Summary: Agentic model risk is the residual exposure left after U.S. banking agencies replaced SR 11-7 with SR 26-2 and carved generative and agentic systems out of that guidance. The letter still governs quantitative models that produce estimates. Agents that plan, call tools, and change production state sit outside that definition. The companion account of the letter change is Banks Lost Their Model-Risk Letter for Agentic AI.
What SR 26-2 replaced, and who it is written for
On April 17, 2026, the Federal Reserve, the OCC, and the FDIC issued SR 26-2. The attached revised guidance supersedes and replaces SR 11-7 and SR 21-8. The Fed page also lists both letters under Supersedes.
The Fed letter is expected to be most relevant to banking organizations with over $30 billion in total assets. OCC Bulletin 2026-13 repeats that over-$30-billion line.
What the letter still calls a model
The OCC bulletin is the public text that still defines an in-scope model. For this guidance, “model” means a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to process input data into quantitative estimates.
The next sentence excludes simple arithmetic calculations and deterministic rule-based processes that have no statistical, economic, or financial theories behind them. The bulletin’s example of simple arithmetic is calculations found within spreadsheets, so the exclusion is written at the level of everyday bank tooling. That exclusion is the neighbor of deterministic AI: rule-bound processes that never entered the model label. The generative and agentic carve-out is a later, separate sentence.
What the carve-out actually says
Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance. That pair of sentences appears in the Highlights and again in the Background of OCC Bulletin 2026-13.
Agentic model risk is the residual category that sentence leaves behind. The letter still covers quantitative models that produce estimates. Agents that plan, call tools, and change production state sit outside that definition.
The Fed letter page does not carry the carve-out sentence. A reader who opens only SR 26-2 sees the date, the supersession, and the asset threshold. OCC 2026-13 is the public page that states the residual.
The agencies plan to issue a request for information that addresses model risk management and banks’ use of AI, including generative and agentic AI. On the bulletin page, that request is planned. It has not been issued.
Why some vendor pages invert the carve-out
Some vendor pages reverse the OCC sentence. An Openlayer article dated July 28, 2026 claims in its TLDR that SR 26-2 extends SR 11-7 to cover AI/ML systems, LLMs, and agentic architectures. The same July 28 page later uses a carveout heading while the body still treats generative and agentic systems as covered. A July 21 sequel says the letter brought generative and agentic systems explicitly into scope and extends independent validation, documentation, and governance to LLMs and agents.
OCC Bulletin 2026-13 says they are not within the scope of this guidance. Explainers that quote that sentence, including Validmind and KPMG, already treat generative and agentic systems as outside the letter. The inverted TLDR is a live misread.
Where U.S. agent standards are moving instead
The leftover category is also separate from classical model validation. The NIST AI Agent Standards Initiative fosters industry-led technical standards and open protocols so agents can function securely on behalf of users and interoperate. NIST hosts convenings, produces voluntary guidelines, and researches agent authentication and identity. The February 17, 2026 announcement lists industry-led standards development, U.S. leadership in international standards bodies, and research on agent security and identity among the initiative’s tracks.
That work is about authentication, identity, and interoperability. AI governance is the broader system of policies and evidence that still has to cover agents after the model-risk letter placed them outside its scope. Agentic model risk is the name for that leftover bank exposure.