Bank Model Risk Guidance No Longer Covers Generative AI. Who Owns the Testing?

Source: Anaconda•

Bank Model Risk Guidance No Longer Covers Generative AI. Who Owns the Testing?

SR 26-2 left generative AI and AI agents out of bank model risk guidance. Here’s who has to test them now, and why 1 in 5 agent incidents had no attacker.

SR 26-2, the 2026 replacement for SR 11-7, takes generative AI and AI agents out of US bank model risk guidance. The obligations around those systems still apply, so someone has to test them. Here’s how I think banks, and the insurers and asset managers facing the same questions, should close that gap.

In April, the Federal Reserve, the Office of the Comptroller of the Currency (OCC), and the Federal Deposit Insurance Corporation (FDIC) rewrote the model risk management guidance that guides how banks manage the risk of their models. The old version, known as , had been in place since 2011, and model risk teams across the country built their programs around it. The new version, , keeps most of the same shape. One footnote stopped me: generative AI and AI agents are out of scope.

Think about what that means from inside a bank. The chatbots answering customer questions, the copilots drafting advice, the agents with access to core systems: the technology moving fastest inside financial institutions no longer sits under the framework designed to check it. The agencies say these systems are too new and changing too quickly to cover yet, and they plan to ask the industry for input.

I understand the reasoning. I also know how this plays out. When a system falls outside the process, nobody clearly owns testing it. Meanwhile, the rules that matter most to customers haven’t gone anywhere. Fair lending still applies. So do consumer protection, third-party risk, cybersecurity, and recordkeeping. A bank that deploys an AI assistant owns what that assistant says.

So here’s the question I’d put to risk and compliance leaders right now: which of your AI systems sit outside your model inventory today, and who is checking them?

When we test these systems, the failures rarely look like a movie hack. They look like ordinary business problems. A customer assistant quotes a fee that isn’t in the disclosure. An internal copilot shows one customer’s account details to a colleague who isn’t cleared to see them. A claims assistant tells a policyholder something is covered when it isn’t, or handles two nearly identical claims differently. An advisor tool recommends a product that doesn’t fit the client, or passes along information that was supposed to stay behind a wall. These are illustrations, not findings from our upcoming report, but they will sound familiar to people who have worked at a bank, an insurer, or an asset manager.

None of them needs an attacker. They happen when a system does exactly what it was built to do, in a situation nobody thought to test. Our Agent Incident Registry shows the pattern: as of September 21, 2026, 109 of the 529 agent incidents it documents involved no adversary at all. That’s about one in five.

Agent Incident Registry

That’s why I believe red teaming belongs at the center of how financial institutions govern AI. Red teaming means testing a system the way the real world will, before customers or examiners do. At Enkrypt AI, we built our approach around a few convictions. Test the whole experience the customer meets, including the tools the AI can use and the data it can reach, because nobody meets a model on its own. Start from the institution’s own obligations, because a claims assistant and an investment copilot fail in different ways. Keep the pressure on the way real people do, by rephrasing, pushing back, and switching languages. And leave behind evidence a risk team can file, map to frameworks like the National Institute of Standards and Technology (NIST) AI Risk Management Framework and the EU AI Act, and hand to an auditor.

This October, we’re publishing Too Big to Fail Safe: AI Risk in Financial Services, our research on how AI holds up across banking, insurance, and asset management. It’s a sector moving fast on AI with little room for error. I’d encourage you to read it with that same question in mind.

You don’t have to wait for the report to start answering it. Our approach powers AI security and guardrails in the Anaconda Platform: testing before release, adaptive red-teaming agents that go beyond a fixed list of attacks, and the same evidence carried into guardrails once a system is live. It runs inside your own environment, so your prompts and data stay within your security boundary. If you want to see how it would test one of your systems, request a demo.

FAQ

What is SR 26-2?

SR 26-2 is the revised model risk management guidance the Federal Reserve, the OCC, and the FDIC . It replaces from 2011 and is most relevant to banking organizations with more than $30 billion in total assets.

Does SR 26-2 cover generative AI or AI agents?

No. A footnote in the guidance places generative AI and agentic AI models outside its scope because they are new and changing quickly. For those systems, banks are pointed to their broader risk management and governance practices instead.

Is generative AI in banking unregulated now?

No. The exclusion applies only to the model risk management guidance. Fair lending, consumer protection, third-party risk management, cybersecurity, and recordkeeping obligations still apply to any AI system a bank deploys.

How can banks test generative AI that falls outside SR 26-2?

Through independent red teaming: adversarial testing of the full workflow a customer or employee uses, built from the institution’s own obligations. Findings are documented and mapped to frameworks such as the NIST AI Risk Management Framework and the EU AI Act, so they can go into a risk register or an audit file.

How many AI agent incidents involve no attacker?

About one in five. As of September 21, 2026, 109 of the 529 agent incidents in Enkrypt AI’s Agent Incident Registry involved no adversary. These failures happen when a system behaves as built in a situation nobody tested.

When do EU AI Act high-risk rules apply to credit scoring and insurance pricing?

From December 2, 2027. The Digital Omnibus, Regulation (EU) 2026/1744, entered into force on July 27, 2026 and moved the deadline for stand-alone high-risk AI systems under the EU AI Act from August 2, 2026. Those systems include AI used to score individuals’ creditworthiness and AI used for risk assessment and pricing in life and health insurance.

What this article says