AI Regulation Tracker · Warnings

What are regulators
warning banks about?

Last updated Aug 26, 2026 · 20 formal warnings tracked

Regulators' AI warnings to banks cluster in three areas: AI-enabled fraud — deepfake identity documents, voice cloning and industrialized scams (FinCEN, FDIC, OCC, CFTC); AI-driven cyber threats — capped by the ECB's July 2026 Dear-CEO letter requiring action plans from every significant institution by October 31, 2026 (with NY DFS and the UK authorities issuing parallel letters); and financial-stability risks from model and vendor concentration (FSB, FSOC, Bank of England). The newest warning tracked here is ESA Statement on ICT risks from frontier AI models (JC 2026 25) (Jul 31, 2026).

What have regulators warned banks about AI fraud and deepfakes?

The most concrete warnings: criminals using generative AI to defeat identity verification, clone voices, forge documents and industrialize scams — with red flags banks are expected to detect and report.

DateAuthorityWarningStatus
Jul 24, 2026FinCENFIN-2026-Alert004 (Federal Student Aid Fraud)FinCEN Alert FIN-2026-Alert004, issued July 24, 2026, asks financial institutions to detect and report fraud rings stealing federal student aid through 'ghost students' and 'straw students.' It states that fraudsters…In force
May 7, 2026OCCOCC Semiannual Risk Perspective, Spring 2026The OCC's Spring 2026 Semiannual Risk Perspective, released May 7, 2026, says artificial intelligence is 'significantly transforming the cyber threat landscape' — lowering the barrier to entry for attackers and…Final
Dec 11, 2025U.S. TreasuryFSOC 2025 Annual ReportFSOC's 2025 annual report, unanimously approved December 11, 2025, made 'harnessing AI to promote financial stability' one of four priority areas and formalized an FSOC Artificial Intelligence Working Group.Final
Jul 14, 2025FDICFDIC 2025 Report on Cybersecurity and ResilienceThe FDIC's 2025 Report on Cybersecurity and Resilience, submitted to the House Financial Services and Senate Banking Committees under Section 108 of the Consolidated Appropriations Act, 2021 and posted in July 2025,…Final
Mar 24, 2025NISTNIST AI 100-2e2025 (Adversarial ML)NIST AI 100-2e2025, finalized on March 24, 2025, is NIST's taxonomy and terminology of adversarial machine learning attacks and mitigations, updating the January 2024 edition (AI 100-2e2023).Final
Nov 14, 2024FSBFSB AI financial stability report (Nov 2024)On 14 November 2024 the FSB published its post-generative-AI assessment of AI's financial-stability implications.Final
Nov 13, 2024FinCENFIN-2024-Alert004 (Deepfake Media)FinCEN Alert FIN-2024-Alert004, issued November 13, 2024, warns that criminals are using generative AI to create deepfake identity documents, images, video, and audio to defeat banks' identity verification,…In force
Oct 16, 2024NY DFSDFS AI Cybersecurity Industry Letter (Oct 2024)On October 16, 2024, DFS issued an Industry Letter telling every DFS-regulated entity how to address AI-related cyber risk under 23 NYCRR Part 500.In force
May 22, 2024FDICFDIC 2024 Risk ReviewThe FDIC's 2024 Risk Review, published May 22, 2024, is the agency's most explicit published treatment of AI as a bank risk.Final
Mar 27, 2024U.S. TreasuryTreasury AI cybersecurity risks report (Mar 2024)On March 27, 2024 the Treasury released 'Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector', written under Executive Order 14110 and led by its Office of Cybersecurity and…Final
Jan 25, 2024CFTCCFTC AI Scams Customer AdvisoryOn January 25, 2024 the CFTC's Office of Customer Education and Outreach warned that fraudsters exploit interest in artificial intelligence to sell trading bots, signal services, and crypto schemes promising guaranteed…In force

What are regulators saying about AI-driven cyber risk to banks?

Supervisors now treat AI as a force multiplier for attackers. The strongest signal yet: the ECB's first technology-focused Dear-CEO letter, requiring significant institutions to file AI-cyber action plans.

