fresh. The comment window will be short when it finally opens.
From Zovos AI

Zovos maintains your AI use-case inventory with each tool’s governance status, covering framework, validation state and owner. Your own documented policy fills the gap the guidance left.

Sources

This is for information only and is not legal advice. Confirm your obligations against the guidance text and counsel before acting.