Regulatory brief · SR 26-2
The guidance that stopped covering agentic AI.
On 17 April 2026 the Federal Reserve, OCC and FDIC jointly issued SR 26-2, replacing the fifteen-year-old SR 11-7 model risk framework. It reorganises oversight around model materiality — and it explicitly places generative and agentic AI outside its scope.
Every claim on this page is quoted from the letter, with the page or footnote it came from. Read it yourself: the source is linked at the bottom.
The gap
Footnote 3 to the model definition removes the two categories of AI that banks are actually deploying right now:
“Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance. Nonetheless, a banking organization’s risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document.”
SR 26-2, page 3, footnote 3Three consequences follow, and they matter in this order:
- There is no regulator-issued framework for agentic AI in US banking. The agencies declined to write one and handed the question back to each institution’s own governance practices.
- Traditional models remain fully in scope. A conventional credit scorecard or non-generative ML underwriting model is governed exactly as before. This is not a general deregulation.
- The legal exposure did not move. ECOA, FCRA, TILA and UDAAP are statutes. Removing agentic AI from model-risk guidance does not remove liability for a discriminatory or unfair agentic lending decision.
Non-binding is not the same as no consequences
The letter says non-compliance “will not result in supervisory criticism.” Footnote 1 to that same sentence adds: “supervisory action may result for any violations of law or unsafe or unsound practices stemming from insufficient management of model risk.”
So a bank running agentic lending now carries the full statutory liability with no regulator-issued framework to discharge it against. That gap is the reason this product exists.
Deterministic rule engines are outside the model definition
“The term ‘model’ in this guidance excludes simple arithmetic calculations, such as those found within spreadsheets, as well as deterministic rule-based processes and software where there are no statistical, economic, or financial theories underpinning their design or use.”
SR 26-2, page 3This matters when you buy a control rather than a model. A vendor product that meets the model definition transfers a validation burden onto you. One that falls under the deterministic exclusion does not.
Sentinel’s enforcement path is rule-based: comparison operators, an AST expression evaluator, condition types and fixed verdict precedence. We do not ask you to take that on faith — the classification of all fourteen pipeline components is verified against the source code by an AST scan, and a component that starts computing a variance fails our build rather than quietly invalidating the claim.
One component is genuinely statistical, and we say so
The anomaly scorer maintains a running mean and variance and flags z-score outliers. It can affect a verdict, and it is disableable — which is what makes a fully deterministic verdict path possible rather than merely asserted. Everything else in the decision path is pattern matching and arithmetic over hand-authored constants.
Materiality replaced the annual cycle
SR 26-2 reorganises oversight rigor around model materiality — exposure plus purpose — rather than calendar intervals.
“The timing, nature, and frequency of validation activities vary based on model purpose, model methodology, frequency and scope of model changes, data limitations, and other practical constraints.”
SR 26-2, on validation frequencyAnnual revalidation is no longer the expected default. A governance system that enforces a fixed 365-day review interval is implementing the retired SR 11-7 posture. Sentinel derives review cadence from exposure and purpose, and reports models with no classification as unclassified rather than silently defaulting them — so the gap is visible instead of hidden.
Section VII on vendor and third-party products survived the rewrite intact: validation, conceptual soundness, ongoing monitoring, and documented justification for any customisation. Sentinel tracks that as a register, inheriting each product’s materiality from the agent types it feeds.
If you are under $30B, this letter is probably not about you
We would rather say this plainly than let you assume otherwise:
- Credit unions are not covered. The NCUA is not a signatory to SR 26-2. Credit unions follow NCUA model-risk expectations.
- Institutions at or below $30B in total assets are outside the letter’s stated primary scope, on the reasoning that risk management appropriate to their size and profile is sufficient. It may still be relevant with significant model risk exposure through the prevalence or complexity of models.
If you are a community bank or a credit union, the reason to govern an AI lending agent is not SR 26-2. It is that ECOA and FCRA apply to you in full, examiners will ask how an automated decision was reached, and “the model decided” has never been an adequate answer. That case stands on its own without borrowing an authority that does not reach you.
What is coming that does bind
SR 26-2 is guidance. These are not, and both have dates:
Sources
Check every claim above against the letter. We would rather you did.
SR 26-2 — Federal Reserve SR letter →
SR 26-2 — full guidance (PDF) →
Colorado SB 26-189 →
If you think we have characterised any of this incorrectly, tell us and we will correct the page.
Design partners
Govern the gap, before it is filled for you.
Start in shadow mode and get a report of what would have been caught, with zero enforcement risk. Graduate to enforcement when the evidence earns it.