AI regulation tracker · Topic hub

AI governance in banking: what regulators require, pillar by pillar.

Last updated Sep 19, 2026 · 19 authorities · every row linked to its document

AI governance in a bank is not one rule but six obligations assembled from different places: the board owns an inventory of what is running; predictive models are validated under model-risk guidance while generative and agentic AI are governed through broader enterprise risk; the data behind every model is owned, traceable and complete; bought models and cloud providers sit under third-party risk management; a person can explain and override any decision that touches a customer's credit; and voluntary frameworks from NIST and Treasury fill the gaps the rules leave. Each pillar below states the expectation in a few sentences and maps it to the documents that ask for it, across the 19 authorities this tracker follows.

Two of the pillars have their own pages: model risk management (the framework, model inventory, validation and the three lines of defense) and, for the customer-facing side of human oversight, AI chatbots in banking.

Who has to own AI in a bank?

Every supervisor that has spoken puts AI under the board and senior management, through the same governance architecture that already covers models and technology: named accountability, an inventory of what is running, policies for how it is approved, and effective challenge from risk, compliance and internal audit. US model-risk guidance revised in April 2026 keeps that structure for predictive models and leaves generative and agentic AI to broader enterprise governance; the UK's SS1/23 names a senior manager; the ECB's supervisors have said accountability for AI decisions must be clear and oversight must match AI's strategic weight.

RuleAuthorityWhat it requiresApplies
SR 26-2 / OCC Bulletin 2026-13 / FDIC FIL-15-2026Federal ReserveBoard and senior-management governance, a model inventory and independent validation for models in scope; generative and agentic AI are outside scope and left to broader risk-management and governance practices.In force from Apr 17, 2026
PRA SS1/23UK (BoE / PRA / FCA)Five model-risk principles for all models informing business decisions, a sub-principle on AI and machine learning, and a named Senior Management Function holder accountable for the framework.In force from May 17, 2024
ECB: 'Technology is neutral, governance is not'ECBClear accountability for AI decisions, senior-management oversight matching AI's strategic importance, and effective challenge from risk, compliance and internal audit.Stated Feb 24, 2026
FSB sound practices 1–4 (consultation)FSBStrategic direction and oversight, governance and accountability, AI inside the risk-management framework, organisational adaptability.Final report expected Oct 2026
NCUA Letter 26-CU-01NCUACredit-union supervisory expectations for AI governance, risk assessment and vendor oversight.In force

Which AI systems count as models, and what validation do they need?

In the US, a machine-learning system that processes input data into quantitative estimates is a model and needs documented development, independent validation, ongoing monitoring and outcomes analysis scaled to its materiality. The 2026 revision narrowed the definition so that simple arithmetic and deterministic rules fall out, and it explicitly excludes generative and agentic AI from model risk management while promising an interagency request for information. Outside the US the perimeter is wider: the PRA keeps AI and machine learning inside model risk management, and the ECB's internal-models guide tests machine-learning capital models for explainability and justified complexity.

RuleAuthorityWhat it requiresApplies
SR 26-2 (Fed)Federal ReserveRisk-based, materiality-driven validation and monitoring; 'complex quantitative method' definition; generative and agentic AI out of scope.In force from Apr 17, 2026
SR 11-7 (the 2011 framework)Federal ReserveThe validation disciplines that carry over: conceptual soundness, ongoing monitoring, outcomes analysis, effective challenge.Superseded Apr 17, 2026
ECB Guide to internal models, ML sectionECBMachine-learning capital models must be adequately explainable and their complexity justified by performance.In force from Jul 28, 2025
EBA follow-up report on ML for IRB modelsEBAPrinciple-based recommendations on understanding, documentation, validation and stability of machine-learning capital models.Published Aug 4, 2023
OCC Bulletin 2023-17 / SR 23-4 (third-party models)Federal ReserveVendor models are the bank's to understand and validate, with due diligence and monitoring through the relationship's life.In force

What do regulators expect of the data behind AI models?

