06/26/2026
You can't govern what you haven't named.
That's the starting point for AI governance at community banks and credit unions right now — not because formal guidance has arrived, but because it hasn't.
SR 26-2 omitted generative AI from scope. The AI RFI hasn't landed yet. But the obligation to identify and manage risk hasn't paused. It never does.
Before the guidance catches up, there are seven things every institution should be doing today:
→ Inventory the AI tools already in use (including ones embedded in third-party products you don't think of as "AI")
→ Document purpose, scope, and known limitations
→ Assign named accountability for every AI application
→ Require human review for any output that drives a material decision
→ Demand explainability from any AI your team relies on
→ Hold AI vendors to your existing third-party risk standards
→ Get ahead of shadow AI — your people are already using it
Our team broke this down in full. 🔗https://ow.ly/CqFS50ZflFx