The Fed Rewrote Model Risk Guidance — and Left Generative AI Out of It

Insights / The Fed Rewrote Model Risk Guidance — and Left Generative AI Out of It

Fed SR 26-2 Generative AI Model Risk Gap

For 15 years, Supervisory Guidance on Model Risk Management (SR 11-7) was the reference point for model risk management at US banks.

On 17 April 2026, the Federal Reserve replaced it with Supervisory Guidance on Model Risk Management (SR 26-2). The new guidance covers traditional statistical and quantitative models and non-generative, non-agentic artificial intelligence (AI) models.

Generative AI and agentic AI are explicitly outside its scope.

For banks and lenders already using these technologies in lending, servicing, fraud and other decisions, that creates an important governance question: what framework governs these models when the Federal Reserve’s model risk guidance does not?

What SR 26-2 Actually Changed

SR 26-2 replaces both SR 11-7 and SR 21-8, the earlier guidance covering model risk in Bank Secrecy Act and anti-money laundering systems.

The new guidance makes a clear distinction between traditional models and newer forms of AI. Generative and agentic AI are described as novel and rapidly evolving and are therefore excluded from the guidance.

The Federal Reserve does not say that banks should ignore these models. Instead, it says banking organisations should continue applying their own risk management practices to them.

That means institutions using generative or agentic AI need to establish their own governance approach rather than relying entirely on a supervisory framework designed for another class of models.

The CFPB Requirement Has Not Changed

The important counterpoint comes from the Consumer Financial Protection Bureau (CFPB).

CFPB Circular 2022-03 requires adverse action notices for credit decisions to identify the specific principal reasons for the decision. The requirement does not change simply because the technology behind the decision is more complex.

The Equal Credit Opportunity Act (ECOA) and its implementing Regulation B also do not create an exception for generative or agentic AI.

In practical terms, a lender cannot rely on the complexity of an AI system as a reason why it cannot explain a credit decision.

What This Means for Enterprise Lenders

This creates a practical situation for banks and lenders using generative or agentic AI in underwriting, servicing or collections.

The Federal Reserve’s new model risk guidance does not cover these models, while CFPB requirements for explaining adverse credit decisions continue to apply. The result is greater responsibility for the institution’s own governance framework.

The organisation needs to know:

  • What models are being used and where they sit within the business
  • Which models fall within SR 26-2 and which require separate governance
  • How a specific AI-influenced decision was reached
  • What information can be provided if a customer, regulator or internal reviewer challenges the decision
  • How the organisation monitors and documents these models over time

The emphasis should be on decision-level explainability.

A model-level report showing that an AI system was operating normally is not necessarily enough. For a specific credit decision, the institution needs to be able to reconstruct the factors and information that contributed to that outcome.

Fragmented AI Investment Valuation Risk for CEO

Building Governance Around Generative and Agentic AI

Enterprise lenders do not need to wait for a future regulatory framework before putting these controls in place.

A practical governance model can start with three things.

  • First, maintain clear model inventories.
    Know which AI systems are being used, what decisions or processes they influence, and which regulatory and internal controls apply to each one.
  • Second, capture decision-level evidence.
    The organisation should be able to trace the information and factors behind an individual AI-influenced decision, particularly where that decision affects a customer’s access to credit.
  • Third, maintain documentation as the system evolves.
    Governance should keep pace with changes to models, data, workflows and use cases rather than being recreated when a regulatory request arrives.

This approach also creates a clearer separation between the technology itself and the governance around it. A generative model may change over time, but the institution still needs a consistent way to document, review and govern the decisions it influences.

Where Worktual's AI Advanced Intelligence Platform Fits

Worktual‘s AI Advanced Intelligence Platform is built around Enterprise Data Sovereignty and Intelligence, providing governed visibility into how customer and credit data is used and how an AI-influenced decision was reached.

The focus is on individual decision-level detail rather than visibility only at the overall model level.

For enterprise lenders using generative or agentic AI, this can provide a structured environment for maintaining the information needed to support internal governance, adverse-action documentation and regulatory review as AI use expands.

Preparing for the Next Stage of AI Governance

SR 26-2 modernises Federal Reserve model risk guidance while leaving generative and agentic AI outside its formal scope.

For enterprise lenders, that does not remove the need for governance. Other regulatory obligations continue to apply, including the CFPB’s requirements around specific and defensible reasons for adverse credit decisions.

The practical response is to build governance around the AI being used today: maintain clear model inventories, capture decision-level evidence and ensure that important decisions can be reconstructed when required.

That gives financial institutions a foundation they can continue to build on as regulatory expectations around generative and agentic AI develop.

Frequently Asked Questions

1. What is SR 26-2 and what did it replace?

SR 26-2 is the Federal Reserve’s revised model risk management guidance, issued 17 April 2026, superseding SR 11-7 (2011) and SR 21-8 (2021 interagency Bank Secrecy Act/anti-money laundering model risk guidance).

2. Does SR 26-2 cover generative or agentic AI models?

No. SR 26-2 explicitly states generative and agentic AI models “are not within the scope of this guidance,” applying instead to traditional statistical and quantitative models and non-generative, non-agentic AI models, though it says institutions should still apply their own risk practices to the excluded models.

3. Do CFPB adverse action requirements still apply to AI-driven credit decisions?

Yes. CFPB Circular 2022-03 requires adverse action notices to be specific about the principal reasons for a denial, regardless of model complexity, and explicitly rejects the defense that a model is too complex or opaque to explain.

4. Can a lender use generic reason codes for an AI-driven credit denial?

No. The CFPB circular states that generic statements citing a creditor’s internal standards or policies are insufficient, and that creditors cannot simply select the closest-sounding reason code if it doesn’t reflect the actual factors evaluated.

5. What should enterprise lenders do about the gap between SR 26-2 and CFPB requirements?

Build decision-level explainability and an internal model risk framework for generative and agentic AI now, rather than waiting for a future SR letter to formally cover it — the CFPB’s adverse action requirements already apply regardless of model type.

6. How does Worktual’s AI Advanced Intelligence Platform help here?

Through Enterprise Data Sovereignty and Intelligence, giving enterprise lenders governed visibility into how a specific AI-influenced credit decision was reached at the individual-decision level, ready to support adverse action and model risk documentation independent of which formal framework applies to the model.

Related Posts

Autonomous Enterprise Velocity Scale Without Overhead

Autonomous Enterprise Velocity: How Market Leaders Scale Without the Overhead

Insurance organizations operate in a complex, regulation-driven, margin-sensitive environment where growth depends on efficient onboarding, strong retention, and effective cross-sell across product lines. AI in insurance is central to this shift, as customers expect seamless digital onboarding journeys, real-time responses, and personalized communication across channels. Whether purchasing a policy, renewing coverage, or managing claims, expectations are shaped by digital-first experiences.

Fragmented AI Investment Valuation Risk CEO

Fragmented AI Investment Is a Valuation Problem, Not Just a Cost Problem

Insurance organizations operate in a complex, regulation-driven, margin-sensitive environment where growth depends on efficient onboarding, strong retention, and effective cross-sell across product lines. AI in insurance is central to this shift, as customers expect seamless digital onboarding journeys, real-time responses, and personalized communication across channels. Whether purchasing a policy, renewing coverage, or managing claims, expectations are shaped by digital-first experiences.

Ai in Ecommerce Complete Guide

Ecommerce AI Is Everywhere. Scaled AI Is Still Rare

Insurance organizations operate in a complex, regulation-driven, margin-sensitive environment where growth depends on efficient onboarding, strong retention, and effective cross-sell across product lines. AI in insurance is central to this shift, as customers expect seamless digital onboarding journeys, real-time responses, and personalized communication across channels. Whether purchasing a policy, renewing coverage, or managing claims, expectations are shaped by digital-first experiences.