Answer capsule
The revised banking guidance applies risk-based model controls to traditional quantitative and non-generative, non-agentic AI models. It expressly leaves generative and agentic AI outside that scope.
What the source establishes
- The Federal Reserve issued SR 26-2 on April 17, 2026 with the OCC and FDIC, and the letter says it is expected to be most relevant to Federal Reserve-regulated banking organizations with more than $30 billion in total assets.
- SR 26-2 supersedes SR 11-7 and SR 21-8 and emphasizes a risk-based approach tailored to a banking organization's model-risk profile, size, and operational complexity.
- The attached guidance defines covered models as complex quantitative methods, systems, or approaches grounded in statistical, economic, or financial theories and distinguishes model risk by inherent risk, exposure, purpose, and use.
- A footnote expressly excludes generative-AI and agentic-AI models from the guidance while stating that its principles apply to traditional statistical and quantitative models and to non-generative, non-agentic AI models.
Classify the system before borrowing the control label
Finance should begin with the actual method, output, and decision rather than the vendor's use of the word AI. SR 26-2 defines a covered model narrowly and excludes simple arithmetic, deterministic rule-based processes, generative AI, and agentic AI from that definition. Record the method class, intended use, financial decision, data, assumptions, output, user, and downstream authority. A familiar model-risk template can still inform questions outside scope, but the control record must not say the guidance governs a generative assistant when the source expressly says otherwise.
The accountable team should translate this point into a named workflow, affected population, source data, human owner, approval right, exception path, retained evidence, and review date. That translation is what separates an interesting AI development from a decision that can be governed and evaluated.
Scale covered-model rigor to purpose and exposure
For models inside the guidance, risk is not a single technical score. The source connects inherent risk with model exposure and purpose, and treats purpose plus exposure as model materiality. A CFO review should therefore show the portfolio or decision affected, possible financial consequence, data and assumption constraints, conditions of misuse, and aggregate dependencies across models. The same method can warrant different rigor when its use, scale, or business consequence changes; a low-risk test result cannot be copied into a materially different finance workflow.
The accountable team should translate this point into a named workflow, affected population, source data, human owner, approval right, exception path, retained evidence, and review date. That translation is what separates an interesting AI development from a decision that can be governed and evaluated.
Keep effective challenge visible
The guidance describes effective challenge as critical analysis by objective experts with the expertise, independence, standing, and influence to effect change. That is more specific than a second signature. For a covered forecasting, valuation, risk, reporting, or decision model, preserve development evidence, validation scope, limitations, outcomes analysis, ongoing monitoring, exceptions, and management response. Show when validation preceded first use and what compensating limits applied if urgent use began earlier. A successful validation does not remove residual model risk or authorize use beyond the documented purpose.
The accountable team should translate this point into a named workflow, affected population, source data, human owner, approval right, exception path, retained evidence, and review date. That translation is what separates an interesting AI development from a decision that can be governed and evaluated.
Build a separate generative-AI decision record
Generative and agentic finance systems still need governance, but SR 26-2 is not the authority for claiming they completed this supervisory model-risk process. Create a parallel record for source grounding, instructions, retrieval, tool access, human approval, segregation of duties, evaluation, incidents, change control, and retirement. Link it to applicable internal controls and qualified review, then label which SR 26-2 principles were used as design prompts rather than requirements. This preserves a useful discipline without turning an explicit exclusion into unsupported assurance.
The accountable team should translate this point into a named workflow, affected population, source data, human owner, approval right, exception path, retained evidence, and review date. That translation is what separates an interesting AI development from a decision that can be governed and evaluated.
Decision test
Ask whether the source changes the decision itself, the evidence required, the implementation sequence, or only the language used to describe an existing capability. Record which claims are directly supported, which are provider statements, which require an independent test, and which remain unknown. A source-linked review should make uncertainty easier to see, not bury it inside a blended score.
Questions to take into review
- Which planning model and dimensions ground the answer?
- Can every assumption be traced to an owner and date?
- Which source supports each number and assertion?
- How is materiality assessed outside the model?
- Is the AI itself in scope for change and access controls?
- Can evidence provenance survive export and retention?
The publication supports research and executive decision preparation. It does not provide legal, financial, accounting, employment, clinical, cybersecurity, investment, procurement, or implementation advice.