The OCC supervises AI at national banks through model risk management and safety-and-soundness examination — not through AI-specific rules. The landscape changed on April 17, 2026: the OCC, Federal Reserve, and FDIC issued revised interagency model risk management guidance (OCC Bulletin 2026-13) that supersedes the 2011 framework, rescinds OCC 2011-12, and explicitly excludes generative and agentic AI from its scope, leaving those to banks' broader risk-management and governance programs.
| Full name | Office of the Comptroller of the Currency |
| Role | Prudential supervisor |
| Force on banks | Supervisory guidance |
| Applies to | National banks, federal savings associations, and federal branches of foreign banks |
| Key document | OCC Bulletin 2026-13 — Revised interagency Model Risk Management guidance (Apr 2026) |
| Latest move | Apr 2026 revised model risk guidance excluding generative/agentic AI; May 2026 risk report on AI-enabled fraud |
| Documents tracked | 8 · all documents → |
For fifteen years the operative document was the 2011 Supervisory Guidance on Model Risk Management (OCC 2011-12 / Fed SR 11-7). The April 2026 revision modernizes that framework and makes a deliberate scoping choice: generative and agentic AI are called 'novel and rapidly evolving' and carved out of formal model-risk requirements, with banks told to govern them through enterprise risk management instead. The OCC simultaneously rescinded older issuances including its 1997 credit-scoring-models bulletin and 2021 BSA/AML model risk FAQ.
Beyond model risk, the OCC's May 2026 Semiannual Risk Perspective flags AI as a driver of fraud and increasingly fast, sophisticated cyberattacks, and signals that AI governance guidance is on the horizon. The practical posture in 2026 is innovation-friendly: examiners test whether banks understand and control their AI, not whether they use it.
What responsible AI practices are expected of large banks as they innovate with AI?
No US regulator has written an AI rulebook for large banks, but the expectation set is now concrete. For banking organizations above roughly $30 billion in assets, the April 2026 interagency model risk guidance (OCC Bulletin 2026-13, SR 26-2, FIL-15-2026) is the operative standard for every quantitative model: sound development, independent validation with outcomes analysis, effective challenge and board-level governance, scaled to materiality. It deliberately leaves generative and agentic AI to 'broader risk management and governance', which supervisors then examine through third-party (SR 23-4), operational-resilience, cybersecurity and consumer-protection frameworks. Internationally the practices are converging on the FSB's twelve proposed sound practices of June 2026: board-set strategic direction, clear accountability, AI inside the enterprise risk framework, materiality-based risk assessment, data governance, explainability, performance monitoring, human oversight with extra measures for highly autonomous agents, cyber and ICT controls, and third-party AI risk. Supervisors on both sides of the Atlantic describe the same observed practice at large banks in almost the same words: guardrails, human-in-the-loop accountability, and use limited to defined cases.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| OCC Bulletin 2026-13 / SR 26-2 / FIL-15-2026 | OCC | Risk-based, materiality-driven model risk management — sound development and testing, independent validation with outcomes analysis, effective challenge, board and senior-management governance — most relevant above $30 billion in assets. Generative and agentic AI are outside its scope and must be managed through broader governance programs. | Since Apr 17, 2026 |
| Acting Comptroller Hood, Responsible AI Symposium | OCC | 'Robust risk management practices for AI applications, consistent with conventional model risk management' — covering bias, security vulnerabilities and explainability — and existing OCC and interagency guidance applied as the AI governance baseline. | Since Apr 2025 |
| OCC Semiannual Risk Perspective, Spring 2026 | OCC | Reports the observed large-bank practice for generative and agentic AI: a measured approach, use limited to specific cases, guardrails and human-in-the-loop accountability — and warns that lack of explainability makes governance 'essential' before use expands to material financial decisions. | May 2026 |
| SR 23-4 / OCC Bulletin 2023-17 / FIL-29-2023 | Federal Reserve | Vendor-supplied AI — cloud-hosted models, foundation-model access, embedded AI in platforms — goes through the full third-party lifecycle: due diligence, contracts with audit and data rights, ongoing monitoring, exit. The bank stays accountable for the outcome; supervisors said in May 2026 they are assessing how these expectations apply to vendor AI. | In force |
