On April 17, 2026, the Federal Reserve, the OCC, and the FDIC jointly issued SR 26-2, the first overhaul of bank model risk guidance in fifteen years. It replaces SR 11-7, the 2011 letter that has shaped how every major bank thinks about models ever since.
Buried in a scope footnote is the line that matters most for anyone building or deploying artificial intelligence inside a regulated institution: generative and agentic systems are explicitly carved out. The guidance calls them "novel and rapidly evolving" and states plainly that they are not within its scope, while adding that a bank's existing risk practices should still guide how it controls anything left uncovered.
No binding rule tells a bank how to govern its AI agents.
What SR 26-2 actually covers
SR 26-2 narrows the definition of a "model" and carves out generative and agentic AI by name, leaving three groups.
Traditional AI & machine learning
Credit scoring models, fraud classifiers. Still meets SR 26-2's model definition.
Still regulated
Generative & agentic AI
LLM assistants, autonomous agents. No binding federal rule exists yet.
The gap
Everything else
Fair lending law, safety-and-soundness authority, vendor risk guidance.
Still applies
SR 26-2 narrowed the definition of a regulated “model” and named generative and agentic AI as out of scope, the open lock. Everything outside the new definition still answers to existing law.
Artificial intelligence in banking is not unregulated. One specific part of it is: generative and agentic AI, the category banks are deploying fastest, has no dedicated rulebook, while still carrying full legal exposure under every law that already existed.
Things to know if you are a bank, or a vendor selling into one
- SR 26-2 is voluntary. Non-compliance will not by itself trigger supervisory criticism. That raises the stakes on the carve-out, since there is not even a firm floor for the systems that are in scope, let alone the ones that are not.
- The exclusion was a choice, not an oversight. Legal and consulting commentary consistently frames it as deliberate. The agencies decided the old model-risk apparatus does not fit generative and agentic systems, rather than forgetting to address them.
- The follow-up guidance is still pending. The OCC has said an AI-specific request for information is coming "in the near future." As of the most recent reporting, it has not been published.
- Examiners are not waiting for it. AI governance, vendor risk, and kill-switch capability are already standing topics in routine bank exams, even with no codified standard to point to.
- A regulator has said the guidance falls short. Federal Reserve Vice Chair for Supervision Michelle Bowman has called for a review of whether existing AI guidance is "fit for the future," noting it reaches only traditional models and basic applications.
The scale of the exposure
Industry surveys taken around the same period suggest the gap is not theoretical.
Self-reported readiness for a generative AI failure
Grant Thornton's 2026 AI Impact Survey found the same pattern from inside the banks themselves.
Grant Thornton, 2026 AI Impact Survey, banking sector
82%
of banking leaders could not confidently pass an independent AI controls review within 90 days
18%
said they could
50%
named governance or compliance as a reason their AI underperforms or fails
Banks were also more likely than any other industry the survey covered to describe their own AI controls as untested.
"No dedicated rule" is not the same thing as "no oversight." It is closer to a bank being asked to defend its AI to an examiner using a rulebook that has not been written yet.
What banks are told to do in the meantime
Across the legal and advisory commentary, the consistent advice is to keep governing generative and agentic AI under whatever enterprise risk framework already exists. Apply model-risk-style discipline, documented assumptions, monitoring, human review, even though these systems fall outside SR 26-2's formal definition of a model. And watch for the pending request for information, since public comment on it will be the first real signal of where binding AI-specific standards might land.
One piece of that carries particular weight. Vendor-sourced AI is treated as a third-party relationship under existing federal examination standards, regardless of whether the AI itself falls inside SR 26-2's scope. A bank buying a generative or agentic tool from an outside vendor, a loan-underwriting assistant, a customer service agent, a document review tool, still has to show its examiners it has oversight over that vendor's AI. The bank carries that burden even when the vendor has no dedicated federal standard to build its product against. That mismatch, an obligation on the buyer with no rulebook for the seller, is quietly becoming one of the more consequential downstream effects of the carve-out.
The bank's compliance surface covers everything examiners hold it responsible for. Where a vendor’s ungoverned AI sits inside that surface is exposure the bank owns but did not build.
Our take: start with NIST AI RMF
Banks and vendors should not wait for the RFI to start governing generative and agentic AI. The most practical starting point available today is the NIST AI RMF (National Institute of Standards and Technology AI Risk Management Framework), a voluntary framework the federal government already publishes. It gives both sides a shared structure to build toward now, so the eventual binding rule is a formality rather than a scramble.
The framework organizes AI governance into four functions. Here is what each one covers, and why it matters for a bank or a vendor sitting in the SR 26-2 gap.
- Govern. Organization-wide policy and accountability, who owns AI risk, what gets approved before deployment, how incidents get escalated. This is the piece an examiner will ask for first: proof that someone is responsible, in writing, before anything else is checked.
- Map. Understanding the specific context a given AI system operates in, what it touches, who it affects, what could go wrong. For a vendor's underwriting assistant or adverse-action chatbot, this means documenting exactly where the AI sits in the credit decision, not just that it exists.
- Measure. Testing and monitoring the system against real metrics: accuracy, bias, drift, security. This is where "the model told us to" stops being a defense, since measurement is what produces the evidence a bank can actually show an examiner.
- Manage. Acting on what Measure finds, treating identified risks, running incident response, deciding when to pull a system back. This is the operational half of the "kill switch" capability examiners are already asking about in routine exams.
NIST also publishes a Generative AI Profile (NIST AI 600-1) that maps twelve risk categories specific to generative and agentic systems, prompt injection, confabulation, data leakage, and others, directly onto these four functions. For a bank or a vendor building the credit-decisioning tools described above, that profile is closer to a working checklist than the underlying framework alone. None of this is required today. But building toward it now is the difference between having an answer ready when the rule finally arrives, and starting from zero.
Where Meilynx fits. SR 26-2 places generative and agentic AI outside its scope — and directs institutions to govern them anyway, using existing risk-management principles. Meilynx operationalizes two of the four NIST functions above directly. Govern: policy runs as code, enforced inline on every request and response, not just written down. Measure: every interaction is written to a tamper-evident, hash-chained audit log, so the evidence an examiner asks for already exists rather than needing to be reconstructed after the fact. Curated control presets ship today for SR 11-7, whose inventory, monitoring, and documentation requirements carry forward unchanged under SR 26-2, plus NYDFS 23 NYCRR 500, FINRA 24-09, and SOC 2; the policy engine already enforces NIST AI RMF-aligned controls as well. Raw prompts and responses never leave your perimeter.