SR 26-2 excluded agents. You still have to govern them.
The most mature model risk regime in the world just told banks the systems they are deploying sit outside the framework. 42 percent of financial firms are using or assessing agents. 21 percent have deployed. The deployment curve is ahead of the guidance curve. Guard ships the interim controls.
Aligned to SR 11-7 pillars while agent-specific guidance is pending.
The regulatory gap you are managing today.
SR 26-2 (April 2026)
The Federal Reserve, OCC, and FDIC replaced SR 11-7 with SR 26-2, the first major revision in 15 years. It explicitly scoped generative and agentic AI out as novel and rapidly evolving. Agent-specific guidance is signaled but not yet issued.
42 percent already using
NVIDIA 2026 State of AI in Financial Services survey. 42 percent of financial firms using or assessing agents. 21 percent have deployed. Banks are not waiting for the framework to catch up.
SR 11-7 principles still apply
The pillars have not changed: model inventory, independent validation, ongoing monitoring, governance. What changed is that the methods behind those pillars no longer fit systems that adapt their steps at runtime. The interim answer is control at the runtime layer, not new validation cadence.
How Guard maps to SR 11-7 pillars.
The pillars have not changed. The runtime layer that satisfies them for agents did not exist. Now it does.
Model inventory
agent_identity registry with owner, source, platform of origin, and risk tier. Observed inventory derived from behavior, not just what was declared.
Independent validation
Guard Verify adversarial battery plus hash-chained audit trail that a third-party auditor can verify without Conduct's cooperation.
Ongoing monitoring
Guard console tracks per-agent block count, warn count, monthly spend, and warns at 80 percent of the committee cap.
Governance
Tier-3 agents require recorded human oversight. Production promotion requires owner attestation. Credit and lending decisions require human-in-the-loop.
Change management
Model swaps warn without a change control event. Every rule change is a versioned, signed audit event.
conduct-financial-services v1.0.0
Eight rules ship in the pack today.
Every rule is tagged to SR 11-7, OCC 2021-19, FFIEC, NYDFS 500, GLBA, ECOA, or FCRA. Compliance evidence attaches to every decision.
Tier-3 agent action without a recorded human oversight event within 24 hours.
Agent promotion to production without documented owner attestation.
Agent write to core banking or ledger systems without segregation-of-duties evidence.
Credit, lending, or underwriting decisions without human-in-the-loop attestation.
Agent action on customer PII or account data without documented control mapping.
Cross-tenant or cross-portfolio customer data read without explicit permit.
Model swap mid-workflow without accompanying change control event.
Monthly agent spend reaching 80 percent of committee cap.
How it plugs in.
Guard sits between your agents and every downstream system. Existing SR 11-7 process wraps around it.
- 1. Install the pack. One click from the Registry. Rules load, framework mappings attach, audit chain begins recording immediately.
- 2. Tag your agents by risk tier. Tier 1 (internal, reversible), Tier 2 (consequential, recoverable), Tier 3 (consequential, irreversible, regulated). Tier drives the obligations.
- 3. Guard evaluates every proposed action. Allow, warn, or block based on tier, target system, and current governance state. Fail closed.
- 4. Every decision is a signed audit row. Model risk committee gets a queryable evidence table, not a screenshot deck. Auditors get proof, not assertions.
- 5. Your existing SR 11-7 process wraps around Guard. Independent validation, model inventory, ongoing monitoring all point at the same audit chain. Guard produces the artifacts your MRM function is already asking for.
Interim controls, credible with the model risk committee.
The pack ships today. Ready when the eventual guidance arrives.
