The U.S. Treasury does not supervise banks' AI directly, but it sets the federal agenda. Its March 27, 2024 report on AI-specific cybersecurity risks, its June 2024 request for information (103 comment letters), and its December 19, 2024 findings report shaped the interagency conversation, and on February 19, 2026 it released a voluntary Financial Services AI Risk Management Framework (FS AI RMF, adapted from the NIST AI RMF) and a shared AI Lexicon through the public-private AIEOG. As FSOC chair, Treasury has flagged AI in every annual report since 2023 and in December 2025 created an FSOC Artificial Intelligence Working Group to promote adoption while monitoring stability risks.
| Full name | U.S. Department of the Treasury (including the Financial Stability Oversight Council) |
| Role | Policy lead, sector risk-management agency, and FSOC chair |
| Force on banks | Voluntary framework |
| Applies to | All U.S. financial institutions indirectly — Treasury issues reports, voluntary frameworks, and FSOC recommendations rather than supervisory rules; the binding follow-through comes from the OCC, Federal Reserve, FDIC, CFPB, SEC, and state regulators |
| Key document | Financial Services AI Risk Management Framework (FS AI RMF) and AI Lexicon — voluntary, NIST-aligned resources released Feb 19, 2026 |
| Latest move | June 2026: FSOC and Treasury's AI Transformation Office concluded the four-roundtable AI Innovation Series (Mar–May 2026); participants asked for regulatory clarity and harmonization to scale AI adoption |
| Documents tracked | 9 · all documents → |
Treasury's AI work runs on three tracks. First, as the Sector Risk Management Agency for financial services, its Office of Cybersecurity and Critical Infrastructure Protection (OCCIP) produced the March 2024 report on managing AI-specific cybersecurity and fraud risks (written under Executive Order 14110) and then, with the FBIIC and the Financial Services Sector Coordinating Council, stood up the Artificial Intelligence Executive Oversight Group (AIEOG). The AIEOG's six workstreams — AI Lexicon and taxonomy, a Financial Services AI Risk Management Framework, explainability, data 'nutrition labels', AI-enhanced fraud, and identity and authentication — were announced complete on February 18, 2026, with the Lexicon and FS AI RMF published the next day as non-binding resources.
Second, Treasury's Domestic Finance office ran the June 2024 Request for Information on the uses, opportunities and risks of AI in financial services and published its findings on December 19, 2024, recommending that regulators clarify supervisory expectations, close gaps in existing frameworks, and that firms review every AI use case for compliance with existing law before deployment. Third, Treasury chairs the Financial Stability Oversight Council: FSOC first named AI an emerging vulnerability in its 2023 annual report, catalogued explainability, data, performance, third-party and bias risks in 2024, and in its 2025 report pivoted to 'harnessing AI to promote financial stability', creating a standing AI Working Group and the 2026 AI Innovation Series of public-private roundtables.
Under the current administration Treasury's posture is explicitly pro-adoption: its 2026 outputs are framed as implementing Executive Order 14179 ('Removing Barriers to American Leadership in Artificial Intelligence', January 2025) and the July 2025 AI Action Plan. Treasury also practices what it recommends — its Office of Payment Integrity credited machine-learning check-fraud detection with $1 billion of the $4 billion in fraud and improper payments it prevented or recovered in fiscal 2024.
What is an AI treasury risk assessment, and which Treasury frameworks apply?
