# AI governance in banking: what the rules require

Source: https://www.bankingnewsai.com/ai-governance
Last updated: Sep 19, 2026

Six pillars of AI governance for a bank — each phrased as the question an examiner asks, answered from the 166 documents in the regulation tracker, with the banks among the 100 largest that have disclosed arrangements.

## Who has to own AI in a bank?

Every supervisor that has spoken puts AI under the board and senior management, through the same governance architecture that already covers models and technology: named accountability, an inventory of what is running, policies for how it is approved, and effective challenge from risk, compliance and internal audit. US model-risk guidance revised in April 2026 keeps that structure for predictive models and leaves generative and agentic AI to broader enterprise governance; the UK's SS1/23 names a senior manager; the ECB's supervisors have said accountability for AI decisions must be clear and oversight must match AI's strategic weight.

| Rule | What it requires | Status | Source |
| --- | --- | --- | --- |
| SR 26-2 / OCC Bulletin 2026-13 / FDIC FIL-15-2026 | Board and senior-management governance, a model inventory and independent validation for models in scope; generative and agentic AI are outside scope and left to broader risk-management and governance practices. | In force from Apr 17, 2026 | [SR 26-2](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-26-2) |
| PRA SS1/23 | Five model-risk principles for all models informing business decisions, a sub-principle on AI and machine learning, and a named Senior Management Function holder accountable for the framework. | In force from May 17, 2024 | [PRA SS1/23](https://www.bankingnewsai.com/ai-regulation/documents/pra-ss1-23-model-risk-management) |
| ECB: 'Technology is neutral, governance is not' | Clear accountability for AI decisions, senior-management oversight matching AI's strategic importance, and effective challenge from risk, compliance and internal audit. | Stated Feb 24, 2026 | [Machado speech: 'Technology is neutral, governance is not' (Feb 2026)](https://www.bankingnewsai.com/ai-regulation/documents/ecb-machado-technology-neutral-governance-speech-2026) |
| FSB sound practices 1–4 (consultation) | Strategic direction and oversight, governance and accountability, AI inside the risk-management framework, organisational adaptability. | Final report expected Oct 2026 | [FSB AI sound practices consultation (June 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fsb-ai-sound-practices-consultation-2026) |
| NCUA Letter 26-CU-01 | Credit-union supervisory expectations for AI governance, risk assessment and vendor oversight. | In force | [NCUA Letter 26-CU-01](https://www.bankingnewsai.com/ai-regulation/documents/ncua-letter-26-cu-01) |

## Which AI systems count as models, and what validation do they need?

In the US, a machine-learning system that processes input data into quantitative estimates is a model and needs documented development, independent validation, ongoing monitoring and outcomes analysis scaled to its materiality. The 2026 revision narrowed the definition so that simple arithmetic and deterministic rules fall out, and it explicitly excludes generative and agentic AI from model risk management while promising an interagency request for information. Outside the US the perimeter is wider: the PRA keeps AI and machine learning inside model risk management, and the ECB's internal-models guide tests machine-learning capital models for explainability and justified complexity.

| Rule | What it requires | Status | Source |
| --- | --- | --- | --- |
| SR 26-2 (Fed) | Risk-based, materiality-driven validation and monitoring; 'complex quantitative method' definition; generative and agentic AI out of scope. | In force from Apr 17, 2026 | [SR 26-2](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-26-2) |
| SR 11-7 (the 2011 framework) | The validation disciplines that carry over: conceptual soundness, ongoing monitoring, outcomes analysis, effective challenge. | Superseded Apr 17, 2026 | [SR 11-7](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-11-7) |
| ECB Guide to internal models, ML section | Machine-learning capital models must be adequately explainable and their complexity justified by performance. | In force from Jul 28, 2025 | [ECB Guide to internal models (July 2025, ML section)](https://www.bankingnewsai.com/ai-regulation/documents/ecb-guide-to-internal-models-2025-machine-learning) |
| EBA follow-up report on ML for IRB models | Principle-based recommendations on understanding, documentation, validation and stability of machine-learning capital models. | Published Aug 4, 2023 | [EBA follow-up report on machine learning for IRB models (EBA/REP/2023/28)](https://www.bankingnewsai.com/ai-regulation/documents/eba-rep-2023-28-ml-irb-follow-up) |
| OCC Bulletin 2023-17 / SR 23-4 (third-party models) | Vendor models are the bank's to understand and validate, with due diligence and monitoring through the relationship's life. | In force | [SR 23-4](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-23-4) |

