# How does the FDIC regulate AI in banking?

Source: https://www.bankingnewsai.com/ai-regulation/fdic
Last updated: Sep 21, 2026

The FDIC has no AI-specific rule. It supervises AI at the roughly 2,800 state non-member banks it oversees through interagency model risk management guidance, third-party risk guidance, and safety-and-soundness examination. On April 17, 2026 it issued FIL-15-2026, adopting the revised interagency Model Risk Management guidance jointly with the OCC and Federal Reserve, rescinding FIL-22-2017 (its 2017 adoption of the 2011 framework) and FIL-27-2021 (the BSA/AML model-risk statement). The revised guidance is most relevant to banks above $30 billion in assets, is explicitly non-binding, and leaves generative and agentic AI to banks' broader risk-management programs.

## At a glance

| Field | Value |
| --- | --- |
| Full name | Federal Deposit Insurance Corporation |
| Jurisdiction | United States (state-chartered banks that are not Federal Reserve members; deposit insurer for all insured banks) |
| Role | Prudential supervisor and deposit insurer |
| How binding | Supervisory guidance |
| Applies to | FDIC-supervised state non-member banks and state savings associations; interagency guidance it co-issues also covers OCC- and Fed-supervised institutions |
| Key document | FIL-15-2026 — Agencies Revise the Interagency Model Risk Management Guidance (Apr 17, 2026) |
| Latest move | Apr 2026 adoption of revised interagency model risk guidance (FIL-15-2026); Jun 2026 testimony describing it as 'an avenue for the safe and sound adoption of technology' |

## Overview

The FDIC is the primary federal regulator for state-chartered banks that are not members of the Federal Reserve System — mostly community banks — so its AI posture is shaped by institutions that buy AI from vendors rather than build it. That is why its most-cited AI-relevant documents are the June 2023 Interagency Guidance on Third-Party Relationships (FIL-29-2023) and the May 2024 community-bank third-party risk guide, alongside the model risk framework it shares with the OCC and Federal Reserve.

Under Chairman Travis Hill (Acting Chairman from January 2025, Chairman since 2026) the FDIC has pivoted to an innovation-permissive stance: his January 10, 2025 'Charting a New Course' speech called for reinvigorating the FDiTech innovation lab and issuing guidance on fintech partnerships, AI, and digital assets, and March 2026 congressional testimony described banks using AI for fraud detection, AML/CFT, and credit underwriting while the FDIC pilots generative AI for its own staff. The April 2026 model risk revision is the first concrete deliverable; the agency's own Risk Review and cybersecurity reports frame generative AI mainly as a fraud and authentication threat — deepfakes, voice cloning, and synthetic identities.

