AI governance in a bank is not one rule but six obligations assembled from different places: the board owns an inventory of what is running; predictive models are validated under model-risk guidance while generative and agentic AI are governed through broader enterprise risk; the data behind every model is owned, traceable and complete; bought models and cloud providers sit under third-party risk management; a person can explain and override any decision that touches a customer's credit; and voluntary frameworks from NIST and Treasury fill the gaps the rules leave. Each pillar below states the expectation in a few sentences and maps it to the documents that ask for it, across the 19 authorities this tracker follows.
Two of the pillars have their own pages: model risk management (the framework, model inventory, validation and the three lines of defense) and, for the customer-facing side of human oversight, AI chatbots in banking.
Who has to own AI in a bank?
Every supervisor that has spoken puts AI under the board and senior management, through the same governance architecture that already covers models and technology: named accountability, an inventory of what is running, policies for how it is approved, and effective challenge from risk, compliance and internal audit. US model-risk guidance revised in April 2026 keeps that structure for predictive models and leaves generative and agentic AI to broader enterprise governance; the UK's SS1/23 names a senior manager; the ECB's supervisors have said accountability for AI decisions must be clear and oversight must match AI's strategic weight.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| SR 26-2 / OCC Bulletin 2026-13 / FDIC FIL-15-2026 | Federal Reserve | Board and senior-management governance, a model inventory and independent validation for models in scope; generative and agentic AI are outside scope and left to broader risk-management and governance practices. | In force from Apr 17, 2026 |
| PRA SS1/23 | UK (BoE / PRA / FCA) | Five model-risk principles for all models informing business decisions, a sub-principle on AI and machine learning, and a named Senior Management Function holder accountable for the framework. | In force from May 17, 2024 |
| ECB: 'Technology is neutral, governance is not' | ECB | Clear accountability for AI decisions, senior-management oversight matching AI's strategic importance, and effective challenge from risk, compliance and internal audit. | Stated Feb 24, 2026 |
| FSB sound practices 1–4 (consultation) | FSB | Strategic direction and oversight, governance and accountability, AI inside the risk-management framework, organisational adaptability. | Final report expected Oct 2026 |
| NCUA Letter 26-CU-01 | NCUA | Credit-union supervisory expectations for AI governance, risk assessment and vendor oversight. | In force |
Which AI systems count as models, and what validation do they need?
In the US, a machine-learning system that processes input data into quantitative estimates is a model and needs documented development, independent validation, ongoing monitoring and outcomes analysis scaled to its materiality. The 2026 revision narrowed the definition so that simple arithmetic and deterministic rules fall out, and it explicitly excludes generative and agentic AI from model risk management while promising an interagency request for information. Outside the US the perimeter is wider: the PRA keeps AI and machine learning inside model risk management, and the ECB's internal-models guide tests machine-learning capital models for explainability and justified complexity.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| SR 26-2 (Fed) | Federal Reserve | Risk-based, materiality-driven validation and monitoring; 'complex quantitative method' definition; generative and agentic AI out of scope. | In force from Apr 17, 2026 |
| SR 11-7 (the 2011 framework) | Federal Reserve | The validation disciplines that carry over: conceptual soundness, ongoing monitoring, outcomes analysis, effective challenge. | Superseded Apr 17, 2026 |
| ECB Guide to internal models, ML section | ECB | Machine-learning capital models must be adequately explainable and their complexity justified by performance. | In force from Jul 28, 2025 |
| EBA follow-up report on ML for IRB models | EBA | Principle-based recommendations on understanding, documentation, validation and stability of machine-learning capital models. | Published Aug 4, 2023 |
| OCC Bulletin 2023-17 / SR 23-4 (third-party models) | Federal Reserve | Vendor models are the bank's to understand and validate, with due diligence and monitoring through the relationship's life. | In force |
What do regulators expect of the data behind AI models?
