On April 17, 2026, the OCC, the Federal Reserve, and the FDIC issued the first rewrite of US bank model risk management guidance in fifteen years. SR 26-2 and OCC Bulletin 2026-13 replace the 2011 framework and its 2021 BSA/AML add-on. Fifteen years is a long time in supervision. It is an eternity in machine learning.

Then there is footnote 3: "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance."

Read that twice, because it is the most consequential sentence written about bank AI governance this year. The agencies rebuilt the rulebook, and the model category moving fastest sits outside it. The same bulletin promises a request for information on banks’ use of AI in the near future. As of October 2, 2026, the Federal Register has no record of it.

Examiners never waited for the text. What follows is what the carve-out actually does, what it does not relieve anyone of, and what to build now, whether you sell AI into banks or run model risk inside one.

What the new guidance actually does

The rewrite is bigger than the AI footnote. SR 26-2 supersedes and replaces SR 11-7, issued April 4, 2011, and SR 21-8, the 2021 BSA/AML model-risk statement, issued April 9, 2021. On the OCC side, Bulletin 2011-12, Bulletin 2021-19, and the old Comptroller’s Handbook booklet are rescinded. The accompanying letter says the revision reflects "supervisory experience and industry feedback accumulated over the past fifteen years."

Three structural changes matter for operating purposes.

The definition of a model is narrower than it was in 2011. Sullivan & Cromwell’s April 29 memo lists it first among the key changes. It matters because a narrower definition can pull simpler systems, including some AI-based decisioning the old guidance would have swept in, out of formal inventory and validation work entirely.

Applicability gets a threshold: the guidance is "expected to be most relevant to banking organizations with over $30 billion in total assets," with smaller model-concentrated organizations remaining relevant cases.

And the whole instrument is voluntary. The OCC bulletin is blunt about it: "This guidance does not set forth enforceable standards or prescriptive requirements; accordingly, non-compliance with this guidance will not result in supervisory criticism against a banking organization." That sentence carries through this article: nothing below is a compliance requirement. The interim pressure comes from examiners, and they started before the ink dried.

Footnote 3, read in full

The excerpt everyone shares is only the first half of the footnote. Here is the paragraph in full:

"Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance. Nonetheless, a banking organization’s risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document. However, the principles described in this guidance apply to traditional statistical and quantitative models and non-generative, non-agentic AI models."

Four things follow from it.

One, the formal model-risk machine, the inventory, the independent validation, the effective challenge discipline, makes no specific demands of generative or agentic AI systems.

Two, the exclusion is not an exemption from governance. The second sentence keeps general risk management and governance practices as the determinant of appropriate controls for anything outside the scope. An examiner can read that sentence and ask what those practices determined. The footnote grants the exclusion and, in its own text, hands examiners a hook.

Three, the principles still apply to everything else, which is the part vendors misread most often. If your product scores credit risk with a gradient-boosted model or sanctions-screens with a statistical matcher, the new guidance reaches it exactly as before. Generative chat inside the same product does not pull the whole product out of scope. Component-level, not product-level.

Four, the agencies said the quiet part on record. Fed Vice Chair for Supervision Michelle Bowman, at the FSOC AI Series roundtable on May 1, 2026: "Today, banks are relying on existing risk-management frameworks to guide their use of AI. While these supervisory tools are intended to support banks in applying sound governance and risk management, we should assess whether our supervisory guidance is fit for the future." She adds that the revised guidance "now applies narrowly to traditional models and basic AI applications" and that the agencies "expect other risk-management and governance practices to support adoption of generative and agentic AI in ways that will encourage ongoing innovation."

Formal model risk stays narrow, general expectations carry the gen/agentic load, and the framework itself is under review.

The RFI that has not landed

The bulletin’s exact sentence: "the agencies plan to issue in the near future a request for information that addresses model risk management generally and considers, in particular, banks’ use of AI, including generative AI and agentic AI and AI-based models."

