Skip to main content
    Back to Insights
    AI Governance

    SR 26-2 Just Created a Governance Gap Banks Can't Ignore

    The Federal Reserve just carved AI out of model risk management. The institutions that treat this as relief instead of a budget signal will be 12 to 18 months behind.

    PG
    Paul GoldmanCEO, iTmethods
    May 12, 20264 min read

    Securing the Agentic Era. Article 12 · AI Governance

    Open RegTechVendor AI DataEU AI Act DelayAgent SprawlThis Article: SR 26-2 Governance Gap

    On April 17, 2026, the Federal Reserve, OCC, and FDIC jointly retired SR 11-7, the 15-year-old framework that defined model risk management for every major U.S. bank, and replaced it with SR 26-2.

    The financial press framed this as a modernization. More flexible, principles-based, less prescriptive. That framing misses the real story.

    SR 26-2 does something much more consequential than update old rules. It explicitly carves generative AI and agentic AI out of scope and leaves their governance to each bank’s own risk-management and governance practices. The institutions reading this as regulatory relief are reading it backwards. The carveout is the spend signal.

    Apr 17, 2026
    SR 26-2 ISSUED
    FED · OCC · FDIC INTERAGENCY
    $30B
    ASSET THRESHOLD
    PRIMARY SCOPE
    2
    SR LETTERS RETIRED
    SR 11-7 AND SR 21-8
    Excluded
    GENERATIVE + AGENTIC AI
    BANK'S OWN GOVERNANCE APPLIES
    $2.5B
    2026 GOVERNANCE
    SPEND WAVE
    12-18 mo
    BUILD HORIZON
    BLANK-SHEET TO READY

    What SR 26-2 Actually Does

    The new guidance applies primarily to banking organizations above $30 billion in assets. Every G-SIB and large regional bank. Two changes matter most.

    1. Scope is drawn around risk-based model definitions, and generative and agentic AI sit outside it. A footnote leaves the governance and controls for anything outside the guidance to the bank’s own risk-management and governance practices. The principles in the guidance apply to traditional statistical and quantitative models and to non-generative, non-agentic AI models.

    2. Materiality-based oversight replaces annual revalidation. Validation cadence is now driven by risk assessment rather than a fixed calendar.


    The Real Impact. A Governance Gap That Didn’t Exist on April 16

    For a Chief Risk Officer at a G-SIB, the shift is stark. Three weeks ago, generative AI deployments were governed under an informal extension of SR 11-7. Today, those same deployments sit outside any specific regulatory framework. The bank must now construct its own AI governance architecture under the risk-management and governance practices the guidance points it back to.

    This is not theoretical. Banks above $30 billion in assets will be examined against SR 26-2’s expectations for the models it covers, and their generative and agentic AI work sits with the risk-management and governance practices each bank sets for itself. Those without a defensible AI governance framework mapped to AIGF v2.0, EU AI Act, OSFI E-23, and DORA will face a difficult conversation with their audit committee and board.

    This is the operational consequence of the same architectural gap the Agent Sprawl piece documented last week. 97% of enterprises run AI agents. Only 12% have centralized control. SR 26-2 converts that 88-point gap into a regulator-relevant exam finding for U.S. banks above the $30 billion threshold.


    The $2.5B Spend Signal

    Institutional research has been forecasting a $2.5 billion 2026 AI governance spend wave in regulated industries for two quarters. SR 26-2 is the document that converts that forecast into mandatory budget.

    The institutions that started building enterprise AI governance frameworks ahead of SR 26-2, mapped to AIGF v2.0 and the EU AI Act, can already show their risk function and their examiners how these systems are governed. Banks that waited will be answering that question defensively, then facing an 18-month implementation cycle from a blank sheet.

    The architectural pattern is the same one the Open RegTech piece three weeks ago laid out. Open standards (CDM, Morphir, DRR, AIGF v2.0) plus managed infrastructure to run them under SLA. SR 26-2 confirms why that pattern is the answer. The same evidence pipeline has to satisfy SR 26-2, AIGF v2.0, OSFI E-23, the EU AI Act, and DORA. One build. Five regimes.

    SR 26-2 carved AI out. The obligation stays with you. The build is now.

    The institutions that treat the carveout as relief instead of a budget signal will be 12 to 18 months behind the institutions building evidence architecture today.

    Get an AI governance readiness assessment

    What Banks Should Build Now

    Five capabilities, built on shared infrastructure, satisfy SR 26-2, AIGF v2.0, third-party AI risk, OSFI E-23, EU AI Act high-risk, and DORA simultaneously.

    A continuously updated inventory of every model and AI system, scored on materiality. Identity and authorization for every non-human actor: models, agents, tools. Authoritative policy decisions in the operational path of every model and tool invocation. Evidence collection as a byproduct of operation, tamper-resistant, identity-attributed, mapped to regulatory clauses. Cross-domain consistency so the same evidence pipeline works for model risk, AI governance, trade reporting, and any regulated workflow.

    These five together are the architectural answer to SR 26-2, AIGF v2.0, the EU AI Act high-risk obligations, OSFI E-23, and DORA, simultaneously. They are not separate projects. They are one infrastructure problem.


    The Bottom Line

    The Federal Reserve, OCC, and FDIC just rewrote fifteen years of bank model risk management and left generative and agentic AI to the risk-management and governance practices each bank sets for itself. The institutions that treat the carveout as relief rather than a budget signal will be 12 to 18 months behind the institutions that already have evidence architecture in place.

    The framework just got rewritten. The carveout is where the next wave of regulated AI governance spend lands. The architectural answer is the same whichever controls a bank concludes its own uses require. The institutions that built for it already are the ones positioned for what comes next.

    The carveout is where the next wave of regulated AI governance spend lands. The obligation moved to the bank the day the guidance issued.


    Paul Goldman is CEO of iTmethods and architect of Reign. Governed AI. Outcomes assured. He has spent 21 years building managed infrastructure for regulated enterprises and writes weekly on AI governance in the agentic era.

    Reign is the AI Governance Platform. AI Gateway, Model Risk Validation, Audit Ledger (CAVR), Assurance Packs. Mapped to the FINOS AIGF v2.0. Reign Ops is the managed runtime layer underneath. Reign for Life Sciences extends the same evidence model to regulated life sciences workflows. Governed AI. Outcomes assured. Learn more at itmethods.com.

    Sources

    Previously in this series: Agent Sprawl Is the New Shadow IT · EU AI Act Delay Doesn’t Change What to Build · Vendor AI Data Governance Problem · Why the AI Governance Stack Was Built for the Wrong Problem

    PG

    Paul Goldman

    CEO, iTmethods

    Founder and CEO of iTmethods, and the author of The Trust Layer. Previously published "MCP Is Exploding. Your Governance Isn’t Ready."

    Continue the AI Governance series

    Get Paul’s next article before it publishes

    Join 500+ security leaders

    The Trust Layer.

    A weekly essay on governing agentic AI in regulated industries. No product pitches.

    Talk to the team behind the Trust Layer.

    We run the platform, do the work, and prove it. Reign Ops operates the engineering toolchain your teams already use. Reign Factory, Gateway and Assurance sit inside that boundary, each at its own stated stage. Tell us what you are solving for and we will route it to the people who own that work.

    Start a conversation