TL;DR: In April 2026, US federal banking regulators retired SR 11-7, the model risk management guidance that had governed financial institutions for fifteen years, and replaced it with SR 26-2. The new guidance modernizes and scales expectations for traditional models, but it explicitly excludes generative and agentic AI from its formal scope — which sounds like a reprieve and isn't one. For fintechs and their AI vendors, the practical governance bar for genAI just got higher, not lower, even though the letter of the rule doesn't name it.
For fifteen years, SR 11-7 was the reference point any fintech touching credit, fraud, or compliance eventually had to reckon with — either directly, as a regulated bank, or indirectly, as a vendor whose models a bank partner had to validate under it. In April 2026, the Federal Reserve, OCC, and FDIC replaced it with SR 26-2. The headline framing in most coverage has been "generative AI is excluded from scope" — which is true, narrowly, and misleading if taken as a signal that AI governance expectations have relaxed.
What SR 26-2 actually changed
SR 26-2 preserves the structural backbone that made SR 11-7 durable: the three-pillar approach of robust model development with conceptual soundness, independent effective challenge through review, and ongoing monitoring against documented performance thresholds. What changes is scope and calibration. The new guidance applies most directly to banking organizations above roughly $30 billion in total assets, moving away from a one-size-fits-all standard toward a risk-based framework calibrated to an institution's size, complexity, and actual model risk exposure — smaller community banks without unusually complex models are largely relieved of the heaviest documentation burden that SR 11-7 imposed uniformly.
Third-party and vendor model risk gets more explicit, standalone treatment than it had before. The revised guidance is clear that using a vendor's model doesn't transfer or dilute the institution's responsibility to understand, validate, monitor, and document how that model is used — a provision with direct relevance for any fintech selling AI-driven underwriting, fraud detection, or compliance tooling into regulated banks, since the diligence burden their bank customers now face is more explicit, not less.
The most consequential line, though, is the exclusion: SR 26-2 explicitly keeps generative AI and agentic AI outside its formal scope, on the stated basis that these technologies are too novel and fast-moving for a durable supervisory standard yet. Regulators have signaled a separate request for information specifically on AI model risk is coming, alongside a Financial Stability Board consultation on AI practices expected later in 2026.
Why the exclusion isn't a green light
It would be a mistake — and a commercially risky one — to read the genAI exclusion from SR 26-2 as reduced supervisory interest in how banks and fintechs govern their AI systems. Multiple readings of the revised guidance and commentary from risk-management practitioners converge on the same point: the absence of a formal rule doesn't mean the absence of an expectation. Banking organizations are still expected to apply "broader risk management and governance practices" to systems that fall outside SR 26-2's explicit scope — meaning examiners retain the latitude to assess an institution's genAI governance against the same underlying principles (soundness, independent challenge, ongoing monitoring) even without a numbered rule to cite chapter and verse.
In practice, several factors point toward tighter scrutiny ahead rather than looser:
The RFI process typically precedes formal rulemaking. A request for information on AI model risk is usually the input-gathering stage before a dedicated rule, not a sign regulators have decided to leave the space unregulated. Institutions that treat the current gap as a permanent exemption are likely to be caught flat-footed when that rule lands.
Examiners don't need a named rule to ask hard questions. Bank examiners assessing an institution's overall risk management posture can and do ask about genAI governance under general safety-and-soundness authority, independent of whether SR 26-2 specifically names it. The exclusion changes what a bank can point to as a compliance checklist; it doesn't change what an examiner can ask about.
Vendor diligence expectations flow downhill. Because SR 26-2 sharpens third-party model risk expectations for the models it does cover, banks are becoming more rigorous about vendor diligence generally — and that heightened diligence culture tends to extend informally to genAI tools even where the formal rule doesn't reach, because risk committees increasingly don't distinguish between "covered by SR 26-2" and "a model our institution is exposed to."