The promise dates to April 17, 2026. As of October 2, 2026, it has not been filed: the Federal Register’s feed of Federal Reserve documents tagged "model risk management" returns 543 records, the newest being the October 2 stress-test requests and the September 29 GENIUS Act proposals, and none of them is the RFI. The agencies never attached a date to "near future," so "outstanding" is as far as an honest count allows. The verifiable state: a named, promised action, five months on, is not on the record.

Treat the RFI as a deadline nobody gave you. Whatever comment letters argue will define what comes after it: what the next guidance covers, how broad the definitions land, whether agentic systems get their own treatment. Banks under $30 billion in particular should consider submitting, because the tailoring conversation is happening now and small deployers have the least written representation in it. Vendors should care for the same reason: scope boundaries drawn in a comment cycle outlast the people who drew them.

Meanwhile, examiners did not wait

Reuters reporting, republished by Quartz on July 3, 2026, describes how the OCC and the Federal Reserve handle AI in the absence of an AI rulebook: "both the OCC and the Federal Reserve have made AI a standing topic in their routine examinations, with no bank review now taking place without some discussion of the technology."

Examiners ask concrete, operational questions: what technical limits constrain the model’s behavior, how human review is structured, whether emergency shutdown capability exists and how it works (the kill switch is now an exam-table topic), which named roles are empowered to act when a system misbehaves, whether documented backup plans exist, whether AI suppliers and their subcontractors are held to governance and security expectations comparable to those required of the banks themselves, how a bank would disentangle itself from a compromised vendor system, and whether AI tools are touching data they were never authorized to touch.

The agencies have stopped short of mandating specific practices and describe the process as fact-finding. Do not mistake fact-finding for harmless: every answer a bank writes into an exam file becomes the record its examiners read back to it next cycle. And the questions do not stay inside the bank. They propagate to the bank’s technology suppliers, which is where most fintech and SaaS readers of this article come in.

What the carve-out does not relieve

If you run model risk or compliance inside a bank deploying generative AI, or advise one, here is the ledger of what changed and what did not.

It did not relieve you of governance. The "nonetheless" sentence in footnote 3 does the work: general risk management and governance practices still determine appropriate controls.

It did not relieve you of vendor-model validation. Section VII, Vendor and Other Third-Party Products, keeps the doctrine intact: the "principles of model risk management remain applicable" to vendor models, validation by "internal or outside parties" is an important element of model risk management, and sound practice includes understanding the vendor model’s "conceptual soundness, design, development data, and performance," plus ongoing monitoring and a documented basis for adjustments. One nuance: the carve-out excludes generative and agentic AI from this guidance’s scope, and generative AI is what most AI vendor models now contain, so Section VII reads as doctrine for the conventional layer of vendor models. In practice its questions are what examiners already ask about AI vendors. Treat it as the checklist your bank customers will grade you against either way.

It did not relieve you of the 2023 interagency TPRM guidance: third-party relationships, including AI vendors, continue to be governed by the June 2023 Interagency Guidance on Third-Party Relationships.

It did not buy you tailoring you had not already earned. The $30 billion line means many community and mid-market banks fall outside the guidance’s most-relevant band. But footnote 3’s controls-now sentence, Bowman’s "other risk-management and governance practices," and examiner practice all still apply at any asset size.

What the carve-out does relieve: gen/agentic AI systems carry no SR 26-2 validation playbook and no formal MRM compliance burden that cites this guidance, and departing from it cannot generate supervisory criticism at all. If a consultant says SR 26-2 requires validating your generative AI, the footnote and the disclaimer both say otherwise; what they are describing is best practice under general expectations, worth the conversation, but it is not SR 26-2.

The interim standards to adopt while the RFI pends

Two voluntary instruments carry weight in the gap.

The first is the Treasury-led Financial Services AI Risk Management Framework, released February 19, 2026 together with an AI Lexicon. It is structurally aligned with the NIST AI RMF and, per Cyber Risk Institute, expanded with 230 control objectives. This is the framework to map a gen/agentic deployment against when a bank asks what controls sit behind it. It does not make you regulator-approved; nothing in the interim does. It gives you a defensible structure with sector-specific vocabulary when the questionnaire gets relayed down the chain.

