Join a community of professionals and get:
on all CeFPro events.
unlock speaker decks and audience polls.
Full library access the moment you sign up.
Digital Content

- Unlimited access to peer-contribution articles and insights
- Global research and market intelligence reports
- Discover Connect Magazine, a monthly publication
- Panel discussion and presentation recordings
- U.S. banking
regulators are increasing scrutiny of AI deployment across the sector
- Supervisors are
examining governance, data access, cybersecurity, and vendor management
controls
- AI discussions are
now reportedly part of routine bank examinations
- Regulators are
focusing on high-risk activities including lending, KYC, and sanctions
screening
- Human oversight, kill
switches, and model guardrails are receiving particular attention
- Vendor and
subcontractor risks are emerging as major supervisory concerns
- Regulators currently
favor principles-based oversight rather than AI-specific rules
- Authorities are
assessing whether existing supervisory frameworks remain fit for purpose
As artificial intelligence becomes
increasingly embedded in banking operations, U.S. regulators are stepping up
oversight of how lenders deploy the technology, raising questions about
governance, cybersecurity, data privacy, and third-party risk management.
The heightened scrutiny comes as
banks accelerate the use of AI across a growing range of activities, from
customer-facing virtual assistants to more sophisticated applications such as
credit underwriting, sanctions screening, anti-money laundering monitoring, and
regulatory compliance.
The rapid expansion of these
capabilities has prompted supervisors to take a closer look at how financial
institutions are managing the risks that accompany them.
According to people familiar with
ongoing supervisory discussions, the Office of the Comptroller of the Currency
and the Federal Reserve have begun incorporating detailed questions about AI
into routine bank examinations.
Institutions are being asked to
explain how artificial intelligence is used in higher-risk activities,
including lending decisions, know-your-customer processes, and sanctions
compliance programs.
The inquiries extend well beyond
technical deployment. Regulators are reportedly seeking detailed information
about governance structures, human oversight mechanisms, data protection
controls, and contingency arrangements should AI systems malfunction.
Supervisors are also examining
whether banks have implemented safeguards such as "kill switches"
that would allow potentially problematic systems to be shut down quickly.
One source familiar with the
discussions said that conversations about artificial intelligence now form part
of virtually every bank examination. However, regulators are not currently
pursuing a prescriptive approach.
Instead, they are focused on
understanding how firms are using the technology and identifying emerging risks
before determining whether additional guidance or regulatory intervention may
be required.
The growing regulatory attention
reflects broader concerns about the risks associated with AI adoption
throughout the financial sector.
Cybersecurity experts have warned
that increasingly powerful AI models could be exploited to identify software
vulnerabilities, automate cyberattacks, or facilitate sophisticated fraud
schemes.
As a result, regulators and
policymakers are examining whether financial institutions are adequately
prepared to manage these evolving threats.
The issue gained additional
prominence following public statements from federal agencies earlier this year.
In April, the OCC announced plans
alongside the Federal Reserve and the Federal Deposit Insurance Corporation to
seek industry input on the use of artificial intelligence, including both
generative AI and emerging agentic systems.
While such requests do not create new
regulatory requirements, they often serve as a precursor to future policy
development.
For now, supervisors appear
determined to rely on existing regulatory frameworks rather than create
AI-specific rules.
Model risk management standards,
third-party risk management requirements, consumer protection obligations, and
operational resilience expectations are being used as the primary tools for
evaluating banks' AI programs.
A central concern is ensuring that AI
systems remain within clearly defined operational boundaries.
Supervisors are examining whether
models can access or infer information beyond authorized limits, creating
potential privacy, confidentiality, or compliance risks.
Banks are being asked to demonstrate
that they have implemented guardrails governing both data access and model
behavior.
Human oversight remains another major
focus. Regulators want clear evidence that employees maintain ultimate
authority over important decisions and that institutions can intervene when
automated systems produce unexpected outcomes.
Questions are also being raised about
who holds responsibility for monitoring and escalating potential issues.
Vendor risk has emerged as a
particularly important area of scrutiny. As banks increasingly depend on
external providers for AI capabilities, regulators are examining how firms
assess the governance, security, and resilience of those vendors.
Institutions are additionally being
asked whether they have viable exit strategies should a vendor experience
operational problems, security breaches, or other failures.
Regulators face challenges of their
own. The pace of AI development is significantly faster than traditional
regulatory and rulemaking cycles, creating concerns that formal guidance could
quickly become outdated.
As a result, authorities are expected
to continue favoring broad principles-based supervision rather than detailed
rulebooks in the near term.
That approach was echoed recently by
Federal Reserve Vice Chair for Supervision Michelle Bowman, who said banks are
currently relying on existing risk management frameworks to guide their use of
artificial intelligence.
However, she also acknowledged the
need to assess whether current supervisory tools remain suitable for a rapidly
evolving technological landscape.