| Vice Chair Bowman, FSOC AI roundtable | Federal Reserve | No pre-emptive AI-specific rulemaking: existing frameworks, regularly reviewed, should accommodate AI. Confirms the generative/agentic carve-out from model risk guidance and frames frontier AI as dual-use in cybersecurity. | May 2026 |
| FSB 12 sound practices for responsible AI adoption | FSB | Organisation-wide: strategic direction and oversight, governance and accountability, AI in the risk framework, organisational adaptability. Lifecycle: materiality and risk assessment, model selection, data governance, explainability, performance management, human oversight (extra measures for highly autonomous agentic AI), cyber/ICT, third-party AI risk. | Final report due Oct 2026 |
| NIST AI RMF 1.0 (AI 100-1) | NIST | Voluntary Govern–Map–Measure–Manage cycle and seven trustworthiness characteristics (valid and reliable, safe, secure and resilient, accountable and transparent, explainable, privacy-enhanced, fair). The common vocabulary US agencies and Treasury keep pointing to. | Since Jan 2023 |
| Treasury FS AI RMF and AI Lexicon | U.S. Treasury | Adapts the NIST AI RMF to financial-services operations, regulation and consumer protection; gives institutions tools to evaluate AI use cases across the lifecycle and a shared lexicon. Non-binding, scalable by size. | Since Feb 19, 2026 |
| NIST AI 600-1 (Generative AI Profile) | NIST | Twelve generative-AI risks — confabulation, information security (prompt injection, data poisoning, model extraction), data privacy, harmful bias, value-chain and component integration — with 200+ suggested actions mapped to RMF subcategories. The de facto control catalogue for the AI that model risk guidance excludes. | Since Jul 2024 |
| ECB: 'Technology is neutral, governance is not' | ECB | Three governance expectations for the 85%+ of large European banks using AI: clear accountability for AI outcomes, senior-management oversight matching AI's strategic importance, effective challenge from risk, compliance and internal audit — plus explainability, lifecycle governance and drift monitoring, data quality and third-party risk. | Feb 2026 |
| SSM supervisory priorities 2026–28 | ECB | Banks 'shall have strategies that effectively reflect opportunities and risks' of new technologies; continued monitoring of general AI use and a targeted, in-depth approach to generative-AI applications, with DORA on-site campaigns on cyber and third-party risk. | 2026–28 |
| PRA SS1/23 | UK (BoE / PRA / FCA) | Five model-risk principles for all models informing business decisions, including vendor models, with a sub-principle on AI and machine-learning risks and a named Senior Management Function holder accountable for the framework. | Since May 17, 2024 |
| DFS Industry Letter on frontier AI models | NY DFS | For New York-regulated institutions: shorter remediation timelines, mapped third-party dependencies, human review of AI-generated code before deployment, stronger logging and alerting, more frequent resilience testing — under 23 NYCRR Part 500. | May 2026 |
| CFPB issue spotlight on chatbots | CFPB | Every top-10 US bank runs a chatbot; institutions remain responsible for accurate answers, dispute recognition and access to a human 'regardless of the processes or technologies used' — UDAAP, Regulation E and Z duties attach to the AI front end. | Since Jun 2023 |
| SEC Examination Priorities FY2026 | SEC | For bank-affiliated broker-dealers and advisers: accurate representations of AI capabilities, and policies and procedures to monitor and supervise AI used in fraud prevention, back-office operations, AML and trading. | FY2026 |
| EU AI Act, Annex III 5(b) and Arts. 9–15, 26 | EU AI Act | For large banks with EU operations: creditworthiness scoring of natural persons is high-risk — risk management, data governance, logging, human oversight and, for deployers, monitoring, six-month log retention and a fundamental-rights impact assessment. | From Dec 2, 2027 |
'Large' has a number in the United States. The April 2026 interagency model risk guidance says it is most relevant to banking organizations with more than $30 billion in total assets, and everything above that line is examined against it: an inventory of models, development evidence, independent validation with outcomes analysis, effective challenge, and a board that owns the framework. Below the line the same disciplines apply proportionately. The guidance replaced SR 11-7 after fifteen years and narrowed the definition of a model to complex quantitative methods — deterministic rules and simple arithmetic are out — which is why the OCC rescinded Bulletins 2011-12, 1997-24 and 2021-19 and the Comptroller's Handbook booklet on the same day.
