SR 26-02 Is Here. The Firms Already Using GenAI for EUC Governance Have a Head Start

The new interagency model risk management guidance, SR 26-02, changes the regulatory landscape in ways that are still being absorbed across the industry. The headline shift is a narrower, more risk-proportionate definition of what qualifies as a "model." That sounds like a simplification. In practice, it creates a significant governance gap.
When the formal model boundary narrows, a large category of risk-bearing tools falls outside it. Spreadsheets, end-user computing assets, rule-based automation, and increasingly the GenAI tools being embedded into workflows, none of these fit cleanly into traditional model risk management. They are consequential. They are often uncontrolled. And they are now less likely to be caught by the formal MRM process than they were before.
That gap is exactly where many firms are already losing ground, and where a growing number are finding substantial return by deploying GenAI intelligently.
What SR 26-02 Actually Changes
The new guidance moves away from the prescriptive checklists that characterized SR 11-7 in practice and toward a risk-based, proportional approach. Regulators are signaling that the field should exercise judgment rather than follow a formula.
That is a reasonable correction. SR 11-7 had, for many institutions, become a compliance theater exercise: inventories maintained for their own sake, validation cycles run on schedule regardless of whether a model had changed, documentation produced to satisfy a reviewer rather than to reflect genuine risk understanding.
But the proportionality shift has a consequence that deserves more attention. As the formal model boundary narrows, real-world risk does not shrink with it. Spreadsheets that drive capital calculations, Python scripts that aggregate regulatory data, Alteryx workflows that feed model inputs, these remain as consequential as they were before the guidance was updated. What changes is the likelihood that they are formally governed.
And AI sits in a particularly ambiguous position. SR 26-02 acknowledges that AI and GenAI present governance challenges, but stops short of providing a specific framework for them. Regulators are being deliberately cautious, unwilling to lock in standards for a technology that is evolving faster than any prior risk category. The result is that firms are making consequential governance decisions about AI without a consistent regulatory lens to calibrate against.
The firms navigating this well are not waiting for that lens to arrive. They are building governance frameworks that match control to actual risk, regardless of formal classification. For many of them, that means applying GenAI to EUC governance specifically, where the ROI is clear, the risk profile is manageable, and the use cases are well-defined enough to deploy with confidence.
Where GenAI Is Already Delivering Return in EUC Governance
The EUC governance use cases covered by CIMCON's AI Agent Suite are not speculative. They are in production at financial institutions that decided not to wait for perfect regulatory clarity before extracting value from the technology. The return is real, the risk is controlled, and the deployment model is straightforward.
Here is where the returns are showing up most clearly.
EUC candidate identification. The average large institution has tens of thousands of files that may or may not qualify as EUCs under its internal policy. Reviewing them manually is not a realistic program. AI agents trained on previously reviewed EUCs can scan network environments and score files for risk automatically, surfacing the population that actually warrants attention. Unsupervised anomaly detection can do the same without any training data, identifying statistical outliers in file complexity, formula structure, and data linkage. What once required a team of analysts working through a file share can now be completed in a fraction of the time, with a qualified risk professional reviewing the flagged output rather than the raw universe.
Risk and materiality assessment. Once candidates are identified, each one needs to be evaluated against internal policy and regulatory requirements. SR 11-7, SS1/23, and now SR 26-02 all carry specific expectations about what materiality means and what controls are appropriate. AI agents can read a spreadsheet or document, extract the relevant attributes, map them against a policy framework, and generate a scored assessment with a written rationale. A subject matter expert reviews and approves the output. The assessment is done in hours rather than days, and the documentation is audit-ready from the start.
Inventory form completion. Completing inventory forms across a large EUC estate is one of the most resource-intensive activities in any EUC program. Each form requires reading the file, understanding its purpose, assessing its risk attributes, and documenting findings against a defined schema. AI agents can populate the relevant fields automatically based on the file content and the firm's inventory criteria. The SME reviews, corrects where needed, and submits. The time reduction on a per-form basis is substantial, and the consistency of output across a large population improves significantly.
Spreadsheet summarization. Many EUC governance workflows require a plain-language summary of what a spreadsheet does before any further assessment can proceed. For complex workbooks with multiple sheets, linked files, and embedded logic, that summary used to take meaningful analyst time to produce. GenAI can generate it in seconds. The output is a structured description of the workbook's purpose, data sources, formula logic, and potential risk indicators, ready for SME review and attachment to the inventory record.