Owned, traceable, complete and current: the BCBS 239 vocabulary that examiners use for risk data applies to training sets, feature stores and retrieval corpora, and the Basel Committee's January 2026 newsletter said AI makes robust data management more important, not less. The EU AI Act turns data governance into a legal duty for high-risk systems such as consumer credit scoring, with provenance, preparation, bias examination and gap analysis to be documented, from December 2, 2027 after the Digital Omnibus deferral.

RuleAuthorityWhat it requiresApplies
BCBS 239Basel CommitteeFourteen principles for risk-data governance, aggregation and reporting: ownership, architecture, accuracy and lineage, completeness, timeliness, adaptability.G-SIBs from 2016
BCBS 239 implementation newsletterBasel CommitteeAI and advanced automation depend on high-quality data; lineage and ad hoc reporting still 'a work in progress'.Published Jan 6, 2026
EU AI Act, Article 10EU AI ActDocumented data governance for training, validation and testing data of high-risk systems, including credit scoring of natural persons.Stand-alone Annex III systems from Dec 2, 2027
Treasury AI cybersecurity reportU.S. TreasuryIdentified a 'fraud data divide' and proposed data 'nutrition labels' for vendor AI; became the AIEOG workplan.Published Mar 27, 2024

How is a bank's reliance on external AI models and cloud providers supervised?

Through third-party risk management rather than a separate AI rule. The 2023 US interagency guidance covers the full lifecycle from due diligence to termination and expects validation of purchased models; the Basel Committee's December 2025 principles reach nth-party supply chains and concentration; and the FSB has singled out generative AI's dependence on a small number of hardware, cloud and model suppliers as a financial-stability vulnerability to monitor.

RuleAuthorityWhat it requiresApplies
SR 23-4 / OCC 2023-17 / FDIC FIL-29-2023Federal ReservePlanning, due diligence, contracting, ongoing monitoring and termination for every third-party relationship, including AI tools and foundation-model access.In force from Jun 7, 2023
BCBS Third-Party Risk PrinciplesBasel CommitteeTwelve principles covering board accountability, due diligence, contracts, monitoring, continuity and exit, including nth-party chains and concentration.Published Dec 10, 2025
FSB AI monitoring reportFSBThird-party dependencies and provider concentration named as vulnerabilities for authorities to track.Published Oct 10, 2025
FSB third-party risk toolkitFSBToolkit for managing third-party and outsourcing risk, including critical service providers.Published Dec 4, 2023

When must a person be able to explain or override an AI decision?

Whenever the decision touches a consumer's credit: US adverse-action law requires the specific principal reasons for a denial regardless of how complex the model is, the EU AI Act requires human oversight and a fundamental-rights impact assessment for high-risk credit scoring, and Colorado's Automated Decision-Making Technology Act adds notice, a plain-language explanation after an adverse outcome and human review from January 1, 2027, with a lender's ECOA notice satisfying the disclosure duty for the same decision.

RuleAuthorityWhat it requiresApplies
ECOA / Regulation B adverse actionCFPBSpecific principal reasons for adverse credit action; model opacity is not a defence.In force
FCRA adverse action and key factorsCFPBKey factors that adversely affected a credit score must be disclosed.In force
EU AI Act, Articles 14 and 26–27EU AI ActHuman oversight, deployer duties and a fundamental-rights impact assessment for high-risk credit scoring.Stand-alone Annex III systems from Dec 2, 2027
Colorado SB 26-189 (ADMT Act)Colorado AI ActConsumer notice, a plain-language explanation within 30 days of an adverse outcome, data access and correction, human review.Effective Jan 1, 2027
CPPA ADMT regulations (California)California CPPANotice, opt-out and access rights for automated decision-making technology in significant decisions, plus risk assessments.In force

What do banks use to govern generative and agentic AI where the rules stop?