What large banks actually do is now on the record from supervisors, not vendors. The OCC's Spring 2026 Risk Perspective describes generative and agentic AI use as 'primarily productivity and customer experience enhancement tools', deployed 'with guardrails and human-in-the-loop accountability' and limited to specific cases, while noting banks may expand to 'material financial decisions'. The ECB's Pedro Machado reported in February 2026 that more than 85% of large European banks use AI, with generative and agentic tools accelerating in IT operations, legal and document analysis and front-line support. The EBA's September 2025 survey put EU adoption at 92%, with 55% of banks already using general-purpose or agentic AI in consumer-facing processes. The CFPB found in 2023 that all of the top ten US commercial banks ran chatbots. The UK's 2024 survey found 75% adoption with only 2% of use cases fully autonomous — and the 2026 edition, the first to ask about agentic AI, will publish later this year.
The gap every large bank's AI governance has to bridge is explicit: the 2026 model risk guidance says generative and agentic AI 'are not within the scope of this guidance', and the agencies have promised an interagency request for information on AI and model risk 'in the near future'. Until it lands, four frameworks fill the space. Third-party guidance (SR 23-4) governs the vendor models and cloud-hosted foundation models most banks actually consume — Vice Chair Bowman said in May 2026 supervisors are assessing exactly how it applies to vendor AI. NIST AI 600-1 supplies the control catalogue for generative-AI-specific risks such as confabulation, prompt injection and value-chain integration. NIST's CAISI has an open workstream on AI agent security — indirect prompt injection, misaligned behaviour, constraining and monitoring agent access — from its January 2026 RFI. And the FSB's Sound Practice 10 sets the international expectation that human oversight scales up, not down, as agents become more autonomous.
Direction of travel matters as much as the current rules, and it runs in two directions at once. On adoption, the posture is pro-innovation: Executive Order 14179 and the July 2025 AI Action Plan frame Treasury's February 2026 FS AI RMF; FSOC's 2025 report made 'harnessing AI' a priority and created a standing AI Working Group; the four-roundtable FSOC AI Innovation Series closed in June 2026 with participants asking for regulatory clarity and harmonization; FDIC Chairman Hill told Congress the revised model risk guidance 'supports the use of innovative technology'; HM Treasury's July 2026 plan wants firms 'beyond isolated pilots'; and the PRA's April 2026 plan keeps regulation technology-agnostic. On cyber, the warnings escalate: DFS's May 2026 frontier-AI letter, the ECB's 'Dear CEO' letter of July 2026 requiring AI-cyber action plans by 31 October, the ESAs' July 2026 statement under DORA, and the FSB Chair's 31 August 2026 letter naming frontier models' 'increasingly sophisticated autonomy' as a stability concern. A large bank's responsible-AI programme has to satisfy both audiences with one set of controls.
In practice the examination question is rarely 'do you have a responsible AI policy'. It is whether the bank can show, for any given AI system, which tier it sits in, who owns it, what it was validated against, what a human can override, what the vendor contract lets the bank see, and what happens when it is wrong. The documents above are the sources of each of those questions.
WHAT THIS MEANS IN PRACTICE
- Tier every AI system by materiality before choosing the control set. Above $30 billion, anything that meets the 2026 definition of a model gets full validation; generative and agentic tools get a documented governance path that names which of SR 23-4, NIST 600-1 and the operational-resilience controls apply.
- Write the generative/agentic gap into policy rather than leaving it implicit: the guidance itself says these tools are managed through 'broader risk management and governance' — examiners will ask to see that program.
- Treat vendor AI as a third-party relationship first and a model second. Due diligence, contract audit rights, data-use terms and exit plans are what supervisors are currently assessing for AI vendors.
- Make human-in-the-loop measurable. The observed large-bank practice supervisors praise is not a checkbox; it is a defined reviewer with authority to override, evidence they actually review, and a threshold at which automation stops.
- Fund explainability as a control, not a research project. Hood in 2025, the Risk Perspective in 2026 and the ECB in 2026 all name explainability as the governance issue that limits where AI can be used.
- Give internal audit and compliance an effective-challenge role over AI — the ECB's third expectation and the FSB's second practice — rather than housing all AI oversight in technology.
- Map the cyber warnings to remediation timelines now: human review of AI-generated code, faster patching, dependency maps and logging are what DFS, the ECB and the ESAs asked for in the same eight weeks of 2026.
- Watch for the interagency RFI on AI and model risk management: it is the first federal document that will speak to generative and agentic AI directly, and comment letters from large banks will shape it.
What has the OCC actually published on AI?
| Date | Document | Status |
|---|---|---|
| May 7, 2026 | OCC Semiannual Risk Perspective, Spring 2026 — Semiannual Risk Perspective from the National Risk Committee, Spring 2026 | Final |
| Apr 17, 2026 | OCC Bulletin 2026-13 — Model Risk Management: Revised Guidance | In force |
| Apr 29, 2025 | Acting Comptroller Hood, 'AI in Financial Services' (Apr 2025) — Remarks by Acting Comptroller Rodney E. Hood at the National Fair Housing Alliance's Responsible AI Symposium: 'AI in Financial Services' | Final |
| Jun 6, 2023 | OCC Bulletin 2023-17 — Third-Party Relationships: Interagency Guidance on Risk Management | In force |
| Apr 9, 2021 | OCC Bulletin 2021-19 — Bank Secrecy Act/Anti-Money Laundering: Interagency Statement on Model Risk Management for Bank Systems Supporting BSA/AML Compliance and Request for Information | Superseded |
| Mar 31, 2021 | 2021 Interagency AI RFI (OCC Bulletin 2021-17) — Request for Information and Comment on Financial Institutions' Use of Artificial Intelligence, Including Machine Learning | Final |
| Apr 4, 2011 | OCC Bulletin 2011-12 — Sound Practices for Model Risk Management: Supervisory Guidance on Model Risk Management | Superseded |
| May 20, 1997 | OCC Bulletin 1997-24 — Credit Scoring Models: Examination Guidance | Superseded |
| Date | Type | Document / event |
|---|---|---|
| May 7, 2026 | Report | OCC Semiannual Risk Perspective, Spring 2026 — Semiannual Risk Perspective from the National Risk Committee, Spring 2026. The OCC's Spring 2026 Semiannual Risk Perspective, released May 7, 2026, says artificial intelligence is 'significantly transforming the cyber threat landscape' — lowering the barrier to entry for attackers and increasing the 'speed, scale, and sophistication' of cyberattacks and fraud — while also giving banks new defensive capabilities. source ↗ |
| Apr 17, 2026 | Guidance | OCC Bulletin 2026-13 — Model Risk Management: Revised Guidance. On April 17, 2026 the OCC, Federal Reserve, and FDIC issued revised interagency Model Risk Management guidance (OCC Bulletin 2026-13; Fed SR 26-2; FDIC FIL-15-2026), replacing the 2011 framework that had governed bank models for 15 years. source ↗ |
| Apr 29, 2025 | Speech | Acting Comptroller Hood, 'AI in Financial Services' (Apr 2025) — Remarks by Acting Comptroller Rodney E. Hood at the National Fair Housing Alliance's Responsible AI Symposium: 'AI in Financial Services'. On April 29, 2025 Acting Comptroller Rodney E. source ↗ |
| Jun 6, 2023 | Guidance | OCC Bulletin 2023-17 — Third-Party Relationships: Interagency Guidance on Risk Management. OCC Bulletin 2023-17, issued June 6, 2023, transmits the interagency Guidance on Third-Party Relationships: Risk Management from the OCC, Federal Reserve, and FDIC. source ↗ |
| Apr 9, 2021 | Guidance | OCC Bulletin 2021-19 — Bank Secrecy Act/Anti-Money Laundering: Interagency Statement on Model Risk Management for Bank Systems Supporting BSA/AML Compliance and Request for Information. OCC Bulletin 2021-19, issued April 9, 2021, transmitted the interagency Statement on Model Risk Management for Bank Systems Supporting BSA/AML Compliance, issued by the OCC, Federal Reserve, FDIC, and NCUA in consultation with FinCEN, together with a request for information (comments due June 11, 2021). source ↗ |
| Mar 31, 2021 | Consultation | 2021 Interagency AI RFI (OCC Bulletin 2021-17) — Request for Information and Comment on Financial Institutions' Use of Artificial Intelligence, Including Machine Learning. On March 31, 2021 the OCC, Federal Reserve, FDIC, CFPB, and NCUA jointly published a Request for Information on financial institutions' use of artificial intelligence, including machine learning — the first coordinated federal inquiry into bank AI. source ↗ |
| Apr 4, 2011 | Guidance | OCC Bulletin 2011-12 — Sound Practices for Model Risk Management: Supervisory Guidance on Model Risk Management. OCC Bulletin 2011-12, issued April 4, 2011, transmitted the interagency Supervisory Guidance on Model Risk Management (the Federal Reserve's SR 11-7). source ↗ |
| May 20, 1997 | Guidance | OCC Bulletin 1997-24 — Credit Scoring Models: Examination Guidance. OCC Bulletin 1997-24, 'Credit Scoring Models: Examination Guidance,' issued May 20, 1997, was the OCC's first supervisory statement on algorithmic credit decisions. source ↗ |
Which of the 100 largest US banks answer to the OCC on AI?
39 of the 100 bank pages on this site name the OCC among the authorities their AI programme answers to. Each page lists the documents that apply and why.
- The interagency request for information on model risk management and banks' use of AI (including generative and agentic AI) that the OCC, Fed, and FDIC promised 'in the near future' in Bulletin 2026-13 and repeated in the Spring 2026 Semiannual Risk Perspective — not yet published as of August 26, 2026
- The OCC's stated review of supervisory expectations, guidance, and regulations to 'right-size' AI expectations for community banks that rely on third-party technology (Spring 2026 Semiannual Risk Perspective)
- How examiners treat generative/agentic AI now that it sits outside formal model-risk requirements
- Interaction between the deregulatory 2025–26 posture and consumer-protection enforcement on AI lending
Does SR 11-7 / OCC 2011-12 still apply to AI models?
No — as of April 17, 2026 the 2011 interagency model risk guidance was superseded by revised guidance from the OCC, Federal Reserve, and FDIC (OCC Bulletin 2026-13). Traditional and machine-learning models fall under the revised framework; generative and agentic AI are explicitly excluded and are instead governed through banks' broader risk-management programs.
Why did the 2026 guidance exclude generative AI?
The agencies concluded generative and agentic AI are 'novel and rapidly evolving' — too fast-moving for prescriptive model-validation requirements. Banks are expected to apply enterprise risk management and governance controls instead, and further AI-specific guidance has been signalled.
Is there any binding US federal AI regulation for banks?
There is no AI-specific federal statute for banks. AI use is regulated through existing law — safety and soundness, fair lending (ECOA), UDAP/UDAAP — and supervisory guidance like the 2026 model risk framework. This contrasts with the EU, where the AI Act imposes binding AI-specific obligations.
Which OCC bulletins did Bulletin 2026-13 rescind?
Four issuances: OCC Bulletin 2011-12 (Supervisory Guidance on Model Risk Management), OCC Bulletin 1997-24 (Credit Scoring Models: Examination Guidance), OCC Bulletin 2021-19 (the interagency statement on model risk management for BSA/AML compliance), and the 'Model Risk Management' booklet of the Comptroller's Handbook. The rescinded bulletins remain readable in the OCC's rescinded-bulletins archive.
Follow every move these regulators make
the daily brief · six sourced stories · in your inbox by 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning