The OCC's Spring 2026 Semiannual Risk Perspective, released May 7, 2026, says artificial intelligence is 'significantly transforming the cyber threat landscape' — lowering the barrier to entry for attackers and increasing the 'speed, scale, and sophistication' of cyberattacks and fraud — while also giving banks new defensive capabilities. It reports that banks are taking a 'measured approach' to generative and agentic AI, with use limited to specific cases with guardrails and human-in-the-loop accountability, restates that the agencies plan an interagency request for information on AI and model risk management, and says the OCC is 'actively reviewing supervisory expectations, guidance, and regulations' to right-size AI expectations for community banks.
| Document | OCC Semiannual Risk Perspective, Spring 2026 — Semiannual Risk Perspective from the National Risk Committee, Spring 2026 |
| Issued by | Office of the Comptroller of the Currency |
| Type | Report |
| Status | Final |
| Published | May 7, 2026 |
| Applies to | National banks and federal savings associations (supervisory priorities, not requirements) |
| Official source | occ.treas.gov ↗ |
| Use cases | Cybersecurity · Fraud detection · Generative & agentic AI · AI governance (general) · Third-party & vendor AI |
What are the key points of OCC Semiannual Risk Perspective, Spring 2026?
- Four headline risk themes: credit, market, operational, and compliance risk; AI appears under operational risk (cyber and fraud) and as an innovation opportunity.
- AI can 'facilitate fraud and enable automated reconnaissance, rapid vulnerability discovery' and increases the speed, scale, and sophistication of attacks; the OCC recommends multifactor authentication, timely patching, and using AI defensively.
- Observes that bank generative-AI and agentic-AI use is 'primarily productivity and customer experience enhancement tools,' generally with guardrails and human-in-the-loop accountability; banks may expand to 'material financial decisions.'
- Flags unique genAI/agentic challenges including lack of explainability, and states that appropriate governance and risk management are essential.
- Restates that genAI and agentic AI are outside the revised model risk guidance (Bulletin 2026-13) and that the agencies plan an interagency RFI on model risk management and banks' use of AI.
- Says the OCC is reviewing supervisory expectations, guidance, and regulations so AI opportunities are available to all OCC-supervised banks, with support for community banks that rely on third-party technology.
- Fraud and scams remain 'elevated' and rising in sophistication; foreign state-sponsored cyber actors continue to pose a threat.
What did OCC Semiannual Risk Perspective, Spring 2026 change for banks?
This is the clearest official statement of how the OCC currently sees bank AI in practice: measured genAI adoption, examiner attention on AI-enabled fraud and cyber, and an explicit intent to revisit supervisory expectations. It confirms the direction set by Bulletin 2026-13 and is the document to cite for the claim that further OCC AI guidance is coming.
What does the OCC say about AI in its Spring 2026 risk report?
That AI is transforming the cyber threat landscape by lowering barriers for attackers and speeding up fraud, that banks are adopting generative and agentic AI cautiously with human-in-the-loop controls, and that the OCC is reviewing supervisory expectations and planning an interagency RFI on AI and model risk.
Is the OCC planning new AI guidance?
The Spring 2026 Semiannual Risk Perspective says the OCC is 'actively reviewing supervisory expectations, guidance, and regulations' around AI and that the OCC, Fed, and FDIC plan to issue a request for information on model risk management and AI. No new guidance had been issued as of August 26, 2026.
| Date | Document | Status |
|---|---|---|
| Apr 17, 2026 | OCC Bulletin 2026-13 — Model Risk Management: Revised Guidance | In force |
| Apr 29, 2025 | Acting Comptroller Hood, 'AI in Financial Services' (Apr 2025) — Remarks by Acting Comptroller Rodney E. Hood at the National Fair Housing Alliance's Responsible AI Symposium: 'AI in Financial Services' | Final |
| Jun 6, 2023 | OCC Bulletin 2023-17 — Third-Party Relationships: Interagency Guidance on Risk Management | In force |
| Apr 9, 2021 | OCC Bulletin 2021-19 — Bank Secrecy Act/Anti-Money Laundering: Interagency Statement on Model Risk Management for Bank Systems Supporting BSA/AML Compliance and Request for Information | Superseded |
| Mar 31, 2021 | 2021 Interagency AI RFI (OCC Bulletin 2021-17) — Request for Information and Comment on Financial Institutions' Use of Artificial Intelligence, Including Machine Learning | Final |
| Apr 4, 2011 | OCC Bulletin 2011-12 — Sound Practices for Model Risk Management: Supervisory Guidance on Model Risk Management | Superseded |
Follow every document these regulators publish
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →