On April 17 the OCC issued Bulletin 2026-13 and the Federal Reserve published SR Letter 26-2, jointly replacing the SR 11-7 model risk framework that had governed banks since 2011. One sentence in it decides how much of the guidance reaches an insurance model risk function: "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance."

Key Takeaways

What the New Guidance Does and Does Not Cover

SR 26-2 is roughly half the length of SR 11-7 and states outright that it "does not set forth enforceable standards or prescriptive requirements." Four changes carry that shift.

The model definition narrows to "a complex quantitative method, system, or approach that applies statistical, economic, or financial theories to process input data into quantitative estimates," which drops deterministic rule-based processes and simple calculators out of scope. Materiality tiering replaces the de facto annual review cycle, combining dollar exposure with regulatory-versus-internal purpose. Validator independence is redefined around "the rigor and effectiveness of the review rather than on organizational structure." Ongoing monitoring rises relative to point-in-time validation.

Then the exclusion. It is a design choice, not an omission, and the agencies have said a separate Request for Information on generative, agentic and AI-based models will follow.

The reasoning holds up. The three validation pillars, conceptual soundness, outcomes analysis and ongoing monitoring, assume a model that transforms defined inputs into quantitative outputs through documented mathematical relationships. A GLM built for auto pricing satisfies that: every coefficient is documented and every prediction is back-testable against observed losses. A large language model reading claims documents does not apply statistical or financial theory in the sense the definition requires, and the same document processed twice may extract differently. An agentic system that perceives, plans, executes and evaluates across steps introduces runtime behavior that pre-deployment validation does not reach.

Other regimes drew the line elsewhere. The UK PRA's SS1/23 does not carve out AI by category, and the EU AI Act classifies insurance AI systems as high-risk on the use case rather than the architecture.

The Insurance Side Has No Document to Exclude From

For banks the exclusion is a hole in an existing framework, and the framework still governs everything else. For insurance carriers there is no SR 11-7 equivalent to have a hole in.

The NAIC adopted AI Principles in 2020 and the Model Bulletin on the Use of AI Systems by Insurers in December 2023, now in force in over half the states. It addresses unfair discrimination, governance, documentation and third-party oversight. It does not say how to establish a model's conceptual soundness, how to structure drift detection, or how to tier governance effort by materiality.

Jurisdiction Framework Focus MRM Equivalent?
Federal banking (SR 26-2) Comprehensive interagency guidance Full model lifecycle: development, validation, monitoring, retirement Yes; the standard
NAIC Model Bulletin Non-binding model guidance Consumer protection, bias, transparency, third-party oversight No; addresses AI governance broadly, not model validation specifically
NAIC AI Evaluation Tool Examination framework (pilot) Structured assessment of AI usage, governance, high-risk systems No; regulatory assessment instrument, not an MRM standard
Colorado (SB 21-169 / Reg 10-1-1) State statute and regulation Algorithmic discrimination prevention, annual attestation Partial; prescriptive on bias testing, silent on broader model risk
ASOP No. 56 Actuarial standard of practice Modeling: data, assumptions, testing, documentation, governance Partial; professional standard for actuaries, not a regulatory framework

That leaves ASOP No. 56 as the working anchor, and it carries more of the load than it was built for. Its data provisions reach training data quality and representativeness; its testing provisions reach performance benchmarking and sensitivity analysis; its reliance-on-others provisions reach models built by data science teams or bought from vendors.

The limit is what kind of obligation it is. SR 26-2 tells a bank's board and senior management what they must oversee. ASOP No. 56 tells an individual actuary what they must do inside their own professional scope. A carrier can be fully compliant with ASOP No. 56, article by article, and still have no model inventory, no materiality tiering, no independent validation function and no board-level model risk reporting. The standard cannot require organizational infrastructure, because it does not bind the organization.

