Compliance & Risk 10 min read Updated August 2026

SR 26-2 and GenAI: What the Regulatory Carve-Out Means for Claude in Bank Credit and Risk (2026)

The Fed, OCC, and FDIC issued SR 26-2 in April 2026, replacing SR 11-7 and explicitly excluding generative AI from formal model risk validation. What this means for banks using Claude in credit underwriting, risk analysis, and financial reporting — and what governance gaps remain.

What SR 26-2 Says About Generative AI

In April 2026, the Federal Reserve, OCC, and FDIC jointly issued SR 26-2, replacing the 2011 SR 11-7 model risk management guidance that had governed bank models for 15 years. The most significant change for banks deploying Claude and other LLMs: SR 26-2 explicitly excludes generative AI and agentic AI from its scope, classifying them as "novel and rapidly evolving" and stating that a separate guidance framework for these technologies is forthcoming.

The practical implication is striking: under SR 26-2, a bank can deploy Claude in credit underwriting decisions without satisfying the formal model validation, documentation, and independent review requirements that applied to statistical credit models under SR 11-7. This creates both an opportunity and a governance gap that every bank CRO, model risk team, and compliance officer needs to understand.

Key fact: SR 26-2 (April 2026) explicitly excludes generative AI from its model risk validation requirements. Banks deploying LLMs in credit decisions no longer need to satisfy SR 11-7's validation, documentation, and independent review framework — but separate GenAI guidance is pending, and the governance risks do not disappear because the regulation does.

What SR 26-2 Changed from SR 11-7

SR 11-7 established a comprehensive model risk management framework that covered every model used in consequential bank decisions: credit scoring models, market risk VaR models, CCAR stress testing models, CECL loss estimation models. The framework required model inventory tracking, development documentation, independent validation before deployment, ongoing performance monitoring, and senior management governance.

SR 26-2 restructures this framework in several ways relevant to AI deployment:

  • The GenAI exclusion. SR 26-2 explicitly excludes generative AI (LLMs, image generation, multimodal models) and agentic AI systems from the scope of model risk management. The guidance acknowledges these technologies are "conceptually distinct" from traditional statistical models in ways that require a different framework — which has not yet been published.
  • Simplified tiering for lower-risk models. For traditional statistical models, SR 26-2 introduces a three-tier risk classification (high, medium, low) with reduced documentation and validation requirements for lower-risk models. This is separate from the GenAI exclusion but matters for banks with large model inventories.
  • Principles-based governance. SR 26-2 moves toward principles-based governance language, giving banks more flexibility in how they implement model risk management — at the cost of less prescriptive guidance on what "adequate" looks like.

The Governance Gap SR 26-2 Creates

The exclusion of generative AI from SR 26-2 does not mean banks face zero regulatory scrutiny for LLM deployments. It means the specific SR 11-7/SR 26-2 validation framework doesn't apply — but other regulatory frameworks still do, and the business risks of LLM errors in banking decisions are real regardless of regulatory classification.

What the GenAI carve-out does NOT exempt banks from:

  • Fair lending obligations. If Claude (or any AI) is used in a credit decision that has disparate impact on protected classes, the Equal Credit Opportunity Act and Fair Housing Act apply regardless of whether the AI is formally "in scope" for model risk management. A credit memo written by Claude that systematically emphasizes certain risk factors for certain borrower types creates fair lending exposure that the bank cannot audit without model validation-style testing.
  • Consumer protection obligations. Adverse action notices under ECOA and FCRA require that lenders be able to explain the specific reasons for adverse credit decisions. If Claude generates a credit recommendation that a loan officer follows, can the bank articulate the specific factors in the format regulators require? The explanation problem doesn't disappear because the model isn't in the MRM framework.
  • Examination scrutiny. Bank examiners from the OCC, FDIC, and Fed have explicitly flagged AI supervision as a 2026 examination priority. "We don't need to validate it under SR 26-2" is a technically correct statement that does not prevent an examiner from asking how the bank governs its AI use, how it prevents errors in consequential decisions, and how it monitors for bias or systematic failures.
  • Operational risk. An AI error in a credit decision, a compliance report, or a regulatory filing is an operational risk event regardless of regulatory classification. The bank's operational risk framework and incident management processes apply.