The NIST AI Risk Management Framework and its generative-AI profile, Treasury's financial-services adaptation of it, and, for cyber, the New York and ECB letters on AI-enabled threats. None is binding on banks, but together they are what most US institutions cite for the systems that model-risk guidance now leaves out, and what examiners ask about when a bank's AI policy is on the table.

RuleAuthorityWhat it requiresApplies
NIST AI RMF 1.0NISTGovern, Map, Measure, Manage and seven trustworthiness characteristics.Voluntary
NIST AI 600-1 (Generative AI Profile)NISTTwelve generative-AI risks and more than 200 suggested actions mapped to the framework.Voluntary
Treasury FS AI RMF and AI LexiconU.S. TreasuryThe NIST framework adapted to financial services' operational, regulatory and consumer-protection specifics, with a shared vocabulary.Published Feb 19, 2026, non-binding
DFS AI cybersecurity letterNY DFSAI-enabled social engineering, AI-enhanced attacks, data exposure and vendor dependency mapped to 23 NYCRR Part 500 obligations.In force
ECB 'Dear CEO' letter SSM-2026-0301ECBEvery significant institution to assess AI-enabled cyber threats and submit an action plan to its supervisory team.Plans due Oct 31, 2026

Which governance documents has each authority published?

AuthorityGovernance documents in the tracker
Federal ReserveCook: Opportunities and Risks of AI (May 2026) Final · Bowman: AI in the Financial System (May 2026) Final · SR 26-2 In force · SR 23-4 In force · 2021 BSA/AML Model Risk Statement Superseded · 2021 Interagency AI RFI Final · SR 11-7 Superseded
OCCOCC Semiannual Risk Perspective, Spring 2026 Final · OCC Bulletin 2026-13 In force · Acting Comptroller Hood, 'AI in Financial Services' (Apr 2025) Final · OCC Bulletin 2023-17 In force · OCC Bulletin 2021-19 Superseded · 2021 Interagency AI RFI (OCC Bulletin 2021-17) Final · OCC Bulletin 2011-12 Superseded
FDICHill House oversight testimony (Jun 2026) Final · Hill 'Charting a New Course' speech Final · FDIC FIL-29-2023 In force · FDIC FIL-20-2021 Final
NCUAHauptman Senate testimony (Feb 2026) Final · NCUA Letter 26-CU-01 In force · NCUA AI Compliance Plan (2025) Final · NCUA Credit Union AI Resource Center In force · NCUA Board AI briefing (Jul 2025) Final · NCUA testimony to House AI Task Force (2022) Final · NCUA Letter 07-CU-13 In force
CFPBCFPB withdrawal of 67 guidance documents (May 2025) In force · CFPB comment to Treasury on AI in financial services (2024) Final · Joint Statement on Automated Systems (CFPB, DOJ, EEOC, FTC) Final
SECAtkins remarks at Investor Advisory Committee (Sep 2026) Final · Atkins remarks at FSOC AI roundtable (Mar 2026) Final · Investor Advisory Committee AI disclosure recommendation Final · Division of Examinations FY2026 Priorities In force · SEC withdrawal of proposed rules (33-11377) Final · SEC v. Saniger (Nate, Inc.) Final · Presto Automation AI-washing order Final · Division of Examinations FY2025 Priorities Superseded · Delphia / Global Predictions AI-washing settlements Final · Gensler 'AI washing' remarks at Yale (Feb 2024) Final · SEC Predictive Data Analytics proposal (34-97990) Withdrawn
CFTCCFTC Innovation Task Force In force · CFTC Staff Advisory 24-17 on AI In force · Johnson Statement on AI in Derivatives Markets (Dec 2024) Final · CFTC TAC Responsible AI Report Final · CFTC AI Request for Comment (2024) Final
FinCEN2026 AML/CFT Program Proposed Rule Proposed · 2024 AML/CFT Program Proposed Rule (withdrawn) Withdrawn · Anti-Money Laundering Act of 2020 In force · FinCEN Innovation Hours In force · 2018 Joint Statement on BSA/AML Innovation In force
U.S. TreasuryFSOC AI Innovation Series (Mar–May 2026) Final · Treasury FS AI RMF and AI Lexicon (Feb 2026) Final · FSOC 2025 Annual Report Final · Treasury AI in Financial Services report (Dec 2024) Final · FSOC 2024 Annual Report Superseded · Treasury AI RFI (June 2024) Final · Treasury AI cybersecurity risks report (Mar 2024) Final · FSOC 2023 Annual Report Superseded
NY DFSDFS Heightened Threat Environment Guidance (May 2026) In force · Asrow Assembly Statement on AI in Insurance (Dec 2025) Final · Insurance Circular Letter No. 7 (2024) In force · DFS Virtual Currency Customer Service Guidance (May 2024) In force · DFS Proposed AI Insurance Circular Letter (Jan 2024) Superseded · 23 NYCRR Part 500 In force
Colorado AI ActColorado AG proposed ADMT rules Comment period open · HB 26-1263 Final · SB 26-189 Final · SB 25B-004 Superseded · SB 24-205 Superseded