The second is FINRA’s 2026 Annual Regulatory Oversight Report, published December 2025, which carries a standalone GenAI section for broker-dealers: Debevoise’s analysis of it highlights testing and monitoring controls, cybersecurity and data-governance safeguards, and emerging agent-based risk. If your customer is a broker-dealer rather than a bank, this is the exam-era document to be conversant in.

The mistake to avoid is framework collecting. One sector framework, mapped once and explainable in a paragraph, beats three badges. Examiners do not ask which framework you joined. They ask who owns the tool, what review preceded deployment, and what happens when it goes wrong.

If you sell AI into banks: the five-part file

Your generative or agentic features will be pulled into your customers’ exam files even though footnote 3 excludes them from formal model risk. The bank answers for its use of you. Here is the file that makes those answers easy, built from the five things examiners are actually asking.

First, inventory and owners. List every generative or agentic tool inside your product, including the ones inside vendor components you bought, and name one accountable owner per tool. When the bank’s questionnaire asks who is responsible for the system inside your system, a list beats a shrug.

Second, pre-deployment review documentation. One document per tool: what it does, what data it touches, what failure looks like, what was tested before release. This is the artifact that answers the "what technical limits constrain the model" exam question from the bank’s side.

Third, a human-oversight description. State plainly which humans review, approve, or override outputs, and where they sit: in a fintech, often the ops team the bank never meets. Name the roles and keep it current.

Fourth, the kill-switch narrative in writing. How the system gets disabled, who can trigger it, how fast, and what the customer sees. Reuters reporting puts kill switches squarely among the exam questions. A written, rehearsed answer separates you from vendors who learned the word last year.

Fifth, the evidence map aligned to Section VII. Take Section VII’s terms, conceptual soundness, design, development data, performance, plus ongoing monitoring, and produce one line of evidence per term: model documentation, test results, monitoring dashboards, adjustment logs. That is the stack the bank’s model-risk team reaches for when it validates you, in scope or not.

None of this is exotic. It is the discipline any serious enterprise review demands, and the September interagency TPRM proposal presses the same points from the relationship side; we covered that instrument separately in the TPRM guidance overhaul breakdown. Banks are being trained, from two directions at once, to ask about owners, oversight, and exit paths.

If you run model risk inside a sub-$30 billion bank, the read is symmetrical: footnote 3 gives your gen/agentic systems no playbook, so build a pocket one before the exam builds it for you. Ten pages of honest documentation in the bank’s own words has historically fared better in an exam file than forty pages of borrowed policy. When a program needs that scaffolding, our AI governance practice exists for exactly that.

What to do this quarter

If you sell AI into banks or broker-dealers:

  1. Run the five-part file against what exists today. The inventory and owner list are usually an afternoon; the kill-switch narrative is the gap. Write it down even if the answer is uncomfortable.
  2. Map your evidence to Section VII’s vocabulary once, so the bank’s model-risk team never has to translate. An artifact-by-claim table is one afternoon and shortens every future review.
  3. Watch for the RFI. When it lands, its definitions become the vocabulary your customers negotiate against. Early comments from operators, not only trade associations, shape scope in ways that decide how much of your product the next guidance pulls in.

If you run or advise model risk inside a sub-$30 billion bank:

  1. Write the pocket playbook for gen/agentic tools now, while the framework question is open and you can set the shape yourself: inventory, owners, pre-deployment review, oversight description, kill-switch note. Ten pages.
  2. Decide your interim framework position, FS AI RMF mapping or documented alignment to existing general expectations
    and write the one-paragraph explanation an examiner can be handed. Then prepare to weigh in: the RFI is the only announced vehicle for public input this cycle, and sub-$30 billion deployers have the least voice in it and the most at stake.

The gap between the formal rulebook and exam practice is where organizations get hurt: they treat the absence of a rule as an absence of expectations, then answer the first serious questionnaire from scratch. The carve-out says generative and agentic AI sit outside the formal framework. It does not say they sit outside the exam. Closing that distance is, in large part, what a fractional CISO does for a fintech selling into banks. If you want a second pair of eyes on your evidence before your next bank review lands, start with the fintech security practice. For a direct conversation, contact NTD Consulting.