US banking regulators replaced SR 11-7 in April 2026 and excluded generative and agentic AI from its successor's scope. GenAI at banks is now governed by everything in general and nothing in particular. The gap is yours to fill.
Fifteen years of one rulebook, then a carve-out
On April 17, 2026, the Federal Reserve, OCC, and FDIC jointly issued revised supervisory guidance on model risk management (SR 26-2 in the Fed's numbering) retiring SR 11-7 after roughly fifteen years. For most of that time, SR 11-7 was the closest thing US banking had to a unified theory of algorithmic risk. Every credit model, every AML detection engine, every pricing tool lived inside its validation regime.
The new guidance gives banks several things they had lobbied for. A narrower definition of "model." A $30 billion asset threshold, where SR 11-7 had none. A principles-based posture, lighter expectations for validating vendor models, and an explicit statement that non-compliance "will not result in supervisory criticism," per Sullivan & Cromwell's summary of the interagency text.
Then the part that matters here: the agencies excluded generative and agentic AI from the guidance's formal scope. They describe these systems as "novel and rapidly evolving," again per the law firm's summary, and recommend that banks apply their broader risk management and governance practices to them instead.
Sit with that. The one document purpose-built to govern models at banks looked at the fastest-growing category of models and stepped back.
The timing is what makes it uncomfortable. Evident's Q1 2026 use-case tracking found nearly one in three newly reported bank AI use cases were agentic, the highest share on record and double the 15% of just one quarter earlier, with specialized vendors beyond the hyperscalers accounting for 68% of deployments. McKinsey put genAI's potential value to global banking at $200–340 billion a year back in 2023, and banks have staffed accordingly: AI headcount across the 50 largest banks grew more than 25% in the period covered by the Evident AI Index 2025, which ranked JPMorganChase first for the fourth consecutive time. Adoption is accelerating into exactly the territory formal model-risk guidance just vacated.
To be precise about what the carve-out means: not deregulation. GenAI risk now lands on general safety-and-soundness expectations, which have no checklist, no threshold, and no safe harbor. That is arguably a worse place to be than inside a rulebook, because you cannot point to a completed validation file and call yourself done.
What the incident record actually shows
The honest version first. As of September 2026, no US bank has been fined by a banking regulator specifically for generative-AI misuse. If a vendor pitch implies otherwise, ask for the docket number.
What exists instead is a set of adjacent cases, and together they sketch what the first real one will look like.
The cleanest is Community Bank, which operates across southwestern Pennsylvania, Ohio, and West Virginia. On May 12, 2026, it filed an 8-K with the SEC after customer names, dates of birth, and Social Security numbers went into an unauthorized AI application. The bank said it filed "due to the volume and sensitive nature of the non-public information," per The Register's reporting. No fine followed. No enforcement action. Just a bank telling the market, on the record, that shadow AI had touched its customers' SSNs and its controls had not caught it in time.
The SEC, meanwhile, has been policing AI claims rather than AI usage. In March 2024 it settled with investment advisers Delphia and Global Predictions, at $225,000 and $175,000 respectively, for exaggerating their AI capabilities. January 2025 brought its first AI-washing action against a public company, Presto Automation, and later that year it charged Rimar Capital over false claims about AI-automated trading. Advisers and fintechs, not banks. But the doctrine being built there (what you say about your AI must match what your AI does) transfers directly to every bank now putting AI talking points in investor decks.
Two older data points round out the record. The CFPB's 2023 chatbot spotlight warned that deficient chatbots blocking access to a live human "can lead to law violations, diminished service, and other harms." And the February 2023 wave of ChatGPT restrictions at JPMorgan, Bank of America, Citigroup, Goldman Sachs, Deutsche Bank, and Wells Fargo, with Deutsche Bank explicitly citing prevention of confidential-data leakage, showed banks understood the exposure three years before their regulators reorganized around it. Most have since deployed gated enterprise versions. The instinct was right; the blanket ban was never the durable control.
FINRA has moved faster than the prudential agencies. Its 2026 annual regulatory report emphasized AI testing and monitoring, and it issued a cybersecurity alert on the Salesloft Drift AI supply-chain attack. A financial regulator formally warning member firms about a breach at a third-party AI chatbot vendor is a boundary marker: the examination perimeter now includes your vendors' AI, not just yours.
The stack that replaced the rulebook
Take away SR 26-2's coverage and what remains is a collection of instruments, each written for a different purpose, each catching a slice of genAI risk by implication rather than design.
| Instrument | What it covers | What it misses for genAI |
|---|---|---|
| SR 26-2 (Fed/OCC/FDIC, April 2026) | Model risk management for banks above $30B in assets: validation, materiality, vendor models | Generative and agentic AI, excluded from formal scope by design |
| NYDFS Part 500 + October 2024 AI letter | Cyber program requirements for NY-licensed entities; the letter maps AI risks onto the existing framework | Imposes no new AI requirements; reaches NY-licensed entities only |
| GLBA Safeguards Rule | A written security program protecting consumer financial information wherever it flows, third-party APIs included | No AI-specific text; silent on prompts, training data, and agent behavior |
| Treasury AI Lexicon + FS AI RMF (February 2026) | Shared vocabulary and a risk framework expected to shape exams, audits, and vendor contracts | Non-binding; creates no obligations and therefore no floor |
| DORA (EU, applied January 2025) | ICT resilience across 22,000+ EU financial entities; direct EU oversight of critical ICT third parties | EU operations only; framed around resilience, not prompt-level data movement |
| FSB, Basel, and BIS reports | System-level vulnerabilities: third-party concentration, model governance, cyber risk | Monitoring and analysis; nothing here binds an individual bank |
Last verified: September 10, 2026.