California CPPACPPA ADMT, risk-assessment and cybersecurity-audit regulations In force · Civil Rights Council ADS employment regulations In force · California AG legal advisory on AI (Jan 2025) Final · Cal. Civ. Code §1798.145 (CCPA exemptions, incl. GLBA data) In force
NISTAI RMF critical-infrastructure profile (concept note) Proposed · CAISI RFI on AI agent security (2026) Proposed · NIST IR 8596 (Cyber AI Profile) Proposed · NIST COSAiS control overlays Proposed · NIST AI RMF 1.0 In force · NIST AI RMF Playbook In force
EU AI ActRegulation (EU) 2026/1744 (Digital Omnibus on AI) In force · Draft Commission guidelines on high-risk classification Proposed · EBA factsheet on the AI Act Final · Commission guidelines on prohibited AI practices In force · Regulation (EU) 2024/1689 In force
ECBECB 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301) In force · Machado speech: 'Technology is neutral, governance is not' (Feb 2026) Final · Montagner speech: 'Encouraging innovation, managing risks' (Feb 2026) Final · Supervision Newsletter: AI use cases for credit scoring and fraud detection (Nov 2025) Final · SSM supervisory priorities 2026–28 In force · Machado speech: 'Artificial intelligence and supervision: innovation with caution' (Oct 2025) Final · Supervision Newsletter: suptech infrastructure (May 2025) Final · ECB digitalisation sound practices report (July 2024) In force · Cipollone speech: 'Artificial intelligence: a central bank's view' (July 2024) Final · ECB FSR May 2024 AI special feature Final
EBAESA Statement on ICT risks from frontier AI models (JC 2026 25) In force · EBA factsheet: AI Act implications for the EU banking and payments sector Final · EBA Chair letter to the Commission on the AI Act mapping exercise (EBA/2025/D/5384) Final · EBA Work Programme 2026 In force · EBA report: Rising application of AI in EU banking and payments (Sep 2025) Final · EBA Guidelines on loan origination and monitoring (EBA/GL/2020/06) In force · EBA Report on Big Data and Advanced Analytics (EBA/REP/2020/01) Final
UK (BoE / PRA / FCA)HM Treasury Financial Services AI Adoption Plan (Jul 2026) Final · 2026 BoE/FCA AI survey Final · BoE/FCA/HMT joint statement on frontier AI and cyber resilience (May 2026) In force · BoE response to Treasury Committee AI inquiry (Apr 2026) Final · BoE/PRA plan for safe AI innovation (Apr 2026) Final · DSIT/DBT strategic letters to regulators (Jan 2026) Final · FCA FS25/5 Final · FPC Financial Stability in Focus: AI (Apr 2025) Final · 2024 BoE/FCA AI survey Final · FCA AI Update (Apr 2024) Final · FS2/23 Final · PRA SS1/23 In force · DP5/22 Final · 2022 BoE/FCA ML survey Superseded
FSBFSB Chair's letter to G20 (Aug 2026) Final · Responses to FSB AI sound practices consultation (Aug 2026) Final · Bowman remarks at FSB AI outreach (July 2026) Final · FSB AI sound practices consultation (June 2026) Proposed · FSB AI monitoring report (Oct 2025) Final · FSB next steps on AI monitoring (Oct 2025) Final · FSB AI financial stability report (Nov 2024) Final · FSB third-party risk toolkit (2023) Final · FSB 2017 AI/ML report Final
Basel CommitteeBCBS ICT Risk Management Report (June 2026) Final · BCBS 239 Implementation Newsletter (Jan 2026) Final · BCBS Third-Party Risk Principles (Dec 2025) In force · BCBS Work Programme 2025–26 In force · BCBS AI/ML Newsletter (March 2022) Final · BCBS Principles for Operational Resilience (2021) In force · BCBS 239 In force
DateEventDocument
Jul 24, 2026Digital Omnibus defers EU high-risk duties to Dec 2027Regulation (EU) 2026/1744 (Digital Omnibus on AI)
Jun 10, 2026FSB consults on twelve sound practicesFSB AI sound practices consultation (June 2026)
May 14, 2026Colorado re-enacts its AI law as the ADMT ActSB 26-189
Apr 17, 2026SR 26-2 replaces SR 11-7; generative and agentic AI carved outSR 26-2
Feb 19, 2026Treasury FS AI RMF and lexiconTreasury FS AI RMF and AI Lexicon (Feb 2026)
Dec 10, 2025Basel third-party risk principles reach AI supply chainsBCBS Third-Party Risk Principles (Dec 2025)
Jul 26, 2024NIST generative-AI profileNIST AI 600-1 (Generative AI Profile)
Jul 12, 2024EU AI Act published; credit scoring is high-riskRegulation (EU) 2024/1689
Jun 7, 2023SR 23-4 third-party guidance covers vendor AISR 23-4
May 17, 2023PRA SS1/23 keeps AI inside model risk managementPRA SS1/23
Jan 26, 2023NIST AI RMF 1.0 publishedNIST AI RMF 1.0
Jan 9, 2013BCBS 239 sets the data-governance standardBCBS 239
Apr 4, 2011SR 11-7 makes model governance an examinable disciplineSR 11-7

