AI Regulation Tracker · United States (state member banks, bank holding companies, large financial institutions)

How does the Federal Reserve regulate AI in banking?

Last updated Aug 26, 2026 · Updated as rules change

The Federal Reserve supervises bank AI through its model risk and safety-and-soundness framework rather than AI-specific rules. Its landmark document, SR 11-7 (2011), was superseded in April 2026 by revised interagency model risk management guidance issued jointly with the OCC and FDIC — which notably excludes generative and agentic AI from its scope. Fed leadership in 2026 has publicly favored an innovation-permissive stance, emphasizing that supervisors should not impede responsible AI adoption.

Full nameBoard of Governors of the Federal Reserve System
RoleCentral bank and prudential supervisor
Force on banksSupervisory guidance
Applies toState member banks, bank and savings-and-loan holding companies, and US operations of foreign banks
Key documentSR 26-2 — Revised interagency Model Risk Management guidance (Apr 2026, supersedes SR 11-7)
Latest moveApr 2026 revised model risk guidance; May 2026 Vice Chair speech on AI in the financial system
Documents tracked7 · all documents →

SR 11-7 was arguably the most influential model-governance document in world banking — the template for how banks validated any quantitative model, including ML. Its April 2026 replacement keeps the core disciplines (validation, effective challenge, governance) while modernizing for machine learning and deliberately leaving generative and agentic AI to enterprise risk management pending further guidance.

Vice Chair for Supervision remarks in May 2026 framed AI as a technology the financial system should adopt with appropriate controls, positioning the Fed against pre-emptive AI-specific rulemaking. Banks should expect examination focus on governance, third-party (foundation-model vendor) risk, and data controls rather than new AI rules.

What has the Federal Reserve actually published on AI?

DateDocumentStatus
May 27, 2026Cook: Opportunities and Risks of AI (May 2026)The Opportunities and Risks AI Presents for the Economy and Financial System — Governor Lisa D. CookFinal
May 1, 2026Bowman: AI in the Financial System (May 2026)Artificial Intelligence in the Financial System — Vice Chair for Supervision Michelle W. BowmanFinal
Apr 17, 2026SR 26-2Revised Guidance on Model Risk ManagementIn force
Jun 7, 2023SR 23-4Interagency Guidance on Third-Party Relationships: Risk ManagementIn force
Apr 9, 20212021 BSA/AML Model Risk StatementInteragency Statement on Model Risk Management for Bank Systems Supporting BSA/AML ComplianceSuperseded
Mar 31, 20212021 Interagency AI RFIRequest for Information and Comment on Financial Institutions' Use of Artificial Intelligence, Including Machine LearningFinal
Apr 4, 2011SR 11-7Supervisory Guidance on Model Risk ManagementSuperseded
DateTypeDocument / event
May 27, 2026SpeechCook: Opportunities and Risks of AI (May 2026) — The Opportunities and Risks AI Presents for the Economy and Financial System — Governor Lisa D. Cook. On May 27, 2026 at the Stanford Institute for Economic Policy Research, Governor Lisa Cook set out the Federal Reserve's financial-stability view of AI: AI-driven algorithmic trading risks 'more correlated trading, endogenous model collusion, potential market manipulation, and greater market concentration'; hyperscalers and data-center developers are increasingly financing AI capital expenditure through debt markets with bank exposure; and AI-generated code may outpace security review. source ↗
May 1, 2026SpeechBowman: AI in the Financial System (May 2026) — Artificial Intelligence in the Financial System — Vice Chair for Supervision Michelle W. Bowman. On May 1, 2026, Vice Chair for Supervision Michelle Bowman told the FSOC Artificial Intelligence Series roundtable on cybersecurity and risk management that AI 'will become a force multiplier for the financial system' and that supervisors must preserve 'a path for innovation' while banks deploy AI 'responsibly and effectively'. source ↗
Apr 17, 2026GuidanceSR 26-2 — Revised Guidance on Model Risk Management. SR 26-2, issued April 17, 2026 jointly by the Federal Reserve, OCC (Bulletin 2026-13), and FDIC, replaces SR 11-7 (2011) and the 2021 BSA/AML model risk statement (SR 21-8) with a risk-based, materiality-driven model risk management framework. source ↗
Dec 14, 2023MilestoneFSOC annual report identifies AI as a financial-system vulnerability for the first time. The Financial Stability Oversight Council's 2023 Annual Report, which the Federal Reserve Chair votes on as a Council member, was the first to list the use of AI in financial services as a vulnerability and recommended that member agencies build capacity to monitor it.
Jun 7, 2023GuidanceSR 23-4 — Interagency Guidance on Third-Party Relationships: Risk Management. SR 23-4, issued June 7, 2023 by the Federal Reserve, OCC, and FDIC, is the interagency guidance on managing risk from third-party relationships and is the framework examiners use when a bank buys AI tools, cloud-hosted models, or foundation-model access from vendors. source ↗
Apr 9, 2021Guidance2021 BSA/AML Model Risk Statement — Interagency Statement on Model Risk Management for Bank Systems Supporting BSA/AML Compliance. On April 9, 2021 the Federal Reserve (as SR 21-8), OCC, FDIC, and NCUA, with FinCEN concurrence, issued a statement on how model risk management principles apply to systems banks use for Bank Secrecy Act / anti-money-laundering compliance, and simultaneously asked for comment on it. source ↗
Mar 31, 2021Consultation2021 Interagency AI RFI — Request for Information and Comment on Financial Institutions' Use of Artificial Intelligence, Including Machine Learning. On March 31, 2021 the Federal Reserve, OCC, FDIC, CFPB, and NCUA jointly published a request for information on how financial institutions use artificial intelligence and machine learning and how existing rules and guidance apply. source ↗
Apr 4, 2011GuidanceSR 11-7 — Supervisory Guidance on Model Risk Management. SR 11-7, issued jointly by the Federal Reserve and OCC on April 4, 2011, was the foundational US framework for bank model risk management for fifteen years and the de facto global template for validating quantitative models, including early machine-learning models. source ↗

Which of the 100 largest US banks answer to the Federal Reserve on AI?

90 of the 100 bank pages on this site name the Federal Reserve among the authorities their AI programme answers to. Each page lists the documents that apply and why.

  • The interagency request for information on model risk management and banks' use of AI — including generative, agentic, and AI-based models — that the Fed, OCC, and FDIC said in April 2026 they would issue 'in the near future'; it had not appeared in the Federal Register as of August 26, 2026
  • Whether the Fed issues follow-on guidance covering generative and agentic AI, which SR 26-2 deliberately left out of scope
  • Examination practice at large banks: how third-party foundation-model dependence is treated under SR 23-4 third-party risk guidance
  • FSOC's AI working group, formalized in the December 2025 annual report, and the AI treatment in the next annual report

Is SR 11-7 still in effect?

No. On April 17, 2026 the Federal Reserve, OCC, and FDIC issued revised interagency model risk management guidance that supersedes the 2011 SR 11-7 framework. The revision covers traditional and ML models but explicitly excludes generative and agentic AI.

Does the Federal Reserve have AI-specific rules for banks?

No. The Fed regulates AI through existing frameworks — model risk management, safety and soundness, and third-party risk guidance. Its 2026 public posture favors allowing responsible AI adoption rather than imposing AI-specific rulemaking.

How should banks govern generative AI if it's excluded from model risk guidance?

The 2026 interagency guidance directs banks to apply their broader risk-management and governance practices to generative and agentic AI — meaning enterprise risk frameworks, vendor risk management, data governance, and board oversight, rather than formal model-validation requirements.

Follow every move these regulators make

the daily brief · six sourced stories · in your inbox by 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning