Close the Gen AI Examination Gap in Financial Services

Access this content by contacting one of our representatives for assistance.

Author(s): Mitchell Fong

On April 17, 2026, US banking agencies issued revised model risk management guidance, replacing the framework in place since 2011. SR 26-2 narrows the definition of a model, and Footnote 3 places generative and agentic AI outside the guidance's scope entirely. That same footnote directs institutions to determine appropriate controls for excluded systems through their own risk management and governance practices. Other jurisdictions are drawing their own boundaries: The EU AI Act classifies certain financial-services uses as high risk, and Canada's OSFI has adopted a broad, risk-based model definition in Guideline E-23, effective May 1, 2027.

The exclusion changes the governance route. It does not remove the need to govern. Institutions must decide who owns oversight of Gen AI systems, which controls apply, and what evidence demonstrates that those controls work, a decision that applies equally to internally developed systems and AI embedded in vendor products.

The control gap is already visible. In a survey of 230 US banking professionals, 72% identified reporting or shutting down an AI incident as the area their institution was least prepared for. Separately, a July 2025 Massachusetts settlement over alleged fair-lending violations involving algorithmic underwriting shows that existing law can already apply to AI-enabled decisions. That case predates SR 26-2 and was not a Gen AI enforcement action.

CIOs and risk leaders can act without waiting for another rule:Assign an accountable owner and review date, adopt a control benchmark, scale oversight to the system's use, consequences, complexity, and autonomy, and maintain a decision record updated whenever the system materially changes. NIST's AI Risk Management Framework and the Cyber Risk Institute's Financial Services AI Risk Management Framework offer voluntary starting points, not substitutes for applicable law or supervisory expectations.