Audit trail review. This is where the return on AI investment in EUC governance is perhaps most immediately visible. A monitored EUC estate generates a continuous stream of change records: formula modifications, cell-level edits, permission changes, macro updates, data source shifts. Reviewing that volume manually to identify anomalies is not practical. AI agents can classify each change by type, apply risk logic to flag outliers, and generate a summary of anomalous activity for human review. GenAI can interpret the semantic content of formula changes, understanding that a scope reduction in a calculation is a different risk signal than an external dependency shift, rather than simply logging that a value changed.
Why This Works: The Role of the SME
None of these use cases remove the expert from the process. They are designed specifically to make the expert more effective.
The difference between a GenAI deployment that delivers return and one that creates new risk is almost always the same thing: whether a qualified subject matter expert is embedded in the workflow at the points where judgment is required.
This is the lesson that the broader AI adoption conversation keeps arriving at from different directions. General-purpose tools deployed without expert oversight produce outputs that look credible but may be wrong in ways that are hard to detect on casual review. In a GxP environment, that produces FDA warning letters. In a financial services environment, it produces findings in examinations and material weaknesses in internal audit reports.
The EUC governance use cases above work because the AI is doing a well-defined task on structured data, and the output goes to someone who knows what correct looks like. The SME is not rubber-stamping a black box. They are reviewing a structured, sourced first draft and applying regulatory judgment to it. That is a fundamentally different and more defensible workflow than either manual production from scratch or unreviewed AI output.
Firms that have deployed this model consistently report meaningful reduction in the time their risk teams spend on production work, and meaningful improvement in the consistency and completeness of their EUC documentation. The ROI case is not theoretical. It shows up in hours saved per assessment, headcount redeployment to higher-judgment work, and examination readiness that does not require a last-minute scramble.
Why General-Purpose AI Is Not the Answer at Scale
The firms that have seen the most durable return from GenAI in EUC governance are not the ones that gave their analysts access to Copilot and called it a program. That approach has a ceiling, and most institutions are finding it quickly.
General-purpose tools are productive for individual tasks in unstructured contexts. They are not designed for the governance requirements of a regulated compliance program. They do not maintain a controlled knowledge base of internal policies and regulatory frameworks. They do not provide source attribution for AI-generated assessments. They do not detect hallucinations before output reaches a reviewer. They do not produce an audit trail that satisfies SR 26-02 expectations.
The scale problem is more fundamental still. An analyst using Copilot to help draft a risk assessment is getting a productivity lift on one task. That is genuinely useful. But it does not create a program. It does not provide a consistent output across thousands of EUCs. It does not route findings to appropriate reviewers automatically. It does not track the assessment history of a file across review cycles.
A production-grade EUC governance program requires infrastructure, not just tools. That infrastructure is what separates the firms that are generating real return from the ones that are still in pilot mode.
The Right Starting Point Under SR 26-02
SR 26-02 does not prescribe how firms should govern EUCs or AI tools. It asks firms to exercise proportionate judgment and align controls with actual risk. For most institutions, that means finally building the governance infrastructure for EUCs that has been deferred because the manual effort was prohibitive.
AI makes that infrastructure buildable at scale for the first time. The use cases are low-risk enough to deploy with confidence. The ROI is measurable. The compliance posture improves immediately. And the SME-led human-in-the-loop model means the outputs are defensible in exactly the way regulators under SR 26-02 are asking for: documented, risk-proportionate, and grounded in genuine expert judgment.
CIMCON's EUC Insight platform and AI Agent Suite are built specifically for this. The platform is in production at 8 of the top 10 global banks. The use cases described above are not demos. They are deployed workflows generating return for compliance and risk teams that decided not to wait for perfect regulatory clarity to start building.
SR 26-02 is here. The gap it creates in EUC and AI governance is real. The firms that move now are building on infrastructure that will only become more valuable as the regulatory framework continues to evolve.
CIMCON Software provides AI-enabled EUC risk management, model validation, and compliance platforms for financial services organizations. Contact us at info@cimcon.com or visit cimcon.com.

Comments