Regulatory / Bank AI governance

Meridian and bank AI governance — the agent inventory SR 26-2 left to you

Banks must now construct agent governance without a prescribed rulebook — and the first artifact any such program needs is a current, evidence-backed inventory of the AI estate.

What it expects

As of August 2026

What changed

SR 26-2 (Fed/OCC/FDIC, April 17, 2026; OCC Bulletin 2026-13, FDIC FIL-15-2026) supersedes SR 11-7 and SR 21-8. It is principles-based and explicitly non-enforceable — and its Footnote 3 places generative and agentic AI outside its scope as “novel and rapidly evolving,” while stating that a bank's existing risk-management and governance practices should guide controls for tools not covered.

The implication

Agent governance at banks now has no prescribed rulebook — institutions construct it from existing risk principles (materiality, monitoring, effective challenge), and examiners still expect it. Every such program starts with the same artifact: a current, evidence-backed inventory of the AI and LLM estate — what's running, who owns it, what it costs, how it's changing.

How Meridian supports it

ExpectationMeridian capabilityEvidence artifact
Inventory of the AI/LLM estateLedger with owner, department, and workflowAgent estate report
Ongoing monitoringMetering, drift, and anomaly alertsRisk & Anomaly report
Documentation and effective-challenge supportAttribution provenance and report historyAudit Evidence Export
Vendor-sourced AI oversightPer-vendor spend and usage viewVendor detail; QBR reports

Why billing-derived records hold up

A billing-derived inventory is a high-confidence view of the AI services visible in your connected billing and usage sources. It surfaces attributable and unattributed spend with evidence — and helps teams identify what sits outside it: bundled SaaS features, free tools, centrally contracted services, or unmanaged use.

See it in your environment

Free two-week read-only assessment, or Zero-Access Assessment (file-based, no credentials).

FAQ

Our MRM program covers statistical models — does AI count?
It depends on the system's function, output, use case, and your institution's model definition. Some ML systems may fall within model governance; generative and agentic AI now sit outside SR 26-2's scope and may be governed through other risk, technology, vendor, privacy, or operational-risk processes. Meridian establishes the AI-system inventory and operational records those teams evaluate — it does not determine scope.
Does this replace our MRM system?
No — it feeds your governance processes the AI/LLM estate with evidence.