## What do regulators expect of the data behind AI models?

Owned, traceable, complete and current: the BCBS 239 vocabulary that examiners use for risk data applies to training sets, feature stores and retrieval corpora, and the Basel Committee's January 2026 newsletter said AI makes robust data management more important, not less. The EU AI Act turns data governance into a legal duty for high-risk systems such as consumer credit scoring, with provenance, preparation, bias examination and gap analysis to be documented, from December 2, 2027 after the Digital Omnibus deferral.

| Rule | What it requires | Status | Source |
| --- | --- | --- | --- |
| BCBS 239 | Fourteen principles for risk-data governance, aggregation and reporting: ownership, architecture, accuracy and lineage, completeness, timeliness, adaptability. | G-SIBs from 2016 | [BCBS 239](https://www.bankingnewsai.com/ai-regulation/documents/bcbs-239) |
| BCBS 239 implementation newsletter | AI and advanced automation depend on high-quality data; lineage and ad hoc reporting still 'a work in progress'. | Published Jan 6, 2026 | [BCBS 239 Implementation Newsletter (Jan 2026)](https://www.bankingnewsai.com/ai-regulation/documents/bcbs-newsletter-bcbs239-implementation-2026) |
| EU AI Act, Article 10 | Documented data governance for training, validation and testing data of high-risk systems, including credit scoring of natural persons. | Stand-alone Annex III systems from Dec 2, 2027 | [Regulation (EU) 2024/1689](https://www.bankingnewsai.com/ai-regulation/documents/eu-ai-act-regulation-2024-1689) |
| Treasury AI cybersecurity report | Identified a 'fraud data divide' and proposed data 'nutrition labels' for vendor AI; became the AIEOG workplan. | Published Mar 27, 2024 | [Treasury AI cybersecurity risks report (Mar 2024)](https://www.bankingnewsai.com/ai-regulation/documents/treasury-ai-cybersecurity-risks-report-2024) |

## How is a bank's reliance on external AI models and cloud providers supervised?

Through third-party risk management rather than a separate AI rule. The 2023 US interagency guidance covers the full lifecycle from due diligence to termination and expects validation of purchased models; the Basel Committee's December 2025 principles reach nth-party supply chains and concentration; and the FSB has singled out generative AI's dependence on a small number of hardware, cloud and model suppliers as a financial-stability vulnerability to monitor.

| Rule | What it requires | Status | Source |
| --- | --- | --- | --- |
| SR 23-4 / OCC 2023-17 / FDIC FIL-29-2023 | Planning, due diligence, contracting, ongoing monitoring and termination for every third-party relationship, including AI tools and foundation-model access. | In force from Jun 7, 2023 | [SR 23-4](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-23-4) |
| BCBS Third-Party Risk Principles | Twelve principles covering board accountability, due diligence, contracts, monitoring, continuity and exit, including nth-party chains and concentration. | Published Dec 10, 2025 | [BCBS Third-Party Risk Principles (Dec 2025)](https://www.bankingnewsai.com/ai-regulation/documents/bcbs-third-party-risk-principles-2025) |
| FSB AI monitoring report | Third-party dependencies and provider concentration named as vulnerabilities for authorities to track. | Published Oct 10, 2025 | [FSB AI monitoring report (Oct 2025)](https://www.bankingnewsai.com/ai-regulation/documents/fsb-monitoring-ai-adoption-vulnerabilities-2025) |
| FSB third-party risk toolkit | Toolkit for managing third-party and outsourcing risk, including critical service providers. | Published Dec 4, 2023 | [FSB third-party risk toolkit (2023)](https://www.bankingnewsai.com/ai-regulation/documents/fsb-third-party-risk-toolkit-2023) |

## When must a person be able to explain or override an AI decision?

Whenever the decision touches a consumer's credit: US adverse-action law requires the specific principal reasons for a denial regardless of how complex the model is, the EU AI Act requires human oversight and a fundamental-rights impact assessment for high-risk credit scoring, and Colorado's Automated Decision-Making Technology Act adds notice, a plain-language explanation after an adverse outcome and human review from January 1, 2027, with a lender's ECOA notice satisfying the disclosure duty for the same decision.

