SR 26-2 agentic AI governance: What MRM leaders are doing now

SR 26-2 updates model risk management standards for traditional AI but explicitly excludes generative and agentic systems, leaving institutions responsible for governing their fastest-growing AI risk without a regulatory blueprint.


Kate Key

Director, Enterprise MRM & ML Governance

Capital One

Arthur Robb

Head of MRM

TIAA

Rodanthy Tzani

Sphaleron Founder & Risk and Compliance Advisor | Former Head of MRM at NY Life

Sphaleron

What you'll take away from this session

SR 26-2 is a calibration, not an overhaul

Institutions with mature model risk programs don't need to rebuild governance from scratch. Companies should reassess validation priorities under the new materiality provisions.

Materiality provisions are the headline change

Low-risk models no longer require the same level of validation as high-stakes models. SR 26-2 provides institutions with guidance to prioritize resources around systems with the greatest financial exposure.

Agentic AI governance still falls on institutions

Generative and agentic systems are excluded from SR 26-2 scope, but this doesn't remove the obligation to govern them. Institutions need a parallel framework now, and what gets built across the industry will likely shape the forthcoming AI-specific guidance.

Risk-based materiality has three practical dimensions

Assess AI systems by reasoning complexity, degree of autonomy, and the impact of output errors. That framework produces a more actionable inventory than model classification alone, and it applies to systems that don't technically qualify as models under SR 26-2.

Vendor models embedded with AI create unresolved scoping questions

Institutions can’t fully inspect vendor models embedded with AI. SR 26-2 doesn't resolve who owns the governance obligation for those components, and the problem grows as AI becomes standard in third-party software.

Proactive examiner engagement is a strategic advantage

Institutions that explain their governance reasoning to examiners early get more constructive feedback. Framing governance decisions around risk and treating exam preparation as an opportunity to educate can improve compliance processes.

Three model risk management leaders from Capital One, New York Life, and TIAA, including an advisor who contributed to the original SR 11-7, gathered at Rev New York to assess what SR 26-2 changes and where it leaves institutions exposed.

The panel's perspective on the guidance was clear: SR 26-2 is a refinement of SR 11-7, not a replacement. The materiality provisions give institutions a stronger foundation for tiering their validation work, and the flexibility is real. But the exclusion of generative and agentic AI from scope is where the harder governance work begins. As one panelist from the session observed, the guidance arrived well-constructed for the traditional side of the model inventory and as an acknowledged placeholder for the rest.

For agentic AI risk management specifically, the panel moved away from technical model definitions and agreed on a risk-based inventory approach organized around reasoning complexity, autonomy, and impact. Institutions are left with open problems that SR 26-2 does not address: vendor models embedded with AI, agentic orchestration layers, and existing validation limits for frameworks handling variable AI outputs.

The strategic posture the panel recommended is to build your parallel governance framework for generative and agentic systems now, engage examiners proactively, and treat the forthcoming regulatory comment process as an opportunity to shape what comes next.

FAQ

What does SR 26-2 change in practice for institutions with mature model risk programs?

Why do traditional validation frameworks like SR 11-7 and SR 26-2 fall short for agentic AI?

What framework should MRM teams use to assess materiality across traditional models and newer AI tools?

Transform the work that matters most

See how Domino helps the world’s most regulated enterprises build, scale, and govern AI-powered applications.