Regulatory Compliance
SR 26-2 Explained: The Federal Reserve Rule Reportedly Superseding SR 11-7 for AI Model Risk Management
SR 26-2 is being discussed as a Federal Reserve update intended to address AI models specifically and to supersede parts of SR 11-7, the Fed's 2011 model risk management guidance. As of this writing, no document titled SR 26-2 could be independently confirmed in official Federal Reserve or FFIEC publications. Risk leaders should verify its existence and exact text with the Federal Reserve or counsel before revising policy citations. This guide explains what is confirmed under SR 11-7, where AI models create gaps in that framework, and what steps to take regardless of SR 26-2's final status.
SR 26-2 has not been independently confirmed as an official Federal Reserve or FFIEC publication. Treat it as an unverified reference until the Federal Reserve or legal counsel confirms its existence, citation, and exact text. Until then, SR 11-7 remains the confirmed baseline for AI model risk governance.
Before Updating Internal Policy Language
Steps to take before any policy document references SR 26-2 by name.
- Confirm directly with the Federal Reserve or legal counsel whether SR 26-2 has been formally issued, and obtain its exact citation and text.
- Avoid representing compliance with a named guidance document until its existence and requirements have been independently verified.
- Map current SR 11-7-based policies against NIST AI RMF functions to identify likely gaps for generative and agentic AI.
- Treat SR 11-7's three pillars, development, validation, and governance, as the baseline that any AI-specific update would extend rather than replace.
- Keep version history of policy documents so citations can be corrected quickly once official guidance is confirmed.
SR 11-7: The Confirmed Model Risk Management Baseline
SR 11-7, issued jointly by the Federal Reserve and the OCC as OCC Bulletin 2011-12 in April 2011, remains the foundational supervisory guidance for model risk management at U.S. financial institutions. It defines a model broadly as any quantitative method, system, or approach that applies statistical, economic, financial, or mathematical techniques to process input data into quantitative estimates. That definition is broad enough that supervisors have historically extended it to advanced analytics and machine learning tools, even though SR 11-7 predates generative and agentic AI systems and does not name them explicitly.
SR 11-7 organizes model risk management around three elements: robust model development, implementation, and use; effective validation, including independent review by parties not involved in building the model; and sound governance, with the board and senior management holding ultimate accountability. It requires "effective challenge" of models by objective, informed reviewers, ongoing monitoring through methods such as back-testing, and documentation sufficient for someone unfamiliar with the model to understand its development, use, and limitations. These three pillars are the reference point against which any AI-specific update, including SR 26-2, would need to be measured.
SR 11-7 vs. Reported SR 26-2: What Can Be Confirmed
The table below summarizes what is documented fact versus what remains an unverified claim about SR 26-2.
Confirmed Baseline
SR 11-7, issued April 2011 jointly with OCC Bulletin 2011-12, remains the active model risk management guidance.
Reported Update
SR 26-2 is referenced as a Fed rule targeting AI models, but its publication could not be verified in official channels.
Known AI Gap
SR 11-7 predates generative and agentic AI and does not name these categories explicitly.
Why AI Models Strain the SR 11-7 Framework
SR 11-7's validation practices, conceptual soundness review, outcomes analysis, and ongoing monitoring, were designed for statistical and econometric models with relatively stable input-output relationships. Generative and agentic AI systems produce probabilistic, context-dependent outputs that are harder to reproduce and benchmark in the same way, which creates a known tension between SR 11-7's principles-based standard and how large language models and autonomous agents actually behave in production.
The NIST AI Risk Management Framework, published in January 2023, introduces AI-specific risk categories such as explainability, robustness, and safety that are not present in SR 11-7's original text. NIST AI RMF remains a voluntary framework and is not confirmed to be incorporated by reference into any Federal Reserve supervisory letter, but it is a useful reference point for identifying where an SR 11-7-based program may fall short for AI use cases. Third-party and vendor AI tools add a further layer: existing interagency guidance on third-party relationships already applies to outsourced models, and any AI-specific update would likely need to be read alongside that guidance rather than in isolation.
Frequently Asked Questions
Has SR 26-2 been officially published by the Federal Reserve?
No official Federal Reserve, OCC, or FFIEC publication confirming a document titled SR 26-2 could be located as of this writing. Organizations should verify its existence, exact citation, and text directly with the Federal Reserve or legal counsel before referencing it in internal policy.
Does SR 11-7 already apply to AI and machine learning models?
SR 11-7's definition of a model is broad enough that supervisors have historically extended it to advanced analytics and machine learning tools, though the guidance predates generative and agentic AI and does not name these categories explicitly.
What should risk teams do while SR 26-2's status is unconfirmed?
Continue building on SR 11-7's three pillars of development, validation, and governance, use frameworks such as NIST AI RMF to identify AI-specific gaps, and update policy citations only once official guidance is confirmed.
Strengthen AI Model Governance on a Confirmed Foundation
Regardless of how SR 26-2 is ultimately confirmed, SR 11-7's validation, documentation, and governance requirements remain the working baseline. Runtime governance and audit logging can help demonstrate ongoing monitoring and effective challenge for AI models and agents today.
See How Runtime Governance Helps