SR-26-2 replaced SR-11-7 this year, the first update to US bank model risk guidance in fifteen years. The interesting part isn’t the new rule, it’s what forced it. A generative model producing inputs for a credit model can contaminate that model’s outputs while sitting entirely outside the credit model’s formal validation boundary. Old model risk frameworks assumed a model has an owner, a version, and a boundary you can draw a box around. Agentic and generative systems don’t respect that box. They sit upstream of everything, quietly, and nobody signed off on that.
What I keep telling people internally: governance has to track outputs across system boundaries, not just within them. If your AI inventory only lists things labeled ‘AI model,’ you have already missed the shadow dependency, the summarization step feeding the forecasting tool, the classifier deciding which documents a RAG pipeline even considers. Draw the box around the workflow, not the model.
Related in this Cluster
- NotesWhat Breaks When LLMs Enter Regulated Enterprise Workflows
Most enterprise AI initiatives do not fail on raw model intelligence. They break on the mundane, structural realities…
- NotesThe cost of abstractions
Just spent the afternoon untangling a "helpful" ORM layer that was executing N+1 queries under the hood. Sometimes…
- NotesShadow AI is just a feedback loop nobody built
Talked to a few people this week who admitted to pasting confidential docs into a public chat tool…