Owned, traceable, complete and current: the BCBS 239 vocabulary that examiners use for risk data applies to training sets, feature stores and retrieval corpora, and the Basel Committee's January 2026 newsletter said AI makes robust data management more important, not less. The EU AI Act turns data governance into a legal duty for high-risk systems such as consumer credit scoring, with provenance, preparation, bias examination and gap analysis to be documented, from December 2, 2027 after the Digital Omnibus deferral.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| BCBS 239 | Basel Committee | Fourteen principles for risk-data governance, aggregation and reporting: ownership, architecture, accuracy and lineage, completeness, timeliness, adaptability. | G-SIBs from 2016 |
| BCBS 239 implementation newsletter | Basel Committee | AI and advanced automation depend on high-quality data; lineage and ad hoc reporting still 'a work in progress'. | Published Jan 6, 2026 |
| EU AI Act, Article 10 | EU AI Act | Documented data governance for training, validation and testing data of high-risk systems, including credit scoring of natural persons. | Stand-alone Annex III systems from Dec 2, 2027 |
| Treasury AI cybersecurity report | U.S. Treasury | Identified a 'fraud data divide' and proposed data 'nutrition labels' for vendor AI; became the AIEOG workplan. | Published Mar 27, 2024 |
How is a bank's reliance on external AI models and cloud providers supervised?
Through third-party risk management rather than a separate AI rule. The 2023 US interagency guidance covers the full lifecycle from due diligence to termination and expects validation of purchased models; the Basel Committee's December 2025 principles reach nth-party supply chains and concentration; and the FSB has singled out generative AI's dependence on a small number of hardware, cloud and model suppliers as a financial-stability vulnerability to monitor.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| SR 23-4 / OCC 2023-17 / FDIC FIL-29-2023 | Federal Reserve | Planning, due diligence, contracting, ongoing monitoring and termination for every third-party relationship, including AI tools and foundation-model access. | In force from Jun 7, 2023 |
| BCBS Third-Party Risk Principles | Basel Committee | Twelve principles covering board accountability, due diligence, contracts, monitoring, continuity and exit, including nth-party chains and concentration. | Published Dec 10, 2025 |
| FSB AI monitoring report | FSB | Third-party dependencies and provider concentration named as vulnerabilities for authorities to track. | Published Oct 10, 2025 |
| FSB third-party risk toolkit | FSB | Toolkit for managing third-party and outsourcing risk, including critical service providers. | Published Dec 4, 2023 |
When must a person be able to explain or override an AI decision?
Whenever the decision touches a consumer's credit: US adverse-action law requires the specific principal reasons for a denial regardless of how complex the model is, the EU AI Act requires human oversight and a fundamental-rights impact assessment for high-risk credit scoring, and Colorado's Automated Decision-Making Technology Act adds notice, a plain-language explanation after an adverse outcome and human review from January 1, 2027, with a lender's ECOA notice satisfying the disclosure duty for the same decision.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| ECOA / Regulation B adverse action | CFPB | Specific principal reasons for adverse credit action; model opacity is not a defence. | In force |
| FCRA adverse action and key factors | CFPB | Key factors that adversely affected a credit score must be disclosed. | In force |
| EU AI Act, Articles 14 and 26–27 | EU AI Act | Human oversight, deployer duties and a fundamental-rights impact assessment for high-risk credit scoring. | Stand-alone Annex III systems from Dec 2, 2027 |
| Colorado SB 26-189 (ADMT Act) | Colorado AI Act | Consumer notice, a plain-language explanation within 30 days of an adverse outcome, data access and correction, human review. | Effective Jan 1, 2027 |
| CPPA ADMT regulations (California) | California CPPA | Notice, opt-out and access rights for automated decision-making technology in significant decisions, plus risk assessments. | In force |
What do banks use to govern generative and agentic AI where the rules stop?
