meilynx

Reference · Model risk management

SR 26-2 and Generative AI: The Carve-Out Explained

Footnote 3 of the Revised Guidance on Model Risk Management

Last reviewed September 23, 2026

SR 26-2, issued jointly by the Federal Reserve, the OCC, and the FDIC on 17 April 2026, governs how banking organizations manage model risk. One footnote places generative and agentic AI outside its scope and hands the question of how to govern those systems to the institution's own risk management.

For a bank deploying large language models or AI agents, and for any vendor whose product puts one inside a bank, that footnote defines the terms of the next examination conversation.

What the footnote says

The carve-out is footnote 3, attached to the definition of a model in Section II (Purpose and Scope). It reads in full: "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance. Nonetheless, a banking organization's risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document. However, the principles described in this guidance apply to traditional statistical and quantitative models and non-generative, non-agentic AI models."

Three statements sit in that footnote. Generative and agentic AI are out of scope. The institution's own risk management and governance practices decide the controls for them. Everything else that meets the model definition, including non-generative machine learning, stays in scope.

What still applies

  • The law. Fair lending and consumer protection law, including ECOA and Regulation B adverse-action notice requirements, BSA/AML obligations, and privacy law, apply to an outcome whatever system produced it.
  • Safety and soundness. SR 26-2 states that it sets no enforceable standards, and notes in the same passage that supervisory action may still follow from violations of law or unsafe or unsound practices.
  • Third-party risk management. The 2023 interagency guidance on third-party relationships covers a vendor's product whether or not the AI inside it is in scope for SR 26-2.
  • The model guidance itself, for every component that is a model. A workflow that pairs a statistical credit model with an LLM that drafts the customer explanation has one component in scope and one outside it.

What a defensible approach contains

The footnote leaves the design of governance to the institution. The principles SR 26-2 applies to models in scope (materiality, ongoing monitoring, effective challenge, and documentation sufficient for review) are the natural starting point, and most programs extend them to generative systems.

  • A written governance approach for generative and agentic systems, approved and dated, with the rationale for why it fits their risk.
  • An inventory of those systems, including models embedded in vendor products.
  • Oversight scaled to materiality: what the system decides or drafts, and who acts on the output.
  • Monitoring in production, including changes the provider makes to a hosted model.
  • Controls on the customer and confidential data that reaches a model.
  • Human review of consequential outputs before they reach a customer.
  • Records sufficient for an independent reviewer to reconstruct what the system did and why.
With no rulebook for these systems, the institution's own written approach is what an examiner tests. An approach backed by evidence that it operates is a position the institution can defend.

Frameworks that give the approach a structure

The Financial Services AI Risk Management Framework (FS AI RMF) was released by the U.S. Treasury on 19 February 2026. It was developed by the Cyber Risk Institute with the Financial Services Sector Coordinating Council (FSSCC), through the Artificial Intelligence Executive Oversight Group that Treasury formed with the FSSCC and the Financial and Banking Information Infrastructure Committee. It adapts the NIST AI Risk Management Framework to financial services: the four NIST functions (Govern, Map, Measure, Manage) break into 72 subcategories and 230 control objectives, each tagged to one of four adoption stages (Initial, Minimal, Evolving, Embedded) so an institution can scope the work to its current use of AI.

The NIST AI Risk Management Framework (AI RMF 1.0, January 2023) and its Generative AI Profile (NIST AI 600-1, July 2024) sit underneath it. The profile names risks specific to generative systems, such as confabulation, data privacy, information security, and value-chain integration, and maps suggested actions onto the same four functions.

Both frameworks are voluntary, and neither creates a safe harbor. Mapping a program to one gives an examiner a recognized structure to test it against.

Control mapping

What a reviewer expects to be able to see.

ObligationWhat the system must doEvidence a reviewer expects
Written approachDocument how generative and agentic systems are governed, and why that approach fits their riskThe approved approach, its rationale, and review dates
InventoryKnow every generative and agentic system in use, including those inside vendor productsInventory with owner, purpose, provider, and materiality
MaterialityScale oversight to what the system decides and who relies on itTiering rationale per system
MonitoringWatch behavior in production, including provider model changesMonitoring records and model version history
Data controlsControl the customer and confidential data that reaches a modelThe enforced policy and a record of what it blocked or redacted
Human reviewReview consequential outputs before they reach a customerReview records tied to the output reviewed
RecordsKeep records sufficient for independent reviewA tamper-evident record of use and governance decisions

Key dates

  • 26 January 2023NIST publishes the AI Risk Management Framework (AI RMF 1.0).
  • June 2023The Federal Reserve, FDIC, and OCC issue the interagency guidance on third-party relationships (SR 23-4).
  • 26 July 2024NIST publishes the Generative AI Profile (NIST AI 600-1).
  • 19 February 2026Treasury releases the FS AI RMF and a shared AI lexicon for the financial sector.
  • 17 April 2026SR 26-2 issued, superseding SR 11-7 and SR 21-8. Footnote 3 places generative and agentic AI outside its scope.

Primary sources

Common gaps

Where institutions most often come up short on systems the guidance leaves out.

  • Out of scope treated as ungoverned. The footnote sends these systems to the institution's own risk management. An inventory that quietly drops them leaves nothing to show when an examiner asks.
  • Vendor-embedded AI missing from the inventory. A generative model inside a purchased product is still in use by the institution, and third-party risk management applies to it.
  • No record of provider model changes. Hosted models change behind a stable name. Without a version history, monitoring results cannot be tied to the model that produced them.
  • Hybrid workflows scoped as one system. When a statistical model and an LLM share a workflow, each needs its own scoping decision and its own evidence.
  • Framework alignment presented as compliance. The FS AI RMF and the NIST AI RMF are voluntary. Describing alignment as compliance overstates the posture to a reviewer who knows the difference.

Last reviewed September 23, 2026. This reference summarises publicly available regulatory guidance and is provided for general information. It is not legal advice. Obligations depend on an institution's charter, registration status, size, and activities. Verify against the primary sources cited above and consult counsel before relying on any summary here.

Regulatory updates

When a regulator changes what an AI examination asks for, hear about it first.

Short notes on SR 26-2, NYDFS 500, FINRA, the NAIC bulletin, the EU AI Act, and the employment-AI statutes, plus what we ship. A few emails a month.