Regulatory / Bank AI governance
Meridian and bank AI governance — the agent inventory SR 26-2 left to you
Banks must now construct agent governance without a prescribed rulebook — and the first artifact any such program needs is a current, evidence-backed inventory of the AI estate.
What it expects
As of August 2026
What changed
SR 26-2 (Fed/OCC/FDIC, April 17, 2026; OCC Bulletin 2026-13, FDIC FIL-15-2026) supersedes SR 11-7 and SR 21-8. It is principles-based and explicitly non-enforceable — and its Footnote 3 places generative and agentic AI outside its scope as “novel and rapidly evolving,” while stating that a bank's existing risk-management and governance practices should guide controls for tools not covered.
The implication
Agent governance at banks now has no prescribed rulebook — institutions construct it from existing risk principles (materiality, monitoring, effective challenge), and examiners still expect it. Every such program starts with the same artifact: a current, evidence-backed inventory of the AI and LLM estate — what's running, who owns it, what it costs, how it's changing.
How Meridian supports it
| Expectation | Meridian capability | Evidence artifact |
|---|---|---|
| Inventory of the AI/LLM estate | Ledger with owner, department, and workflow | Agent estate report |
| Ongoing monitoring | Metering, drift, and anomaly alerts | Risk & Anomaly report |
| Documentation and effective-challenge support | Attribution provenance and report history | Audit Evidence Export |
| Vendor-sourced AI oversight | Per-vendor spend and usage view | Vendor detail; QBR reports |
Why billing-derived records hold up
A billing-derived inventory is a high-confidence view of the AI services visible in your connected billing and usage sources. It surfaces attributable and unattributed spend with evidence — and helps teams identify what sits outside it: bundled SaaS features, free tools, centrally contracted services, or unmanaged use.
See it in your environment
Free two-week read-only assessment, or Zero-Access Assessment (file-based, no credentials).
FAQ
- Our MRM program covers statistical models — does AI count?
- It depends on the system's function, output, use case, and your institution's model definition. Some ML systems may fall within model governance; generative and agentic AI now sit outside SR 26-2's scope and may be governed through other risk, technology, vendor, privacy, or operational-risk processes. Meridian establishes the AI-system inventory and operational records those teams evaluate — it does not determine scope.
- Does this replace our MRM system?
- No — it feeds your governance processes the AI/LLM estate with evidence.