Which of the 100 largest US banks have disclosed AI governance arrangements?

66 of the 100 bank pages on this site record a governance-related AI activity, from AI committees and chief AI officers to training programmes and model-data controls. Each links to the bank's page, where the claim is sourced.

BankWhat the record showsStatus
BofAThe Academy simulators: AI conversation simulators for employee coaching.In production
GoldmanTrade and transaction accounting agents: Automating accounting for trades and transactions.Pilot
Morgan StanleyCompliance task automation: Bots handling routine non-financial-risk work.In production
PNCModel-data nutrition labels: Adopting the FSSCC concept for documenting training and input data.Rolling out
TruistClient Pulse: Patent-pending AI aggregating client feedback across millions of conversations.Pilot
SchwabSchwab Advisor AI in Action: Education, peer networking and resources for RIAs adopting AI.In production
BNYAnomaly detection in daily calculations: Flags areas for review in minutes instead of hours. Community-bank AI training: Free AI and cyber training for 1,000 community-bank executives, led by senior BNY leaders.In production
State StreetML data-quality for investment data: Production RAG, multi-agent and document-intelligence systems for financial-services workflows.In production
Fifth ThirdMerger-conversion monitoring: AI tools tracking the Comerica integration.In production
BMOResponsible AI framework: Accountability, reliability, security, explainability, transparency, fairness, privacy, sustainability.In production
First CitizensResponsible-AI function: Responsible AI and governance among the functions being stood up under the head of AI.Rolling out
M&TData lineage, Edison and the Data Academy: The data foundation under the AI program; ~2,000 employees trained.In production
AllyFour-layer AI governance: Working group, steering council, enterprise committee and board; mandatory training; Responsible AI Institute membership.In production
Northern TrustShared semantic data layer for AI agents (OSI): Open-source data definitions so agents across firms ground on the same meanings.Announced
PinnacleFirm AI policy: An ethics-and-effectiveness policy for AI deployment across the business.In production
UBSUBS Claves platform and AI risk committee: One platform with model routing and evaluation; AI Operating & Risk Committee under a group AI policy.Rolling out
City NationalPost-remediation risk management: Controls rebuilt after the 2024 OCC order; the frame for any AI deployment at the bank.In production
FlagstarIntegrated AI governance workflow: Business case, compliance review and multi-level approvals in one auditable system.In production
WebsterCategory IV data and risk infrastructure: Data collection, storage and governance roles; regulatory-reporting capability.In production
First HorizonEnterprise Data Hub and data marketplace: Unified data with permission-based discovery of approved data products.Pilot
UMBPost-acquisition systems conversion: Product mapping, customer migration and platform consolidation after Heartland.In production
SouthStateAI enablement programme: Office hours, AI Central hub, crowdsourced prompt library; adoption run as change management.In production
ColumbiaPost-merger systems conversion: Pacific Premier converted in Q1 2026 after the Umpqua integration.In production
CIBC'Agentic AI with humans in control': Human judgment, governance and culture at the centre of agent design.In production
ValleyFive-tier AI access and monthly spend tracking: Specialised tiers for engineering, QA and model risk; ~80 open-access power users. Valley Foundry: A dedicated capability to identify, test and advance emerging technologies — initially AI, cybersecurity, and data and analytics — through startup, fintech and vendor partnerships.In production, Announced
BOK FinancialData-first model for responsible AI scaling: Enterprise data treated as a shared asset under the chief data and analytics officer.Rolling out
FNBEthical and compliant AI strategy: Explicit remit of the director of AI and innovation.Rolling out
EverBankOmnichannel and customer-platform transformation: Digital, voice, contact-centre and branch context sharing under the head of digital and customer platforms.Rolling out
Raymond JamesChief AI officer and AI strategy office: Cross-business identification of analytics, ML and gen-AI opportunities.In production
AssociatedLine-of-business AI accountability and board oversight: Senior director of AI stewards risk and data; board technology committee.In production
