NobleCloak
Governance Watch

SR 26-2 carved generative AI out of model-risk rules

Author

Audrey

NobleCloak's AI Correspondent · AI-drafted, fact-checked against our sourced evidence before publishing.

Date Published

What happened

On April 17, 2026, the Federal Reserve issued SR 26-2, "Revised Guidance on Model Risk Management," superseding the long-standing SR 11-7. The revised guidance keeps the familiar model-risk architecture — sound development, effective validation, and governance across a model's life cycle — and applies it to traditional statistical and quantitative models and to non-generative, non-agentic AI models.

The line that matters for anyone thinking about AI: in a footnote, the guidance states that generative AI and agentic AI models are novel and rapidly evolving and are not within the scope of this guidance. It hands responsibility back to the institution, saying a banking organization's own risk-management and governance practices should determine the appropriate controls for tools not covered here.

The other boundary to keep in mind is size. SR 26-2 is expected to be most relevant to banking organizations with more than $30 billion in total assets. Smaller institutions are generally outside its direct reach. So for most credit unions and community banks, SR 26-2 is neither their rule nor the rule that governs the AI they're most anxious about. That double exclusion is the whole story.

Why it matters

Read plainly, SR 26-2 says two things at once: the AI you're most worried about (generative and agentic) is out of scope, and this guidance is aimed at institutions far larger than you anyway. It is tempting to treat that as relief. It is the opposite.

A carve-out is not the absence of risk — it's the absence of a rulebook for a risk that still exists. SR 11-7 gave a generation of model-risk officers a shared vocabulary and a checklist: identify the model, validate it, govern it, document it. When the Fed explicitly removes generative and agentic AI from that framework, it doesn't remove the risk those systems carry. It removes the scaffolding you'd normally lean on to manage it. The obligation doesn't disappear; it gets pushed back onto your own governance, with the regulator's own words telling you to figure it out.

This is the pattern worth internalizing, because you'll see it again and again in 2026: regulators are describing the gap, not filling it. SR 26-2 names generative AI as novel and evolving and declines to scope it. That is a supervisor telling you, in writing, that the controls are your responsibility and that "there's no specific rule yet" is not a defense — it's a description of exactly the space where examiners will start asking what you did. Fed Vice Chair for Supervision Bowman's May 2026 remarks on AI in the financial system point the same direction: the supervisory posture is risk-based and institution-led, not prescriptive-checklist. The homework is yours.

What it means for you

If you're a credit union or community bank: SR 26-2 is not your rule — you're under the NCUA or your prudential regulator, and you're almost certainly below the $30B line. Don't skip it, though. It's the reference point everything else gets measured against, and its carve-out logic is the logic your own examiner will inherit. The do-this-Monday version:

  • Inventory your generative-AI touchpoints — every place a large-language-model tool influences a decision, a communication, or a customer interaction, whether it's your own tool or a feature a vendor added. This is the surface SR 26-2 explicitly declined to cover, which means it's the surface you own outright. (The mechanics are in running an AI data call.)
  • Don't wait for a generative-AI rule to build governance. The signal from SR 26-2 is that the rule may not come soon, and the expectation exists anyway. Apply the spirit of model-risk discipline — know what the tool does, who validated it, how it's monitored — even where the letter of SR 26-2 doesn't reach.

If you're a larger bank inside SR 26-2's scope: the revised guidance is now your operative model-risk framework for traditional and non-generative AI models — align your program to it. But the harder work is the carve-out. Your generative and agentic AI is governed by your practices, and an examiner reviewing your risk management will expect those practices to exist, be documented, and be proportionate. Build the generative-AI governance SR 26-2 chose not to prescribe, because "not in scope" reads to a supervisor as "your job," not "no job."

For everyone: the vendor angle is the sharp one. Your third-party providers are adding generative and agentic AI to their products — the exact category SR 26-2 excludes. So the AI entering your institution through your vendors sits in the least-scoped, least-scaffolded corner of the entire regulatory map. That's not comfort. That's the corner examiners will get curious about first.

How to get ahead of it

The prepared institution treats the carve-out as an invitation to set its own standard before anyone sets it for them. Concretely: take the discipline SR 11-7 taught your model-risk team and extend it, in a lightweight way, to the generative and agentic AI the new guidance leaves uncovered. You don't need a validation team and a quarterly model-review committee for a chatbot. You need to be able to answer, on paper: what does this AI do, whose is it, what did we check before trusting it, and how would we know if it started behaving badly?

Do that for your vendors' AI too, because that's where most of your generative-AI exposure actually lives. A vendor-oversight file that captures each provider's AI features, subprocessors, and data behavior is the same artifact that satisfies Reg S-P service-provider oversight on the RIA side and NCUA vendor diligence on the credit-union side. One file, several exams. That's the leverage.

If you want the crosswalk that turns "we have no framework" into examiner-legible language, NIST's AI Risk Management Framework is the vocabulary supervisors already recognize — and it covers exactly the generative-AI space SR 26-2 stepped around.

What to watch out for

The overreaction cuts both ways. One camp reads "not in scope" as "no obligation" and does nothing — that's the institution that gets an uncomfortable exam conversation. The other camp overbuilds, importing a full quantitative-model validation regime onto a summarization tool, and burns a one- or two-person compliance program to the ground on process theater. Neither survives contact with a risk-based examiner.

The specific snake-oil to reject: vendors marketing "SR 26-2 compliance" products. There is nothing to be compliant with for generative AI under SR 26-2 — the guidance explicitly excluded it. Any tool selling you SR-26-2-flavored generative-AI compliance is selling you a rule that doesn't exist. What genuinely helps is more modest and more honest: something that inventories your AI surface, structures a proportionate review, and keeps the evidence current — so that when an examiner asks what you did in the space the Fed left open, you have a dated, defensible answer.

The bottom line

SR 26-2 didn't relieve you of anything — it drew a boundary and left generative and agentic AI on the outside of it, with your own governance named as the backstop. For most credit unions and community banks the guidance won't apply directly, but its logic will: the risk is real, the rulebook is absent, and the burden lands on you. Getting ahead of it means governing the AI the regulators declined to scope — starting with the AI your vendors are quietly adding, which is exactly the exposure a Discover scan is built to surface.

Request your Discover scan. We run it with you.