## What FDIC guidance applies to agentic AI in banks, and how does it compare with other regulators?

The FDIC has issued no guidance addressed to agentic AI, and its most recent statement on the subject is a carve-out: the revised interagency Model Risk Management guidance it adopted on April 17, 2026 as FIL-15-2026 says generative and agentic AI are not within its scope and are to be managed through banks' broader risk-management and governance programmes, while the agencies promised a request for information on AI and model risk. What does apply at the roughly 2,800 state non-member banks the FDIC supervises is the surrounding framework: the third-party guidance of FIL-29-2023 for any agent built on a vendor model or platform, the safety-and-soundness and consumer-protection law that attaches to whatever an agent does, and the FDIC's own risk reporting, which since the 2024 Risk Review has described generative AI as a threat to identity and authentication controls. The FDIC's public posture is pro-adoption: Chairman Travis Hill told Congress in June 2026 that the model-risk revision 'supports the use of innovative technology' and that the pending BSA/AML programme rule encourages AI to detect illicit finance, and RMS Director Ryan Billingsley said in March 2026 that supervised banks are already testing generative AI to write code, summarise calls and summarise loan files. Compared with its peers, the FDIC is the quietest: the OCC has published what large banks' agentic use looks like, DFS has told New York firms to review AI-generated code, NIST has an open workstream on agent security, and the FSB's Sound Practice 10 asks for extra human-oversight measures for highly autonomous agents.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| FIL-15-2026 (revised interagency model risk management guidance) | [FDIC](https://www.bankingnewsai.com/ai-regulation/fdic) | Risk-based model risk management scaled to size and complexity, most relevant above $30 billion; generative and agentic AI expressly outside scope and left to broader risk management and governance; an interagency RFI on AI promised. | Apr 17, 2026 | [FDIC FIL-15-2026](https://www.bankingnewsai.com/ai-regulation/documents/fdic-fil-15-2026) |
| FIL-29-2023 (interagency third-party guidance) | [FDIC](https://www.bankingnewsai.com/ai-regulation/fdic) | Planning, due diligence, contracting, ongoing monitoring and termination for any third-party relationship — the framework an agent built on a vendor model, orchestration platform or cloud service is examined against; the bank keeps responsibility for the outcome. | Jun 6, 2023 | [FDIC FIL-29-2023](https://www.bankingnewsai.com/ai-regulation/documents/fdic-fil-29-2023) |
| FDIC 2024 Risk Review, operational and cyber risks | [FDIC](https://www.bankingnewsai.com/ai-regulation/fdic) | Generative AI named as a new risk to critical infrastructure and as a tool for circumventing identity- and authentication-based controls through deepfakes, voice cloning and forged documents. | May 22, 2024 | [FDIC 2024 Risk Review](https://www.bankingnewsai.com/ai-regulation/documents/fdic-risk-review-2024) |
| FDIC 2025 Report on Cybersecurity and Resilience | [FDIC](https://www.bankingnewsai.com/ai-regulation/fdic) | Nation-state and criminal actors using generative AI for reconnaissance, malware and phishing; AI-generated synthetic identities complicating onboarding and verification. | Jul 2025 | [FDIC 2025 Report on Cybersecurity and Resilience](https://www.bankingnewsai.com/ai-regulation/documents/fdic-cybersecurity-resilience-report-2025) |
| Billingsley testimony, House Financial Services Subcommittee | [FDIC](https://www.bankingnewsai.com/ai-regulation/fdic) | Supervised banks use AI for fraud, AML/CFT and underwriting and are testing generative AI to answer staff questions, summarise calls, write code and summarise applicant financials; the FDIC itself is piloting generative AI internally. | Mar 26, 2026 | [FDIC House testimony on AI and innovation (Mar 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fdic-testimony-innovation-speed-of-markets-2026) |
| Chairman Hill, oversight testimony | [FDIC](https://www.bankingnewsai.com/ai-regulation/fdic) | The revised model-risk guidance 'supports the use of innovative technology'; the BSA programme proposal encourages emerging technologies including AI to detect and disrupt illicit finance; no AI-specific rulemaking announced. | Jun 4, 2026 | [Hill House oversight testimony (Jun 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fdic-testimony-oversight-prudential-regulators-2026) |
| FinCEN AML/CFT programme NPRM | [FinCEN](https://www.bankingnewsai.com/ai-regulation/fincen) | 'Effective use of artificial intelligence' would count in an institution's favour if finalised — the BSA rule Hill tied to AI adoption. | Proposed 2026 | [2026 AML/CFT Program Proposed Rule](https://www.bankingnewsai.com/ai-regulation/documents/fincen-aml-cft-program-nprm-2026) |
| OCC Semiannual Risk Perspective, Spring 2026 | [OCC](https://www.bankingnewsai.com/ai-regulation/occ) | The comparison point: the OCC describes national banks' generative and agentic AI as productivity and customer-experience tools used with guardrails and human-in-the-loop accountability, and warns that governance is essential before use expands to material financial decisions. | May 7, 2026 | [OCC Semiannual Risk Perspective, Spring 2026](https://www.bankingnewsai.com/ai-regulation/documents/occ-semiannual-risk-perspective-spring-2026) |
| Vice Chair Bowman, FSOC AI roundtable | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | The Fed's parallel position: no pre-emptive AI rulemaking, existing frameworks accommodate AI, generative and agentic AI stay outside model-risk guidance. | May 2026 | [Bowman: AI in the Financial System (May 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fed-bowman-speech-ai-financial-system-2026) |
| DFS Industry Letter on frontier AI models | [NY DFS](https://www.bankingnewsai.com/ai-regulation/ny-dfs) | For New York-regulated banks, including FDIC-supervised state banks: human review of AI-generated code before deployment, mapped dependencies, faster remediation — the most specific agent-adjacent expectation any US regulator has issued. | May 21, 2026 | [DFS Frontier AI Models Industry Letter (May 2026)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-industry-letter-2026-05-21-frontier-ai-models) |
| NIST CAISI request for information on AI agent security | [NIST](https://www.bankingnewsai.com/ai-regulation/nist) | The federal technical workstream on agents: indirect prompt injection, misaligned behaviour, and constraining and monitoring what an agent can access. | Jan 12, 2026 | [CAISI RFI on AI agent security (2026)](https://www.bankingnewsai.com/ai-regulation/documents/nist-caisi-rfi-ai-agent-security-2026) |
| FSB Sound Practice 10 (human oversight) | [FSB](https://www.bankingnewsai.com/ai-regulation/fsb) | Human oversight proportionate to autonomy, with additional measures for highly autonomous agentic AI; named agentic risks include autonomous multi-step actions and agentic memory poisoning. | Final report due Oct 2026 | [FSB AI sound practices consultation (June 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fsb-ai-sound-practices-consultation-2026) |
| EU AI Act (for FDIC-supervised banks with EU operations) | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | No 'agent' category: an agent is regulated by what it does, and high-risk uses such as credit scoring of natural persons carry risk-management, logging and human-oversight duties whatever the architecture. | Stand-alone Annex III obligations from Dec 2, 2027 | [Regulation (EU) 2024/1689](https://www.bankingnewsai.com/ai-regulation/documents/eu-ai-act-regulation-2024-1689) |

