The AI Model Risk Rule Everyone Cites Died in April
Every citation below was checked against the issuing body's own text on 31 July 2026. Links are included so you can check them yourself, which is the point.
If you have read anything about AI governance in banking this year, you have read a reference to SR 11-7. It is the model risk guidance every vendor deck, conference panel and consulting memo leans on.
It was superseded on 17 April 2026.
That alone would be a footnote. What makes it worth writing about is what replaced it, and what the replacement says about AI agents specifically. Most of the market has not noticed yet, and a few of the things people are confidently saying right now are simply out of date.
What replaced it
The Federal Reserve, the OCC and the FDIC issued revised interagency model risk management guidance on 17 April 2026. It appears as Fed SR 26-2 and OCC Bulletin 2026-13. It supersedes SR 11-7 and OCC Bulletin 2011-12, which had stood since 2011.
Two sentences in it matter more than the rest.
On its own force:
"This guidance does not set forth enforceable standards or prescriptive requirements; accordingly, non-compliance with this guidance will not result in supervisory criticism against a banking organization."
And on scope, in footnote 3:
"Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance. Nonetheless, a banking organization's risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document."
Read that twice. The guidance most often cited as the reason banks must control AI now says two things: it is not enforceable, and agentic AI is not in it.
It is not just the banking regulators
The securities side moved away from AI rules as well, not toward them. The SEC's 2023 proposal on conflicts of interest in predictive data analytics was formally withdrawn on 17 June 2025, with the Commission stating it does not intend to issue final rules on those proposals. There is now no US rule in that area for broker dealers or advisers.
FINRA has been the clearest voice on the actual problem. Regulatory Notice 24-09 applies existing supervision rules to generative AI, and states plainly that it creates no new requirements. The 2026 Annual Regulatory Oversight Report added a generative AI chapter that defines AI agents, and asks for testing, human review of outputs, and storing prompt and output logs for accountability. A January 2026 post from FINRA's Chief Regulatory Operations Officer notes that multi step agent reasoning can make outcomes difficult to trace or explain, complicating auditability.
All useful. None of it a rule.
There is a cleaner way to say the whole US picture. Search the eCFR for the word "agentic" and you get zero results. Search the Federal Register for "agentic AI" among final rules and you get zero results. As of today the phrase appears in no binding US financial regulation. The one place US financial supervisors put it in an official issuance, they put it in a scope exclusion.
Europe binds, but the date moved four days ago
The EU AI Act is real, binding law. Two financial uses are high risk under Annex III point 5: evaluating creditworthiness or credit scoring, and risk assessment and pricing for insurance. Both carry limits that summaries routinely drop. Credit scoring excludes systems used to detect financial fraud. The insurance item covers life and health only, not property and casualty.
For those systems, Article 12 requires automatic recording of events over the system lifetime, Article 14 requires human oversight including the ability to override or interrupt, and Article 26 puts log retention on the deployer at a minimum of six months. Article 12 itself sets no retention period, which is a common miscitation.
Here is the part that is genuinely new. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was adopted on 8 July 2026 and entered into force on 27 July 2026. It pushes the Annex III high risk obligations from 2 August 2026 to 2 December 2027.
It does not touch Article 12, Article 14, Article 26 or Annex III. Only the date moved. So any plan built on an August 2026 deadline is now wrong by sixteen months, and a consolidated text of the AI Act reflecting the change has not been published yet.
What actually binds an agent today
If you operate in the EU, the answer is not an AI regulation at all. It is DORA, Regulation (EU) 2022/2554, which has applied since 17 January 2025. It requires a documented ICT risk management framework reviewed at least annually and after any major incident, and requires firms to record all ICT related incidents and to identify, track, log, categorise and classify them.
The specific logging mandate is one level down, in Delegated Regulation (EU) 2024/1774, Article 12: documented logging procedures, identification of which events get logged, a defined retention period, and measures securing log data against alteration.
DORA never mentions AI or agents. It binds anyway, because an agent is ICT. That is the live obligation while everyone watches the AI Act calendar.
So the burden got heavier, not lighter
It is tempting to read all this as breathing room. It is closer to the opposite.
When a supervisor publishes a framework, you can show you followed it. That is a cheap way to be defensible. What happened in April is that US supervisors looked at agentic systems and said, in effect, this is not covered, use your own governance to work out the right controls.
That leaves you without a template and without a deadline, but not without the question. When something an agent did comes up in an exam, in litigation, or in a board meeting, "we followed the guidance" is not available, because the guidance says it does not cover this. What is left is your own evidence: what the system did, on whose authority, and whether the record can be shown to be intact.
That evidence is buildable today. It is mostly not being built, because nothing is forcing it. The firms that build it early will be doing it without a rule to point at, which is exactly why it will be worth something when the question finally arrives.
Dates and quotations above were verified against primary sources on 31 July 2026. Two things worth knowing if you go deeper: the interagency request for information on AI in model risk management is announced in the April guidance but has not been published, and the consolidated post-Omnibus text of the AI Act is not out yet, so read Article 113 together with the amending regulation.