The Federal Reserve, the Office of the Comptroller of the Currency and the Federal Deposit Insurance Corporation issued new supervisory guidance on model risk on 17 April 2026, replacing the framework banks had worked under since 2011. The new letter, SR 26-2, is the first rewrite of AI model risk management rules since machine learning and generative tools became routine in bank operations, and it narrows rather than expands what counts as a model under formal supervisory scrutiny.
What SR 11-7 was, and why AI model risk management needed a rewrite
The original guidance, SR 11-7, set out how banks should develop, validate and govern quantitative models back in 2011, years before machine learning reached mainstream banking. It defined a model broadly: any method that processes inputs into quantitative outputs using statistical, economic or financial theory. That definition proved wide enough to capture far more than examiners originally intended once banks began deploying machine learning, and more recently generative tools, across lending, fraud detection and customer service.
What SR 26-2 changes
SR 26-2 supersedes both SR 11-7 and the 2021 Bank Secrecy Act model risk letter, SR 21-8, folding fifteen years of supervisory experience into one document. The agencies describe the new approach as risk-based and proportional, tailored to each institution’s size, complexity and model risk profile, and state it is expected to be most relevant to banking organisations with more than $30 billion in total assets. Smaller, less complex banks are not exempt from sound model governance, but the letter no longer expects them to run the same validation programme as a globally systemic bank.
For AI governance in banking, the practical change is narrower than the headline figure suggests. Michelle Bowman, the Federal Reserve’s vice chair for supervision, told an audience on 1 May 2026 that supervisors had “expanded the scope of the previous guidance beyond its original purpose to apply it in unintended ways,” and said the revised guidance “now applies narrowly to traditional models and basic AI applications.”
Where generative and agentic AI fit now
Bowman’s clearest point concerned the newer technologies banks are rushing to adopt. Generative and agentic AI tools, she said, no longer sit inside the traditional model risk framework: the agencies see them as different enough from statistical models that they need a different supervisory approach rather than a stretched version of SR 11-7’s validation and documentation requirements. That distinction matters for banks building agentic AI into core processes while managing the operational risks it introduces, since it removes the assumption that every AI deployment automatically needs a full model-validation file.
It does not mean generative and agentic AI face no oversight. Bowman was explicit that the change reflects a judgement about what kind of scrutiny fits the technology, not a decision to stop scrutinising it. Her framing lines up with how boards are being told to approach governance choices that will determine which banks get agentic AI right: a separate track from legacy model risk committees, built around the specific failure modes of systems that act rather than only predict.
Materiality, not technology type, now drives the governance trigger
In a follow-up speech on 7 July 2026, Bowman set out the questions she wants supervisors asking instead of applying one rulebook to every use case: is the AI application material to the bank’s business, is it broadly available to staff or tightly limited, and does it touch customers directly. She linked the approach to the Financial Stability Board’s consultation report on responsible AI adoption, due to be finalised later in 2026, and said “lower-risk uses of AI should receive a lighter supervisory and regulatory touch.”
For a community bank running a customer-service chatbot, that points towards light-touch governance. For a regional lender using a generative model to draft credit memos that feed an underwriting decision, materiality pushes the other way, even though SR 26-2 no longer treats that tool as a traditional model requiring full validation.
What this means for compliance teams now
Banks still working from SR 11-7-era model inventories have a gap to close. The first task is mapping which AI tools now fall outside SR 26-2’s traditional-model definition, then building the separate governance track Bowman described for them, rather than assuming the old validation checklist still applies or, worse, assuming nothing applies at all. Regtech vendors serving this gap, with model inventory, documentation and AI-specific governance tooling, are listed on Fintechly’s regtech sector directory.
Does SR 26-2 mean banks no longer need to govern AI models at all?
No. The letter narrows which tools count as a traditional model under formal validation requirements; it does not remove supervisory interest in AI. Bowman described a separate, proportionate approach for generative and agentic AI rather than an exemption from oversight.
Which banks does SR 26-2 apply to?
It applies across institutions supervised by the Federal Reserve, the OCC and the FDIC, but the agencies say it is expected to be most relevant to banking organisations with more than $30 billion in total assets. Community banks remain subject to sound model governance principles scaled to their size and complexity.
What happened to SR 21-8?
SR 21-8, the 2021 interagency statement on model risk management for Bank Secrecy Act and anti-money laundering systems, is superseded by SR 26-2 along with SR 11-7. Banks that built anti-money laundering model governance around SR 21-8 need to reconcile it with the new letter.
Is there a deadline for banks to update their model risk policies?
The 17 April 2026 letter does not set out a separate effective date or transition period on its face. Banks should treat it as current supervisory expectation from the date of issuance and raise timing questions with their primary regulator at the next examination cycle.