Sebastien Rousseau

MODEL RISK MANAGEMENT

Out of Scope Is Not Out of Risk: The 2026 Model-Risk Rewrite Left Out the Models Banks Are Actually Deploying

A governance reading for chief risk officers and heads of model risk: the US agencies rewrote model risk management in April 2026 and expressly excluded generative and agentic AI, while the UK's technology-neutral supervisory statement continues to pull the same models in — leaving group banks running one model under two answers.

9 min read
Banner for: Out of Scope Is Not Out of Risk: The 2026 Model-Risk Rewrite Left Out the Models Banks Are Actually Deploying

Fifteen years of model risk doctrine was rewritten in April, and the most consequential paragraph is the one that says what the guidance does not cover. On 17 April 2026 the Federal Reserve, the OCC and the FDIC issued revised guidance on model risk management, superseding the 2011 framework that the industry has organised itself around for a decade and a half. The revision is careful, risk-based and largely welcome. It also states, in terms, that generative AI and agentic AI models are not within its scope — with a request for information to follow. Banks are therefore in an interval: deploying the models the framework excludes, under a framework that has not yet been written.

Executive Summary

  • The 2011 settlement is retired. SR 26-2 and OCC Bulletin 2026-13, both dated 17 April 2026, supersede the long-standing 2011 guidance and its 2021 companion. The three-pillar architecture — sound development, effective challenge, ongoing monitoring — carries forward.
  • Proportionality is now explicit. The agencies say the guidance is expected to be most relevant to banking organisations with over $30 billion in total assets, while remaining relevant to smaller institutions with significant model risk. That is a meaningful change of emphasis, not a carve-out.
  • The AI question was deferred, not answered. Generative and agentic AI are excluded from this guidance, with a request for information to follow addressing model risk management generally and banks' use of AI in particular.
  • Deferral is not permission. The correct reading is that the agencies have not yet decided how to supervise these models — which is materially different from deciding they need no governance.

What the Agencies Actually Changed #

Strip away the commentary and the April revision does three things.

It retires the 2011 settlement. The revised guidance supersedes the model risk guidance issued in 2011 and its 2021 companion, closing a fifteen-year chapter during which SR 11-7 became the de facto global reference for model governance well beyond the institutions it bound.

It makes proportionality explicit. The guidance is expected to be most relevant to banking organisations with over $30 billion in total assets, and remains relevant to smaller organisations with significant exposure to model risk because of the prevalence and complexity of their models or activities outside traditional community banking. Sophistication should track size, complexity and risk profile.

It keeps the architecture. Conceptual soundness in development, effective challenge through independent review, and ongoing monitoring against documented thresholds all survive. Institutions that built well against the 2011 framework are not starting again.

Table 1: What changed, and what carried forward #

Element 2011 framework 2026 revised guidance
Status SR 11-7 and its 2021 companion Superseded and replaced, 17 April 2026
Core architecture Development, validation, governance Carried forward substantially intact
Proportionality Implicit, applied through supervision Explicit: tailored to size, complexity and risk profile
Stated relevance Broad Most relevant above $30bn total assets; still relevant below where model risk is significant
Generative and agentic AI Predates the question Expressly out of scope, with an RFI to follow

The Sentence That Matters #

Most of the revision is evolution. One passage is not:

Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance.

Read alongside the commitment to issue a request for information addressing model risk management generally, and banks' use of AI including generative and agentic AI in particular, the meaning is clear enough. The agencies are not saying these systems are low risk. They are saying they have not settled how to supervise them, and would rather consult than legislate a framework that a fast-moving technology outruns within a cycle.

That is defensible regulatory craft. It is also an awkward position for a bank that already has generative AI in production.

Because the practical question a risk committee asks is not "is this in scope of the April guidance?" It is "if this goes wrong, what will we be asked?" And the answer to the second question has not changed.

Out of Scope Is Not Out of Risk #

The most expensive misreading available in 2026 is that exclusion from the model risk guidance means exclusion from supervision. It does not. A model that falls outside this particular framework still sits squarely inside several others.

Table 2: Where an out-of-scope GenAI system still lands #

The model does this Framework it still answers to The question you will be asked
Runs on a vendor foundation model Third-party and outsourcing risk Can you evidence due diligence, exit and concentration analysis on the provider?
Touches a credit or pricing decision Consumer protection and fair lending Can you demonstrate the outcome was not discriminatory, and reconstruct why it was reached?
Sits in a customer-facing or operational process Operational risk and resilience What happens when it degrades, and who notices?
Produces output staff rely on Governance and senior accountability Who owns this system, and what were they told about its limits?
Is deployed in the EU or the UK EU AI Act; PRA SS1/23 The scoping answer here is different — see below

None of those are new obligations. That is exactly the point: the April guidance narrowed what it covers, and moved nothing out of anything else.

There is also a supervisory-expectation asymmetry worth naming plainly. When a framework is silent, examiners do not become silent. They fall back on general safety-and-soundness expectations, which are broader and less predictable than a written model-risk standard. Being out of scope of a specific rule frequently means being judged against a vaguer one.