That is what the 24% confidence figure measures. Three quarters of insurance executives cannot demonstrate AI governance on demand within 90 days while 63% have AI in production, and the reason is not that the profession lacks validation technique. It is that nothing tells the enterprise to build the structure the technique runs inside.

Three State Regimes, None of Them a Framework

What fills the gap is state action, and it fills it unevenly. Colorado's SB 21-169 prohibits algorithms, predictive models and external consumer data that produce unfair discrimination, and Regulation 10-1-1 expanded in October 2025 to private passenger auto and health benefit plans on top of life. Annual compliance reports on governance, testing and model oversight begin in July 2026. Connecticut's Senate Bill 5 cleared both chambers on May 1, 2026, covering automated decisions across sectors. Maryland relies on the Model Bulletin framework rather than bespoke legislation.

A national bank runs one model risk framework across every state it operates in. A multi-state insurer running the same claims triage model in those three states answers a bias attestation regime, an omnibus automated-decision statute and a bulletin-based governance expectation. None of the three, individually or together, specifies how to validate that model's conceptual soundness or monitor it for drift.

The vendor layer compounds it. Carriers buying generative AI capability inherit stacked exposure: the carrier depends on the vendor's model, the vendor depends on a foundation model provider's base model, and the actuary validates the combination without full visibility into either layer. SR 26-2 handles this for banks by requiring vendor models be validated as rigorously as internally built ones. Insurance regulators have not set a comparable expectation.

The pilot is the mechanism that could change that, and not in the direction carriers would choose. The NAIC Big Data and Artificial Intelligence Working Group is already weighing whether the Model Bulletin should become an enforceable model law. Twelve state examiners are about to run a structured governance assessment against an industry where 43% have no formal AI risk framework. Findings of that shape are the argument for binding requirements, made with the industry's own examination data.

Further Reading

Sources

  1. OCC Bulletin 2026-13: Model Risk Management Revised Guidance (April 17, 2026)
  2. Federal Reserve SR Letter 26-2: Revised Guidance on Model Risk Management (April 17, 2026; replaces SR 11-7 and SR 21-8)
  3. OCC/Federal Reserve/FDIC, Revised Interagency Guidance on Model Risk Management, full text (April 2026)
  4. Domino Data Lab, "What Changes with SR 26-2: Model Risk Management Guidance" (model definition, risk-based tiering, validation independence analysis)
  5. ValidMind, "SR 26-2: What Every Bank Needs to Know" (materiality framework, narrowed model definition, governance comparison)
  6. AI2Work, "Fed and OCC Overhaul Bank Model Risk Rules but Leave AI Uncharted" (AI exclusion analysis, planned RFI details)
  7. Lumenova AI, "SR 26-2: Actionable Guide to Model Risk Management" (three validation pillars, board responsibilities, GenAI exclusion scope)
  8. Grant Thornton, 2026 AI Impact Survey Report (950 executives; 63% AI operationalization, 24% governance confidence, 43% lacking formal AI risk frameworks)
  9. NAIC, Artificial Intelligence Insurance Topics (AI Principles 2020, Model Bulletin 2023, AI evaluation tool pilot 2026)
  10. Fenwick, "NAIC Expands AI Systems Evaluation Tool Pilot Program to 12 States" (Exhibits A-D structure, March-September 2026 timeline, proportionality principle)
  11. Plante Moran, "How the NAIC AI Model Bulletin Is Evolving and Why Insurers Should Prepare Now" (Model Law transition, state adoption status)
  12. Actuarial Standards Board, ASOP No. 56: Modeling (effective October 2020; Sections 3.2, 3.4, 3.7, 4.1 on data, testing, reliance, documentation)
  13. Sia Partners, "SR 11-7 vs. SR 26-2: Model Risk Management Modernization" (side-by-side comparison of validation and governance changes)
  14. Roots Automation, "What Insurers Need to Know About Colorado's New AI Regulations" (SB 21-169, Regulation 10-1-1, annual compliance reports)