The Governance Gap Regulators Won't Close for You

On April 17, 2026, the OCC, Federal Reserve, and FDIC jointly issued SR 26-2 — the first comprehensive revision to model risk management guidance since SR 11-7 landed in 2011. Banks with more than $30 billion in total assets are now expected to align their model risk programs to this updated framework. But buried in the guidance is a clause that should concern every Chief Risk Officer and Head of AI: generative AI and agentic AI models are explicitly excluded from SR 26-2's scope.

The agencies were candid about why. "Generative AI and agentic AI models are novel and rapidly evolving," the guidance states. "As such, they are not within the scope of this guidance." A request for information on AI-specific model risk is forthcoming — but forthcoming is not the same as now. And banks deploying large language models for credit underwriting commentary, customer-facing chatbots, fraud narrative generation, and internal risk analysis cannot wait for regulators to catch up.

The message, read carefully, is this: the governance obligation exists. The framework does not. Your institution must build it.

What SR 26-2 Actually Changes — and What It Doesn't

SR 26-2 supersedes SR 11-7 across three substantive areas. First, it broadens the definition of "model" to explicitly include non-generative, non-agentic AI systems — meaning machine learning models used in credit scoring, capital allocation, stress testing, and AML are now unambiguously in scope for formal model risk management. Second, it updates validation expectations to reflect the reality of ensemble methods, neural networks, and continuous learning pipelines. Third, it introduces clearer expectations for model inventory completeness and tiering by materiality.

What it does not do is provide a compliance framework for the AI systems that are transforming bank operations fastest. Generative AI tools used by relationship managers to draft client proposals, agentic AI systems that route and partially resolve disputes, and LLM-based contract analysis tools all sit in a regulatory grey zone. SR 26-2 acknowledges this directly: "A banking organization's risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document."

Translation: regulators expect you to govern these systems rigorously. They have simply declined to specify exactly how — yet.

Why "Out of Scope" Is Not the Same as "Unregulated"

Risk officers who interpret the GenAI exclusion as permission to defer governance will be caught flat-footed during the next examination cycle. The prudential regulators — OCC, Federal Reserve, FDIC — have been explicit in examination findings and public remarks that they expect institutions to apply appropriate governance to all AI systems, not merely those covered by formal guidance.

The NYDFS, which supervises the largest concentration of U.S. financial institutions by asset value, has separately issued AI governance expectations that apply to any AI system used in a regulated activity. The EU AI Act's Article 12 — now entering full enforcement for high-risk AI in August 2026 — requires six months of structured logs for every high-risk AI deployment. For internationally active banks, the regulatory perimeter around GenAI is narrowing from multiple directions simultaneously.

Examination teams are already asking for AI inventories, risk ratings, and evidence of human oversight checkpoints. Institutions that cannot produce this documentation face findings that drive remediation timelines measured in quarters, not weeks.

The Four Governance Controls Banks Need Right Now

In the absence of a formal regulatory framework for GenAI, the most defensible approach is to apply the spirit of SR 26-2's core controls to your generative and agentic AI systems. This means four things specifically:

The Examination Risk Is Not Theoretical

The agencies have been deliberate in signalling that AI governance is an active supervisory priority. The Federal Reserve's 2025 Supervision and Regulation Report identified "AI risk management" as an emerging horizontal across the large bank portfolio. OCC examiners have included AI governance questions in technology examinations since mid-2025. The FDIC has published guidance on third-party AI risk that extends beyond the formal SR 26-2 perimeter.

Institutions that have not begun building a GenAI governance framework before the agencies publish a formal successor to SR 26-2 will face two compounding problems: a remediation backlog from current examination findings, and a compressed timeline to implement a new framework once it arrives. The banks that build now — even on voluntary frameworks like the NIST AI RMF or ISO 42001 — will have the defensible documentation regulators expect.

The timeline for the forthcoming AI-specific request for information has not been specified. What has been specified is that the governance obligation exists today, under existing safety and soundness standards, regardless of whether a specific rule has been written for it.

Building the Evidence Layer Before the Rule Arrives

The most operationally effective approach to GenAI governance in the SR 26-2 era is to treat it as an evidence-first discipline. Policies matter less than logs. Procedures matter less than demonstrable human oversight checkpoints. Governance committees matter less than audit trails that can be produced within 48 hours of an examiner request.

This requires infrastructure, not just documentation. Banks need the ability to capture AI inputs and outputs at the workflow level, tag decisions with the AI system and version that informed them, store those logs in tamper-evident form for at least the retention period required by the longest-running applicable regulation, and surface them for human review on demand.

The institutions that build this infrastructure now are not over-engineering a response to a gap. They are making a bet that has near-certain payoff: when the AI-specific guidance does arrive, they will have the foundation already in place.

Key Takeaways
  • SR 26-2, effective April 2026, explicitly excludes generative AI and agentic AI from its formal scope — but does not exempt these systems from governance obligations.
  • Regulators expect banks to apply appropriate controls to all AI tools. Examination teams are already asking for AI inventories, audit trails, and human oversight documentation.
  • The four governance controls that matter now: AI inventory with risk tiering, complete decision audit trails, human-in-the-loop checkpoints, and third-party model due diligence.
  • International banks face converging obligations: NYDFS AI governance expectations, EU AI Act Article 12 audit log requirements, and forthcoming federal AI-specific guidance are all moving simultaneously.
  • Institutions that build audit trail infrastructure now will be best positioned when formal AI model risk management guidance is published — expected later in 2026.

Provara helps regulated financial institutions build and evidence the AI governance controls that examiners are starting to demand — from AI system inventories to tamper-evident audit trails structured to the 12-field minimum schema converging across U.S. and EU regulation. If your institution is preparing for its next technology examination, speak with the Provara team.