Two rows deserve expansion. NYDFS said the quiet part in October 2024: its industry letter on AI-related cyber risk imposes no new requirements because Part 500 already covers this. Risk assessment, access controls, audit trails, third-party vendor management, if AI touches nonpublic information at a NY-licensed institution, those obligations already attach. The letter names four AI risk buckets, and two of them, NPI exposure and third-party vulnerability, are exactly what the Community Bank 8-K and the Drift attack look like in practice.
DORA is the sleeper for US institutions. It has applied since January 17, 2025, and a US bank's AI vendor serving EU operations can be swept into its ICT third-party regime, with critical-provider designations underway since 2025. The FSB's October 2025 monitoring report explains why supervisors care: genAI depends on "a small number of key suppliers" for hardware, cloud, and pre-trained models, even as institutions remain, in the FSB's words, "cautiously adopting GenAI with apparently limited use for critical functions" so far. Concentration risk is accumulating faster than deployment risk. For the moment.
What examiners will ask anyway
An examiner does not need an AI rulebook to examine your AI. Safety-and-soundness authority plus long-standing third-party doctrine, under which a bank answers for vendor failures as if the models were its own, covers most of the ground. The Treasury framework tells you where the questions are heading even though it binds nobody.
The first question is inventory, and it is the one the Community Bank incident proves banks fail. "Unauthorized AI application" is another way of saying nobody knew the tool was in use until customer SSNs were inside it. If you cannot produce a live list of every genAI tool your workforce touches, sanctioned or not, everything downstream is guesswork. This is a discovery problem before it is a policy problem, which is why we built workforce AI governance around finding the tools first and enforcing policy inline second.
The second is data control at the prompt level. Not "do you have a DLP program" but whether NPI, MNPI, and credentials are classified and blocked before they leave for a model endpoint. The 2023 trading-floor ChatGPT restrictions were aimed at precisely this, and no public enforcement case of MNPI leaking through an LLM exists yet, which means it remains a control objective you get to meet before it becomes a headline. AccuroAI runs this inline across 14M+ prompts a day with 40+ data classifiers at under 38ms p99, and maps the resulting evidence to 8 compliance frameworks, because the artifact examiners want is proof the control fired, not a policy PDF.
The third is reconstruction. If an agentic workflow moved money, changed a record, or answered a customer, can you show who initiated it, what data it saw, and why it acted? Part 500 already expects audit trails; agentic systems just make them harder to produce. We have written separately about runtime controls for agents and getting AI audit trails into your SIEM, and the one-in-three agentic figure says this stops being optional sometime this budget cycle.
Put these to your AI vendors before the examiner does
Treasury's FS AI RMF points institutions toward interrogating vendor AI directly, and 68% of bank AI deployments now come from specialized vendors. A workable due-diligence set, drawn from where the framework and current practice converge:
- Model documentation and independent validation or testing evidence, refreshed on a cadence, not once at onboarding
- Training-data provenance, and contractual restrictions on using your data to train anything
- A complete data-flow diagram, including geographic processing locations and every fourth party behind the vendor
- Change-notification procedures, since a model that updates silently between annual reviews has escaped your review cycle entirely
- Contract terms with teeth: performance thresholds, bias-testing obligations, incident notification windows, audit rights
- Evidence of continuous monitoring on the vendor's side, and a feed you can consume on yours
The pattern across all six: annual point-in-time review assumes a static product, and genAI products are not static. Our financial services AI security playbook works through the full control build, and the financial services page covers how banks run this on our platform.
The first genAI enforcement action against a bank will not cite an AI rule. It will cite GLBA, or Part 500, or plain safety-and-soundness, applied to a tool nobody inventoried. The carve-out changed which document gets quoted. It did not change who pays.
Questions bank teams keep asking
Does the SR 26-2 carve-out mean our genAI tools skip validation?
No. It means formal model-risk guidance does not prescribe how to govern them, while the agencies still expect your broader risk and governance practices to cover them. Data-protection obligations under GLBA and, for NY-licensed entities, Part 500 apply regardless of how the model is classified.
Has any bank actually been penalized over generative AI?
Not by a US banking regulator as of September 2026. The closest real cases are Community Bank's self-reported 8-K over customer data in an unauthorized AI app, and SEC AI-washing actions against advisers and fintechs such as Delphia, Global Predictions, and Presto Automation. Treat the absence as runway, not immunity.
We are US-based. Can DORA still reach us?
Through your EU operations, yes. DORA has applied since January 2025 across more than 22,000 EU financial entities, and AI vendors serving your EU business can fall under its ICT third-party regime, including direct EU regulator oversight for providers designated critical.
Where should a bank start this quarter?
Inventory. Every subsequent control, from prompt-level data classification to agent audit trails to vendor diligence, presumes you know which AI tools are in use. The incident record so far is a record of banks discovering tools after the data was already inside them.