Why the model-risk rulebook stops short of AI, and how supervisors, boards, and auditors are judging AI position anyway. Includes an eight-condition self-diagnostic you can run against your own institution.
An institution can be fully aligned with SR 11-7 and SR 26-2 model-risk practice, ECOA and Regulation B fair-lending requirements, and SR 23-4 third-party risk guidance, and still fail to demonstrate AI maturity in the way an examiner or a board experiences it.
Because maturity is not read off a compliance artifact. It is inferred from how the institution actually operates: how decisions get made, where authority sits, and whether the independent challenge function can halt a model when it behaves in a way no one predicted. That judgment is beginning to surface in examinations, model validation, board oversight, and audit.
This paper maps what supervisors now require, including the April 2026 SR 26-2 guidance and its deliberate AI carve-out, SR 23-4, the NAIC Model Bulletin, the Colorado AI Act, and the EU AI Act, and introduces the Octant AIR Index™ for assessing what is actually being judged.
For each condition, the paper shows what weak and strong look like to an examiner, director, or auditor, so you can read your own institution honestly.
Enter your details and we'll take you straight to the download. We'll only use your email to share related Octant research, never spam, never shared.