| Rule | What it requires | Status | Source |
| --- | --- | --- | --- |
| ECOA / Regulation B adverse action | Specific principal reasons for adverse credit action; model opacity is not a defence. | In force | [ECOA / Regulation B adverse action (15 U.S.C. 1691(d); 12 CFR 1002.9)](https://www.bankingnewsai.com/ai-regulation/documents/cfpb-ecoa-regulation-b-adverse-action) |
| FCRA adverse action and key factors | Key factors that adversely affected a credit score must be disclosed. | In force | [FCRA adverse action and credit-score disclosures (15 U.S.C. 1681m, 1681g(f))](https://www.bankingnewsai.com/ai-regulation/documents/cfpb-fcra-adverse-action-key-factors) |
| EU AI Act, Articles 14 and 26–27 | Human oversight, deployer duties and a fundamental-rights impact assessment for high-risk credit scoring. | Stand-alone Annex III systems from Dec 2, 2027 | [Regulation (EU) 2024/1689](https://www.bankingnewsai.com/ai-regulation/documents/eu-ai-act-regulation-2024-1689) |
| Colorado SB 26-189 (ADMT Act) | Consumer notice, a plain-language explanation within 30 days of an adverse outcome, data access and correction, human review. | Effective Jan 1, 2027 | [SB 26-189](https://www.bankingnewsai.com/ai-regulation/documents/co-sb26-189) |
| CPPA ADMT regulations (California) | Notice, opt-out and access rights for automated decision-making technology in significant decisions, plus risk assessments. | In force | [CPPA ADMT, risk-assessment and cybersecurity-audit regulations](https://www.bankingnewsai.com/ai-regulation/documents/ca-cppa-admt-risk-cyber-regulations-2025) |

## What do banks use to govern generative and agentic AI where the rules stop?

The NIST AI Risk Management Framework and its generative-AI profile, Treasury's financial-services adaptation of it, and, for cyber, the New York and ECB letters on AI-enabled threats. None is binding on banks, but together they are what most US institutions cite for the systems that model-risk guidance now leaves out, and what examiners ask about when a bank's AI policy is on the table.

| Rule | What it requires | Status | Source |
| --- | --- | --- | --- |
| NIST AI RMF 1.0 | Govern, Map, Measure, Manage and seven trustworthiness characteristics. | Voluntary | [NIST AI RMF 1.0](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-1) |
| NIST AI 600-1 (Generative AI Profile) | Twelve generative-AI risks and more than 200 suggested actions mapped to the framework. | Voluntary | [NIST AI 600-1 (Generative AI Profile)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-600-1) |
| Treasury FS AI RMF and AI Lexicon | The NIST framework adapted to financial services' operational, regulatory and consumer-protection specifics, with a shared vocabulary. | Published Feb 19, 2026, non-binding | [Treasury FS AI RMF and AI Lexicon (Feb 2026)](https://www.bankingnewsai.com/ai-regulation/documents/treasury-fs-ai-rmf-and-ai-lexicon-2026) |
| DFS AI cybersecurity letter | AI-enabled social engineering, AI-enhanced attacks, data exposure and vendor dependency mapped to 23 NYCRR Part 500 obligations. | In force | [DFS AI Cybersecurity Industry Letter (Oct 2024)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-industry-letter-2024-10-16-ai-cyber-risks) |
| ECB 'Dear CEO' letter SSM-2026-0301 | Every significant institution to assess AI-enabled cyber threats and submit an action plan to its supervisory team. | Plans due Oct 31, 2026 | [ECB 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301)](https://www.bankingnewsai.com/ai-regulation/documents/ecb-letter-ai-enabled-cybersecurity-threats-2026) |

## Which of the 100 largest US banks have disclosed ai governance (general) work?

| Bank | What the record shows | Status |
| --- | --- | --- |
| [Bank of America](https://www.bankingnewsai.com/banks/bank-of-america) | The Academy simulators: AI conversation simulators for employee coaching. | In production |
| [Goldman Sachs](https://www.bankingnewsai.com/banks/goldman-sachs) | Trade and transaction accounting agents: Automating accounting for trades and transactions. | Pilot |
| [Morgan Stanley](https://www.bankingnewsai.com/banks/morgan-stanley) | Compliance task automation: Bots handling routine non-financial-risk work. | In production |
| [PNC Financial Services](https://www.bankingnewsai.com/banks/pnc) | Model-data nutrition labels: Adopting the FSSCC concept for documenting training and input data. | Rolling out |
| [Truist Financial](https://www.bankingnewsai.com/banks/truist) | Client Pulse: Patent-pending AI aggregating client feedback across millions of conversations. | Pilot |
| [The Charles Schwab Corporation](https://www.bankingnewsai.com/banks/charles-schwab) | Schwab Advisor AI in Action: Education, peer networking and resources for RIAs adopting AI. | In production |
| [BNY (Bank of New York Mellon)](https://www.bankingnewsai.com/banks/bny-mellon) | Anomaly detection in daily calculations: Flags areas for review in minutes instead of hours. · Community-bank AI training: Free AI and cyber training for 1,000 community-bank executives, led by senior BNY leaders. | In production · In production |
| [State Street](https://www.bankingnewsai.com/banks/state-street) | ML data-quality for investment data: Production RAG, multi-agent and document-intelligence systems for financial-services workflows. | In production |
| [Fifth Third Bancorp](https://www.bankingnewsai.com/banks/fifth-third) | Merger-conversion monitoring: AI tools tracking the Comerica integration. | In production |
| [BMO (U.S.)](https://www.bankingnewsai.com/banks/bmo-us) | Responsible AI framework: Accountability, reliability, security, explainability, transparency, fairness, privacy, sustainability. | In production |
| [First Citizens BancShares](https://www.bankingnewsai.com/banks/first-citizens) | Responsible-AI function: Responsible AI and governance among the functions being stood up under the head of AI. | Rolling out |
| [M&T Bank](https://www.bankingnewsai.com/banks/mt-bank) | Data lineage, Edison and the Data Academy: The data foundation under the AI program; ~2,000 employees trained. | In production |
| [Ally Financial](https://www.bankingnewsai.com/banks/ally) | Four-layer AI governance: Working group, steering council, enterprise committee and board; mandatory training; Responsible AI Institute membership. | In production |
| [Northern Trust](https://www.bankingnewsai.com/banks/northern-trust) | Shared semantic data layer for AI agents (OSI): Open-source data definitions so agents across firms ground on the same meanings. | Announced |
| [Pinnacle Financial Partners](https://www.bankingnewsai.com/banks/pinnacle) | Firm AI policy: An ethics-and-effectiveness policy for AI deployment across the business. | In production |
| [UBS (US)](https://www.bankingnewsai.com/banks/ubs-usa) | UBS Claves platform and AI risk committee: One platform with model routing and evaluation; AI Operating & Risk Committee under a group AI policy. | Rolling out |
| [City National Bank (RBC)](https://www.bankingnewsai.com/banks/city-national) | Post-remediation risk management: Controls rebuilt after the 2024 OCC order; the frame for any AI deployment at the bank. | In production |
| [Flagstar Bank](https://www.bankingnewsai.com/banks/flagstar) | Integrated AI governance workflow: Business case, compliance review and multi-level approvals in one auditable system. | In production |
| [Webster Bank](https://www.bankingnewsai.com/banks/webster) | Category IV data and risk infrastructure: Data collection, storage and governance roles; regulatory-reporting capability. | In production |
| [First Horizon](https://www.bankingnewsai.com/banks/first-horizon) | Enterprise Data Hub and data marketplace: Unified data with permission-based discovery of approved data products. | Pilot |
| [UMB Financial](https://www.bankingnewsai.com/banks/umb) | Post-acquisition systems conversion: Product mapping, customer migration and platform consolidation after Heartland. | In production |
| [SouthState Bank](https://www.bankingnewsai.com/banks/southstate) | AI enablement programme: Office hours, AI Central hub, crowdsourced prompt library; adoption run as change management. | In production |
| [Columbia Banking System](https://www.bankingnewsai.com/banks/columbia) | Post-merger systems conversion: Pacific Premier converted in Q1 2026 after the Umpqua integration. | In production |
| [CIBC Bank USA](https://www.bankingnewsai.com/banks/cibc-us) | 'Agentic AI with humans in control': Human judgment, governance and culture at the centre of agent design. | In production |
| [Valley National Bancorp](https://www.bankingnewsai.com/banks/valley) | Five-tier AI access and monthly spend tracking: Specialised tiers for engineering, QA and model risk; ~80 open-access power users. · Valley Foundry: A dedicated capability to identify, test and advance emerging technologies — initially AI, cybersecurity, and data and analytics — through startup, fintech and vendor partnerships. | In production · Announced |
| [BOK Financial Corporation](https://www.bankingnewsai.com/banks/bok-financial) | Data-first model for responsible AI scaling: Enterprise data treated as a shared asset under the chief data and analytics officer. | Rolling out |
| [F.N.B. Corporation](https://www.bankingnewsai.com/banks/fnb) | Ethical and compliant AI strategy: Explicit remit of the director of AI and innovation. | Rolling out |
| [EverBank Financial Corp](https://www.bankingnewsai.com/banks/everbank) | Omnichannel and customer-platform transformation: Digital, voice, contact-centre and branch context sharing under the head of digital and customer platforms. | Rolling out |
| [Raymond James Financial](https://www.bankingnewsai.com/banks/raymond-james) | Chief AI officer and AI strategy office: Cross-business identification of analytics, ML and gen-AI opportunities. | In production |
| [Associated Banc-Corp](https://www.bankingnewsai.com/banks/associated) | Line-of-business AI accountability and board oversight: Senior director of AI stewards risk and data; board technology committee. | In production |
| [Prosperity Bancshares](https://www.bankingnewsai.com/banks/prosperity) | Real-time core platform: New processing system as the stated base for future innovation; no AI use disclosed. | In production |
| [Bank OZK](https://www.bankingnewsai.com/banks/bank-ozk) | No disclosed internal AI use: Transcripts and releases contain no operational AI, automation or model references. | Announced |