The FDIC's silence on agents is deliberate rather than accidental. Chairman Hill's stated preference is a technology-neutral supervisory approach, and the agency's two 2026 statements to Congress frame AI as something the revised model-risk guidance and the BSA programme rule make easier to adopt, not something that needs a new rulebook. The 2021 interagency RFI on AI, which the FDIC transmitted as FIL-20-2021, produced no AI guidance; the agencies chose instead to rewrite model risk management, and the April 2026 result draws the line at generative and agentic systems. Until the promised interagency RFI turns into guidance, an FDIC examiner assessing an agent has three questions from existing frameworks: is any component a model under the 2026 definition (validate it), is any component a third-party service (FIL-29-2023 lifecycle), and does the agent's action create a safety-and-soundness or consumer-compliance exposure (the law that already applies).

The comparison with other regulators is one of specificity, not direction. Every US agency has taken the same line — existing frameworks, no pre-emptive rule — but the OCC has said in print what it observes at large banks and when governance becomes 'essential'; DFS has told New York firms to put a human between AI-generated code and production; NIST has put agent security out for comment; and the FSB has written the international expectation that oversight tightens as autonomy grows. State non-member banks in New York are bound by DFS's letters as well as by FDIC supervision, so the most concrete agent-adjacent expectation many FDIC banks face comes from Albany rather than Washington.

The impact question — what agentic AI does to an FDIC-supervised bank's supervisory position — therefore turns on materiality. An agent that drafts, summarises or routes for a person sits in the 'productivity tool' category the OCC describes and the FDIC's own generative-AI pilots occupy; the controls are third-party, cyber and data. An agent that decides or acts toward a customer pulls in the consumer-protection law the FDIC enforces directly, and if it embeds a scoring or monitoring model, that model is validated under FIL-15-2026. The forthcoming RFI is the document that will speak to agents by name, and the FDIC will sign it jointly with the OCC and the Fed.

### What this means in practice

- Classify each agent by what it touches: staff productivity, customer-indirect, or customer-direct decisions and actions. The FDIC's applicable framework changes at each step even though none of it names agents.
- Treat the orchestration platform, the foundation model and any tool the agent calls as third-party relationships under FIL-29-2023, with due diligence, contract audit and data rights, monitoring and an exit plan.
- Validate any scoring, fraud or monitoring model an agent invokes under FIL-15-2026; the agent does not change the model's status.
- For New York state banks, implement DFS's code-review, dependency-mapping and remediation expectations now — FDIC examiners coordinate with DFS on those institutions.
- Prepare a comment for the interagency RFI on AI and model risk: it is the first federal document that will address agentic AI directly, and the FDIC will be a co-signatory.

## Documents (9)

- Jun 4, 2026 — [Hill House oversight testimony (Jun 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fdic-testimony-oversight-prudential-regulators-2026): Statement of Chairman Travis Hill: Oversight of Prudential Regulators (Final)
- Apr 17, 2026 — [FDIC FIL-15-2026](https://www.bankingnewsai.com/ai-regulation/documents/fdic-fil-15-2026): Agencies Revise the Interagency Model Risk Management Guidance (In force)
- Mar 26, 2026 — [FDIC House testimony on AI and innovation (Mar 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fdic-testimony-innovation-speed-of-markets-2026): Innovation at the Speed of Markets: How Regulators Keep Pace with Technology (Final)
- Jul 14, 2025 — [FDIC 2025 Report on Cybersecurity and Resilience](https://www.bankingnewsai.com/ai-regulation/documents/fdic-cybersecurity-resilience-report-2025): 2025 Report on Cybersecurity and Resilience (Final)
- Jan 10, 2025 — [Hill 'Charting a New Course' speech](https://www.bankingnewsai.com/ai-regulation/documents/fdic-charting-new-course-speech-2025): Charting a New Course: Preliminary Thoughts on FDIC Policy Issues (Final)
- May 22, 2024 — [FDIC 2024 Risk Review](https://www.bankingnewsai.com/ai-regulation/documents/fdic-risk-review-2024): 2024 Risk Review — Section 5: Operational and Cyber Risks (Final)
- Jun 6, 2023 — [FDIC FIL-29-2023](https://www.bankingnewsai.com/ai-regulation/documents/fdic-fil-29-2023): Interagency Guidance on Third-Party Relationships: Risk Management (In force)
- Apr 9, 2021 — [FDIC FIL-27-2021](https://www.bankingnewsai.com/ai-regulation/documents/fdic-fil-27-2021): Interagency Statement on Model Risk Management for Bank Systems Supporting BSA/AML and OFAC Compliance (Superseded)
- Mar 29, 2021 — [FDIC FIL-20-2021](https://www.bankingnewsai.com/ai-regulation/documents/fdic-fil-20-2021): Request for Information and Comment on Financial Institutions' Use of Artificial Intelligence, Including Machine Learning (Final)

## Timeline

- Jun 4, 2026 — [Hill House oversight testimony (Jun 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fdic-testimony-oversight-prudential-regulators-2026): Hill House oversight testimony (Jun 2026) — Statement of Chairman Travis Hill: Oversight of Prudential Regulators — In June 4, 2026 testimony to the House Financial Services Committee, FDIC Chairman Travis Hill described the April 2026 model risk revision as replacing 2011-era standards that had constrained banks' ability to use innovative modeling approaches, saying the revised guidance 'supports the use of innovative technology and sets forth a risk-based approach tailored to size and complexity.' He also said the FDIC's proposal to implement the BSA program rule 'encourages responsible innovation and the use of emerging technologies, such as artificial intelligence, to detect and disrupt illicit finance activity more effectively.'
- Apr 17, 2026 — [FDIC FIL-15-2026](https://www.bankingnewsai.com/ai-regulation/documents/fdic-fil-15-2026): FDIC FIL-15-2026 — Agencies Revise the Interagency Model Risk Management Guidance — On April 17, 2026 the FDIC issued FIL-15-2026, adopting revised interagency Model Risk Management guidance jointly with the OCC and Federal Reserve and rescinding FIL-22-2017 and FIL-27-2021.
- Mar 26, 2026 — [FDIC House testimony on AI and innovation (Mar 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fdic-testimony-innovation-speed-of-markets-2026): FDIC House testimony on AI and innovation (Mar 2026) — Innovation at the Speed of Markets: How Regulators Keep Pace with Technology — On March 26, 2026 Ryan Billingsley, Director of the FDIC's Division of Risk Management Supervision, told the House Financial Services Subcommittee on Digital Assets, Financial Technology and Artificial Intelligence that banks are using AI and machine learning for fraud detection, AML/CFT, and credit underwriting, and are testing generative AI to answer customer questions, summarize service calls, write code, and summarize loan-applicant financials.
- Jul 14, 2025 — [FDIC 2025 Report on Cybersecurity and Resilience](https://www.bankingnewsai.com/ai-regulation/documents/fdic-cybersecurity-resilience-report-2025): FDIC 2025 Report on Cybersecurity and Resilience — 2025 Report on Cybersecurity and Resilience — The FDIC's 2025 Report on Cybersecurity and Resilience, submitted to the House Financial Services and Senate Banking Committees under Section 108 of the Consolidated Appropriations Act, 2021 and posted in July 2025, warns that nation-state actors and cybercriminals are using generative AI to research targets and vulnerabilities, write malware, and run phishing campaigns, and that AI is being used to circumvent banks' identity and authentication controls.
- Jan 10, 2025 — [Hill 'Charting a New Course' speech](https://www.bankingnewsai.com/ai-regulation/documents/fdic-charting-new-course-speech-2025): Hill 'Charting a New Course' speech — Charting a New Course: Preliminary Thoughts on FDIC Policy Issues — In a January 10, 2025 speech to the American Bar Association, then-Vice Chairman Travis Hill set out the agenda he would pursue as Acting Chairman, including 'a shift in supervisory attitude towards new technology.' He called for reinvigorating the FDiTech innovation lab, hiring staff with hands-on technology experience, and having the FDIC consider additional guidance on fintech partnerships, artificial intelligence, and digital assets and tokenization.
- May 22, 2024 — [FDIC 2024 Risk Review](https://www.bankingnewsai.com/ai-regulation/documents/fdic-risk-review-2024): FDIC 2024 Risk Review — 2024 Risk Review — Section 5: Operational and Cyber Risks — The FDIC's 2024 Risk Review, published May 22, 2024, is the agency's most explicit published treatment of AI as a bank risk.
- Jun 6, 2023 — [FDIC FIL-29-2023](https://www.bankingnewsai.com/ai-regulation/documents/fdic-fil-29-2023): FDIC FIL-29-2023 — Interagency Guidance on Third-Party Relationships: Risk Management — FIL-29-2023, issued June 6, 2023, transmits the final Interagency Guidance on Third-Party Relationships: Risk Management from the FDIC, Federal Reserve, and OCC.
- Jul 1, 2021 — [Comment period closes on the interagency AI RFI](https://www.fdic.gov/news/financial-institution-letters/2021/fil21034.html) — After a 30-day extension announced in FIL-34-2021, the comment window on the five-agency AI/ML request for information closed July 1, 2021. No follow-on interagency AI rule or guidance was issued from it.
- Apr 9, 2021 — [FDIC FIL-27-2021](https://www.bankingnewsai.com/ai-regulation/documents/fdic-fil-27-2021): FDIC FIL-27-2021 — Interagency Statement on Model Risk Management for Bank Systems Supporting BSA/AML and OFAC Compliance — FIL-27-2021, dated April 9, 2021, transmitted an interagency statement explaining how the 2011 model risk management principles apply to the systems and models banks use for Bank Secrecy Act/anti-money-laundering and OFAC sanctions compliance — including machine-learning transaction monitoring.
- Mar 29, 2021 — [FDIC FIL-20-2021](https://www.bankingnewsai.com/ai-regulation/documents/fdic-fil-20-2021): FDIC FIL-20-2021 — Request for Information and Comment on Financial Institutions' Use of Artificial Intelligence, Including Machine Learning — On March 29, 2021 the FDIC issued FIL-20-2021 transmitting the first coordinated federal request for information on banks' use of AI and machine learning, issued jointly with the Federal Reserve, OCC, CFPB, and NCUA (FDIC docket RIN 3064-ZA24).

## What to watch next

- Whether the FDIC, OCC, and Federal Reserve follow the April 2026 model risk revision with a request for information or guidance specifically covering generative and agentic AI
- Delivery on Chairman Hill's stated agenda of guidance on fintech partnerships and AI, and the revived FDiTech lab
- How FDIC examiners apply FIL-29-2023 third-party risk expectations to community banks that source AI fraud, underwriting, and chatbot tools from vendors — the FDIC proposed replacing FIL-29-2023 on September 11, 2026 (FIL-58-2026), jointly with the OCC, Fed and NCUA; comments due November 16, 2026
- The final BSA/AML program rule, which the FDIC says should encourage AI-driven detection of illicit finance

## FAQ

### Does the FDIC have its own AI guidance for banks?

No. The FDIC regulates AI through interagency documents it co-issues — the April 2026 revised Model Risk Management guidance (FIL-15-2026) and the June 2023 third-party risk management guidance (FIL-29-2023) — plus safety-and-soundness, fair-lending, and BSA/AML examination. Chairman Travis Hill has said AI is a topic on which the FDIC should consider issuing additional guidance.

### Which FDIC FIL adopted the 2026 model risk guidance, and what did it rescind?

FIL-15-2026, issued April 17, 2026, adopts the revised interagency Model Risk Management guidance and rescinds FIL-22-2017 (FDIC adoption of the 2011 supervisory guidance) and FIL-27-2021 (the 2021 statement on model risk for BSA/AML and OFAC systems). It applies to all FDIC-supervised institutions but is expected to be most relevant to banks over $30 billion in assets.

### How does the FDIC treat AI bought from a vendor?

As a third-party relationship. The June 2023 interagency guidance (FIL-29-2023) expects planning, due diligence, contract negotiation, ongoing monitoring, and termination controls scaled to risk, and states that using a third party does not diminish the bank's responsibility for safe and sound operation and compliance. The 2026 model risk guidance separately addresses third-party vendor models.
## Which fintechs does the FDIC supervise or license?

[Block](https://www.bankingnewsai.com/fintech/block)


## Compare

- [SR 11-7 vs SR 26-2](https://www.bankingnewsai.com/ai-regulation/compare/sr-11-7-vs-sr-26-2): SR 11-7 vs SR 26-2: What Changed in Bank Model Risk Guidance

Related authorities: [OCC](https://www.bankingnewsai.com/ai-regulation/occ), [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve), [CFPB](https://www.bankingnewsai.com/ai-regulation/cfpb), [FinCEN](https://www.bankingnewsai.com/ai-regulation/fincen), [NCUA](https://www.bankingnewsai.com/ai-regulation/ncua).

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/fdic
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