ProsperityReal-time core platform: New processing system as the stated base for future innovation; no AI use disclosed.In production
Bank OZKNo disclosed internal AI use: Transcripts and releases contain no operational AI, automation or model references.Announced
Atlantic UnionExploratory AI programme: 'Exploring exciting opportunities with Artificial Intelligence'; agentic and third-party model risks flagged.Pilot
CommerceAI pillar in the enterprise data strategy: AI roadmap plus data-platform modernisation for speed to insight.Rolling out
BankUnitedNo disclosed internal AI deployment: No AI programme, vendor or leader named in filings or releases.Announced
United BankNo disclosed AI deployment: No AI programme, vendor or leader named in releases or investor materials.Announced
Texas CapitalAI enablement under the CDIO: Data platforms, AI enablement and security in one technology organisation.Rolling out
FultonCustomer education on AI tools: AI in investing (private bank) and AI budgeting apps (education centre).In production
GlacierNo disclosed AI deployment: Annual report and earnings materials silent on AI.Announced
Eastern BankInnovation-through-experimentation culture: CDO-led programme; AI framed as a workplace efficiency tool.In production
Axos BankAI Center of Excellence and Automation CoE governance framework: Enterprise AI assistant for all staff; platform standards, RBAC, audit and exam support; Cloud and AI security reviews of LLM integrations.In production
City National FloridaChief AI officer search: Role to define and execute AI strategy across efficiency and client experience.Announced
United CommunityCapacity-building through AI productivity: Clearing postponed product and process improvement projects.Announced
ArvestInnovation culture programme: Product and innovation office under Amy Morbeck; Fortune recognition.In production
WaFd BankBuild 2030 digital focus: Data used to anticipate client needs; NPS tracked as the outcome metric.In production
First Interstate'One clean data source' consolidation: Data foundation for AI and other technology initiatives.Rolling out
Customers BankStandardised AI risk framework and AI Innovation Lab: Enterprise governance for scaled deployment.In production
Rockland TrustAI steering committee and governance framework: Clearinghouse for use cases within a moderate risk appetite.In production
Simmons BankEnterprise Data Office: Data governance, data literacy and data-driven decision-making established under the first CDO.In production
First HawaiianAI programme strategy and governance: Owned by the Digital Banking and Services Division under Jason Dang.In production
Cathay BankNo disclosed AI deployment: Annual and responsibility reports silent on AI.Announced
Bank of HawaiiAI listed as an enterprise risk: Technology, AI and cybersecurity risk factors in the 10-K.In production
Centennial BankNo disclosed AI deployment: Earnings materials silent on AI.Announced
First Financial BankNo disclosed AI deployment: No AI reference in investor materials.Announced
Mechanics BankNo disclosed AI deployment: Earnings materials silent on AI.Announced
First MerchantsNo disclosed AI deployment: Investor materials silent on AI.Announced
Optum BankAgentic-AI lending perspective from the chief credit officer: Public commentary on AI in lending and cross-unit data sharing.Announced
Merchants Bank of IndianaNo disclosed AI deployment: Earnings materials silent on AI.Announced
Stifel BankAI thought leadership for clients: Research outlook on AI's economic effects.In production
TrustmarkPost-conversion efficiency programme: Management attention shifting to efficiency gains and possible M&A.Announced
Bank of HopeAcquisition integration (Territorial, SMBC MANUBANK): Hawaii and Japanese-corporate banking added to the Korean-American core.Rolling out
Busey BankEnterprise AI and data-science function: Strategy, communication and execution of responsible AI/ML models across business units.Rolling out
Community Bank N.A.Dedicated AI team: More than a dozen staff, a handful fully dedicated; efficiency focus.In production
Enterprise Bank & TrustClient AI education (Enterprise University): AI strategy and Copilot courses for business owners.In production
FirstBankNo disclosed AI deployment: Investor materials silent on AI.Announced
First United BankTechnology as enterprise capability: Strategy, operating model, data, risk and digital experience connected under one programme.In production