DateAuthorityWarningStatus
Jul 31, 2026EBAESA Statement on ICT risks from frontier AI models (JC 2026 25)On July 31, 2026 the EBA, EIOPA and ESMA published joint statement JC 2026 25 on ICT risks from frontier AI models, warning that highly capable AI models sharply accelerate vulnerability discovery and exploitation and…In force
Jul 7, 2026ECBECB 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301)On 7 July 2026 Claudia Buch, Chair of the ECB Supervisory Board, sent letter SSM-2026-0301, 'Addressing AI-enabled cybersecurity threats', to the CEO of every significant institution.In force
May 21, 2026NY DFSDFS Frontier AI Models Industry Letter (May 2026)On May 21, 2026, DFS issued an Industry Letter warning that 'frontier AI models' able to identify vulnerabilities and build exploits at unprecedented speed and scale will soon become widely available, and directing…In force
May 21, 2026NY DFSDFS Heightened Threat Environment Guidance (May 2026)Issued May 21, 2026 as the companion to DFS's frontier-AI letter, this guidance defines a 'heightened cybersecurity threat environment' as one where risks are significantly elevated with a high likelihood of impacting…In force
May 15, 2026UK (BoE / PRA / FCA)BoE/FCA/HMT joint statement on frontier AI and cyber resilience (May 2026)On 15 May 2026 the Bank of England, FCA and HM Treasury jointly warned that frontier AI models' cyber capabilities already exceed what a skilled practitioner could achieve, at higher speed, scale and lower cost, and…In force
Oct 10, 2025FSBFSB AI monitoring report (Oct 2025)Published 10 October 2025, this report gives national authorities key considerations and candidate indicators for tracking AI adoption and the vulnerabilities identified in November 2024 — third-party dependencies,…Final
Apr 9, 2025UK (BoE / PRA / FCA)FPC Financial Stability in Focus: AI (Apr 2025)The Bank of England's Financial Policy Committee published its first dedicated assessment of AI and financial stability on 9 April 2025.Final
May 1, 2024ECBECB FSR May 2024 AI special featureIn May 2024 the ECB's Financial Stability Review carried a special feature, 'The rise of artificial intelligence: benefits and risks for financial stability', by Leitner, Singh, van der Kraaij and Zsámboki.Final

What systemic AI risks are authorities monitoring?

Concentration in a few model and cloud providers, herding from common models, and AI-washing — claims about AI that the SEC has already brought enforcement over.

DateAuthorityWarningStatus
Feb 13, 2024SECGensler 'AI washing' remarks at Yale (Feb 2024)On February 13, 2024 SEC Chair Gary Gensler used a Yale Law School speech to put 'AI washing' on the record as a securities-law problem: public companies and investment advisers that overstate their AI use or make…Final

What has FinCEN warned banks about deepfakes?

FinCEN's November 2024 alert (FIN-2024-Alert004) warns that criminals are using generative AI to create deepfake identity documents and media that defeat bank onboarding and verification, lists red flags — inconsistencies between documents and live verification, re-used device fingerprints, synthetic photos — and tells banks to reference the alert in Suspicious Activity Reports. A July 2026 follow-up alert covers AI-assisted federal student-aid fraud schemes.

What is the ECB's 'Dear CEO' letter on AI?

On July 7, 2026 the ECB sent letter SSM-2026-0301 — its first Dear-CEO letter devoted to a technology threat — warning every significant euro-area institution about AI-enabled cybersecurity risks: accelerated vulnerability exploitation, AI-enhanced phishing and deepfake-assisted intrusion. Each institution must submit a comprehensive action plan to its Joint Supervisory Team by October 31, 2026.

Is AI-enabled fraud a US supervisory priority?

Yes. The OCC's Spring 2026 Semiannual Risk Perspective flags AI as amplifying fraud and the speed and sophistication of cyberattacks; the FDIC's 2024 Risk Review devotes a section to deepfakes, voice cloning and check fraud; the CFTC issued a customer advisory on AI scams; and New York DFS has issued three industry letters on AI cyber risk, including two in May 2026 on frontier-model threats.

Every new warning lands in the brief

6 curated AI stories for banking executives · Every morning · Free

Subscribe to BankingNewsAI →