Fifteen years of model risk doctrine was rewritten in April, and the most consequential paragraph is the one that says what the guidance does not cover. On 17 April 2026 the Federal Reserve, the OCC and the FDIC issued revised guidance on model risk management, superseding the 2011 framework that the industry has organised itself around for a decade and a half. The revision is careful, risk-based and largely welcome. It also states, in terms, that generative AI and agentic AI models are not within its scope — with a request for information to follow. Banks are therefore in an interval: deploying the models the framework excludes, under a framework that has not yet been written.
Executive Summary
- The 2011 settlement is retired. SR 26-2 and OCC Bulletin 2026-13, both dated 17 April 2026, supersede the long-standing 2011 guidance and its 2021 companion. The three-pillar architecture — sound development, effective challenge, ongoing monitoring — carries forward.
- Proportionality is now explicit. The agencies say the guidance is expected to be most relevant to banking organisations with over $30 billion in total assets, while remaining relevant to smaller institutions with significant model risk. That is a meaningful change of emphasis, not a carve-out.
- The AI question was deferred, not answered. Generative and agentic AI are excluded from this guidance, with a request for information to follow addressing model risk management generally and banks' use of AI in particular.
- Deferral is not permission. The correct reading is that the agencies have not yet decided how to supervise these models — which is materially different from deciding they need no governance.
What the Agencies Actually Changed #
Strip away the commentary and the April revision does three things.
It retires the 2011 settlement. The revised guidance supersedes the model risk guidance issued in 2011 and its 2021 companion, closing a fifteen-year chapter during which SR 11-7 became the de facto global reference for model governance well beyond the institutions it bound.
It makes proportionality explicit. The guidance is expected to be most relevant to banking organisations with over $30 billion in total assets, and remains relevant to smaller organisations with significant exposure to model risk because of the prevalence and complexity of their models or activities outside traditional community banking. Sophistication should track size, complexity and risk profile.
It keeps the architecture. Conceptual soundness in development, effective challenge through independent review, and ongoing monitoring against documented thresholds all survive. Institutions that built well against the 2011 framework are not starting again.
Table 1: What changed, and what carried forward #
| Element | 2011 framework | 2026 revised guidance |
|---|---|---|
| Status | SR 11-7 and its 2021 companion | Superseded and replaced, 17 April 2026 |
| Core architecture | Development, validation, governance | Carried forward substantially intact |
| Proportionality | Implicit, applied through supervision | Explicit: tailored to size, complexity and risk profile |
| Stated relevance | Broad | Most relevant above $30bn total assets; still relevant below where model risk is significant |
| Generative and agentic AI | Predates the question | Expressly out of scope, with an RFI to follow |
The Sentence That Matters #
Most of the revision is evolution. One passage is not:
Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance.
Read alongside the commitment to issue a request for information addressing model risk management generally, and banks' use of AI including generative and agentic AI in particular, the meaning is clear enough. The agencies are not saying these systems are low risk. They are saying they have not settled how to supervise them, and would rather consult than legislate a framework that a fast-moving technology outruns within a cycle.
That is defensible regulatory craft. It is also an awkward position for a bank that already has generative AI in production.
Because the practical question a risk committee asks is not "is this in scope of the April guidance?" It is "if this goes wrong, what will we be asked?" And the answer to the second question has not changed.
Out of Scope Is Not Out of Risk #
The most expensive misreading available in 2026 is that exclusion from the model risk guidance means exclusion from supervision. It does not. A model that falls outside this particular framework still sits squarely inside several others.
Table 2: Where an out-of-scope GenAI system still lands #
| The model does this | Framework it still answers to | The question you will be asked |
|---|---|---|
| Runs on a vendor foundation model | Third-party and outsourcing risk | Can you evidence due diligence, exit and concentration analysis on the provider? |
| Touches a credit or pricing decision | Consumer protection and fair lending | Can you demonstrate the outcome was not discriminatory, and reconstruct why it was reached? |
| Sits in a customer-facing or operational process | Operational risk and resilience | What happens when it degrades, and who notices? |
| Produces output staff rely on | Governance and senior accountability | Who owns this system, and what were they told about its limits? |
| Is deployed in the EU or the UK | EU AI Act; PRA SS1/23 | The scoping answer here is different — see below |
None of those are new obligations. That is exactly the point: the April guidance narrowed what it covers, and moved nothing out of anything else.
There is also a supervisory-expectation asymmetry worth naming plainly. When a framework is silent, examiners do not become silent. They fall back on general safety-and-soundness expectations, which are broader and less predictable than a written model-risk standard. Being out of scope of a specific rule frequently means being judged against a vaguer one.
The Transatlantic Split a Group Bank Now Has to Run #
For an institution operating on both sides of the Atlantic, the April decision creates a live divergence.
The UK's supervisory statement on model risk management principles for banks, SS1/23, took effect on 17 May 2024. It is built on five principles — identification and model inventory, governance, development and implementation and use, independent validation, and mitigants for models with deficiencies — and it is deliberately technology-neutral. Artificial intelligence and machine learning are not carved out; they are contemplated.
So the same generative model, deployed in the same group, in the same business line, is inside the UK model-risk perimeter and outside the newly revised US one. Add the EU AI Act's obligations for a European deployment and there are three answers, not two.
Institutions have exactly two coherent responses.
Run one framework at the strictest standard. Govern generative AI as though it were in scope everywhere, because it is in scope somewhere and will be in scope more broadly once the RFI resolves. This costs more now and is defensible in every jurisdiction.
Run genuinely separate perimeters. Legally possible, operationally miserable. It means two inventories, two validation standards and two sets of evidence for one model — and the reputational exposure of explaining, after an incident, that the version of the control that would have caught it was the one applied in the other jurisdiction.
The first is the right answer for almost every institution large enough for this to be a question. The second is what happens by default when nobody decides.
What to Do With the Interval #
The RFI is coming. The window between now and a settled framework is the part that has to be managed deliberately, because it is the period in which deployment continues and documentation does not.
Three commitments make that interval survivable.
Inventory now, classify later. The single most valuable artefact is a complete register of where generative and agentic systems are actually running — including the ones procured as features inside SaaS products, which is where most of them hide. Whether each is formally a "model" under some future definition is a question you can answer once you know they exist. You cannot classify what you have not found.
Write the validation approach you would defend. Traditional backtesting does not transfer cleanly to a non-deterministic system, which is precisely why the agencies deferred. That is not a reason to have no approach. Generation testing against held-out cases, human-override tracking, parallel outcome analysis against the incumbent process, and documented acceptance thresholds are all available today and all legible to a supervisor.
Respond to the RFI. An institution that has built a working approach in the interval has something concrete to say, and the consultation is where the eventual standard gets shaped. Firms that stay silent inherit whatever the vocal ones negotiate.
The Operating Playbook #
- Re-baseline against the revised guidance now. Confirm which of your existing models move under the explicit proportionality language, in both directions. Some will need less; some will need more.
- Do not remove anything from the model inventory because of the AI exclusion. Removal is a decision that will read very badly in hindsight, and re-discovery costs more than retention.
- Tag every generative and agentic system in the inventory as pending-classification. Make the interval visible in the register rather than absent from it.
- Map each one to the frameworks it does answer to — third-party, operational, consumer protection, fair lending — and confirm each has a named owner under those.
- Adopt the stricter transatlantic standard as group policy. One inventory, one validation bar, one evidence pack.
- Prepare an RFI response. It is the cheapest available influence over the standard you will be examined against.
The agencies did something reasonable in April: they declined to write a rule for a technology they do not yet understand well enough to bound. The corresponding reasonable act for a bank is to decline to treat that as permission.
Frequently Asked Questions #
Does the April 2026 guidance mean generative AI is unregulated in US banking?
No. It means generative and agentic AI models are outside the scope of that specific guidance. Those systems remain subject to third-party risk management, operational risk, consumer protection, fair lending and general safety-and-soundness expectations. The agencies have also committed to a request for information addressing banks' use of AI, including generative and agentic AI.
What exactly was superseded?
The revised guidance, issued 17 April 2026 by the Federal Reserve, the OCC and the FDIC, supersedes the 2011 model risk management guidance and its 2021 companion. The core architecture — sound development, effective challenge, ongoing monitoring — carries forward.
Does the $30 billion threshold mean smaller banks can ignore this?
No. The guidance states it is expected to be most relevant to organisations above that size, and adds that it may also be relevant to smaller organisations with significant exposure to model risk because of the prevalence and complexity of their models, or activities outside traditional community banking. It is a statement of proportionality, not an exemption line.
How does this interact with the UK's SS1/23?
It diverges from it. SS1/23, effective 17 May 2024, is technology-neutral and does not exclude AI or machine learning. A group bank running the same model in both jurisdictions now faces different scoping answers, which is why governing to the stricter standard is the practical route.
Should we remove generative AI tools from our model inventory now that they are out of scope?
No — and this is the decision most likely to be regretted. Inventory completeness is cheap to maintain and expensive to rebuild. Tag those systems as pending classification instead, so the register reflects what is actually deployed when the framework arrives.
References #
- Board of Governors of the Federal Reserve System, 2026. SR 26-2: Revised Guidance on Model Risk Management. Washington, DC: Federal Reserve. Available at: Board of Governors of the Federal Reserve System, 2026..
- Office of the Comptroller of the Currency, 2026. OCC Bulletin 2026-13, Model Risk Management: Revised Guidance. Washington, DC: OCC. Available at: Office of the Comptroller of the Currency, 2026..
- Prudential Regulation Authority, 2023. SS1/23, Model risk management principles for banks. London: Bank of England. Available at: Prudential Regulation Authority, 2023..
- European Parliament and Council of the European Union, 2024. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Brussels: Official Journal of the European Union. Available at: European Parliament and Council of the European Union, 2024..
Last reviewed .
