One Big Idea
Generative AI has moved out of model-risk scope — not out of governance. You cannot validate math you are not allowed to see, so the control has to move outward: assure the system, not the weights.
Last week's issue mapped the operating model and the pillar that binds it. This week goes inside one of those pillars — trust and governance — and finds a hole. Take the risk-committee slide that has not changed in a decade — validate, backtest, monitor, repeat — and ask whether it covers the generative model your bank deployed last quarter. It does not.
Generative and agentic AI break the four assumptions classical model risk was built on: that a model is stable, inspectable, backtestable, and owned by the bank. A third-party foundation model is none of those — it is non-deterministic, closed, drifting on silent vendor updates, and, once it is an agent, no longer passive. Supervisors have now said so. SR 26-2, issued 17 April 2026 by the Federal Reserve, the OCC and the FDIC, supersedes SR 11-7 (4 April 2011) and SR 21-8 (9 April 2021), and its footnote 3 places generative and agentic AI expressly outside that guidance's scope — while stating the firm's own risk-management practices must still govern them. Out of scope is not out of governance.
Two pieces of precision before anyone reads that as relief: applicability is most direct for banks above roughly thirty billion dollars in assets, and the guidance itself says non-compliance "will not result in supervisory criticism". It is guidance, not an enforceable standard. Neither fact hands the problem back to the supervisor; both hand it to you.
The Insight · Two failures, one wrong tool
Most banks fail here in one of two directions. The first camp deploys generative AI faster than it can assure it, then reaches for the model-risk playbook it already owns — the wrong tool for a model that is closed, drifting, and not theirs. The second failure sits earlier and quieter: much of this AI never reaches the risk team at all, because it arrives embedded inside vendor software as a helpful feature and bypasses model-risk intake entirely. The gap is not validation depth. It is visibility.
Then the honest concession, because it locates the fix. A generative model reached through an interface behaves like non-deterministic software, so much of the real work sits in technology risk, cybersecurity and third-party risk rather than the model-risk lineage you already run. SR 26-2 effectively agrees — that is why it carved these systems out. It is not a demotion of the discipline but a relocation of where the discipline lives. Sharper still: a risk tier gives false comfort the moment autonomy changes, so when an agent can move money, tier it on its entitlements — the tools and limits actually granted — not the polite task it was built to do.
The proof that the hole is in the system and not the math: the Apple Card, underwritten by Goldman Sachs, was cleared of intentional bias by New York regulators — yet a dispute-handling workflow that could not route and investigate tens of thousands of customer complaints drew a CFPB order of more than eighty-nine million dollars. A sound model. A failed system around it.
Out of scope is not out of governance. You cannot validate a core you are not allowed to open — so wrap it: five control rings, read as a build order with a return arc, not a checklist.
Framework of the Week · The GenAI Assurance Grid
The framework is The GenAI Assurance Grid — five control rings around a model you cannot open, read as a build order of 5 steps with a return arc, not a checklist ticked left to right:
- Inventory — one AI System Registry for every generative and agentic system, built, bought, or embedded in a vendor feature you already pay for. What is not inventoried cannot be governed.
- Tier — by materiality, autonomy and entitlements together, re-tiered the moment permissions change. Tier on entitlements, not on intention.
- Orchestrate — the load-bearing ring, where the signature mechanic lives: a control plane between the model and the systems of record, carrying guardrails, tool permissions, transaction limits, human-in-the-loop for material actions, a kill-switch and an immutable audit trail of every call. AI proposes. The orchestration layer disposes.
- Evaluate — continuous, system-level evaluation in production instead of an annual report, because the pipeline of retrieval, prompts and guardrails is the unit under test, not the bare model.
- Challenge vendors — accountability without access: test your own boundary, secure audit rights and change-notice clauses, keep a concentration register on your frontier providers.
The return arc is what a checklist loses: what Evaluate learns in production changes the tier, the tier changes the entitlements the orchestration layer enforces, and vendor challenge changes what you are willing to register at all.
The full grid, with all five rings and the Assurance-Gap Read drawn out, lives in the Frameworks library.
Use Case · One quarter, two moves
One or two rings bind per system. When it can move money, the binding rings are usually Tier and Orchestrate; when it is customer-facing, Orchestrate and Challenge; when it is an internal copilot, Inventory and Evaluate.
Picture a second line spending a quarter not on a new model but on the two moves that make the rest possible. First, an AI System Registry fed by network and data-loss-prevention monitoring, surfacing every generative feature already live inside procured software — the shadow AI nobody had counted. Second, a thin orchestration layer in front of one customer-facing copilot: entitlement checks, a hard transaction limit, and a kill-switch wired to the incident desk before it ever touches a live account. Neither move required opening a foundation model's weights, and both gave the second line something concrete to show a supervisor applying materiality-based oversight.
Risk Note
The risk this week is the calendar, not the model. The EU AI Act's Article 50 transparency duties begin to apply 2 August 2026, scoped by use case rather than a blanket watermark. In Vietnam, the PDPL (91/2025) has been in force since 1 January 2026, and the AI Law 134/2025 followed on 1 March 2026, with a grace window for financial services to roughly 1 September 2027. The State Bank of Vietnam has a draft circular on AI in banking out for consultation — a draft, not yet a rule. A bank that waits for every clause to settle before starting the registry will still face a live examination under a regime that has already moved to materiality-based oversight. Build the registry and the orchestration layer against the current guidance; refine the detail as the texts settle.
Assure the system, not the weights.
Latest Video
This week's briefing — Stop Validating the Model. Assure the System. — walks the five rings in build order and the Assurance-Gap Read you can run on Monday: name one generative or agentic system already live in the bank, find the ring that is weakest for it, and fix that ring instead of commissioning a longer validation report. Then re-tier it on what it is actually permitted to call, not on the task it was built to do.
Watch: youtu.be/yQ5_Du1-QVA
The full deep-dive — the four broken assumptions, all five rings in build order, the tiering matrix and the Assurance-Gap Read — is in The GenAI Assurance Grid: How to Govern AI You Cannot Open.
The free five-page playbook in the Frameworks library turns it into an Assurance-Gap Read for your own portfolio.
Reply and tell me which ring is weakest for the generative system you have already deployed — most teams name Evaluate by reflex, then find it was Inventory all along, because nobody had counted the AI inside the software they already bought. I read every response. Forward this to a banking executive about to validate a model they are not allowed to open.
Was this forwarded to you? Subscribe to The AI Architect Letter — free, every Saturday.
Minh Tran · AI Business Architect · LinkedIn · Workshops & advisory: aibusinessarchitect.ai