The NIST AI Risk Management Framework and its generative-AI profile, Treasury's financial-services adaptation of it, and, for cyber, the New York and ECB letters on AI-enabled threats. None is binding on banks, but together they are what most US institutions cite for the systems that model-risk guidance now leaves out, and what examiners ask about when a bank's AI policy is on the table.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| NIST AI RMF 1.0 | NIST | Govern, Map, Measure, Manage and seven trustworthiness characteristics. | Voluntary |
| NIST AI 600-1 (Generative AI Profile) | NIST | Twelve generative-AI risks and more than 200 suggested actions mapped to the framework. | Voluntary |
| Treasury FS AI RMF and AI Lexicon | U.S. Treasury | The NIST framework adapted to financial services' operational, regulatory and consumer-protection specifics, with a shared vocabulary. | Published Feb 19, 2026, non-binding |
| DFS AI cybersecurity letter | NY DFS | AI-enabled social engineering, AI-enhanced attacks, data exposure and vendor dependency mapped to 23 NYCRR Part 500 obligations. | In force |
| ECB 'Dear CEO' letter SSM-2026-0301 | ECB | Every significant institution to assess AI-enabled cyber threats and submit an action plan to its supervisory team. | Plans due Oct 31, 2026 |
Which governance documents has each authority published?
| Date | Event | Document |
|---|---|---|
| Jul 24, 2026 | Digital Omnibus defers EU high-risk duties to Dec 2027 | Regulation (EU) 2026/1744 (Digital Omnibus on AI) |
| Jun 10, 2026 | FSB consults on twelve sound practices | FSB AI sound practices consultation (June 2026) |
| May 14, 2026 | Colorado re-enacts its AI law as the ADMT Act | SB 26-189 |
| Apr 17, 2026 | SR 26-2 replaces SR 11-7; generative and agentic AI carved out | SR 26-2 |
| Feb 19, 2026 | Treasury FS AI RMF and lexicon | Treasury FS AI RMF and AI Lexicon (Feb 2026) |
| Dec 10, 2025 | Basel third-party risk principles reach AI supply chains | BCBS Third-Party Risk Principles (Dec 2025) |
| Jul 26, 2024 | NIST generative-AI profile | NIST AI 600-1 (Generative AI Profile) |
| Jul 12, 2024 | EU AI Act published; credit scoring is high-risk | Regulation (EU) 2024/1689 |
| Jun 7, 2023 | SR 23-4 third-party guidance covers vendor AI | SR 23-4 |
| May 17, 2023 | PRA SS1/23 keeps AI inside model risk management | PRA SS1/23 |
| Jan 26, 2023 | NIST AI RMF 1.0 published | NIST AI RMF 1.0 |
| Jan 9, 2013 | BCBS 239 sets the data-governance standard | BCBS 239 |
| Apr 4, 2011 | SR 11-7 makes model governance an examinable discipline | SR 11-7 |
Which of the 100 largest US banks have disclosed AI governance arrangements?
66 of the 100 bank pages on this site record a governance-related AI activity, from AI committees and chief AI officers to training programmes and model-data controls. Each links to the bank's page, where the claim is sourced.
| Bank | What the record shows | Status |
|---|---|---|
| BofA | The Academy simulators: AI conversation simulators for employee coaching. | In production |
| Goldman | Trade and transaction accounting agents: Automating accounting for trades and transactions. | Pilot |
| Morgan Stanley | Compliance task automation: Bots handling routine non-financial-risk work. | In production |
| PNC | Model-data nutrition labels: Adopting the FSSCC concept for documenting training and input data. | Rolling out |
| Truist | Client Pulse: Patent-pending AI aggregating client feedback across millions of conversations. | Pilot |
| Schwab | Schwab Advisor AI in Action: Education, peer networking and resources for RIAs adopting AI. | In production |
| BNY | Anomaly detection in daily calculations: Flags areas for review in minutes instead of hours. Community-bank AI training: Free AI and cyber training for 1,000 community-bank executives, led by senior BNY leaders. | In production |
| State Street | ML data-quality for investment data: Production RAG, multi-agent and document-intelligence systems for financial-services workflows. | In production |
| Fifth Third | Merger-conversion monitoring: AI tools tracking the Comerica integration. | In production |
| BMO | Responsible AI framework: Accountability, reliability, security, explainability, transparency, fairness, privacy, sustainability. | In production |
| First Citizens | Responsible-AI function: Responsible AI and governance among the functions being stood up under the head of AI. | Rolling out |
| M&T | Data lineage, Edison and the Data Academy: The data foundation under the AI program; ~2,000 employees trained. | In production |
| Ally | Four-layer AI governance: Working group, steering council, enterprise committee and board; mandatory training; Responsible AI Institute membership. | In production |
| Northern Trust | Shared semantic data layer for AI agents (OSI): Open-source data definitions so agents across firms ground on the same meanings. | Announced |
| Pinnacle | Firm AI policy: An ethics-and-effectiveness policy for AI deployment across the business. | In production |
| UBS | UBS Claves platform and AI risk committee: One platform with model routing and evaluation; AI Operating & Risk Committee under a group AI policy. | Rolling out |
| City National | Post-remediation risk management: Controls rebuilt after the 2024 OCC order; the frame for any AI deployment at the bank. | In production |
| Flagstar | Integrated AI governance workflow: Business case, compliance review and multi-level approvals in one auditable system. | In production |
| Webster | Category IV data and risk infrastructure: Data collection, storage and governance roles; regulatory-reporting capability. | In production |
| First Horizon | Enterprise Data Hub and data marketplace: Unified data with permission-based discovery of approved data products. | Pilot |
| UMB | Post-acquisition systems conversion: Product mapping, customer migration and platform consolidation after Heartland. | In production |
| SouthState | AI enablement programme: Office hours, AI Central hub, crowdsourced prompt library; adoption run as change management. | In production |
| Columbia | Post-merger systems conversion: Pacific Premier converted in Q1 2026 after the Umpqua integration. | In production |
| CIBC | 'Agentic AI with humans in control': Human judgment, governance and culture at the centre of agent design. | In production |
| Valley | Five-tier AI access and monthly spend tracking: Specialised tiers for engineering, QA and model risk; ~80 open-access power users. Valley Foundry: A dedicated capability to identify, test and advance emerging technologies — initially AI, cybersecurity, and data and analytics — through startup, fintech and vendor partnerships. | In production, Announced |
| BOK Financial | Data-first model for responsible AI scaling: Enterprise data treated as a shared asset under the chief data and analytics officer. | Rolling out |
| FNB | Ethical and compliant AI strategy: Explicit remit of the director of AI and innovation. | Rolling out |
| EverBank | Omnichannel and customer-platform transformation: Digital, voice, contact-centre and branch context sharing under the head of digital and customer platforms. | Rolling out |
| Raymond James | Chief AI officer and AI strategy office: Cross-business identification of analytics, ML and gen-AI opportunities. | In production |
| Associated | Line-of-business AI accountability and board oversight: Senior director of AI stewards risk and data; board technology committee. | In production |
| Prosperity | Real-time core platform: New processing system as the stated base for future innovation; no AI use disclosed. | In production |
| Bank OZK | No disclosed internal AI use: Transcripts and releases contain no operational AI, automation or model references. | Announced |
| Atlantic Union | Exploratory AI programme: 'Exploring exciting opportunities with Artificial Intelligence'; agentic and third-party model risks flagged. | Pilot |
| Commerce | AI pillar in the enterprise data strategy: AI roadmap plus data-platform modernisation for speed to insight. | Rolling out |
| BankUnited | No disclosed internal AI deployment: No AI programme, vendor or leader named in filings or releases. | Announced |
| United Bank | No disclosed AI deployment: No AI programme, vendor or leader named in releases or investor materials. | Announced |
| Texas Capital | AI enablement under the CDIO: Data platforms, AI enablement and security in one technology organisation. | Rolling out |
| Fulton | Customer education on AI tools: AI in investing (private bank) and AI budgeting apps (education centre). | In production |
| Glacier | No disclosed AI deployment: Annual report and earnings materials silent on AI. | Announced |
| Eastern Bank | Innovation-through-experimentation culture: CDO-led programme; AI framed as a workplace efficiency tool. | In production |
| Axos Bank | AI Center of Excellence and Automation CoE governance framework: Enterprise AI assistant for all staff; platform standards, RBAC, audit and exam support; Cloud and AI security reviews of LLM integrations. | In production |
| City National Florida | Chief AI officer search: Role to define and execute AI strategy across efficiency and client experience. | Announced |
| United Community | Capacity-building through AI productivity: Clearing postponed product and process improvement projects. | Announced |