| [Atlantic Union Bankshares](https://www.bankingnewsai.com/banks/atlantic-union) | Exploratory AI programme: 'Exploring exciting opportunities with Artificial Intelligence'; agentic and third-party model risks flagged. | Pilot |
| [Commerce Bancshares](https://www.bankingnewsai.com/banks/commerce) | AI pillar in the enterprise data strategy: AI roadmap plus data-platform modernisation for speed to insight. | Rolling out |
| [BankUnited](https://www.bankingnewsai.com/banks/bankunited) | No disclosed internal AI deployment: No AI programme, vendor or leader named in filings or releases. | Announced |
| [United Bankshares](https://www.bankingnewsai.com/banks/united-bankshares) | No disclosed AI deployment: No AI programme, vendor or leader named in releases or investor materials. | Announced |
| [Texas Capital Bancshares](https://www.bankingnewsai.com/banks/texas-capital) | AI enablement under the CDIO: Data platforms, AI enablement and security in one technology organisation. | Rolling out |
| [Fulton Financial Corporation](https://www.bankingnewsai.com/banks/fulton) | Customer education on AI tools: AI in investing (private bank) and AI budgeting apps (education centre). | In production |
| [Glacier Bancorp](https://www.bankingnewsai.com/banks/glacier) | No disclosed AI deployment: Annual report and earnings materials silent on AI. | Announced |
| [Eastern Bankshares](https://www.bankingnewsai.com/banks/eastern) | Innovation-through-experimentation culture: CDO-led programme; AI framed as a workplace efficiency tool. | In production |
| [Axos Financial](https://www.bankingnewsai.com/banks/axos) | AI Center of Excellence and Automation CoE governance framework: Enterprise AI assistant for all staff; platform standards, RBAC, audit and exam support; Cloud and AI security reviews of LLM integrations. | In production |
| [City National Bank of Florida](https://www.bankingnewsai.com/banks/city-national-florida) | Chief AI officer search: Role to define and execute AI strategy across efficiency and client experience. | Announced |
| [United Community Banks](https://www.bankingnewsai.com/banks/united-community) | Capacity-building through AI productivity: Clearing postponed product and process improvement projects. | Announced |
| [Arvest Bank](https://www.bankingnewsai.com/banks/arvest) | Innovation culture programme: Product and innovation office under Amy Morbeck; Fortune recognition. | In production |
| [WaFd, Inc.](https://www.bankingnewsai.com/banks/wafd) | Build 2030 digital focus: Data used to anticipate client needs; NPS tracked as the outcome metric. | In production |
| [First Interstate BancSystem](https://www.bankingnewsai.com/banks/first-interstate) | 'One clean data source' consolidation: Data foundation for AI and other technology initiatives. | Rolling out |
| [Customers Bancorp](https://www.bankingnewsai.com/banks/customers) | Standardised AI risk framework and AI Innovation Lab: Enterprise governance for scaled deployment. | In production |
| [Independent Bank Corp. (Rockland Trust)](https://www.bankingnewsai.com/banks/rockland-trust) | AI steering committee and governance framework: Clearinghouse for use cases within a moderate risk appetite. | In production |
| [Simmons First National Corporation](https://www.bankingnewsai.com/banks/simmons) | Enterprise Data Office: Data governance, data literacy and data-driven decision-making established under the first CDO. | In production |
| [First Hawaiian, Inc.](https://www.bankingnewsai.com/banks/first-hawaiian) | AI programme strategy and governance: Owned by the Digital Banking and Services Division under Jason Dang. | In production |
| [Cathay General Bancorp](https://www.bankingnewsai.com/banks/cathay) | No disclosed AI deployment: Annual and responsibility reports silent on AI. | Announced |
| [Bank of Hawaii Corporation](https://www.bankingnewsai.com/banks/bank-of-hawaii) | AI listed as an enterprise risk: Technology, AI and cybersecurity risk factors in the 10-K. | In production |
| [Home BancShares (Centennial Bank)](https://www.bankingnewsai.com/banks/home-bancshares) | No disclosed AI deployment: Earnings materials silent on AI. | Announced |
| [First Financial Bancorp](https://www.bankingnewsai.com/banks/first-financial-ohio) | No disclosed AI deployment: No AI reference in investor materials. | Announced |
| [Mechanics Bancorp](https://www.bankingnewsai.com/banks/mechanics) | No disclosed AI deployment: Earnings materials silent on AI. | Announced |
| [First Merchants Corporation](https://www.bankingnewsai.com/banks/first-merchants) | No disclosed AI deployment: Investor materials silent on AI. | Announced |
| [Optum Bank (UnitedHealth Group)](https://www.bankingnewsai.com/banks/optum-bank) | Agentic-AI lending perspective from the chief credit officer: Public commentary on AI in lending and cross-unit data sharing. | Announced |
| [Merchants Bancorp](https://www.bankingnewsai.com/banks/merchants-indiana) | No disclosed AI deployment: Earnings materials silent on AI. | Announced |
| [Stifel Financial (Stifel Bank & Trust)](https://www.bankingnewsai.com/banks/stifel-bank) | AI thought leadership for clients: Research outlook on AI's economic effects. | In production |
| [Trustmark Corporation](https://www.bankingnewsai.com/banks/trustmark) | Post-conversion efficiency programme: Management attention shifting to efficiency gains and possible M&A. | Announced |
| [Hope Bancorp (Bank of Hope)](https://www.bankingnewsai.com/banks/bank-of-hope) | Acquisition integration (Territorial, SMBC MANUBANK): Hawaii and Japanese-corporate banking added to the Korean-American core. | Rolling out |
| [First Busey Corporation](https://www.bankingnewsai.com/banks/busey) | Enterprise AI and data-science function: Strategy, communication and execution of responsible AI/ML models across business units. | Rolling out |
| [Community Financial System (Community Bank, N.A.)](https://www.bankingnewsai.com/banks/community-bank-na) | Dedicated AI team: More than a dozen staff, a handful fully dedicated; efficiency focus. | In production |
| [Enterprise Financial Services Corp](https://www.bankingnewsai.com/banks/enterprise-bank) | Client AI education (Enterprise University): AI strategy and Copilot courses for business owners. | In production |
| [FB Financial Corporation (FirstBank)](https://www.bankingnewsai.com/banks/fb-financial) | No disclosed AI deployment: Investor materials silent on AI. | Announced |
| [First United Bank & Trust (Spend Life Wisely Company)](https://www.bankingnewsai.com/banks/first-united) | Technology as enterprise capability: Strategy, operating model, data, risk and digital experience connected under one programme. | In production |

