AlpacaX

Insights

Bank regulators wrote AI agents out of model-risk review

SR 26-2 excludes agentic AI from formal bank model-risk scope, leaving runtime governance to each bank's own risk program.

Marco Kwak
Marco KwakHead of GTM · 22 September 2026

SR 26-2 excludes agentic AI from formal bank model-risk scope, leaving runtime governance to each bank's own risk program.

Your AI agent will never fail a model-risk review

AI governance in financial services now splits into two separate tracks: formal model-risk validation, and everything else a bank's own risk program has to cover. That split became explicit in April 2026, when regulators excluded agentic AI from the first track by name—leaving banks to build the second one themselves.

In April 2026, the Federal Reserve, the Office of the Comptroller of the Currency (OCC), and the Federal Deposit Insurance Corporation (FDIC) issued SR 26-2 (SR = Supervision and Regulation letter), the revised interagency guidance on model risk management. It supersedes SR 11-7—the 2011 letter that governed how US banks validate models for fifteen years—and SR 21-8, the 2021 interagency statement on applying those principles to BSA/AML (Bank Secrecy Act/Anti-Money Laundering) systems.

SR 26-2 does something SR 11-7 never had to consider, because agentic AI didn't exist in 2011: it names generative and agentic AI directly and puts them outside the guidance's scope. The letter's own footnote is direct: "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance." Traditional statistical and quantitative models, and "non-generative, non-agentic AI models," are in scope. The AI agents your bank is deploying right now are not.

An agent built on top of an in-scope statistical model still sits inside the guidance's scope for that model. What falls outside SR 26-2 is the agent's own sequence of actions, not necessarily every model underneath it.

If you're a CISO or a platform lead at a bank, or you run a fintech that sells into one, that sounds like good news at first read. It isn't. It means the formal model-validation program—the process your model-risk team already runs, the one with independent review and documented assumptions—is not going to be the place your agent's behavior gets governed. There's no compliance box to check here. There's just a gap, and the letter tells you who owns it.

SR 26-2 isn't your letter—it's your model-risk team's. What makes it yours is the sentence at the end of the footnote.

What SR 26-2 actually says, and what it doesn't

A few specifics worth being precise about, because vague paraphrase is exactly what gets law-firm summaries wrong:

  • It's guidance, not a binding rule. SR 26-2 states plainly that it "does not set forth enforceable standards or prescriptive requirements," and non-compliance won't by itself trigger supervisory criticism. Supervisory action can still follow from "unsafe or unsound practices," but that's a separate hook, not an SR 26-2 violation.
  • It applies most directly to larger banks. The letter says it's "expected to be most relevant to banking organizations with over $30 billion in total assets." Smaller banks are generally left to their own internal risk practices, which SR 26-2 treats as already appropriate to their size. The letter keeps a door open, though: it "also may be relevant" to smaller banks with significant model-risk exposure or activities outside traditional community banking.
  • The definition of "model" is narrow and deliberate. SR 26-2 defines a model as something that "applies statistical, economic, or financial theories to process input data into quantitative estimates," and explicitly excludes "deterministic rule-based processes and software where there are no statistical, economic, or financial theories underpinning their design or use." An AI agent executing a sequence of infrastructure or transaction actions produces no quantitative estimate, so it doesn't reach the definition either way.
  • The guidance doesn't say agentic AI needs no governance. The same footnote that excludes it adds: "a banking organization's risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document." Read plainly, that's the agencies handing the problem back to the bank's own program—not closing the file on it. Fed Vice Chair for Supervision Michelle Bowman said as much directly in May 2026 remarks: "Going forward, we expect other risk-management and governance practices to support adoption of generative and agentic AI in ways that will encourage ongoing innovation."
  • Third-party model provisions don't quietly cover it either. SR 26-2's vendor-model section (§VII) discusses validating vendor and third-party model products. That section is written about in-scope models—the kind with statistical estimates to validate—not agentic tools generally. Nothing in that section extends coverage to the agentic AI the footnote just excluded.

This is a fresh exclusion, not an old gap finally noticed. SR 11-7 (2011) predates AI agents as a category entirely and simply never mentions them. SR 26-2, issued in April 2026, is the first of these letters to name agentic AI at all—and it names it to say, in writing, that the guidance doesn't apply.

