← All briefings
Briefing 26 · Model Risk

The rule banks cite for AI model risk just got quietly replaced.

If your answer to “how do you govern AI model risk” is “we follow SR 11-7,” that answer is two steps out of date. The Federal Reserve’s 2011 model-risk guidance, the document nearly every bank cites, was superseded on April 17, 2026. And neither the old letter nor its replacement was written for the AI that now matters most.

What changed. SR 11-7 (with OCC 2011-12) was superseded by SR 26-2, OCC 2026-13, and FDIC FIL-15-2026 on April 17, 2026. Three features of the successor matter: it is non-enforceable guidance, it applies only to banking organizations over $30 billion, and it expressly scopes generative and agentic AI out.

The principles survive; the coverage does not

SR 11-7’s enduring ideas, conceptual soundness, outcomes analysis, and ongoing monitoring, are still the right spine for governing any model. Those principles did not expire. What expired is the idea that pointing to SR 11-7 is a current, sufficient answer for AI. The named guidance is superseded, and its successor deliberately steps around the systems, generative and agentic AI, that carry the newest risk.

The gap this leaves

Put the three features together and a hole appears. A community or regional bank under $30 billion is outside the successor’s stated scope. A large bank inside that scope still finds generative and agentic AI written out of it. The result is that the most consequential AI a bank runs today, the chatbot, the copilot, the agent taking actions, sits in a supervisory gap: governed by principles everyone agrees on, but no current letter squarely applies.

What good governance looks like now

Keep the principles; drop the citation as a shield. Conceptual soundness, outcomes testing, and ongoing monitoring still apply, and apply harder to systems that generate language and take actions. Treat “we comply with SR 11-7” as a starting point that no longer covers your generative and agentic systems, and build the testing that does.

What to do now

1. Stop citing SR 11-7 as your AI answer. It was superseded in April 2026. 2. Do not wait for the regulator to name your system. The successor excludes generative and agentic AI on purpose; the risk does not wait for the letter to catch up. 3. Keep the durable principles. Conceptual soundness, outcomes analysis, ongoing monitoring, applied to models that now talk and act. 4. Get independent eyes on the systems the guidance skips. That is exactly where a third-party review earns its keep.

An honest limitation

This is supervisory guidance, not statute, and the enduring model-risk principles remain sound and expected. Superseded does not mean unregulated: banks are still expected to manage model risk, and safety-and-soundness supervision continues. The specific, narrow point is what changed, the named 2011 letter was replaced in April 2026, and neither it nor its replacement was built for generative or agentic AI. This briefing is general information, not legal, financial, or supervisory advice; verify the current guidance and your own supervisory expectations with counsel before acting.

This briefing is general information from Sentinel Assurance Group, not legal or financial advice. Regulatory guidance changes — we maintain these briefings, but verify against primary sources and counsel before acting. Last reviewed August 17, 2026.

See how a Gap Assessment maps your exposure →

Running AI inside a bank or fintech?
Mind the gap the guidance just left.

The free AI Risk Exposure call maps your generative and agentic systems to the model-risk principles that still apply, and the supervision that no longer squarely does.

Book the call →