NobleCloak
Governance Watch

The AI model-risk RFI is coming

Author

Audrey

NobleCloak's AI Correspondent · AI-drafted, fact-checked against our sourced evidence before publishing.

Date Published

What happened

The regulatory groundwork for a real AI rule in banking has been laid, piece by piece, and it's worth reading the sequence because it tells you where this is heading. In June 2024, the U.S. Treasury issued a Request for Information on the uses, opportunities, and risks of AI in financial services and drew 103 comment letters. The resulting report recommended that regulators coordinate to enhance risk-management frameworks, clarify supervisory expectations for AI, and consider how existing tools like NIST's AI Risk Management Framework align with prudential standards. In 2026, Treasury followed up with a shared AI lexicon and a Financial Services AI Risk Management Framework — the connective tissue a future rule would need.

Meanwhile, the banking regulators sent the opposite-looking signal. In April 2026, the Federal Reserve's SR 26-2 revised model-risk guidance and explicitly carved generative and agentic AI out of scope — aimed at the largest banks, and declining to prescribe controls for exactly the AI everyone's anxious about.

Put those together and you get a live regulatory vacuum with a lot of scaffolding being built around its edges. Nobody has published the prescriptive AI model-risk rule yet. But a lexicon, a framework, a completed RFI cycle, and a documented supervisory intent to "clarify expectations" are what tends to come before one. This post is about what to expect when the next request for information — or the rule it seeds — actually lands. Read the timing as expectation, not certainty: we're reading a docket, not a done deal.

Why it matters

Here's the counterintuitive part every small institution should sit with: a real, prescriptive AI rule would probably make your compliance life harder, not easier.

The instinct is to wait for the rule as if it will bring clarity and, with clarity, relief. And it's true that a rule ends the guessing. But look at what SR 11-7 meant for model risk once it was the standard: model inventories, documented development standards, independent validation, ongoing monitoring, governance committees, examination against all of it. A rule doesn't remove work — it specifies work, and then examiners hold you to the specification. Today, a small institution operates in a low-formality, high-uncertainty world: not much prescribed, so not much to fail — but also no safe harbor, and an examiner free to ask what you did. A prescriptive AI model-risk rule flips that to high-formality: now there's a checklist, and the checklist is the exam.

For a bank or credit union running compliance on one or two people, "more specification" is not obviously good news. The institutions with model-validation teams absorb a new rule as process. The one- and two-person shops absorb it as a mountain of new documentation, arriving on a deadline, for AI they may barely have inventoried. That's the asymmetry to plan around: the rule everyone's waiting for lands hardest on the smallest.

That's also why the current SR 26-2 carve-out is exposure and not relief — a point we made in full in why the SR 26-2 carve-out isn't the relief it sounds like. The vacuum is temporary. The scaffolding says so.

What it means for you

If you're a credit union: you're not under SR 26-2, and you're almost certainly below the asset thresholds any first AI model-risk rule would target. But NCUA reasons from the same prudential playbook, and — because NCUA can't examine your AI vendors directly — the diligence burden already lands on you by structural design. The do-this-now version: build a proportionate AI inventory and a light governance record before a rule sets the format. Know what AI operates in your institution and in your vendors' products, who validated it, and how you'd notice if it misbehaved. When a rule or RFI arrives, you're formatting existing evidence instead of starting cold. Start with an AI data call.

If you're a community or regional bank: you may be closer to the line a first rule draws. Read every AI-related RFI and proposed rule as it comes, and comment if you can — RFIs are the rare moment when small institutions can shape a rule before it's written to a big-bank template that then crushes them on implementation. Between now and then, extend the model-risk discipline you already run to your generative and agentic AI in a lightweight way, so a future rule is an alignment exercise, not a rebuild.

For both: the vendor dimension is where a future rule will bite hardest and where you can prepare most cheaply now. Your third parties are adding AI faster than any rulebook moves, and a prescriptive rule will almost certainly reach the AI your vendors supply. A current vendor-oversight file — what each provider's AI does, what it touches, what's documented — is the artifact a future rule will ask for, and it does double duty for Reg S-P and NCUA diligence today.

How to get ahead of it

The prepared institution treats the absence of a rule as its build window. Three moves:

  1. Watch the docket. Follow the Federal Register and your prudential regulator for AI-related RFIs and proposed rules. When one opens, read it — and if it's an RFI, consider commenting. The comment window is the cheapest influence you'll ever have on a rule that will cost you to implement.
  2. Build the inventory and the governance record now, proportionately. Not a validation lab — a defensible answer to what AI do we and our vendors use, who checked it, and how would we know if it failed? Map it to a vocabulary regulators already recognize; NIST's AI RMF and Treasury's own framework are the crosswalks a future rule will most likely echo.
  3. Keep it current. A rule that arrives in 2027 will ask about the AI you're running then, and both your stack and your vendors' will have drifted. A living file beats a heroic pre-exam scramble — the case is in point-in-time vs. continuous monitoring.

Do those, and whenever the RFI or the rule lands, it's a formality for you — the difference between reformatting evidence you already have and manufacturing evidence you don't.

What to watch out for

The first trap is waiting. "There's no rule yet" is not a reason to do nothing; it's the window in which doing something is cheap. The institutions that wait for the rule to tell them what to build are the ones who then build it all at once, on a deadline, understaffed.

The second is over-preparing to a rule that doesn't exist yet — importing a full quantitative-model-validation regime onto a summarization tool because you're bracing for the strictest possible outcome. You don't yet know the rule's thresholds or shape; building to your worst guess burns a small compliance program on process theater. Build proportionate governance now and scale it when the actual specification appears.

And be skeptical of any vendor selling "AI model-risk rule compliance" today. There is no such rule to comply with yet. What's real and useful is more modest: a current inventory, a proportionate governance record, and evidence kept fresh — so that when the rule does arrive, you're aligning, not scrambling.

The bottom line

The AI model-risk rule everyone is waiting for won't be relief for a small institution — a prescriptive rule specifies work and then examines you against it, and that lands hardest on the one- and two-person programs. The vacuum you're in now is the build window: inventory your AI and your vendors' AI, keep a proportionate governance record, and watch the docket so the rule is a formality when it comes. Surfacing and maintaining that inventory — especially the AI your vendors quietly add — is exactly what a Discover scan is built to do.

Request your Discover scan. We run it with you.