Invest1 publisher3 min readPublished
Former Philadelphia Fed president urges examiners to police AI model vendors under a 1962 law
Former Philadelphia Fed president wants examiners to use a 1962 law on AI vendors after the April 17 SR 11-7 rewrite excluded generative AI. The plan skips Congress but still asks for a new supervisory letter within 12 months, aimed at the few suppliers whose models many banks share.
The Investor · Invest desk

What happened
- On April 17 the Fed, the OCC and the FDIC published a replacement for SR 11-7, the model-risk letter supervisors have used since April 2011.
- The replacement says generative and agentic AI models are novel and rapidly evolving and are not within the scope of the new guidance.
- A former Philadelphia Fed president proposes examining AI model suppliers under the 1962 Bank Service Company Act, a law the Richmond Fed used to examine an Amazon facility in Virginia.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure A flaw in one widely licensed frontier model would hit many banks at the same time, and no supervisor has yet reviewed that risk across the vendors themselves.
- constraint Examiners have no written model-risk standard to hold banks to on generative or agentic tools, and cannot criticize non-compliance, until the agencies issue something new.
- decision Banks deploying these tools now must decide for themselves what to require from a vendor that will not disclose model details, the question the proposed letter would settle.
American Banker ran the essay under the headline "Bank examiners already have a good template for regulating AI" [18]. Its author, who writes of having spent a decade running the Federal Reserve Bank of Philadelphia [1], calls the 2011 model-risk letter "essentially the country's oldest working AI governance regime" [3]. The first proposal, though, is new guidance. It asks for a supervisory letter on foundation models within 12 months, covering what banks must know about the models they license and what examiners need to see [12]. The step the plan leaves out is legislation. "Here's what I would do, and none of it requires Congress to act," the former president wrote [16].
SR 11-7 ran to 21 pages without once using the words "artificial intelligence" [2]. It still governed the models behind credit scoring, fraud detection and stress testing for 15 years, and it held as those models grew more complex [3]. The replacement's carve-out falls on the tools banks are putting into fraud detection, customer service, underwriting support and document review now [9]. "Obviously, banks cannot wait for this guidance," the former president wrote [19]. The essay also concedes the agencies' difficulty: "I understand the reasons behind the strategy, since it's very difficult to write guidance around a target you can't clearly pin down" [8].
The stronger argument is about market structure. According to the essay, three companies supply most cloud computing and a few supply most frontier AI models [10]. If several banks license the same model and it fails on one type of transaction, the problem is correlated across all of them. Supervisors have a tool for that, horizontal review, and have never applied it to AI vendors [11]. For now, a risk held by a handful of suppliers is examined one bank at a time [11]. On publishing the proposed review without names, the former president wrote: "The names of banks and vendors are not important to disclose publicly; it's the understanding of where the risks are in this system, risks that are growing each day" [21].
The 1962 Bank Service Company Act lets agencies examine any company that performs services for a bank, core processors included [13]. It predates SR 11-7 by 49 years [1]. The essay's case for applying it is direct: a firm supplying the frontier model for bank fraud "is clearly providing a bank service and should fall under this act" [22]. The objection it anticipates is that the statute was written with check-processing companies in mind [17].
The agencies could turn their promised request for information [7] into a letter inside a year, as proposed [12]. They could also leave the request open while deployment continues [9]. Or an examiner could use the 1962 act on a model supplier before any letter exists. I think the third route has the most near-term force, because it needs no settled definition of generative AI, only a showing that the supplier provides a bank service [22]. The counter-thesis is the objection the essay itself names: a check-processing statute may not stretch to a frontier model company [17]. The view is also wrong if the concentration is overstated, with banks' deployments spread across enough models that one vendor's flaw stays inside one bank [10]. SR 11-7 went 180 months before it was revised; the proposal gives a foundation-model letter 12 [2].
What to watch
- Timing and content of the Fed, OCC and FDIC request for information on AI in banking, and whether it becomes a supervisory letter within the proposed 12 months.
- The first use of the Bank Service Company Act to examine a frontier AI model supplier, and whether that firm contests the statute's reach.
- Whether any agency runs and publishes a horizontal review of AI vendors across the largest banks.