## Which of the 100 largest US banks have disclosed model risk management work?

| Bank | What the record shows | Status |
| --- | --- | --- |
| [M&T Bank](https://www.bankingnewsai.com/banks/mt-bank) | AI Risk Oversight (second line): Independent oversight program for responsible AI adoption. | In production |
| [SouthState Bank](https://www.bankingnewsai.com/banks/southstate) | Per-use-case model testing: Expert Q&A sets for accuracy, privacy, security, toxicity and jailbreaks; retested as models change. | In production |
| [F.N.B. Corporation](https://www.bankingnewsai.com/banks/fnb) | Decisioning, forecasting and regulatory models: Data-science team under Tangirala maintains strategic decisioning systems and regulatory models. | In production |
| [Atlantic Union Bankshares](https://www.bankingnewsai.com/banks/atlantic-union) | AI and machine-learning models in use: Disclosed in the 10-K with training-data, bias and interpretability risks. | In production |
| [Axos Financial](https://www.bankingnewsai.com/banks/axos) | AI risk-factor disclosure: 10-K covers agentic and generative AI, third-party model dependence, bias, explainability and evolving regulation. | In production |
| [SLM Corporation (Sallie Mae)](https://www.bankingnewsai.com/banks/sallie-mae) | AI as a credit-risk variable: Management analysis of AI's effect on graduate employment and cosigner strength. | In production |

