Research note | Checked October 4, 2026
What SR 26-2 leaves for AI governance.
The revised model-risk guidance excludes generative and agentic AI from its scope. That exclusion does not decide whether an institution's proposed AI use is acceptable.
What the primary source says.
The Federal Reserve's April 17, 2026 letter replaces SR 11-7 and SR 21-8. It says the guidance is expected to be most relevant to its supervised banking organizations over $30 billion. Read SR 26-2.
The attachment excludes generative and agentic AI while directing banks to their risk management and governance practices for systems outside its scope. It describes tailored, nonbinding guidance; it is not an AI approval process. Read the attachment, scope and footnote 3.
A practical review question.
Our recommendation: identify the workflow, allowed sources, required cases and human decision owner before accepting an AI-pilot result. An excluded system still needs an institution-owned use boundary; a slide saying the guidance does not cover it answers a different question.
Keep the source versions and what your reviewers actually tested. Retain failures, exclusions, missing evidence and the reason to wait or narrow. These are proposed method choices, not a claim that SR 26-2 mandates our packet.
What this note does not establish.
It does not apply a bank letter to a credit union, impose the same process on every community bank or claim every routine exam asks new AI questions. The institution must determine applicability with its own advisers.
Inspect the AI Pilot Acceptance Review Read the separate credit-union note
A file to inspect. A decision your institution owns.
Public tools run on supplied inputs and fictional examples. An engagement uses only sources you are allowed to share. We do not connect to a core, compile or execute institution code, take a financial action, certify compliance, give a legal opinion or claim achieved savings.