← Blog
ai-agentscompliancegovernance

What Is Agentic Model Risk

Agentic model risk is the residual exposure after the revised guidance announced in OCC Bulletin 2026-13 placed generative and agentic AI out of scope, leaving agents outside the model definition.

MightyBot ·
A navy model cube with a carved-out notch holding a leftover amber residual solid beside a dim network sphere.

Summary: Agentic model risk is the residual exposure left after U.S. banking agencies replaced SR 11-7 with SR 26-2 and carved generative and agentic systems out of that guidance. The letter still governs quantitative models that produce estimates. Agents that plan, call tools, and change production state sit outside that definition. The companion account of the letter change is Banks Lost Their Model-Risk Letter for Agentic AI.

What SR 26-2 replaced, and who it is written for

On April 17, 2026, the Federal Reserve, the OCC, and the FDIC issued SR 26-2. The attached revised guidance supersedes and replaces SR 11-7 and SR 21-8. The Fed page also lists both letters under Supersedes.

The Fed letter is expected to be most relevant to banking organizations with over $30 billion in total assets. OCC Bulletin 2026-13 repeats that over-$30-billion line.

What the letter still calls a model

The OCC bulletin is the public text that still defines an in-scope model. For this guidance, “model” means a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to process input data into quantitative estimates.

The next sentence excludes simple arithmetic calculations and deterministic rule-based processes that have no statistical, economic, or financial theories behind them. The bulletin’s example of simple arithmetic is calculations found within spreadsheets, so the exclusion is written at the level of everyday bank tooling. That exclusion is the neighbor of deterministic AI: rule-bound processes that never entered the model label. The generative and agentic carve-out is a later, separate sentence.

What the carve-out actually says

Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance. That pair of sentences appears in the Highlights and again in the Background of OCC Bulletin 2026-13.

Agentic model risk is the residual category that sentence leaves behind. The letter still covers quantitative models that produce estimates. Agents that plan, call tools, and change production state sit outside that definition.

The Fed letter page does not carry the carve-out sentence. A reader who opens only SR 26-2 sees the date, the supersession, and the asset threshold. OCC 2026-13 is the public page that states the residual.

The agencies plan to issue a request for information that addresses model risk management and banks’ use of AI, including generative and agentic AI. On the bulletin page, that request is planned. It has not been issued.

Why some vendor pages invert the carve-out

Some vendor pages reverse the OCC sentence. An Openlayer article dated July 28, 2026 claims in its TLDR that SR 26-2 extends SR 11-7 to cover AI/ML systems, LLMs, and agentic architectures. The same July 28 page later uses a carveout heading while the body still treats generative and agentic systems as covered. A July 21 sequel says the letter brought generative and agentic systems explicitly into scope and extends independent validation, documentation, and governance to LLMs and agents.

OCC Bulletin 2026-13 says they are not within the scope of this guidance. Explainers that quote that sentence, including Validmind and KPMG, already treat generative and agentic systems as outside the letter. The inverted TLDR is a live misread.

Where U.S. agent standards are moving instead

The leftover category is also separate from classical model validation. The NIST AI Agent Standards Initiative fosters industry-led technical standards and open protocols so agents can function securely on behalf of users and interoperate. NIST hosts convenings, produces voluntary guidelines, and researches agent authentication and identity. The February 17, 2026 announcement lists industry-led standards development, U.S. leadership in international standards bodies, and research on agent security and identity among the initiative’s tracks.

That work is about authentication, identity, and interoperability. AI governance is the broader system of policies and evidence that still has to cover agents after the model-risk letter placed them outside its scope. Agentic model risk is the name for that leftover bank exposure.

FAQ

Frequently Asked Questions

Does SR 26-2 replace SR 11-7?

Yes. SR 26-2 supersedes and replaces SR 11-7, the 2011 model risk guidance, and it supersedes SR 21-8 as well. The revised guidance attached to the letter is now the operative interagency text.

Does SR 26-2 apply to chatbots and AI agents?

No, OCC Bulletin 2026-13 states that generative AI and agentic AI models are not within the scope of this guidance. The guidance still covers quantitative models that produce estimates. Explainers such as KPMG and Validmind read that definition as still reaching AI that is neither generative nor agentic.

What counts as a model under SR 26-2?

Under OCC Bulletin 2026-13, a model is a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to process input data into quantitative estimates. Simple arithmetic, such as spreadsheet calculations, sits outside that label. Deterministic rule-based processes with no such theories behind their design or use are excluded as well.

How does SR 26-2 treat generative AI?

OCC Bulletin 2026-13 calls generative AI and agentic AI models novel and rapidly evolving, and for that reason leaves them outside the scope of the guidance. Explainers such as KPMG read the bulletin as leaving those systems to a bank's established risk management practices.

What is agentic model risk after the carve-out?

Agentic model risk names the leftover bank exposure after OCC Bulletin 2026-13 placed generative and agentic AI models outside the guidance. Agents that plan, call tools, and change production state fall outside the bulletin's quantitative-estimate definition of a model. The phrase names that leftover category rather than a new supervisory letter for agents.

Who does SR 26-2 apply to?

SR 26-2 is expected to be most relevant to banking organizations with more than $30 billion in total assets. OCC Bulletin 2026-13 repeats that over-$30-billion line. That is the audience the agencies flag for the revised model-risk text.