## Timeline

- Jul 24, 2026 — Digital Omnibus defers EU high-risk duties to Dec 2027 ([Regulation (EU) 2026/1744 (Digital Omnibus on AI)](https://www.bankingnewsai.com/ai-regulation/documents/eu-digital-omnibus-ai-regulation-2026-1744))
- Jun 10, 2026 — FSB consults on twelve sound practices ([FSB AI sound practices consultation (June 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fsb-ai-sound-practices-consultation-2026))
- May 14, 2026 — Colorado re-enacts its AI law as the ADMT Act ([SB 26-189](https://www.bankingnewsai.com/ai-regulation/documents/co-sb26-189))
- Apr 17, 2026 — SR 26-2 replaces SR 11-7; generative and agentic AI carved out ([SR 26-2](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-26-2))
- Feb 19, 2026 — Treasury FS AI RMF and lexicon ([Treasury FS AI RMF and AI Lexicon (Feb 2026)](https://www.bankingnewsai.com/ai-regulation/documents/treasury-fs-ai-rmf-and-ai-lexicon-2026))
- Dec 10, 2025 — Basel third-party risk principles reach AI supply chains ([BCBS Third-Party Risk Principles (Dec 2025)](https://www.bankingnewsai.com/ai-regulation/documents/bcbs-third-party-risk-principles-2025))
- Jul 26, 2024 — NIST generative-AI profile ([NIST AI 600-1 (Generative AI Profile)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-600-1))
- Jul 12, 2024 — EU AI Act published; credit scoring is high-risk ([Regulation (EU) 2024/1689](https://www.bankingnewsai.com/ai-regulation/documents/eu-ai-act-regulation-2024-1689))
- Jun 7, 2023 — SR 23-4 third-party guidance covers vendor AI ([SR 23-4](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-23-4))
- May 17, 2023 — PRA SS1/23 keeps AI inside model risk management ([PRA SS1/23](https://www.bankingnewsai.com/ai-regulation/documents/pra-ss1-23-model-risk-management))
- Jan 26, 2023 — NIST AI RMF 1.0 published ([NIST AI RMF 1.0](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-1))
- Jan 9, 2013 — BCBS 239 sets the data-governance standard ([BCBS 239](https://www.bankingnewsai.com/ai-regulation/documents/bcbs-239))
- Apr 4, 2011 — SR 11-7 makes model governance an examinable discipline ([SR 11-7](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-11-7))

## FAQ

### Is there a single AI governance rule for banks?

No. In the US, AI governance is assembled from model-risk guidance (SR 26-2 and its OCC and FDIC twins), third-party guidance (SR 23-4), consumer law on automated decisions (ECOA, FCRA), state laws (Colorado, California, New York) and voluntary frameworks (NIST, Treasury). The EU AI Act is the closest thing to a single rule, and it applies to banks mainly through high-risk credit scoring from December 2, 2027.

### Does model risk management cover generative AI?

Not in the US since April 17, 2026. SR 26-2 states that generative and agentic AI models are outside its scope and directs banks to broader risk-management and governance practices; the agencies have promised a request for information. In the UK the PRA's SS1/23 keeps AI and machine learning inside model risk management.

### What does an examiner ask to see?

An inventory of AI systems with owners and risk tiers, the approval and validation record for each material one, the data lineage behind it, the vendor due diligence where it is bought, the monitoring and the route to a human, and evidence that the board has been told what is running and why. The pillars above map each of those to the document that asks for it.

### How many of the largest US banks have disclosed AI governance arrangements?

The bank pages on this site record governance-related AI activity at most of the 100 largest US banks, from named AI committees and chief AI officers to model-data 'nutrition labels'; the section below lists them with the source for each.

---

Canonical page: https://www.bankingnewsai.com/ai-governance
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (19 authorities, 166 documents) and AI-strategy profiles of the 100 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
