AI Regulation Tracker · United States (state-chartered banks that are not Federal Reserve members; deposit insurer for all insured banks)

How does the FDIC regulate AI in banking?

Last updated Aug 26, 2026 · Updated as rules change

The FDIC has no AI-specific rule. It supervises AI at the roughly 2,800 state non-member banks it oversees through interagency model risk management guidance, third-party risk guidance, and safety-and-soundness examination. On April 17, 2026 it issued FIL-15-2026, adopting the revised interagency Model Risk Management guidance jointly with the OCC and Federal Reserve, rescinding FIL-22-2017 (its 2017 adoption of the 2011 framework) and FIL-27-2021 (the BSA/AML model-risk statement). The revised guidance is most relevant to banks above $30 billion in assets, is explicitly non-binding, and leaves generative and agentic AI to banks' broader risk-management programs.

Full nameFederal Deposit Insurance Corporation
RolePrudential supervisor and deposit insurer
Force on banksSupervisory guidance
Applies toFDIC-supervised state non-member banks and state savings associations; interagency guidance it co-issues also covers OCC- and Fed-supervised institutions
Key documentFIL-15-2026 — Agencies Revise the Interagency Model Risk Management Guidance (Apr 17, 2026)
Latest moveApr 2026 adoption of revised interagency model risk guidance (FIL-15-2026); Jun 2026 testimony describing it as 'an avenue for the safe and sound adoption of technology'
Documents tracked9 · all documents →

The FDIC is the primary federal regulator for state-chartered banks that are not members of the Federal Reserve System — mostly community banks — so its AI posture is shaped by institutions that buy AI from vendors rather than build it. That is why its most-cited AI-relevant documents are the June 2023 Interagency Guidance on Third-Party Relationships (FIL-29-2023) and the May 2024 community-bank third-party risk guide, alongside the model risk framework it shares with the OCC and Federal Reserve.

Under Chairman Travis Hill (Acting Chairman from January 2025, Chairman since 2026) the FDIC has pivoted to an innovation-permissive stance: his January 10, 2025 'Charting a New Course' speech called for reinvigorating the FDiTech innovation lab and issuing guidance on fintech partnerships, AI, and digital assets, and March 2026 congressional testimony described banks using AI for fraud detection, AML/CFT, and credit underwriting while the FDIC pilots generative AI for its own staff. The April 2026 model risk revision is the first concrete deliverable; the agency's own Risk Review and cybersecurity reports frame generative AI mainly as a fraud and authentication threat — deepfakes, voice cloning, and synthetic identities.

What has the FDIC actually published on AI?

DateDocumentStatus
Jun 4, 2026Hill House oversight testimony (Jun 2026)Statement of Chairman Travis Hill: Oversight of Prudential RegulatorsFinal
Apr 17, 2026FDIC FIL-15-2026Agencies Revise the Interagency Model Risk Management GuidanceIn force
Mar 26, 2026FDIC House testimony on AI and innovation (Mar 2026)Innovation at the Speed of Markets: How Regulators Keep Pace with TechnologyFinal
Jul 14, 2025FDIC 2025 Report on Cybersecurity and Resilience2025 Report on Cybersecurity and ResilienceFinal
Jan 10, 2025Hill 'Charting a New Course' speechCharting a New Course: Preliminary Thoughts on FDIC Policy IssuesFinal
May 22, 2024FDIC 2024 Risk Review2024 Risk Review — Section 5: Operational and Cyber RisksFinal
Jun 6, 2023FDIC FIL-29-2023Interagency Guidance on Third-Party Relationships: Risk ManagementIn force
Apr 9, 2021FDIC FIL-27-2021Interagency Statement on Model Risk Management for Bank Systems Supporting BSA/AML and OFAC ComplianceSuperseded
Mar 29, 2021FDIC FIL-20-2021Request for Information and Comment on Financial Institutions' Use of Artificial Intelligence, Including Machine LearningFinal
DateTypeDocument / event
Jun 4, 2026SpeechHill House oversight testimony (Jun 2026) — Statement of Chairman Travis Hill: Oversight of Prudential Regulators. In June 4, 2026 testimony to the House Financial Services Committee, FDIC Chairman Travis Hill described the April 2026 model risk revision as replacing 2011-era standards that had constrained banks' ability to use innovative modeling approaches, saying the revised guidance 'supports the use of innovative technology and sets forth a risk-based approach tailored to size and complexity.' He also said the FDIC's proposal to implement the BSA program rule 'encourages responsible innovation and the use of emerging technologies, such as artificial intelligence, to detect and disrupt illicit finance activity more effectively.' source ↗
Apr 17, 2026GuidanceFDIC FIL-15-2026 — Agencies Revise the Interagency Model Risk Management Guidance. On April 17, 2026 the FDIC issued FIL-15-2026, adopting revised interagency Model Risk Management guidance jointly with the OCC and Federal Reserve and rescinding FIL-22-2017 and FIL-27-2021. source ↗
Mar 26, 2026SpeechFDIC House testimony on AI and innovation (Mar 2026) — Innovation at the Speed of Markets: How Regulators Keep Pace with Technology. On March 26, 2026 Ryan Billingsley, Director of the FDIC's Division of Risk Management Supervision, told the House Financial Services Subcommittee on Digital Assets, Financial Technology and Artificial Intelligence that banks are using AI and machine learning for fraud detection, AML/CFT, and credit underwriting, and are testing generative AI to answer customer questions, summarize service calls, write code, and summarize loan-applicant financials. source ↗
Jul 14, 2025ReportFDIC 2025 Report on Cybersecurity and Resilience — 2025 Report on Cybersecurity and Resilience. The FDIC's 2025 Report on Cybersecurity and Resilience, submitted to the House Financial Services and Senate Banking Committees under Section 108 of the Consolidated Appropriations Act, 2021 and posted in July 2025, warns that nation-state actors and cybercriminals are using generative AI to research targets and vulnerabilities, write malware, and run phishing campaigns, and that AI is being used to circumvent banks' identity and authentication controls. source ↗
Jan 10, 2025SpeechHill 'Charting a New Course' speech — Charting a New Course: Preliminary Thoughts on FDIC Policy Issues. In a January 10, 2025 speech to the American Bar Association, then-Vice Chairman Travis Hill set out the agenda he would pursue as Acting Chairman, including 'a shift in supervisory attitude towards new technology.' He called for reinvigorating the FDiTech innovation lab, hiring staff with hands-on technology experience, and having the FDIC consider additional guidance on fintech partnerships, artificial intelligence, and digital assets and tokenization. source ↗
May 22, 2024ReportFDIC 2024 Risk Review — 2024 Risk Review — Section 5: Operational and Cyber Risks. The FDIC's 2024 Risk Review, published May 22, 2024, is the agency's most explicit published treatment of AI as a bank risk. source ↗
Jun 6, 2023GuidanceFDIC FIL-29-2023 — Interagency Guidance on Third-Party Relationships: Risk Management. FIL-29-2023, issued June 6, 2023, transmits the final Interagency Guidance on Third-Party Relationships: Risk Management from the FDIC, Federal Reserve, and OCC. source ↗
Jul 1, 2021MilestoneComment period closes on the interagency AI RFI. After a 30-day extension announced in FIL-34-2021, the comment window on the five-agency AI/ML request for information closed July 1, 2021. No follow-on interagency AI rule or guidance was issued from it.
Apr 9, 2021GuidanceFDIC FIL-27-2021 — Interagency Statement on Model Risk Management for Bank Systems Supporting BSA/AML and OFAC Compliance. FIL-27-2021, dated April 9, 2021, transmitted an interagency statement explaining how the 2011 model risk management principles apply to the systems and models banks use for Bank Secrecy Act/anti-money-laundering and OFAC sanctions compliance — including machine-learning transaction monitoring. source ↗
Mar 29, 2021ConsultationFDIC FIL-20-2021 — Request for Information and Comment on Financial Institutions' Use of Artificial Intelligence, Including Machine Learning. On March 29, 2021 the FDIC issued FIL-20-2021 transmitting the first coordinated federal request for information on banks' use of AI and machine learning, issued jointly with the Federal Reserve, OCC, CFPB, and NCUA (FDIC docket RIN 3064-ZA24). source ↗
  • Whether the FDIC, OCC, and Federal Reserve follow the April 2026 model risk revision with a request for information or guidance specifically covering generative and agentic AI
  • Delivery on Chairman Hill's stated agenda of guidance on fintech partnerships and AI, and the revived FDiTech lab
  • How FDIC examiners apply FIL-29-2023 third-party risk expectations to community banks that source AI fraud, underwriting, and chatbot tools from vendors
  • The final BSA/AML program rule, which the FDIC says should encourage AI-driven detection of illicit finance

Does the FDIC have its own AI guidance for banks?

No. The FDIC regulates AI through interagency documents it co-issues — the April 2026 revised Model Risk Management guidance (FIL-15-2026) and the June 2023 third-party risk management guidance (FIL-29-2023) — plus safety-and-soundness, fair-lending, and BSA/AML examination. Chairman Travis Hill has said AI is a topic on which the FDIC should consider issuing additional guidance.

Which FDIC FIL adopted the 2026 model risk guidance, and what did it rescind?

FIL-15-2026, issued April 17, 2026, adopts the revised interagency Model Risk Management guidance and rescinds FIL-22-2017 (FDIC adoption of the 2011 supervisory guidance) and FIL-27-2021 (the 2021 statement on model risk for BSA/AML and OFAC systems). It applies to all FDIC-supervised institutions but is expected to be most relevant to banks over $30 billion in assets.

How does the FDIC treat AI bought from a vendor?

As a third-party relationship. The June 2023 interagency guidance (FIL-29-2023) expects planning, due diligence, contract negotiation, ongoing monitoring, and termination controls scaled to risk, and states that using a third party does not diminish the bank's responsibility for safe and sound operation and compliance. The 2026 model risk guidance separately addresses third-party vendor models.

Follow every move these regulators make

6 curated AI stories for banking executives · Every morning · Free

Subscribe to BankingNewsAI →