Design Partner ProgramWe're accepting applications for the next cohort of design partners in finance, insurance, healthcare, and HR. Apply now →

meilynx
← All posts

The Rule That Isn't There

SR 26-2 rewrote the bank model-risk rulebook for the first time in 15 years, and left out the exact AI systems banks are racing to deploy.

Julia MeloJulia MeloCo-Founder7 min readCompliance

On April 17, 2026, the Federal Reserve, the OCC, and the FDIC jointly issued SR 26-2, the first overhaul of bank model risk guidance in fifteen years. It replaces SR 11-7, the 2011 letter that has shaped how every major bank thinks about models ever since.

Buried in a scope footnote is the line that matters most for anyone building or deploying artificial intelligence inside a regulated institution: generative and agentic systems are explicitly carved out. The guidance calls them "novel and rapidly evolving" and states plainly that they are not within its scope, while adding that a bank's existing risk practices should still guide how it controls anything left uncovered.

No binding rule tells a bank how to govern its AI agents.

What SR 26-2 actually covers

SR 26-2 narrows the definition of a "model" and carves out generative and agentic AI by name, leaving three groups.

Traditional AI & machine learning

Credit scoring models, fraud classifiers. Still meets SR 26-2's model definition.

Still regulated

Generative & agentic AI

LLM assistants, autonomous agents. No binding federal rule exists yet.

The gap

Everything else

Fair lending law, safety-and-soundness authority, vendor risk guidance.

Still applies

SR 26-2 narrowed the definition of a regulated “model” and named generative and agentic AI as out of scope, the open lock. Everything outside the new definition still answers to existing law.

Generative and agentic AI is the exception, and it's the category banks are deploying fastest. It carries full legal exposure under every law that already applies, just without a dedicated rulebook of its own.

Things to know if you are a bank, or a vendor selling into one

  • SR 26-2 is voluntary. Non-compliance will not by itself trigger supervisory criticism. That raises the stakes on the carve-out, since there is not even a firm floor for the systems that are in scope, let alone the ones that are not.
  • The exclusion was a choice, not an oversight. Legal and consulting commentary consistently frames it as deliberate. The agencies decided the old model-risk apparatus does not fit generative and agentic systems, rather than forgetting to address them.
  • The follow-up guidance is still pending. The OCC has said an AI-specific request for information is coming "in the near future." As of the most recent reporting, it has not been published.
  • Examiners are not waiting for it. AI governance, vendor risk, and kill-switch capability are already standing topics in routine bank exams, even with no codified standard to point to.
  • A regulator has said the guidance falls short. Federal Reserve Vice Chair for Supervision Michelle Bowman has called for a review of whether existing AI guidance is "fit for the future," noting it reaches only traditional models and basic applications.

The scale of the exposure

Industry surveys taken around the same period suggest the gap is not theoretical.

Self-reported readiness for a generative AI failure

72%of banks surveyed in June 2026 said they were unprepared for a generative-AI-related failure, even as agentic systems spread through compliance and fraud monitoring.
0%100%

Grant Thornton's 2026 AI Impact Survey found the same pattern from inside the banks themselves.

Grant Thornton, 2026 AI Impact Survey, banking sector

82%

of banking leaders could not confidently pass an independent AI controls review within 90 days

50%

named governance or compliance as a reason their AI underperforms or fails

Not confidentConfident

Banks were also more likely than any other industry the survey covered to describe their own AI controls as untested.

"No dedicated rule" does not mean "no oversight." Banks still have to defend their AI to examiners, without a rulebook to point to.

What banks are told to do in the meantime

The advice is consistent: keep governing generative and agentic AI under existing risk frameworks anyway. Documented assumptions, monitoring, human review, the same discipline SR 26-2 already expects for in-scope models. Watch the pending request for information too; public comment on it will be the first real signal of where binding standards land.

Vendor-sourced AI carries the same weight. Banks already treat any AI they buy from an outside vendor, an underwriting assistant, a customer-service agent, a document-review tool, as a third-party relationship, regardless of whether the AI itself falls inside SR 26-2's scope. That means the bank has to show examiners it has oversight over the vendor's AI, even though the vendor has no federal standard to build against. The gap sits squarely on vendors: their buyers need proof of governance, and there's no rulebook telling vendors what to build.

BankCompliance surfaceVendorAI workflowsand featuresRisk exposureUngoverned vendor AI inside the bank’s obligation

The bank's compliance surface covers everything examiners hold it responsible for. Where a vendor’s ungoverned AI sits inside that surface is exposure the bank owns but did not build.

Our take: start with NIST AI RMF

Banks and vendors should not wait for the RFI to start governing generative and agentic AI. The most practical starting point available today is the NIST AI RMF (National Institute of Standards and Technology AI Risk Management Framework), a voluntary framework the federal government already publishes. It gives both sides a shared structure to build toward now, so the eventual binding rule is a formality rather than a scramble.

The framework organizes AI governance into four functions. Here is what each one covers, and why it matters for a bank or a vendor sitting in the SR 26-2 gap.

  • Govern. Organization-wide policy and accountability, who owns AI risk, what gets approved before deployment, how incidents get escalated. This is the piece an examiner will ask for first: proof that someone is responsible, in writing, before anything else is checked.
  • Map. Understanding the specific context a given AI system operates in, what it touches, who it affects, what could go wrong. For a vendor's product, this means documenting exactly where the AI sits in the customer's workflow and what decision it influences, not just that it exists.
  • Measure. Testing and monitoring the system against real metrics: accuracy, bias, drift, security. This is where "the model told us to" stops being a defense, since measurement is what produces the evidence a bank can actually show an examiner.
  • Manage. Acting on what Measure finds, treating identified risks, running incident response, deciding when to pull a system back. This is the operational half of the "kill switch" capability examiners are already asking about in routine exams.

NIST also publishes a Generative AI Profile (NIST AI 600-1) that maps twelve risk categories specific to generative and agentic systems, prompt injection, confabulation, data leakage, and others, directly onto these four functions. For a bank or a vendor building AI products like these, that profile is closer to a working checklist than the underlying framework alone. None of this is required today. But building toward it now is the difference between having an answer ready when the rule finally arrives, and starting from zero.

Banks also have a version of this already translated into their world. In February 2026 the U.S. Treasury released the Financial Services AI Risk Management Framework, which the Cyber Risk Institute built with the FSSCC and more than 100 financial institutions. It keeps NIST's four functions and breaks them into 230 control objectives, each tagged to how far along a firm is with AI, so a bank with one internal chatbot and a bank running agents in underwriting don't get handed the same to-do list. Like NIST's framework, it's voluntary. We've written up how it fits next to the SR 26-2 carve-out, with the footnote quoted in full.

Where Meilynx fits. Meilynx operationalizes two of the four NIST functions above directly. Govern: policy runs as code, enforced inline on every request and response, not just written down. Measure: each response the proxy delivers and each request it blocks is written to a tamper-evident, hash-chained audit log, so the evidence an examiner asks for already exists rather than needing to be reconstructed after the fact. Curated control presets ship today for SR 11-7, whose inventory, monitoring, and documentation requirements carry forward unchanged under SR 26-2, plus NYDFS 23 NYCRR 500, FINRA 24-09, and SOC 2; the policy engine already enforces NIST AI RMF-aligned controls as well. Raw prompts and responses never leave your perimeter.

More from the blog

Regulatory updates

When a regulator changes what an AI examination asks for, hear about it first.

Short notes on SR 26-2, NYDFS 500, FINRA, the NAIC bulletin, the EU AI Act, and the employment-AI statutes, plus what we ship. A few emails a month.