AI Governance

Recalibrating model risk guidance for generative AI: reading the Bowman speech

The Federal Reserve's Vice Chair for Supervision on AI as a force multiplier, and the deliberate decision to exclude generative and agentic systems from legacy model risk guidance.

By Jonas Osman AbdelghafourPublished April 27, 2026

Summary Speaking at the Financial Stability Oversight Council's roundtable on artificial intelligence, cybersecurity and risk management, the Federal Reserve's Vice Chair for Supervision described AI as a force multiplier for the financial system and set out how oversight is being recalibrated.

Source: Federal Reserve Board · 27 April 2026 · read the original article

The deliberate carve-out The central supervisory move is the amendment of model risk management guidance to exclude generative and agentic artificial intelligence, on the view that rapidly evolving technologies may require a technology-specific approach rather than an extension of existing text.

This is a fork in the road rather than a gap. It signals that new frameworks are being drafted instead of old ones stretched, and it puts a temporary obligation on institutions: for the period before new guidance exists, the firm's own framework is the standard against which it will be examined.

What a technology-specific framework has to solve Legacy guidance assumes a model can be documented as a specification, validated against that specification, and monitored for divergence. Generative systems break each assumption. Their behaviour is defined partly by prompts, retrieval context and tool access; their outputs are open-ended; and their vendors change them without notice.

A credible interim framework therefore controls the envelope rather than the function: constrained inputs and tools, defined prohibited uses, output sampling against named failure modes, logged human review, and contractual change notification from providers.

International alignment The speech pointed to Financial Stability Board work on sound practices for AI adoption, with a consultation draft expected in the third quarter of 2026. For internationally active groups this matters more than any single national text, because it determines whether the group can run one framework or must reconcile several. Firms should track the FSB draft alongside the EU AI Act timetable and the US interagency work.

Methodology and limitations This summarises a public speech as at the date shown and links to the original. Speeches reflect the views of the speaker rather than formal agency policy, and the consultation referenced was pending at the time of writing.

Related reading See [Model Risk](/expertise/model-risk), [Banking Risk](/expertise/banking-risk), [Board risk governance](/governance) and the overview in [AI governance in insurance and banking](/insights/ai-governance-insurance-banking-2026).

Frequently asked questions

What should risk leaders know about the deliberate carve-out?

The central supervisory move is the amendment of model risk management guidance to exclude generative and agentic artificial intelligence, on the view that rapidly evolving technologies may require a technology-specific approach rather than an extension of existing text.

What a technology-specific framework has to solve?

Legacy guidance assumes a model can be documented as a specification, validated against that specification, and monitored for divergence. Generative systems break each assumption. Their behaviour is defined partly by prompts, retrieval context and tool access; their outputs are open-ended; and their vendors change them without notice.

What should risk leaders know about international alignment?

The speech pointed to Financial Stability Board work on sound practices for AI adoption, with a consultation draft expected in the third quarter of 2026. For internationally active groups this matters more than any single national text, because it determines whether the group can run one framework or must reconcile several. Firms should track the FSB draft alongside the EU AI Act timetable and the US interagency work.

What should risk leaders know about methodology and limitations?

This summarises a public speech as at the date shown and links to the original. Speeches reflect the views of the speaker rather than formal agency policy, and the consultation referenced was pending at the time of writing.

What should risk leaders know about related reading?

See [Model Risk](/expertise/model-risk), [Banking Risk](/expertise/banking-risk), [Board risk governance](/governance) and the overview in [AI governance in insurance and banking](/insights/ai-governance-insurance-banking-2026).