The Transatlantic Split a Group Bank Now Has to Run #

For an institution operating on both sides of the Atlantic, the April decision creates a live divergence.

The UK's supervisory statement on model risk management principles for banks, SS1/23, took effect on 17 May 2024. It is built on five principles — identification and model inventory, governance, development and implementation and use, independent validation, and mitigants for models with deficiencies — and it is deliberately technology-neutral. Artificial intelligence and machine learning are not carved out; they are contemplated.

So the same generative model, deployed in the same group, in the same business line, is inside the UK model-risk perimeter and outside the newly revised US one. Add the EU AI Act's obligations for a European deployment and there are three answers, not two.

Institutions have exactly two coherent responses.

Run one framework at the strictest standard. Govern generative AI as though it were in scope everywhere, because it is in scope somewhere and will be in scope more broadly once the RFI resolves. This costs more now and is defensible in every jurisdiction.

Run genuinely separate perimeters. Legally possible, operationally miserable. It means two inventories, two validation standards and two sets of evidence for one model — and the reputational exposure of explaining, after an incident, that the version of the control that would have caught it was the one applied in the other jurisdiction.

The first is the right answer for almost every institution large enough for this to be a question. The second is what happens by default when nobody decides.

What to Do With the Interval #

The RFI is coming. The window between now and a settled framework is the part that has to be managed deliberately, because it is the period in which deployment continues and documentation does not.

Three commitments make that interval survivable.

Inventory now, classify later. The single most valuable artefact is a complete register of where generative and agentic systems are actually running — including the ones procured as features inside SaaS products, which is where most of them hide. Whether each is formally a "model" under some future definition is a question you can answer once you know they exist. You cannot classify what you have not found.

Write the validation approach you would defend. Traditional backtesting does not transfer cleanly to a non-deterministic system, which is precisely why the agencies deferred. That is not a reason to have no approach. Generation testing against held-out cases, human-override tracking, parallel outcome analysis against the incumbent process, and documented acceptance thresholds are all available today and all legible to a supervisor.

Respond to the RFI. An institution that has built a working approach in the interval has something concrete to say, and the consultation is where the eventual standard gets shaped. Firms that stay silent inherit whatever the vocal ones negotiate.

The Operating Playbook #

  1. Re-baseline against the revised guidance now. Confirm which of your existing models move under the explicit proportionality language, in both directions. Some will need less; some will need more.
  2. Do not remove anything from the model inventory because of the AI exclusion. Removal is a decision that will read very badly in hindsight, and re-discovery costs more than retention.
  3. Tag every generative and agentic system in the inventory as pending-classification. Make the interval visible in the register rather than absent from it.
  4. Map each one to the frameworks it does answer to — third-party, operational, consumer protection, fair lending — and confirm each has a named owner under those.
  5. Adopt the stricter transatlantic standard as group policy. One inventory, one validation bar, one evidence pack.
  6. Prepare an RFI response. It is the cheapest available influence over the standard you will be examined against.

The agencies did something reasonable in April: they declined to write a rule for a technology they do not yet understand well enough to bound. The corresponding reasonable act for a bank is to decline to treat that as permission.

Frequently Asked Questions #

Does the April 2026 guidance mean generative AI is unregulated in US banking?
No. It means generative and agentic AI models are outside the scope of that specific guidance. Those systems remain subject to third-party risk management, operational risk, consumer protection, fair lending and general safety-and-soundness expectations. The agencies have also committed to a request for information addressing banks' use of AI, including generative and agentic AI.

What exactly was superseded?
The revised guidance, issued 17 April 2026 by the Federal Reserve, the OCC and the FDIC, supersedes the 2011 model risk management guidance and its 2021 companion. The core architecture — sound development, effective challenge, ongoing monitoring — carries forward.

Does the $30 billion threshold mean smaller banks can ignore this?
No. The guidance states it is expected to be most relevant to organisations above that size, and adds that it may also be relevant to smaller organisations with significant exposure to model risk because of the prevalence and complexity of their models, or activities outside traditional community banking. It is a statement of proportionality, not an exemption line.

How does this interact with the UK's SS1/23?
It diverges from it. SS1/23, effective 17 May 2024, is technology-neutral and does not exclude AI or machine learning. A group bank running the same model in both jurisdictions now faces different scoping answers, which is why governing to the stricter standard is the practical route.

Should we remove generative AI tools from our model inventory now that they are out of scope?
No — and this is the decision most likely to be regretted. Inventory completeness is cheap to maintain and expensive to rebuild. Tag those systems as pending classification instead, so the register reflects what is actually deployed when the framework arrives.

References #

Last reviewed .

Syndicate this article

Format for Medium

# Out of Scope Is Not Out of Risk: The 2026 Model-Risk Rewrite Left Out the Models Banks Are Actually Deploying

> Originally published at [https://sebastienrousseau.com/2026-07-30-model-risk-management-generative-ai-out-of-scope-2026/](https://sebastienrousseau.com/2026-07-30-model-risk-management-generative-ai-out-of-scope-2026/)

The April 2026 model-risk rewrite put generative and agentic AI expressly out of scope. Out of scope is not out of risk, and the UK disagrees.

