On March 27, 2024 the Treasury released 'Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector', written under Executive Order 14110 and led by its Office of Cybersecurity and Critical Infrastructure Protection. Based on 42 in-depth interviews conducted in late 2023, it found a widening AI capability gap between large and small institutions and a 'fraud data divide' that leaves smaller banks without enough data to train anti-fraud models. Its recommended next steps — a financial-sector expansion of the NIST AI RMF, data 'nutrition labels' for vendor AI, explainability research, and an AI information-sharing forum — became the workplan for the AIEOG resources published in February 2026.
| Document | Treasury AI cybersecurity risks report (Mar 2024) — Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector |
| Issued by | U.S. Department of the Treasury (including the Financial Stability Oversight Council) |
| Type | Report |
| Status | Final |
| Published | Mar 27, 2024 |
| Applies to | U.S. financial institutions of all sizes, their AI and data vendors, and financial regulators (recommendations are non-binding) |
| Official source | home.treasury.gov ↗ |
| Use cases | Cybersecurity · Fraud detection · Third-party & vendor AI · Generative & agentic AI · AI governance (general) |
What are the key points of Treasury AI cybersecurity risks report (Mar 2024)?
- Mandated by EO 14110 (Oct 2023); Treasury's OCCIP led the work as Sector Risk Management Agency for financial services
- Findings drawn from 42 interviews with financial institutions, IT firms, data providers, and anti-fraud/AML companies in late 2023
- Identifies a growing capability gap: large institutions build in-house AI, smaller ones lack the data and expertise; cloud-migrated firms have an advantage
- Identifies a 'fraud data divide': insufficient cross-firm fraud-data sharing disadvantages smaller institutions building anti-fraud models
- Warns of regulatory fragmentation as state, federal, and international regulators consider AI rules
- Recommends expanding the NIST AI Risk Management Framework with financial-services-specific governance content
- Calls for data supply-chain mapping best practices and standardized 'nutrition labels' disclosing what data trained a vendor model and how customer inputs are used
- Flags explainability of black-box and generative AI, and the need for shared AI-specific cyber threat information
What did Treasury AI cybersecurity risks report (Mar 2024) change for banks?
This was the first federal report to treat AI as a distinct cybersecurity and fraud risk vector for the financial sector, covering both banks' defensive use of AI and attackers' use of generative AI for fraud. It did not impose obligations, but it set the agenda that Treasury has since executed through the AIEOG public-private partnership: the 2026 AI Lexicon, the FS AI RMF, and the explainability, data-labeling, and fraud workstreams all trace directly to this report's next-steps list.
What did the Treasury's 2024 AI cybersecurity report recommend banks do?
Map their business lines and data supply chains for AI use, apply existing risk frameworks such as the NIST AI RMF to AI systems, seek 'nutrition label' disclosures from AI and data vendors, and participate in sector information sharing on AI-enabled fraud and cyber threats.
Is the March 2024 Treasury AI report binding?
No. It is a report with recommendations and next steps; it created no rules. Its recommendations were later turned into voluntary AIEOG resources in 2026.
| Date | Document | Status |
|---|---|---|
| Jun 24, 2026 | FSOC AI Innovation Series (Mar–May 2026) — Artificial Intelligence Innovation Series — FSOC and Treasury AI Transformation Office roundtables | Final |
| Feb 19, 2026 | Treasury FS AI RMF and AI Lexicon (Feb 2026) — Financial Services AI Risk Management Framework (FS AI RMF) and Artificial Intelligence Lexicon | Final |
| Dec 11, 2025 | FSOC 2025 Annual Report — Financial Stability Oversight Council 2025 Annual Report — Section 3.4, Harnessing Artificial Intelligence to Promote Financial Stability | Final |
| Dec 19, 2024 | Treasury AI in Financial Services report (Dec 2024) — Artificial Intelligence in Financial Services — Report on the Uses, Opportunities, and Risks of AI in the Financial Services Sector | Final |
| Dec 6, 2024 | FSOC 2024 Annual Report — Financial Stability Oversight Council 2024 Annual Report — Section 3.3.3, The Use of Artificial Intelligence in Financial Services | Superseded |
| Oct 17, 2024 | Treasury $4B AI fraud-prevention announcement (Oct 2024) — Treasury Announces Enhanced Fraud Detection Processes, Including Machine Learning AI, Prevented and Recovered Over $4 Billion in Fiscal Year 2024 | Final |
Follow every document these regulators publish
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →