.text-rich-text, .code-block { /* Encourage the browser to break lines within words only when necessary */ overflow-wrap: break-word; /* Use word-break with 'break-word' instead of 'break-all' */ word-break: break-word; } .text-rich-text table { border-collapse: collapse; width: 100%; margin: 32px 0; font-size: 0.95em; } .text-rich-text table th, .text-rich-text table td { border: 1px solid #e2e8f0; padding: 12px 16px; text-align: left; vertical-align: top; } .text-rich-text table th { background: #f7f9fb; font-weight: 600; color: #1a1a1a; } .text-rich-text table tr:nth-child(even) td { background: #fafbfc; }
Blog
Articles
SR 26-2 Excludes Generative AI From Bank Model Risk Governance

SR 26-2 Excludes Generative AI From Bank Model Risk Governance

Articles
July 20, 2026
Team Foundational
Subscribe to our Newsletter
Get the latest from our team delivered to your inbox
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Ready to get started?
Try It Free

Why This Matters Now

Banks spent the past year waiting for federal guidance on how generative and agentic AI should be governed under model risk management. That guidance arrived on April 17, 2026, when the Federal Reserve, the OCC, and the FDIC jointly issued SR 26-2, superseding SR 11-7 after fifteen years. The update does not close the gap institutions expected it to close. SR 26-2 explicitly excludes generative and agentic AI models from its model risk management scope, leaving banks to decide, document, and defend their own governance approach with no prescriptive federal floor underneath it.

For a Governance and Compliance Leader, that is not a loophole. It is an assignment. Examiners will still ask how a bank governs the AI systems making or influencing credit, underwriting, and operational decisions. SR 26-2 simply removed the checklist they might have used to answer that question for generative and agentic models. This post covers what SR 26-2 actually changed, what it left uncovered, and what a defensible governance program for agentic AI looks like when no regulator has written the rules for you.

What SR 26-2 Replaced and Who It Covers

SR 26-2 is the Federal Reserve's updated model risk management guidance, issued jointly with OCC Bulletin 2026-13 and FDIC FIL-15-2026. It supersedes SR 11-7, the interagency guidance that had defined model risk expectations since 2011. It sets refreshed model inventory, validation, and governance expectations for traditional statistical and machine learning models used in credit decisioning, stress testing, and forecasting. Any bank still citing SR 11-7 in its model risk policy is now referencing guidance that has been formally replaced.

Model typeSR 26-2 model risk scopeTraditional statistical and ML models (credit scoring, stress testing, forecasting)Covered, with updated validation and inventory expectationsGenerative AI modelsExplicitly excluded from model risk management scopeAgentic AI systemsExplicitly excluded from model risk management scope

The Explicit Gap: Generative and Agentic AI Models

According to analysis from Sullivan and Cromwell, confirmed by Kevin D. Oden and Associates on June 24, 2026, SR 26-2 draws a clear line around what it governs. Generative and agentic AI models sit outside that line entirely. The guidance does not defer a decision on these systems. It states plainly that they fall outside model risk management scope as written.

Agentic AI refers to AI systems that plan and execute multi-step actions toward a goal with limited direct human input at each step, rather than returning a single output to a single prompt. In a banking context, an agentic system might pull customer data, apply underwriting logic, and draft a decision recommendation across several linked actions. Because SR 26-2 does not classify these systems under model risk management, none of its inventory, validation, or ongoing monitoring requirements apply to them by default.

What Banks Must Document and Defend Without a Regulatory Floor

The absence of a prescriptive federal framework does not remove the obligation. It relocates it. A bank deploying generative or agentic AI in any customer-facing or decision-influencing process still has to be able to show an examiner three things: what data the system touched, what logic it applied, and why that logic is trustworthy enough to rely on. SR 26-2 will not hand a bank the audit trail. The bank has to build it and defend it as its own governance judgment, not a compliance checkbox borrowed from someone else's rulebook.

That defense has to hold up in an audit conversation, not just a policy document. Examiners will ask where a system's inputs originated and how a given output traces back to the data and code that produced it. A policy statement that AI is "governed" is not evidence. A reconstructible record of data lineage and decision logic is.

What Good Governance Looks Like Here

Foundational is a data and AI governance platform, and the differentiator that matters most for this gap is source code analysis. Most governance tools infer lineage from query logs or warehouse metadata, which shows where data landed but not how it got there or what logic transformed it along the way. Source code analysis traces lineage directly from the application and pipeline code that moves and shapes the data, including the code behind agentic workflows, so a bank can reconstruct exactly what an AI system touched and why, without waiting for a regulator to define the requirement first.

This is proactive governance, not paperwork assembled after the fact. When Lemonade needed to demonstrate governance for AI-driven underwriting to regulators, source code-level lineage was a direct contributor to significantly accelerating that regulatory approval. Regulated institutions do not get credit for policies they cannot evidence. They get credit for lineage they can produce on demand, for both the traditional models SR 26-2 covers and the agentic systems it leaves to the bank's own judgment.

Foundational's Governance Readiness Model gives compliance teams a structured way to assess where a given AI system sits today and what evidence is missing before an examiner asks for it, which is the practical answer to a guidance document that declined to provide one. For banks building out a broader compliance program, see how the same lineage discipline applies to CCAR and BCBS 239 requirements, which rest on the same underlying need to prove where regulated data came from.

Frequently Asked Questions


No. SR 26-2 explicitly excludes generative AI models from its model risk management scope, even though it refreshes expectations for the traditional statistical and machine learning models banks have used for years. A bank cannot point to SR 26-2 as evidence that its generative AI use is governed, because the guidance never evaluated it in the first place. Banks deploying generative AI still need their own governance approach, built and defended independently, since no federal standard currently covers it.


SR 11-7 was superseded by SR 26-2 on April 17, 2026, alongside OCC Bulletin 2026-13 and FDIC FIL-15-2026, ending fifteen years as the interagency model risk standard. Any bank policy, validation framework, or examination response that still cites SR 11-7 as current guidance is now out of date. Compliance teams should treat updating those references as a near-term priority, since an examiner citing SR 26-2 against an SR 11-7-based policy is a predictable and avoidable finding.


Not under SR 26-2. Agentic AI systems, defined as AI that plans and executes multi-step actions toward a goal rather than returning a single output to a single prompt, are explicitly excluded from the guidance's model risk scope, the same as generative AI models. That exclusion applies regardless of how consequential the agentic system's actions are, which means a bank cannot rely on SR 26-2 to define what oversight an agentic underwriting or servicing workflow needs.


By building its own evidentiary trail rather than waiting for one to be prescribed: reconstructible data lineage and decision logic traced from the source code that actually runs the system, not just policy language describing intent. Source code analysis produces that trail directly from the application and pipeline code involved, including agentic workflows, so a bank can show an examiner exactly what data a system touched, what logic it applied, and why, on demand rather than after the fact.


No. It means the oversight has to come from the bank's own governance program rather than a prescriptive federal checklist built into SR 26-2 itself. Examiners still expect banks to demonstrate control over any system influencing credit, underwriting, or customer-facing decisions, regardless of whether a named regulation covers that specific system. The absence of a federal floor raises the bar for a bank's internal evidence, it does not lower it.

Where to Go From Here

SR 26-2 answered the model risk question for traditional models and left the generative and agentic AI question to each bank's own judgment. That is a governance gap a policy statement cannot close, but reconstructible, source code-level lineage can. See how Foundational's approach to deterministic lineage applies to agentic AI systems, or request a demo to walk through what evidence an examiner would expect to see from your current AI deployments.

code snippet <goes here>
<style>.horizontal-trigger {height: calc(100% - 100vh);}</style>
<script src="https://cdnjs.cloudflare.com/ajax/libs/gsap/3.8.0/gsap.min.js"></script>
<script src="https://cdnjs.cloudflare.com/ajax/libs/gsap/3.8.0/ScrollTrigger.min.js"></script>
<script>
// © Code by T.RICKS, https://www.timothyricks.com/
// Copyright 2021, T.RICKS, All rights reserved.
// You have the license to use this code in your projects but not to redistribute it to others
gsap.registerPlugin(ScrollTrigger);
let horizontalItem = $(".horizontal-item");
let horizontalSection = $(".horizontal-section");
let moveDistance;
function calculateScroll() {
 // Desktop
 let itemsInView = 3;
 let scrollSpeed = 1.2;  if (window.matchMedia("(max-width: 479px)").matches) {
   // Mobile Portrait
   itemsInView = 1;
   scrollSpeed = 1.2;
 } else if (window.matchMedia("(max-width: 767px)").matches) {
   // Mobile Landscape
   itemsInView = 1;
   scrollSpeed = 1.2;
 } else if (window.matchMedia("(max-width: 991px)").matches) {
   // Tablet
   itemsInView = 2;
   scrollSpeed = 1.2;
 }
 let moveAmount = horizontalItem.length - itemsInView;
 let minHeight =
   scrollSpeed * horizontalItem.outerWidth() * horizontalItem.length;
 if (moveAmount <= 0) {
   moveAmount = 0;
   minHeight = 0;
   // horizontalSection.css('height', '100vh');
 } else {
   horizontalSection.css("height", "200vh");
 }
 moveDistance = horizontalItem.outerWidth() * moveAmount;
 horizontalSection.css("min-height", minHeight + "px");
}
calculateScroll();
window.onresize = function () {
 calculateScroll();
};let tl = gsap.timeline({
 scrollTrigger: {
   trigger: ".horizontal-trigger",
   // trigger element - viewport
   start: "top top",
   end: "bottom top",
   invalidateOnRefresh: true,
   scrub: 1
 }
});
tl.to(".horizontal-section .list", {
 x: () => -moveDistance,
 duration: 1
});
</script>

See Your AI Governance Evidence Gap

Book a demo to see how source code analysis gives your compliance team defensible lineage for every AI system, covered or not by SR 26-2.

See Your AI Governance Evidence Gap

Book a demo to see how source code analysis gives your compliance team defensible lineage for every AI system, covered or not by SR 26-2.

See Your AI Governance Evidence Gap

Book a demo to see how source code analysis gives your compliance team defensible lineage for every AI system, covered or not by SR 26-2.

Share this post
Subscribe to our Newsletter
Get the latest from our team delivered to your inbox
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Ready to get started?
Try It Free

Govern data and AI at the source code