Read the full article on sebastienrousseau.com: https://sebastienrousseau.com/2026-07-30-model-risk-management-generative-ai-out-of-scope-2026/

Format for Mastodon

Out of Scope Is Not Out of Risk: The 2026 Model-Risk Rewrite Left Out the Models Banks Are Actually Deploying

The April 2026 model-risk rewrite put generative and agentic AI expressly out of scope. Out of scope is not out of risk, and the UK disagrees.

https://sebastienrousseau.com/2026-07-30-model-risk-management-generative-ai-out-of-scope-2026/

Copy formatted for LinkedIn

Out of Scope Is Not Out of Risk: The 2026 Model-Risk Rewrite Left Out the Models Banks Are Actually Deploying

The April 2026 model-risk rewrite put generative and agentic AI expressly out of scope. Out of scope is not out of risk, and the UK disagrees.

Here are the key strategic takeaways:

- The exclusion is explicit, not an oversight. "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance." The agencies then commit to a request for information covering exactly those models.
- Out of scope is not out of risk. A GenAI tool that drafts credit memos or triages fraud alerts still lands under third-party risk, operational risk, consumer protection and fair lending. Nothing about the April rewrite moves it out of those.
- The UK did not follow. SS1/23 is deliberately technology-neutral and brings AI and machine learning into scope. Same model, same institution, two supervisory answers across the Atlantic.
- The interval is the risk. An institution that pauses its model-risk work on GenAI until the RFI resolves will have accumulated two years of undocumented deployment by the time it does.

What is your organisation's approach to the challenges outlined in this piece?

→ https://sebastienrousseau.com/2026-07-30-model-risk-management-generative-ai-out-of-scope-2026/

#ModelRiskManagement #Sr262 #Sr117 #OccBulletin202613 #GenerativeAiGovernance

Sebastien Rousseau | CC-BY-4.0
Cite this article

Out of Scope Is Not Out of Risk: The 2026 Model-Risk Rewrite Left Out the Models Banks Are Actually Deploying

The April 2026 model-risk rewrite put generative and agentic AI expressly out of scope. Out of scope is not out of risk, and the UK disagrees.

BibTeX

@online{rousseau2026out,
  author  = {Rousseau, Sebastien},
  title   = {{Out of Scope Is Not Out of Risk: The 2026 Model-Risk Rewrite Left Out the Models Banks Are Actually Deploying}},
  year    = {2026},
  url     = {https://sebastienrousseau.com/2026-07-30-model-risk-management-generative-ai-out-of-scope-2026/},
  urldate = {2026}
}

RIS

TY  - GEN
AU  - Rousseau, Sebastien
TI  - Out of Scope Is Not Out of Risk: The 2026 Model-Risk Rewrite Left Out the Models Banks Are Actually Deploying
PY  - 2026
UR  - https://sebastienrousseau.com/2026-07-30-model-risk-management-generative-ai-out-of-scope-2026/
ER  -

Vancouver

Rousseau S. Out of Scope Is Not Out of Risk: The 2026 Model-Risk Rewrite Left Out the Models Banks Are Actually Deploying. sebastienrousseau.com. 2026 Jul 30. Available from: https://sebastienrousseau.com/2026-07-30-model-risk-management-generative-ai-out-of-scope-2026/

Chicago

Rousseau, Sebastien. "Out of Scope Is Not Out of Risk: The 2026 Model-Risk Rewrite Left Out the Models Banks Are Actually Deploying." sebastienrousseau.com. July 30, 2026. https://sebastienrousseau.com/2026-07-30-model-risk-management-generative-ai-out-of-scope-2026/.

APA

Rousseau, S. (2026, July 30). Out of Scope Is Not Out of Risk: The 2026 Model-Risk Rewrite Left Out the Models Banks Are Actually Deploying. sebastienrousseau.com. https://sebastienrousseau.com/2026-07-30-model-risk-management-generative-ai-out-of-scope-2026/

Republish this article

Out of Scope Is Not Out of Risk: The 2026 Model-Risk Rewrite Left Out the Models Banks Are Actually Deploying

The April 2026 model-risk rewrite put generative and agentic AI expressly out of scope. Out of scope is not out of risk, and the UK disagrees.

This article is licensed under Creative Commons Attribution 4.0 International. Republication requires attribution to the canonical URL.

Out of Scope Is Not Out of Risk: The 2026 Model-Risk Rewrite Left Out the Models Banks Are Actually Deploying

The April 2026 model-risk rewrite put generative and agentic AI expressly out of scope. Out of scope is not out of risk, and the UK disagrees.

Originally published at https://sebastienrousseau.com/2026-07-30-model-risk-management-generative-ai-out-of-scope-2026/ by Sebastien Rousseau.
Licensed under CC-BY-4.0.