Your model risk framework does not reach the agent.
The Federal Reserve's SR 26-2 replaced SR 11-7 and SR 21-8 in April 2026, and its footnote 3 says generative and agentic AI models "are not within the scope of this guidance". You still have to govern them.
Building AI for banks, payments or lenders rather than operating one? Yours is sell into the enterprise.
What a rule looks like
constants:
operator_approves_daily_total_above_usd: 3000
state_models:
user:
key: "{{ event.entity_id }}"
buckets:
# Counted from the terminal event, when the money has actually moved.
refunded_today:
type: fixed_window
window: "24h"
timezone: "UTC"
rules:
refund_needs_an_operator_for_the_day:
all:
- path: "event.type"
op: eq
value: "mcp.input"
- path: "event.data.tool.name"
op: eq
value: "refund_transaction"
- path: "state.user.buckets.refunded_today"
op: gte
value: "{{ constants.operator_approves_daily_total_above_usd }}"
effects:
verdict: flagged
actions:
- action: hitl/create_case
params:
queue: "finance"
priority: 80
timeout_duration: "24h"
timeout_decision: "reject" The rule keeps a running total of refunds for each customer for the day. Above the threshold it sends the refund to a person in the finance queue, and if nobody decides within 24 hours, the refund is rejected. Each refund on its own is defensible. The hundredth in a day is not, and a check that looks at one call at a time never sees it.
The regulator names the problem and leaves the method to you
The same footnote continues: a banking organization's own risk management and governance practices "should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document."
The supervisor has named the gap in writing, so you no longer have to argue that it exists.
Whether the letter binds you. It says: "This guidance does not set forth enforceable standards or prescriptive requirements; accordingly, non-compliance with this guidance will not result in supervisory criticism against a banking organization." Its footnote 1 adds: "However, supervisory action may result for any violations of law or unsafe or unsound practices stemming from insufficient management of model risk."
The exposure is safety and soundness, not non-compliance with a letter.
On who it reaches. Banking organizations with more than $30 billion in total assets; smaller ones are generally left out. The exception: it can also reach a smaller organization with "significant exposure to model risk because of the prevalence and complexity of their models or because of activities outside the scope of traditional community banking." For an AI-native lender, that second clause can reach it whatever its total assets.
On what counts as a model. The definition excludes deterministic rule-based processes and software "where there are no statistical, economic, or financial theories underpinning their design or use". A threshold, a counter and a comparison fall outside it, so a rule you write here is a control you add, not another model your validation team has to validate.
Footnote 3 also says which models the guidance does cover: "the principles described in this guidance apply to traditional statistical and quantitative models and non-generative, non-agentic AI models."
Who is asking, and what you can show them
| They ask about | You show |
|---|---|
| Model risk under SR 26-2 | the controls on the layer the framework does not cover, and the evidence they ran |
| A change to a limit | the candidate, the backtest against real history, and who promoted it |
| Why this transaction was held | the rule that decided, on the frozen version that was live |
| Financial crime controls, FFIEC, FinCEN, FATF, Wolfsberg | enforcement and evidence for the rules your AML and KYC vendors define |
The boundary your procurement team will ask about: Swiftward enforces and proves the rules you and your AML and KYC vendors define. Swiftward is not an AML data vendor or a KYC provider.
Across the businesses
Payments and transfers — caps, velocity, cooldowns, screening before the money moves. Lending — approval logic and the adverse action notice a declined applicant has a right to. Capital markets — pre-trade validation, position and notional limits, on the order path. Insurance has its own page: claims and underwriting.
An AI-native team with no risk tooling starts here. A bank that already runs AML screening and model risk management adds Swiftward for the decisions its agents make, and forwards the records to the SIEM it already has.
Where it connects
Your own code calls the engine before it acts, or you place a gateway in the path: MCP between your agent and its tools, FIX on the order path.