On April 17, American bank regulators replaced a document that had governed how banks manage model risk for fifteen years. Then they left the fastest-moving category of models out of it.
SR 26-2, issued jointly by the Federal Reserve, the FDIC and the Office of the Comptroller of the Currency, is the revised interagency guidance on model risk management. It retires SR 11-7, the 2011 framework that every large bank’s validation team has been built around. It covers governance, validation, documentation and the scaling of expectations to an institution’s size and complexity. What it does not cover is generative or agentic AI, which the agencies placed outside its scope, leaving banks to govern those systems under whatever risk management practices they already have.
Why the carve-out matters
A traditional model takes inputs and produces a score. You can validate it, backtest it, document its assumptions and re-check it on a schedule. That is what SR 11-7 was built for and what SR 26-2 modernises.
An agentic system is a different object. It combines a foundation model the bank did not build with proprietary data, retrieval tools, prompts, business rules, workflow software and human approvals, and then it takes actions. The thing being governed is not a model. It is a pipeline, and much of that pipeline changes underneath the institution without a release note.
SR 26-2 is aimed primarily at banking organisations with more than $30 billion in total assets, and it arrives as supervisory guidance rather than as a rule, which means it does not carry the force of law. Smaller institutions got the clarification they had asked for: expectations scale to size, complexity and risk profile.
FINRA got there first
Broker-dealers received sharper direction. FINRA’s 2026 Annual Regulatory Oversight Report, published on December 9, 2025, addresses autonomous AI agents head on, and its framing is the useful part. Once a system can take an action rather than merely generate content, a firm’s supervisory, books-and-records and governance obligations shift materially.
The report sets out the questions firms should be answering: how to monitor an agent’s system access and data handling, where to place human-in-the-loop oversight, how to track the actions and decisions an agent takes, and how to build guardrails limiting what it is able to do. None of that is exotic. It is close to what a bank would ask about a junior employee holding system credentials, which is a fair way to think about what is actually being deployed.
The deployment curve
Adoption is not waiting for any of this. A Wolters Kluwer survey found 44 percent of finance teams expected to use agentic AI during 2026, a steep jump on the year before. The deployments that are working sit in the back office rather than the customer channel: know-your-customer verification, loan document processing, transaction monitoring and regulatory reporting, where the output is checkable and a mistake gets caught before it reaches anyone outside the bank.
That ordering is telling. Banks are putting agents where the work is repetitive, the ground truth is knowable, and a human signs at the end. The chatbot-first strategy that dominated 2023 has largely been abandoned by institutions that measured what it returned.
Europe set a date
The European Union’s AI Act reached a milestone on August 2, 2026, when its transparency obligations took effect. Customers interacting with an AI system have to know that is what they are doing. For any bank running retail operations in the EU, that is a concrete, dated compliance requirement rather than a set of considerations, and it applies regardless of how the institution has classified the system internally.
Set the two regimes side by side and the contrast is stark. Brussels has a deadline. Washington has a scope carve-out and a report full of questions worth asking.
Where this lands
The gap will close, and probably not through new guidance. It will close the first time an agent at a large institution executes something it should not have and the bank cannot produce a clean record of what it did or why. Supervisory expectations in banking have a habit of arriving as enforcement before they arrive as text.
Institutions building agent-level logging, access controls and decision trails now will be answering an examiner’s questions rather than reconstructing the answers under pressure. Anyone treating the SR 26-2 carve-out as permission to wait is making a bet on timing.
For more coverage of AI in finance, visit Mylistingo.