| Arvest | Innovation culture programme: Product and innovation office under Amy Morbeck; Fortune recognition. | In production |
| WaFd Bank | Build 2030 digital focus: Data used to anticipate client needs; NPS tracked as the outcome metric. | In production |
| First Interstate | 'One clean data source' consolidation: Data foundation for AI and other technology initiatives. | Rolling out |
| Customers Bank | Standardised AI risk framework and AI Innovation Lab: Enterprise governance for scaled deployment. | In production |
| Rockland Trust | AI steering committee and governance framework: Clearinghouse for use cases within a moderate risk appetite. | In production |
| Simmons Bank | Enterprise Data Office: Data governance, data literacy and data-driven decision-making established under the first CDO. | In production |
| First Hawaiian | AI programme strategy and governance: Owned by the Digital Banking and Services Division under Jason Dang. | In production |
| Cathay Bank | No disclosed AI deployment: Annual and responsibility reports silent on AI. | Announced |
| Bank of Hawaii | AI listed as an enterprise risk: Technology, AI and cybersecurity risk factors in the 10-K. | In production |
| Centennial Bank | No disclosed AI deployment: Earnings materials silent on AI. | Announced |
| First Financial Bank | No disclosed AI deployment: No AI reference in investor materials. | Announced |
| Mechanics Bank | No disclosed AI deployment: Earnings materials silent on AI. | Announced |
| First Merchants | No disclosed AI deployment: Investor materials silent on AI. | Announced |
| Optum Bank | Agentic-AI lending perspective from the chief credit officer: Public commentary on AI in lending and cross-unit data sharing. | Announced |
| Merchants Bank of Indiana | No disclosed AI deployment: Earnings materials silent on AI. | Announced |
| Stifel Bank | AI thought leadership for clients: Research outlook on AI's economic effects. | In production |
| Trustmark | Post-conversion efficiency programme: Management attention shifting to efficiency gains and possible M&A. | Announced |
| Bank of Hope | Acquisition integration (Territorial, SMBC MANUBANK): Hawaii and Japanese-corporate banking added to the Korean-American core. | Rolling out |
| Busey Bank | Enterprise AI and data-science function: Strategy, communication and execution of responsible AI/ML models across business units. | Rolling out |
| Community Bank N.A. | Dedicated AI team: More than a dozen staff, a handful fully dedicated; efficiency focus. | In production |
| Enterprise Bank & Trust | Client AI education (Enterprise University): AI strategy and Copilot courses for business owners. | In production |
| FirstBank | No disclosed AI deployment: Investor materials silent on AI. | Announced |
| First United Bank | Technology as enterprise capability: Strategy, operating model, data, risk and digital experience connected under one programme. | In production |
Is there a single AI governance rule for banks?
No. In the US, AI governance is assembled from model-risk guidance (SR 26-2 and its OCC and FDIC twins), third-party guidance (SR 23-4), consumer law on automated decisions (ECOA, FCRA), state laws (Colorado, California, New York) and voluntary frameworks (NIST, Treasury). The EU AI Act is the closest thing to a single rule, and it applies to banks mainly through high-risk credit scoring from December 2, 2027.
Does model risk management cover generative AI?
Not in the US since April 17, 2026. SR 26-2 states that generative and agentic AI models are outside its scope and directs banks to broader risk-management and governance practices; the agencies have promised a request for information. In the UK the PRA's SS1/23 keeps AI and machine learning inside model risk management.
What does an examiner ask to see?
An inventory of AI systems with owners and risk tiers, the approval and validation record for each material one, the data lineage behind it, the vendor due diligence where it is bought, the monitoring and the route to a human, and evidence that the board has been told what is running and why. The pillars above map each of those to the document that asks for it.
How many of the largest US banks have disclosed AI governance arrangements?
The bank pages on this site record governance-related AI activity at most of the 100 largest US banks, from named AI committees and chief AI officers to model-data 'nutrition labels'; the section below lists them with the source for each.
When a regulator changes what governance means, you'll read it the next morning.
when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning