AI Regulation Tracker · Federal Reserve · Speech

What does Bowman: AI in the Financial System (May 2026) say about AI in banking?

Published May 1, 2026 · Last reviewed Sep 26, 2026

In remarks delivered on April 27, 2026 and published by the Fed on May 1, 2026, Vice Chair for Supervision Michelle Bowman told the FSOC Artificial Intelligence Series roundtable on cybersecurity and risk management that AI 'will become a force multiplier for the financial system' and that supervisors must preserve 'a path for innovation' while banks deploy AI 'responsibly and effectively'. She confirmed the Fed had 'recently amended our model risk management guidance to clarify that it does not apply to generative or agentic AI', said supervisors are assessing third-party risk-management expectations for vendor-provided AI tools, and framed frontier AI as both a cybersecurity defense and a potential attack tool.

OFFICIAL TEXT: federalreserve.gov ↗ · FINAL · FEDERAL RESERVE

DocumentBowman: AI in the Financial System (May 2026) — Artificial Intelligence in the Financial System — Vice Chair for Supervision Michelle W. Bowman
Issued byBoard of Governors of the Federal Reserve System
TypeSpeech
StatusFinal
PublishedMay 1, 2026
Applies toStatement of supervisory philosophy; not binding, but signals examination priorities for all Fed-supervised institutions
Official sourcefederalreserve.gov ↗
Use casesGenerative & agentic AI · Third-party & vendor AI · Cybersecurity · AI governance (general) · Model risk management

What are the key points of Bowman: AI in the Financial System (May 2026)?

  • Delivered at the FSOC Artificial Intelligence Series Roundtable on Cybersecurity and Risk Management, Washington, D.C., on April 27, 2026; published May 1, 2026, after the April 28–29 FOMC meeting
  • Positions the Fed against pre-emptive AI-specific rulemaking: existing frameworks, regularly reviewed, should accommodate AI's evolution
  • Confirms SR 26-2's carve-out of generative and agentic AI from model risk management guidance
  • Identifies vendor-provided AI tools and third-party risk-management expectations as an active supervisory question
  • Describes frontier AI models as dual-use in cybersecurity — able to enhance defenses and to identify and exploit weaknesses
  • Notes that Fed supervisors have engaged with banks on AI use for nearly a decade and are building internal AI understanding

What did Bowman: AI in the Financial System (May 2026) change for banks?

The speech is the clearest public articulation of the Fed's 2026 posture: innovation-permissive, no new AI rulebook, and reliance on model risk, third-party, and cybersecurity frameworks. For banks it signals that examiners will ask about governance of vendor AI and AI-enabled cyber threats rather than demand AI-specific policies.

What is the Federal Reserve's stance on AI regulation for banks in 2026?

Innovation-permissive. In remarks published May 1, 2026, Vice Chair for Supervision Bowman said supervisors should preserve a path for innovation, rely on existing frameworks that are regularly reviewed, and focus on responsible deployment, vendor AI risk, and cybersecurity rather than new AI-specific rules.

Did the Fed say generative AI is outside model risk management guidance?

Yes. Bowman confirmed the Fed 'recently amended our model risk management guidance to clarify that it does not apply to generative or agentic AI', referring to SR 26-2 issued April 17, 2026.

DateDocumentStatus
May 27, 2026Cook: Opportunities and Risks of AI (May 2026) — The Opportunities and Risks AI Presents for the Economy and Financial System — Governor Lisa D. CookFinal
Apr 17, 2026SR 26-2 — Revised Guidance on Model Risk ManagementIn force
Jun 7, 2023SR 23-4 — Interagency Guidance on Third-Party Relationships: Risk ManagementIn force
Apr 9, 20212021 BSA/AML Model Risk Statement — Interagency Statement on Model Risk Management for Bank Systems Supporting BSA/AML ComplianceSuperseded
Mar 31, 20212021 Interagency AI RFI — Request for Information and Comment on Financial Institutions' Use of Artificial Intelligence, Including Machine LearningFinal
Apr 4, 2011SR 11-7 — Supervisory Guidance on Model Risk ManagementSuperseded

Follow every document these regulators publish

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning