Summary: On 17 April 2026 the OCC, Federal Reserve, and FDIC replaced the 2011 model-risk letter. OCC Bulletin 2026-13 and Federal Reserve SR 26-2 take generative and agentic AI out of scope because those systems are novel and rapidly evolving. The letter is most relevant above $30 billion in assets and does not set enforceable standards. Examiners will still ask how uncovered tools are governed. Broader AI governance practices apply while the agencies’ promised request for information is pending.
What the new letter covers, and who it is for
OCC Bulletin 2026-13 is the OCC issuance of that interagency rewrite. The Federal Reserve issued the same revised guidance as SR 26-2, which supersedes and replaces SR letter 11-7, issued April 4, 2011, and SR letter 21-8, issued April 9, 2021. On the OCC side, the bulletin rescinds the Model Risk Management booklet of the Comptroller’s Handbook, OCC Bulletin 1997-24, OCC Bulletin 2011-12, and OCC Bulletin 2021-19.
For the purposes of the guidance, a model is a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to process input data into quantitative estimates. Simple arithmetic and deterministic rule-based software sit outside that term.
The agencies say the guidance is expected to be most relevant to banking organizations with over $30 billion in total assets. OCC adds that it may be relevant below that line if model-risk exposure is significant. The guidance does not set forth enforceable standards or prescriptive requirements, and non-compliance will not result in supervisory criticism.
The sentence that took agentic AI out of the letter
OCC Bulletin 2026-13 states the carve-out twice, in Highlights and Background: “Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance.” The HTML page for SR 26-2 does not reprint that sentence. The exclusion lives on the OCC bulletin and in the attached guidance PDF.
In remarks delivered April 27, 2026 and published on 1 May 2026, Vice Chair for Supervision Michelle W. Bowman said that the Fed, with the OCC and FDIC, had amended model-risk guidance “to clarify that it does not apply to generative or agentic AI.” Orrick notes that the exclusion also appears as a footnote, on the same novel-and-rapidly-evolving rationale. Some vendor glossaries still tell teams the new letter brought agents into scope. That reading contradicts the official bulletin.
What the letter still applies to
Sullivan & Cromwell, in a 29 April 2026 memo, says the revised guidance does apply to traditional statistical and quantitative models and to non-generative, non-agentic AI models. Bowman put the residual in official language: the revised guidance “now applies narrowly to traditional models and basic AI applications.” Those sentences describe what the letter still covers. Banks still have a model-risk letter for traditional quantitative models. They no longer have that letter for generative and agentic systems.
The hole examiners will walk through while the RFI is pending
OCC Bulletin 2026-13 says the agencies plan to issue in the near future a request for information that addresses model risk management generally and considers banks’ use of AI, including generative AI and agentic AI. No issued RFI text or comment deadline sits on the public record used for this piece.
Bowman said the agencies “expect other risk-management and governance practices to support adoption of generative and agentic AI in ways that will encourage ongoing innovation.” Sullivan & Cromwell writes that banking organizations should apply their broader risk management and governance practices to tools not covered by the revised guidance, including generative and agentic AI models. Those tools stay under the expectations that apply to banking organizations in general.
American Banker published the examiner line on 1 June 2026. Examiners will still ask, on the basis of safety and soundness, what unique monitoring and testing framework a bank uses for generative and agentic AI, and what its effective challenge is. The opinion treats SR 26-2 as leaving the form of the answer to each institution while still requiring that an answer exist.
Broader governance while the agencies collect comments
While the request for information is only a promise, governance still matters when the model-risk letter is silent. Banks stay exam-ready by knowing which tools sit outside OCC Bulletin 2026-13, naming an owner for those tools, and keeping a file an examiner can read. Orrick flags the forthcoming request as a watch item. The agencies have not published a replacement letter for generative or agentic AI. They have also not told banks to wait for one.