Reference · Model risk management
SR 26-2 and Generative AI: The Carve-Out Explained
Footnote 3 of the Revised Guidance on Model Risk Management
SR 26-2, issued jointly by the Federal Reserve, the OCC, and the FDIC on 17 April 2026, governs how banking organizations manage model risk. One footnote places generative and agentic AI outside its scope and hands the question of how to govern those systems to the institution's own risk management.
For a bank deploying large language models or AI agents, and for any vendor whose product puts one inside a bank, that footnote defines the terms of the next examination conversation.
What the footnote says
The carve-out is footnote 3, attached to the definition of a model in Section II (Purpose and Scope). It reads in full: "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance. Nonetheless, a banking organization's risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document. However, the principles described in this guidance apply to traditional statistical and quantitative models and non-generative, non-agentic AI models."
Three statements sit in that footnote. Generative and agentic AI are out of scope. The institution's own risk management and governance practices decide the controls for them. Everything else that meets the model definition, including non-generative machine learning, stays in scope.
What still applies
- The law. Fair lending and consumer protection law, including ECOA and Regulation B adverse-action notice requirements, BSA/AML obligations, and privacy law, apply to an outcome whatever system produced it.
- Safety and soundness. SR 26-2 states that it sets no enforceable standards, and notes in the same passage that supervisory action may still follow from violations of law or unsafe or unsound practices.
- Third-party risk management. The 2023 interagency guidance on third-party relationships covers a vendor's product whether or not the AI inside it is in scope for SR 26-2.
- The model guidance itself, for every component that is a model. A workflow that pairs a statistical credit model with an LLM that drafts the customer explanation has one component in scope and one outside it.
What a defensible approach contains
The footnote leaves the design of governance to the institution. The principles SR 26-2 applies to models in scope (materiality, ongoing monitoring, effective challenge, and documentation sufficient for review) are the natural starting point, and most programs extend them to generative systems.
- A written governance approach for generative and agentic systems, approved and dated, with the rationale for why it fits their risk.
- An inventory of those systems, including models embedded in vendor products.
- Oversight scaled to materiality: what the system decides or drafts, and who acts on the output.
- Monitoring in production, including changes the provider makes to a hosted model.
- Controls on the customer and confidential data that reaches a model.
- Human review of consequential outputs before they reach a customer.
- Records sufficient for an independent reviewer to reconstruct what the system did and why.
Frameworks that give the approach a structure
The Financial Services AI Risk Management Framework (FS AI RMF) was released by the U.S. Treasury on 19 February 2026. It was developed by the Cyber Risk Institute with the Financial Services Sector Coordinating Council (FSSCC), through the Artificial Intelligence Executive Oversight Group that Treasury formed with the FSSCC and the Financial and Banking Information Infrastructure Committee. It adapts the NIST AI Risk Management Framework to financial services: the four NIST functions (Govern, Map, Measure, Manage) break into 72 subcategories and 230 control objectives, each tagged to one of four adoption stages (Initial, Minimal, Evolving, Embedded) so an institution can scope the work to its current use of AI.
The NIST AI Risk Management Framework (AI RMF 1.0, January 2023) and its Generative AI Profile (NIST AI 600-1, July 2024) sit underneath it. The profile names risks specific to generative systems, such as confabulation, data privacy, information security, and value-chain integration, and maps suggested actions onto the same four functions.
Control mapping
What a reviewer expects to be able to see.
| Obligation | What the system must do | Evidence a reviewer expects |
|---|---|---|
| Written approach | Document how generative and agentic systems are governed, and why that approach fits their risk | The approved approach, its rationale, and review dates |
| Inventory | Know every generative and agentic system in use, including those inside vendor products | Inventory with owner, purpose, provider, and materiality |
| Materiality | Scale oversight to what the system decides and who relies on it | Tiering rationale per system |
| Monitoring | Watch behavior in production, including provider model changes | Monitoring records and model version history |
| Data controls | Control the customer and confidential data that reaches a model | The enforced policy and a record of what it blocked or redacted |
| Human review | Review consequential outputs before they reach a customer | Review records tied to the output reviewed |
| Records | Keep records sufficient for independent review | A tamper-evident record of use and governance decisions |
Key dates
- 26 January 2023NIST publishes the AI Risk Management Framework (AI RMF 1.0).
- June 2023The Federal Reserve, FDIC, and OCC issue the interagency guidance on third-party relationships (SR 23-4).
- 26 July 2024NIST publishes the Generative AI Profile (NIST AI 600-1).
- 19 February 2026Treasury releases the FS AI RMF and a shared AI lexicon for the financial sector.
- 17 April 2026SR 26-2 issued, superseding SR 11-7 and SR 21-8. Footnote 3 places generative and agentic AI outside its scope.
Primary sources
- Federal Reserve SR 26-2
- Revised Guidance on Model Risk Management (SR 26-2 attachment, PDF)
- U.S. Treasury: Treasury Releases Two New Resources to Guide AI Use in the Financial Sector
- Cyber Risk Institute: Financial Services AI Risk Management Framework
- NIST AI Risk Management Framework
- Federal Reserve SR 23-4, Interagency Guidance on Third-Party Relationships
Common gaps
Where institutions most often come up short on systems the guidance leaves out.
- Out of scope treated as ungoverned. The footnote sends these systems to the institution's own risk management. An inventory that quietly drops them leaves nothing to show when an examiner asks.
- Vendor-embedded AI missing from the inventory. A generative model inside a purchased product is still in use by the institution, and third-party risk management applies to it.
- No record of provider model changes. Hosted models change behind a stable name. Without a version history, monitoring results cannot be tied to the model that produced them.
- Hybrid workflows scoped as one system. When a statistical model and an LLM share a workflow, each needs its own scoping decision and its own evidence.
- Framework alignment presented as compliance. The FS AI RMF and the NIST AI RMF are voluntary. Describing alignment as compliance overstates the posture to a reviewer who knows the difference.
Related
Last reviewed September 23, 2026. This reference summarises publicly available regulatory guidance and is provided for general information. It is not legal advice. Obligations depend on an institution's charter, registration status, size, and activities. Verify against the primary sources cited above and consult counsel before relying on any summary here.