The fastest-growing part of your model estate sits outside the guidance that governs the rest.
SR 26-2 revised US model risk guidance in April 2026 and put generative and agentic AI outside its own scope. OSFI E-23 went the other way and wrote AI/ML into its definition of a model. Either way the question lands with you, and it lands without a cycle to answer it on.
A single-tenant dedicated instance, in your own AWS or Azure account or in infrastructure iTmethods operates. Both available today; Google Cloud is planned for 2027. Air-gapped and sovereign are in development.
A gap that is arithmetic, rather than opinion.
Model risk management was built around a population you could enumerate and a change you could schedule. Neither assumption survives an agent that invokes a model a thousand times a day against a prompt somebody edited on Tuesday.
It also removed the at-least-annual validation cadence and narrowed the definition of a model. The principles still apply to traditional and non-generative AI models; the part of your estate growing fastest is handed back to your own governance.
It sets review frequency by risk rating rather than by calendar, requires monitoring standards with defined thresholds and escalation, and prescribes the fields a model inventory has to carry. If you operate on both sides of the border, you are managing to two different scopes.
That divergence is not detectable from a validation report. It is detectable from a record of what was actually authorized, at the moment it was authorized.
It is a supervisory statement rather than a regulation, and it binds indirectly through supervised entities. It is also the clearest signal available about which direction the next set of expectations comes from.
Governance, validation, monitoring, change control — at the rate AI actually moves.
The four components of model risk management, and what each needs from the infrastructure underneath before it can be evidenced rather than asserted.
Governance that names an owner
Every model in use has a named owner, an approved purpose and a documented boundary, or it does not have governance — it has a spreadsheet. At the boundary, a model that is not on your policy list is not reachable, so the inventory and the enforcement are the same object.
Validation against a moving target
A model validated in March is not the model answering in June if the provider shipped in between. The record carries which model answered each call and when, so a change of model is a thing you can see rather than a thing you have to be told.
Monitoring between cycles
An annual review tells you about the year. It does not tell you what a model did on a Tuesday, which is the granularity an exception gets argued at. A record per call is the shortest interval there is.
Change control that holds
Requirements become checks that run against work as it moves, and a check that cannot decide is routed to a named person rather than resolved quietly in the system’s favour.
The operating record your framework already assumes exists.
Which limits applied at the moment of each action, what was authorized, what the outcome was, and who decided each exception. That record is produced by Reign Gateway, and it is the part of this that exists today.
The record is hash-linked as it is written and exported write-once into storage you hold, under your retention and your Object Lock. Whether that satisfies your framework is a second-line judgment about model risk, and the risk function is the only party positioned to make it.
What this does not settle for you.
A record is an input to a model risk judgment. It is not the judgment, and nothing here is a compliance conclusion.
Reign produces operating evidence. What it means for your model risk framework is a second-line determination, reached by the people who own that framework and defensible to your supervisor.
It states that it does not set forth enforceable standards, and it places generative and agentic AI outside its scope. Anyone citing it as a reason to buy AI governance is misreading it.
When a model does not answer, the call is recorded as failed. It does not fall back to a model your policy has not permitted, because it does not fall back at all.
It does not certify, does not attest, does not issue an audit opinion and does not provide independent assurance, in any tense. Reign prepares the evidence; the people who own the risk decide.
Regulatory references on this page are to SR 26-2, OSFI E-23 and the ESAs’ July 2026 joint statement on frontier AI models. Each is cited for what it says, including where what it says is that something is out of scope.
The questions that arrive before the scoping call.
Does SR 26-2 require any of this?
We are federally regulated in Canada. Does E-23 change the answer?
What is actually recorded on a model call?
Is Reign Assurance available?
The same estate, three other questions.
Whoever else is in the room is reading a different page about the same infrastructure. These are theirs.
Bring us the model inventory you have to defend.
We will look at what exists between validation cycles today, which of it is generative or agentic and therefore outside SR 26-2, and what a supervisor would find if they asked what a model did on a Tuesday.