Invest1 distinct publisher3 min readPublished
The guidance that retired fifteen years of model-risk validation in April puts generative and agentic AI outside its scope, which leaves the accountability sitting with the bank and the design decisions sitting with a vendor it cannot audit.
The Investor · Invest desk
invest
Gartner's 40% abandonment rate forces an in-house AI build to undercut the vendor by 40%1 distinct publisher
invest
Agents that move money turn deposit stickiness into an assumption, not a fact1 distinct publisher
product
Rillet's $100M reads as proof mid-market ERP is rip-and-replace, mostly at the cheap end1 distinct publisher
leadership
Disney swaps raises for discounted stock and a full health-plan re-enrollment1 distinct publisher
Compiled by The InvestorSomething wrong?How this is made
The mismatch worth pricing sits in the calendar rather than the rulebook. A bank layering a client insights dashboard onto a third-party model spends months moving it through internal approvals, and inside that same window the model underneath gets replaced more than once, according to the American Banker column [7], which means the version validated on the way in is not the version rendering decisions on the way out [8]. Validation paperwork is a description of an object, and the object has already been swapped.
Stack that against the scope problem. SR 11-7 ran the model-risk franchise for fifteen years [2], call it 2011 by arithmetic against an April 2026 replacement [9], and the validation machinery built on top of it does not, in the regulators' own words, reach the class of technology vendors are shipping fastest [6]. The bank keeps the accountability [10] and loses the checklist [15]. Contracts do not fix that: banks are buying a decision architecture, not the answer they owe their supervisor and their customer [11].
The cost is attention, and attention is the scarce input here. A compliance function spending its quarters re-validating the wrapper is a compliance function not spending them negotiating model-logic disclosure into the vendor agreement, which is where the leverage sits while the supplier field is still a handful of large infrastructure providers underneath everyone's tooling [5]. Fintech partners will keep absorbing the speed risk, since they move faster and are more willing to hold it [16], and speed risk is the cheap half.
One path: the request for information regulators have promised becomes scoped guidance on a supervisory clock [4], and the gap closes with the industry's own submissions setting the terms. A second path: the FDIC's floated standard-setting body, still at a very early meeting stage [13], gets real traction, and vendor concentration is what makes that tractable, because certifying a few providers covers most deployments [5]; the columnist's objection is that no new body will command enough trust for banks to take a certificate at face value, and that every deployment differs enough to require in-house vetting anyway [14]. A third: nothing formal arrives in time and the standard gets written by the first case that looks like the column's fraud-detection example, where a legitimate small business is flagged on a spurious cash-flow pattern, denied credit, and the bank absorbs the fair-lending exposure for logic its own staff cannot reconcile [12].
The third path looks likeliest, though the more useful case is that the second and third happen together, with a certification scheme arriving just late enough to be used as a litigation defence rather than a design constraint. What would prove it wrong is a request for information that lands quickly and asks narrow, answerable questions about base-model substitution and disclosure [4], because that is the one intervention that would make a bank's approval cycle and its vendor's release cycle describe the same system.
Ranked by verification strength, evidence, and original report placement.
In April 2026, regulators introduced SR 26-2, which replaced SR 11-7 and SR 21-8.
For the last 15 years, SR 11-7 was the framework U.S. banks used to manage model risk, including risk from models they bought rather than built.
In a footnote, regulators said they purposefully carved generative and agentic AI out of SR 26-2 because these are "novel and rapidly evolving, and as a result are not within the scope of the guidance."
The 15 years of validation machinery banks built under SR 11-7 does not, by the regulators' own words, reach the one class of technology their vendors are shipping fastest.
Banks carry full accountability for advanced AI decisions, but most of the time it is a vendor setting the tone, and if a bank is not deliberate those providers' choices become the bank's AI strategy by default.
A good vendor can make risk legible but can never make it someone else's responsibility, and accountability to customers and regulators is the one thing no vendor can take off a bank's plate.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One column, one quoted footnote
The entire argument rests on a single American Banker opinion piece, and the most checkable item in it — the footnote wording placing generative and agentic AI outside SR 26-2's scope — is quoted without a link and confirmed by nobody else here. The regulatory spine is specific enough to verify and specific enough to be wrong; the surrounding assertions about how banks buy AI and how fast models turn over carry no data at all.
No deployments on the record
Not a single institution, vendor contract, or production system is named. The one deployment described — a bank layering a dashboard on a third-party model — is generic, and the fraud-detection case is introduced as a scenario to picture. There is no basis here to measure how widely vendor generative or agentic AI actually sits inside regulated banks.
Modest stretch on a real gap
The column is unusually restrained for the genre — it argues against its own preferred remedy and calls the FDIC effort early — so the overstatement is narrow rather than systemic. It sits in the two claims doing the heaviest lifting: that a model is replaced more than once inside a single approval cycle, and that a spurious fraud flag converts into fair-lending exposure and a discrimination complaint. The first is asserted, the second is imagined, and the headline verdict that banks are outsourcing their AI strategies leans on both.
Trade press writing to its own readership
The framing runs with the grain of the audience: banks as the party holding unfair liability, vendors as the party that won't open the model, caution as the recommended stance. That is a natural editorial posture for a banking trade publication and not evidence of bad faith, but it is a posture — no vendor is asked to respond, and the piece routes readers to more of its own coverage mid-argument. The score is capped rather than low because the text never discloses who the author is or whether they sell into either side of the bank-vendor relationship.
Confident on the carve-out, thin on everything else
We would stand behind the shape of this story — a supervisory framework was replaced and the newest AI was written out of it — because the claim is narrow, dated, and quoted. Beyond that, confidence drops fast: with one publisher, no corroborating document, no deployment evidence, and the most vivid harm openly hypothetical, there is little here to hold the wider argument steady if the footnote reads differently in the original.