Why "we passed model-risk review" was never going to be the story

Sullivan & Cromwell's client memo reads SR 26-2 as regulators tailoring model risk management (MRM) to a higher asset threshold and narrowing scope away from AI. That's true as far as it goes, but it undersells what changed.

SR 26-2 doesn't take an option off the table so much as close a question a bank could previously leave unasked: with the exclusion written into a footnote, no one can assume the model-validation pipeline—independent review, documented performance testing, ongoing monitoring—will pick up an agent's behavior by default.

That's not a relaxation of scrutiny. It's a relocation of it. Model-risk management, as a discipline, answers a specific question: is this model's statistical output sound and well-validated? That's a different question from: what did this agent actually do on our infrastructure, under what authorization, and can we show it after the fact? SR 26-2 is explicit that the first question doesn't apply here. It doesn't answer the second either.

For a bank's own risk team, that means the audit story for an AI agent deployment can't lean on "it cleared model-risk review"—SR 26-2's own scope exclusion means that review was never evidence about the agent's behavior in the first place. It has to come from somewhere else: the bank's own governance practices, which the letter names but doesn't define.

The AI governance gap this leaves for banks running AI agents

AI governance in financial services, for agentic AI specifically, now falls entirely to each bank's own risk program—SR 26-2 doesn't cover it and doesn't tell a bank how to build it. Whatever governance program a bank builds to fill that gap needs an answer for what an agent actually executes once it has infrastructure access, not just whether its statistical outputs are sound. That's a runtime question, not a model-validation one, and it's the layer a bank's own governance program has to cover precisely because SR 26-2 won't. Where Alpacon's command judgment is enabled, this is the layer it operates on: every command an agent runs is scored in real time, and file transfers are gated against a static path ACL.

SR 26-2 doesn't create an obligation to satisfy—it explicitly declines to. What it does is make the case for a separate, real-time governance layer for agent execution more concrete: the formal model-risk program isn't coming to cover this, so whatever a bank builds instead has to actually watch what the agent does, not just how it was trained or validated. That's a distinct discipline from model-risk management, and it's one banks in the CISO / platform-lead seat are already having to stand up on their own, ahead of any interagency letter telling them how.

What to check before your next model-risk review

If you sit on a bank's risk or platform team, or you sell into one, three things worth confirming now, not after an examiner asks:

  1. Don't route new agentic AI deployments through the existing MRM validation pipeline and call it done. SR 26-2's principles don't reach agentic AI, so a validation done under them isn't evidence about the agent's behavior. If your model-risk inventory currently includes agentic tools, that's worth a conversation with whoever owns model-risk policy internally.
  2. Ask who owns the "risk management and governance practices" SR 26-2 defers to. The letter names this as the fallback but doesn't specify an owner, a framework, or a review cadence. If the honest answer inside your organization is "nobody yet," that's the finding worth raising before an examiner raises it for you.
  3. Watch for the promised interagency follow-up. The agencies have said they "plan to issue in the near future a request for information that addresses model risk management generally and considers, in particular, banks' use of AI, including generative AI and agentic AI and AI-based models" (OCC Bulletin 2026-13). Separately, in May 2026 remarks, Fed Vice Chair for Supervision Michelle Bowman said the Federal Reserve is "also working to update and simplify" third-party risk-management guidance to reflect actual and future risk. Neither has been published as of this writing. Treat the current gap as the operating reality, not a placeholder waiting on a rule that closes it.

SR 11-7 governed bank models for fifteen years without ever mentioning an AI agent. SR 26-2 is the first of these letters to name agentic AI, and it names it to exclude it. The governance question didn't go away—it just stopped being the model-risk team's problem to answer alone.

Marco Kwak
About the authorMarco KwakHead of GTM

Marco Kwak is Head of GTM at AlpacaX, where he leads enterprise go-to-market and partnerships for Alpacon, an AI-native PAM platform with runtime execution control for AI agents. He previously held senior roles at H2O.ai and VMware, spanning AI cloud presales, global enterprise partnerships, and infrastructure software. He brings together engineering depth and commercial experience to help emerging infrastructure technologies move from technical validation to global adoption.


Bank regulators wrote AI agents out of model-risk review | AlpacaX