A lot of banking commentary this year has treated the April 2026 revised model risk management guidance from the OCC, Federal Reserve, and FDIC as a comprehensive AI rulebook. It isn't — and understanding exactly what it does and doesn't cover matters, because assuming the wrong scope is its own compliance risk.
What the guidance actually covers
The revised guidance — issued jointly by the OCC, Federal Reserve, and FDIC as OCC Bulletin 2026-13 and, on the Federal Reserve side, as Supervisory Letter SR 26-2 — formally supersedes the fifteen-year-old SR 11-7 framework (and SR 21-8's BSA/AML-specific model risk guidance) with a more risk-based, proportionate approach. It applies to banking organizations with more than $30 billion in total assets and governs traditional quantitative and machine learning models used in decisions like credit scoring, pricing, and stress testing. If your institution's advisors are discussing "SR 26-2," that's the same guidance as OCC Bulletin 2026-13 — one interagency framework, issued under each agency's own numbering convention.
The line that matters most
The guidance states directly that generative AI and agentic AI models are "novel and rapidly evolving" and are therefore not within its scope. The agencies have signaled a request for information is coming that will specifically address how model risk management principles should apply to generative and agentic AI — but as of this writing, no such framework exists yet.
That leaves a real gap for any institution deploying large language models, AI copilots, or autonomous agents in lending, servicing, or compliance workflows: the newest and arguably highest-risk category of AI tools currently sits outside the one formal model risk framework built to govern it.
Why "not formally in scope" doesn't mean "not being examined"
Examiners haven't waited for a finished rulebook. Both the OCC and Federal Reserve have made AI a standing agenda item in every periodic bank exam — meaning institutions should expect questions about AI governance whether or not a specific AI model risk regulation exists yet. Examiners are asking pointed, practical questions: how is the AI system's behavior technically constrained, what human oversight sits in the workflow, and does an emergency shutdown mechanism — a "kill switch" — exist if the system misbehaves.
Separately, both European regulators and U.S. agencies have flagged a related but distinct risk: AI's ability to accelerate cyberattacks against financial institutions. In July 2026, the European Systemic Risk Board and the Bank of England both published reports on this, and the European Central Bank gave 110 EU banks until the end of October 2026 to submit AI-specific cybersecurity action plans. U.S. institutions should expect a parallel supervisory expectation even without a formal rule forcing it yet.
What institutions should actually do now
Waiting for the RFI and eventual generative/agentic AI framework is not a defensible strategy, given that examiners are already asking governance questions in the field. A reasonable interim posture: maintain an inventory of every generative and agentic AI tool in use (including ones embedded in vendor products), document the human-oversight checkpoint for each, and be able to describe — in writing — what happens if one of these systems needs to be shut off. That's the substance behind what examiners are already asking for, formal rule or not.
This same governance logic applies directly to AI credit decisioning and AI fraud detection models — both are exactly the kind of material, customer-affecting systems examiners expect institutions to be able to explain, monitor, and shut down if needed. For how this plays out below the $30 billion asset threshold, see our community bank AI strategy playbook and credit union AI technology insight.
Sources
- OCC Bulletin 2026-13 — Model Risk Management: Revised Guidance
- Federal Reserve SR 26-2 — Revised Guidance on Model Risk Management (April 17, 2026)
- Davis Polk — Visual memo on the revised federal model risk management guidance
- IndexBox — "AI Now a Permanent Topic in All U.S. Bank Exams"
- PYMNTS — "Banking Regulators Warn That AI Could Threaten Financial System"