A lot of banking commentary this year has treated the April 2026 revised model risk management guidance from the OCC, Federal Reserve, and FDIC as a comprehensive AI rulebook. It isn't — and understanding exactly what it does and doesn't cover matters, because assuming the wrong scope is its own compliance risk.

What the guidance actually covers

The revised guidance (issued via OCC Bulletin 2026-13) replaces the old, comprehensive SR 11-7-style model risk framework with a more risk-based, proportionate approach, and it applies to banking organizations with more than $30 billion in total assets. It governs traditional quantitative and machine learning models used in decisions like credit scoring, pricing, and stress testing.

$30B+
Asset threshold for the revised MRM guidance to apply
Excluded
Generative AI and agentic AI models — explicitly out of scope
Standing
AI is now a permanent topic in every OCC and Fed exam regardless

The line that matters most

The guidance states directly that generative AI and agentic AI models are "novel and rapidly evolving" and are therefore not within its scope. The agencies have signaled a request for information is coming that will specifically address how model risk management principles should apply to generative and agentic AI — but as of this writing, no such framework exists yet.

That leaves a real gap for any institution deploying large language models, AI copilots, or autonomous agents in lending, servicing, or compliance workflows: the newest and arguably highest-risk category of AI tools currently sits outside the one formal model risk framework built to govern it.

"The newest, fastest-moving category of AI in banking is the one with no formal model risk framework yet built for it."

Why "not formally in scope" doesn't mean "not being examined"

Examiners haven't waited for a finished rulebook. Both the OCC and Federal Reserve have made AI a standing agenda item in every periodic bank exam — meaning institutions should expect questions about AI governance whether or not a specific AI model risk regulation exists yet. Examiners are asking pointed, practical questions: how is the AI system's behavior technically constrained, what human oversight sits in the workflow, and does an emergency shutdown mechanism — a "kill switch" — exist if the system misbehaves.

Separately, both European regulators and U.S. agencies have flagged a related but distinct risk: AI's ability to accelerate cyberattacks against financial institutions. In July 2026, the European Systemic Risk Board and the Bank of England both published reports on this, and the European Central Bank gave 110 EU banks until the end of October 2026 to submit AI-specific cybersecurity action plans. U.S. institutions should expect a parallel supervisory expectation even without a formal rule forcing it yet.

What institutions should actually do now

Waiting for the RFI and eventual generative/agentic AI framework is not a defensible strategy, given that examiners are already asking governance questions in the field. A reasonable interim posture: maintain an inventory of every generative and agentic AI tool in use (including ones embedded in vendor products), document the human-oversight checkpoint for each, and be able to describe — in writing — what happens if one of these systems needs to be shut off. That's the substance behind what examiners are already asking for, formal rule or not.

Sources