Insights
Posted 27 September 2026

Outside the guidance, not outside your responsibility

Generative AI sits outside the new federal model risk guidance. It does not sit outside the bank’s responsibility to govern it.

If you sit on an AI governance or risk committee at a community bank, or sell AI into one, two documents from this year change what you may be asked to show.

The first is SR 26-2, issued in April by the Federal Reserve, OCC and FDIC. It replaced SR 11-7 and says it is “expected to be most relevant to banking organizations with over $30 billion in total assets.” It also says: “Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance.”

That is not an exemption. The next sentence points back at the bank: its own “risk management and governance practices should guide the determination of appropriate governance and controls” for anything the guidance does not cover.

The second is the AI Supervisory Framework the Conference of State Bank Supervisors released on 16 September: an examiner guide, a work program, an optional risk-tiering worksheet and two supporting documents. It “does not create new legal obligations or supervisory requirements”, and each state decides how far to use it. But it shows what a state examiner may look at: where AI is used, including AI embedded in vendor products; how each use case was evaluated for risk and who approved that evaluation; generative AI and its controls; and governance, reporting and oversight.

Read together, and this is my reading, not something either body said: neither hands a community bank a control standard for generative AI or agents. What the bank will be asked to explain is its own.

Four things worth having on paper, then.

An inventory that includes the AI inside products you bought, not only the tools you built.

Tiering criteria written down before a use case arrives, so the sponsor is not the one deciding how much review it gets.

For each tier, the evidence it requires: testing, human review, data restrictions, approval.

A record of the decisions, including what was not brought to committee and why.

A vendor’s documentation can inform each of these. It cannot be the decision record, because the decision is the bank’s.

So at your bank: who owns the tiering criteria, and could they show an examiner how a use case landed where it did?

Sources:
  • SR 26-2, Board of Governors of the Federal Reserve System, OCC and FDIC, 17 April 2026 (the $30 billion sentence, the generative and agentic AI scope sentence, and the governance-practices sentence): federalreserve.gov (PDF)
  • CSBS Artificial Intelligence Supervisory Framework, 16 September 2026, all five components: csbs.org
  • CSBS Core Examiner Guide, Version 1.0 (“does not create new legal obligations or supervisory requirements”; the examination areas): csbs.org (PDF)

Scope note. SR 26-2 states that it “does not set forth enforceable standards or prescriptive requirements.” The CSBS framework is optional, and each state agency decides how far to incorporate it into its supervisory program. The reading that joins the two documents is the author’s, not a position either body has taken. This piece is written about banks; whether and how the CSBS framework applies to state-chartered credit unions was not checked.

Written for compliance and risk readers in regulated financial firms. Informational, not legal advice; Mike Bidun is not a lawyer.