← Blog
compliancefinancial-servicesgovernance

Banks Lost Their Model-Risk Letter for Agentic AI. Examiners Will Still Ask.

OCC Bulletin 2026-13 and Fed SR 26-2 take generative and agentic AI out of model-risk guidance. Examiners will still ask how banks govern those tools while an AI request for information is pending.

MightyBot ·
A vacant slot in a stack of frost-white documents under a magnifying glass, with an amber glow where a withdrawn letter should sit.

Summary: On 17 April 2026 the OCC, Federal Reserve, and FDIC replaced the 2011 model-risk letter. OCC Bulletin 2026-13 and Federal Reserve SR 26-2 take generative and agentic AI out of scope because those systems are novel and rapidly evolving. The letter is most relevant above $30 billion in assets and does not set enforceable standards. Examiners will still ask how uncovered tools are governed. Broader AI governance practices apply while the agencies’ promised request for information is pending.

What the new letter covers, and who it is for

OCC Bulletin 2026-13 is the OCC issuance of that interagency rewrite. The Federal Reserve issued the same revised guidance as SR 26-2, which supersedes and replaces SR letter 11-7, issued April 4, 2011, and SR letter 21-8, issued April 9, 2021. On the OCC side, the bulletin rescinds the Model Risk Management booklet of the Comptroller’s Handbook, OCC Bulletin 1997-24, OCC Bulletin 2011-12, and OCC Bulletin 2021-19.

For the purposes of the guidance, a model is a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to process input data into quantitative estimates. Simple arithmetic and deterministic rule-based software sit outside that term.

The agencies say the guidance is expected to be most relevant to banking organizations with over $30 billion in total assets. OCC adds that it may be relevant below that line if model-risk exposure is significant. The guidance does not set forth enforceable standards or prescriptive requirements, and non-compliance will not result in supervisory criticism.

The sentence that took agentic AI out of the letter

OCC Bulletin 2026-13 states the carve-out twice, in Highlights and Background: “Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance.” The HTML page for SR 26-2 does not reprint that sentence. The exclusion lives on the OCC bulletin and in the attached guidance PDF.

In remarks delivered April 27, 2026 and published on 1 May 2026, Vice Chair for Supervision Michelle W. Bowman said that the Fed, with the OCC and FDIC, had amended model-risk guidance “to clarify that it does not apply to generative or agentic AI.” Orrick notes that the exclusion also appears as a footnote, on the same novel-and-rapidly-evolving rationale. Some vendor glossaries still tell teams the new letter brought agents into scope. That reading contradicts the official bulletin.

What the letter still applies to

Sullivan & Cromwell, in a 29 April 2026 memo, says the revised guidance does apply to traditional statistical and quantitative models and to non-generative, non-agentic AI models. Bowman put the residual in official language: the revised guidance “now applies narrowly to traditional models and basic AI applications.” Those sentences describe what the letter still covers. Banks still have a model-risk letter for traditional quantitative models. They no longer have that letter for generative and agentic systems.

The hole examiners will walk through while the RFI is pending

OCC Bulletin 2026-13 says the agencies plan to issue in the near future a request for information that addresses model risk management generally and considers banks’ use of AI, including generative AI and agentic AI. No issued RFI text or comment deadline sits on the public record used for this piece.

Bowman said the agencies “expect other risk-management and governance practices to support adoption of generative and agentic AI in ways that will encourage ongoing innovation.” Sullivan & Cromwell writes that banking organizations should apply their broader risk management and governance practices to tools not covered by the revised guidance, including generative and agentic AI models. Those tools stay under the expectations that apply to banking organizations in general.

American Banker published the examiner line on 1 June 2026. Examiners will still ask, on the basis of safety and soundness, what unique monitoring and testing framework a bank uses for generative and agentic AI, and what its effective challenge is. The opinion treats SR 26-2 as leaving the form of the answer to each institution while still requiring that an answer exist.

Broader governance while the agencies collect comments

While the request for information is only a promise, governance still matters when the model-risk letter is silent. Banks stay exam-ready by knowing which tools sit outside OCC Bulletin 2026-13, naming an owner for those tools, and keeping a file an examiner can read. Orrick flags the forthcoming request as a watch item. The agencies have not published a replacement letter for generative or agentic AI. They have also not told banks to wait for one.

FAQ

Frequently Asked Questions

Does SR 26-2 cover generative or agentic AI?

OCC Bulletin 2026-13 states that generative AI and agentic AI models are not within the scope of the guidance, because those systems are novel and rapidly evolving. Vice Chair Bowman later said the Fed, with the OCC and FDIC, amended the guidance to clarify that it does not apply to generative or agentic AI.

What did OCC Bulletin 2026-13 replace?

On the OCC side, OCC Bulletin 2026-13 rescinds the Model Risk Management booklet of the Comptroller's Handbook, OCC Bulletin 1997-24, OCC Bulletin 2011-12, and OCC Bulletin 2021-19. The Federal Reserve issued the same revised guidance as SR 26-2, which supersedes SR letter 11-7 and SR letter 21-8.

Is SR 11-7 still the current model-risk letter?

No. Federal Reserve SR 26-2, dated 17 April 2026, supersedes and replaces SR letter 11-7 and SR letter 21-8. The 2011 letter is no longer the current model-risk guidance.

Does the new letter still apply to traditional statistical models?

Sullivan & Cromwell wrote on 29 April 2026 that the revised guidance applies to traditional statistical and quantitative models and to non-generative, non-agentic AI models. Bowman described the revised guidance as applying narrowly to traditional models and basic AI applications.

Will examiners still ask about generative and agentic AI after the carve-out?

American Banker put the point on 1 June 2026: examiners will still ask, on the basis of safety and soundness, what monitoring and testing framework a bank uses for generative and agentic AI. SR 26-2 leaves the answer format to each institution. It does not remove the obligation to have an answer ready.

What should banks do while the agencies’ AI request for information is pending?

The agencies plan to issue in the near future a request for information that considers banks’ use of AI, including generative and agentic AI, but they have not published that request. Bowman said other risk-management and governance practices should support adoption. Sullivan & Cromwell says uncovered tools stay under the risk management and governance expectations that apply to banking organizations in general.