SR 26-2 Punted on AI. Here's What Actually Regulates Your Models.

For fifteen years, if you built anything quantitative inside a bank, one document governed your life: SR 11-7. Issued in 2011, it defined a "model" so broadly that a spreadsheet with a regression in it qualified, and it demanded documentation, independent validation, and ongoing monitoring for all of it. Examiners lived by it.

On April 17, 2026, the Fed, OCC, and FDIC replaced it. SR 26-2 (OCC Bulletin 2026-13) supersedes both SR 11-7 and its 2021 update. It's lighter across the board — and on AI, it barely speaks at all.

What changed

  • It's explicitly non-binding. The guidance "does not set forth enforceable standards or prescriptive requirements," and non-compliance "will not result in supervisory criticism." A real posture shift from how SR 11-7 was examined.
  • It targets organizations over $30 billion in total assets, with a carve-in for smaller shops carrying significant model risk.
  • The definition of "model" narrowed to a "complex quantitative method," explicitly excluding spreadsheet arithmetic and deterministic rule-based processes with no statistical or economic theory underneath.
  • Materiality is now the organizing idea: model exposure (how much output drives decisions) plus purpose (regulatory or risk function) determines how much oversight a model gets.
  • Independence loosened. Hard independent validation becomes "effective challenge," and quality "depends on the rigor and effectiveness of the review rather than on organizational structure."

The AI part: a footnote and a promise

Here's what surprised people. In the entire guidance, AI is addressed in exactly one place — footnote 3. Machine learning and artificial intelligence, spelled out, appear zero times. The footnote says generative and agentic AI are "novel and rapidly evolving. As such, they are not within the scope of this guidance," while traditional statistical models and non-generative, non-agentic AI models stay in.

So SR 26-2 didn't write AI rules. It carved GenAI out and deferred the real work to a forthcoming interagency request for information — announced in the press release, not the guidance itself — that will address model risk and "banks' use of AI, including generative AI and agentic AI." That RFI is the document to watch. The current guidance is a placeholder.

Read footnote 3 to the end, though: anything not covered still needs governance under "a banking organization's risk management and governance practices." Out of model-risk scope is not out of risk scope.

Where your stack actually lands

Map the line onto a live architecture: a customer-facing AI assistant, a RAG retriever over policy docs, an analyst agent that writes SQL from natural language, an LLM that scores the other models, and a deterministic loan scorecard.

  • The assistant, retriever, NL-to-SQL analyst, and LLM-judge are all generative or agentic — out of formal model-risk scope.
  • The loan scorecard is the interesting one. Deterministic, which sounds excluded, but it applies credit-risk theory to drive a lending decision, and the rescinded issuances included the old credit-scoring bulletin. I'd call it in scope on purpose and exposure grounds. Document that as a judgment call.

Four of five components exit formal scope, and the one that stays is the least glamorous.

So what actually regulates your AI?

Everything you didn't just read about. US financial regulators regulate the outcome and the harm, not the technology. A discriminatory denial is illegal whether a human, a scorecard, or an LLM produced it. The frameworks that still apply:

  • Fair lending and consumer protection: ECOA/Regulation B (adverse-action reasons — the reason black boxes are dangerous in lending), FCRA, the Fair Housing Act, and UDAAP. A hallucinating assistant giving wrong fee info is a UDAAP exposure no matter what generated it.
  • Third-party risk: the 2023 interagency guidance on third-party relationships is what governs your foundation-model vendor. This is where your GenAI obligation actually lives now that MRM punted.
  • Data privacy and security: GLBA and the Safeguards Rule, state privacy laws (CCPA/CPRA), and GDPR Article 22 for solely-automated decisions if you touch EU data subjects.
  • AI-specific frameworks: NIST AI RMF (voluntary, but the de facto structure to map GenAI to), the EU AI Act (credit scoring is high-risk) if you operate in-scope, and emerging state AI laws like Colorado's.

What an organization actually has to do

The controls don't change much whether a component is in or out of MRM scope — the point is to build them once and let them satisfy whichever regulation applies:

  • Inventory everything, including the "out of scope" GenAI. One register, tiered by materiality (exposure times purpose), with a documented in-scope/out-of-scope call and rationale for each system.
  • Map each system to the regimes it triggers: does it make a customer decision (fair lending, UDAAP), touch personal data (GLBA, privacy law), or ride on a vendor model (third-party risk)? Most systems trigger several.
  • Wire in explainability wherever a customer decision happens. Reg B adverse-action reasons are non-negotiable; if you can't state why, you can't deny.
  • Run fair-lending testing — disparate-impact analysis on model outcomes across protected classes — not just accuracy metrics.
  • Do real vendor due diligence on foundation models: security, data handling, model-change notification, SLAs, concentration risk. Keep the paper trail.
  • Gate releases on evaluation: grounding and hallucination thresholds, faithfulness testing on RAG output, and input/output screening for prompt injection and data leakage.
  • Treat ongoing monitoring as the center of gravity. Drift detection and outcomes analysis catch what a one-time validation never will — and it's expected in or out of scope.
  • Keep a human in the loop for consequential automated decisions. Reg B, GDPR Article 22, the EU AI Act, and Colorado all point the same direction.
  • Govern the data underneath: PII classification, lineage, retention, least-privilege access.
  • Stand up the governance structure: named model owners, board-level awareness of material AI risk, independent-enough effective challenge, and internal audit over the framework itself.

Map the whole thing to NIST AI RMF so it reads as one coherent program rather than a pile of point controls.

The takeaway

SR 26-2 didn't deregulate your AI. It stopped pretending the 2011 model-risk lens was the right tool for generative systems, and it handed the problem back to you — to be solved with fair-lending law, vendor-risk guidance, privacy law, and your own governance until the RFI produces something purpose-built. The best position isn't "we validated everything." It's "we know what's in scope, what isn't, and we govern the out-of-scope AI anyway, because the risk didn't disappear when the definition changed." That sentence survives an exam. It's also just good engineering.

0 Comments

Leave a Comment