Where AI governance is genuinely mature in fintech today
Traditional machine learning models used for credit scoring, fraud detection, and AML — the models SR 26-2 does formally cover — have the most mature governance infrastructure in the industry, largely because fifteen years of SR 11-7 supervision built the muscle: documented validation processes, independent model risk teams, and monitoring dashboards tracking drift against thresholds. Fintechs building on top of these categories can lean on an established compliance vocabulary that examiners and bank partners already understand.
Generative AI used for internal productivity — code assistance, document summarization, customer service drafting that a human reviews before it goes out — carries comparatively low regulatory exposure today, precisely because it doesn't make or materially influence a credit, fraud, or compliance decision on its own.
Where the picture gets genuinely underdeveloped is generative and agentic AI applied directly to regulated decisions: an LLM-assisted underwriting narrative that a loan officer relies on, an agentic AI system initiating fraud investigation actions, or a genAI tool drafting compliance narratives that feed into a filing. These are the use cases sitting in the gap between "clearly should be governed like a model" and "not yet formally required to be."
Implementation risks in this transition period
Building genAI governance to the exact letter of SR 26-2 and stopping there. Because SR 26-2 explicitly excludes genAI, an organization that treats the rule as its full governance scope will have a documented gap the moment the promised AI-specific guidance arrives — and will likely have to retrofit under time pressure rather than design deliberately.
Underestimating third-party diligence burden as a fintech vendor. If your product sells into banks above the roughly $30 billion threshold, expect substantially more detailed validation, monitoring, and documentation requests from your bank customers' model risk teams than SR 11-7-era relationships typically required — this is one of the most concretely strengthened provisions in the revised guidance.
Assuming smaller-bank exemptions apply to you. The size-based relief in SR 26-2 is calibrated to the bank's complexity and risk profile, not simply its asset size — a smaller institution running unusually complex AI-driven products can still fall under heightened scrutiny despite being under the general threshold.
Explainability gaps compounding the ambiguity. In a period where the formal rule is silent on genAI, an institution's ability to explain what its AI system did and why becomes the de facto standard examiners fall back on — which is exactly the capability many fintechs still lack, as covered in our related piece on the explainability gap in fintech AI audits.
How to evaluate whether your governance is ready
A few direct questions surface most of the exposure before an examiner or a bank partner does:
If a regulator asked you today to walk through how a specific AI-assisted underwriting or fraud decision was made, could you produce a documented trail — not just a technical log, but a narrative a non-technical examiner could follow? If not, that's the highest-priority gap regardless of which formal rule technically applies.
Does your genAI governance framework mirror SR 26-2's three-pillar structure (development soundness, independent challenge, ongoing monitoring) even though the rule doesn't require it for genAI yet? Building to that structure now is materially cheaper than retrofitting once formal guidance arrives.
If you're a vendor selling into regulated banks, have you proactively prepared the validation and monitoring documentation a model risk team is likely to request, rather than waiting to be asked? The revised guidance's sharper third-party language means that request is coming sooner than it might have under SR 11-7.
Do you have a designated owner — not a committee, an actual named role — responsible for tracking the promised AI-specific RFI and FSB guidance as it develops, so your governance framework can adapt before it's mandatory rather than after?
Where Syslabs fits in
Building the documentation trail, monitoring infrastructure, and audit-ready governance that examiners and bank partners now expect around AI-driven decisions is fundamentally a custom software and systems-integration problem, not a policy-writing exercise — it requires connecting model outputs, decision logs, and human review checkpoints into something that produces evidence on demand rather than after the fact. Syslabs works with fintechs on exactly that layer: building the technical infrastructure that makes AI governance demonstrable, not just declared, ahead of the AI-specific guidance regulators have already signaled is coming.
Sources: FINOS, Sia Partners, Bespoke Mentis, Baker Tilly, Domino.ai, and Federal Reserve supervisory letter SR 26-2 (April 17, 2026), on model risk management guidance for 2026.