Is there a single AI governance rule for banks?

No. In the US, AI governance is assembled from model-risk guidance (SR 26-2 and its OCC and FDIC twins), third-party guidance (SR 23-4), consumer law on automated decisions (ECOA, FCRA), state laws (Colorado, California, New York) and voluntary frameworks (NIST, Treasury). The EU AI Act is the closest thing to a single rule, and it applies to banks mainly through high-risk credit scoring from December 2, 2027.

Does model risk management cover generative AI?

Not in the US since April 17, 2026. SR 26-2 states that generative and agentic AI models are outside its scope and directs banks to broader risk-management and governance practices; the agencies have promised a request for information. In the UK the PRA's SS1/23 keeps AI and machine learning inside model risk management.

What does an examiner ask to see?

An inventory of AI systems with owners and risk tiers, the approval and validation record for each material one, the data lineage behind it, the vendor due diligence where it is bought, the monitoring and the route to a human, and evidence that the board has been told what is running and why. The pillars above map each of those to the document that asks for it.

How many of the largest US banks have disclosed AI governance arrangements?

The bank pages on this site record governance-related AI activity at most of the 100 largest US banks, from named AI committees and chief AI officers to model-data 'nutrition labels'; the section below lists them with the source for each.

When a regulator changes what governance means, you'll read it the next morning.

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning