A bank with less than $30 billion in assets should bring every generative AI tool it runs under its own written policy this quarter, with one named owner for each tool, because the model risk guidance the federal banking agencies revised in April 2026 generally excludes banks that size and, at every size, puts generative and agentic AI outside its scope.
The Federal Reserve, the OCC and the FDIC issued that guidance on April 17, 2026, and the OCC's release states that generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance. A footnote in the attached guidance carries the instruction a CFO can act on: a banking organization's risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document. Where the guidance does reach a bank, its principles still apply to traditional statistical and quantitative models and non-generative, non-agentic AI models. In the whole document, generative and agentic AI are named in that footnote and nowhere else.
The Conference of State Bank Supervisors and state banking supervisors administered their annual survey of community banks from April 15 to July 15, 2025 and presented the findings that October; 268 banks responded, all of them institutions with less than $10 billion in total assets, participating on a self-selected basis. Asked which technological developments would be promising opportunities over the next five years, and able to select all that apply, respondents put Artificial intelligence for customer support at 47 percent. That sample stops at $10 billion, so it reaches only the lower part of the range this post addresses, and the survey never uses the word generative, so it records appetite for AI rather than the controls around it.
The policy can borrow the structure of the document that excluded these tools. The guidance says Effective policies define risk management expectations and establish a framework for assessing the magnitude of model risk and for applying model risk management practices commensurate with that risk, with procedures that support policy implementation by establishing a monitoring and control process and specifying the allocation of resources to that process. On accountability it says Sound governance practices delineate the individual(s) responsible for key activities throughout the model lifecycle, from development through validation and ongoing monitoring.
In the first month the CFO and the chief risk officer write one page for each generative tool in use, covering what it drafts or summarises, which decisions it may not make alone, and who signs for it. In the second, the head of vendor management asks each supplier what the bank can and cannot inspect, and the answer goes on the page. In the third, the tools carrying the most weight get a monitoring cadence and a standing line in the report to the board's risk committee.
Two limits hold. The guidance does not set forth enforceable standards or prescriptive requirements. And it is aimed above the $30 billion line, so a smaller bank writing this policy answers to its own board, stopping at a policy, an owner and a monitoring cadence rather than the validation apparatus a larger institution staffs.
For the vendor models it does cover, the guidance records that banking organizations may not receive from the vendor the underlying code, data, or methodology that they would have if a model were developed internally, and states that Nevertheless, the principles of model risk management remain applicable.