What Good Governance Looks Like Without SR 26-2 Applying

Sophisticated banks are not treating the SR 26-2 exclusion as permission to deploy GenAI without governance — they're building lightweight governance frameworks that address the real risks without the full weight of statistical model validation. The emerging best practices:

  • Use case classification. Distinguish between Claude being used for drafting and summarization (writing a credit memo based on human-provided analysis) vs. Claude being used to make or inform consequential decisions (generating a credit recommendation that a loan officer acts on). The governance requirements should be proportional — the former is lower risk and needs lighter oversight; the latter needs human-in-the-loop controls and output monitoring.
  • AI use policy and approved use cases. A written policy documenting which Claude use cases are approved, what data can be input, what outputs require human review, and who is accountable for governance. Without this, banks have no basis for supervision or accountability.
  • Sampling and review. For any Claude-assisted workflow that influences consequential decisions, establish a sampling review program — similar to loan review — where a percentage of AI-assisted outputs are reviewed by a senior professional for accuracy, bias, and consistency with credit standards. This is lighter than full model validation but creates the feedback loop that prevents systematic errors from going undetected.
  • Incident tracking. Any AI-assisted output that caused a material error (wrong credit recommendation, incorrect regulatory filing, biased analysis) should be tracked as an operational risk incident and fed back into the governance program.
  • Pending SR 26-2 GenAI guidance. The separate GenAI framework referenced in SR 26-2 is expected in late 2026 or 2027. Banks with minimal governance established before that framework arrives will face a more difficult transition than those that built lightweight but principled governance during the interim period.

How This Affects Banks Using Claude Today

For the specific workflows where banks are using Claude most actively, the SR 26-2 framework change has practical implications:

  • CECL ACL methodology documentation. Claude generating the written methodology documentation for a CECL model that is itself validated under SR 26-2 is not subject to model validation requirements — Claude is a drafting tool, not a model. The CECL model (the statistical loss estimation methodology) still needs validation; Claude's output is the documentation of that methodology.
  • Credit memo and underwriting drafts. Claude drafting the credit memo based on analyst-provided analysis is a drafting tool; Claude analyzing loan data and generating a credit recommendation that informs the lending decision is closer to a model. The former is low governance risk; the latter is higher and needs the human-in-the-loop controls described above.
  • Regulatory filing narrative. Claude drafting the narrative sections of call reports, 10-Qs, or regulatory filings is a drafting tool and not subject to SR 26-2. The bank's normal review and sign-off process for regulatory filings is the appropriate governance control.
  • Automated AML screening or fraud detection. If Claude or any LLM is running automated screening that directly generates compliance alerts without human review, this is higher-risk and the pending GenAI guidance will almost certainly impose requirements. Building human-in-the-loop review now is lower cost than retrofitting later.

The Bottom Line for Bank Risk and Compliance Teams

SR 26-2's exclusion of generative AI is a regulatory reality, not a governance recommendation. The practical advice for bank CROs and model risk teams:

  1. Document current Claude use cases by risk tier — identify which are drafting/summarization (lower risk) and which inform consequential decisions (higher risk).
  2. Establish an AI use policy before the pending GenAI guidance arrives — retrofit is harder than build-from-scratch.
  3. Implement sampling review for higher-risk use cases now; this is the audit trail regulators will eventually ask for.
  4. Engage fair lending compliance early on any AI-assisted credit workflow — this is the area with the most certain existing regulatory exposure.
  5. Watch for the pending SR 26-2 GenAI supplement — the industry expects it in H1 2027, and early movers in governance will have an easier transition.

The Commercial Banking and Compliance & Risk templates on ClaudeFinLab are designed for use cases that keep humans in the loop — drafting, analysis structuring, and documentation — rather than autonomous decision-making. Used this way, they sit clearly in the lower-risk tier and support rather than undermine the governance structures that thoughtful banks are building.

For more on AI governance in financial services, see AI Security in Finance and AI Best Practices for Finance Professionals.