'AI treasury risk assessment' means two different things, and both route through the same documents. For the U.S. Department of the Treasury it is the sector-level assessment it has run since 2024: the March 27, 2024 report on AI-specific cybersecurity and fraud risks, built on 42 institutional interviews and naming a capability gap between large and small banks and a 'fraud data divide'; the December 19, 2024 report synthesising 103 responses to its AI request for information; FSOC's annual AI vulnerability assessments; and, since February 19, 2026, the Financial Services AI Risk Management Framework (FS AI RMF), which adapts NIST's Govern–Map–Measure–Manage cycle to banks and is the closest thing to an official template. For a bank's own treasury function — liquidity and cash-flow forecasting, asset-liability management, funding, hedging and payments — an AI risk assessment is the use-case-level review both Treasury reports recommend before deployment, carried out under the model risk (SR 26-2), third-party (SR 23-4) and risk-data (BCBS 239) frameworks that already govern treasury models, with fraud and cyber controls layered on for payments.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| Treasury report on AI-specific cybersecurity risks | U.S. Treasury | The first federal AI risk assessment for the sector: a widening capability gap between large and small institutions, a 'fraud data divide', data supply-chain and vendor-model opacity, explainability of black-box and generative AI, and regulatory fragmentation — with a recommendation to extend the NIST AI RMF for financial services. | Mar 27, 2024 |
| Treasury report on AI in financial services (RFI findings) | U.S. Treasury | Firms should review every AI use case for compliance with existing law before deployment and re-evaluate periodically; regulators should clarify supervisory expectations and close framework gaps. Names data privacy, bias and third-party dependence as the amplified risks. | Dec 19, 2024 |
| Financial Services AI Risk Management Framework (FS AI RMF) and AI Lexicon | U.S. Treasury | The assessment template: NIST's Govern, Map, Measure and Manage functions adapted to financial-services operations, regulation and consumer protection, with tools to evaluate individual AI use cases across their lifecycle and a common lexicon for risk categories. Voluntary, scalable to institution size. | Since Feb 19, 2026 |
| FSOC 2025 Annual Report — AI Working Group | U.S. Treasury | Standing FSOC Artificial Intelligence Working Group to monitor financial-stability risks from AI adoption inside and outside finance and to identify high-value use cases; 'harnessing AI' is one of four Council priorities. | Since Dec 11, 2025 |
| FSOC AI Innovation Series | U.S. Treasury | Four roundtables (strategy and governance; value and efficiency; cybersecurity and risk management; financial stability) whose readouts record what large institutions consider the binding constraints — regulatory clarity and harmonization — and the risk themes supervisors expect assessments to cover. | Mar–May 2026 |
| NIST AI RMF 1.0 (AI 100-1) | NIST | The parent framework: Govern (cross-cutting), Map (context and risk identification), Measure (testing and metrics), Manage (prioritise, respond, monitor), plus seven trustworthiness characteristics the assessment scores against. | Since Jan 2023 |
| NIST AI 600-1 (Generative AI Profile) | NIST | For generative-AI assistants in the treasury function: confabulation, data privacy, information security (prompt injection, data poisoning), and value-chain integration are the named risks, each with suggested actions mapped to RMF subcategories. | Since Jul 2024 |
| SR 26-2 / OCC Bulletin 2026-13 / FIL-15-2026 | Federal Reserve | Liquidity, interest-rate-risk, funding and cash-flow forecasting models are models in the 2026 definition: development evidence, independent validation with outcomes analysis, ongoing monitoring and governance scaled to materiality. Generative and agentic tools sit outside and need a separate governance path. | Since Apr 17, 2026 |
| SR 23-4 / OCC Bulletin 2023-17 | Federal Reserve | AI embedded in treasury management systems, cash-forecasting platforms or bank-provided portals is a third-party relationship: due diligence on the provider's security and resilience, contract terms on data access and incident notification, ongoing monitoring and an exit plan. | In force |
| BCBS 239 | Basel Committee | Risk data feeding liquidity and funding reports must be accurate, complete, timely and adaptable — the January 2026 Basel newsletter notes AI and automation depend on the same data quality, and data lineage is still 'a work in progress' at many banks. | G-SIBs since 2016 |
| BCBS Principles for Operational Resilience | Basel Committee | Payments, funding and settlement are critical operations: map the internal and external dependencies — including AI components and their vendors — and keep tested continuity, incident and recovery programmes. | Since Mar 2021 |
| FinCEN Alert FIN-2024-Alert004 (deepfake media) | FinCEN | Treasury and payments teams are the target of AI-generated voice and video used in business email compromise and payment fraud; FinCEN recommends phishing-resistant multifactor authentication, live verification and re-verification of high-risk counterparties. | Since Nov 2024 |
| FSB Sound Practice 5 — materiality and risk assessment | FSB | The international shape of a use-case assessment: materiality-based risk assessment before selection, then data governance, explainability, performance management, human oversight, cyber and third-party controls proportionate to the use. | Final report due Oct 2026 |
| Governor Cook on AI and the financial system | Federal Reserve | For AI in trading, hedging and funding decisions: correlated strategies, endogenous model collusion and market concentration are the stability channels the Fed is watching — an assessment of AI in markets-facing treasury activity should cover them. | May 2026 |
The U.S. Treasury's own assessment has a structure worth copying because the sector's regulators helped write it. The March 2024 report, produced by the Office of Cybersecurity and Critical Infrastructure Protection under Executive Order 14110, sorted AI risk into a capability gap (large institutions build in-house, small ones lack data and expertise), a fraud data divide (too little cross-firm fraud data to train models), data supply-chain opacity (nobody can say what trained a vendor model or how customer inputs are reused), explainability of black-box and generative systems, and regulatory fragmentation. Each of those became a workstream of the AIEOG public-private group, and two of its six deliverables — the AI Lexicon and the FS AI RMF — were published on February 19, 2026. The remaining four (explainability, data 'nutrition labels', AI-enhanced fraud, identity and authentication) are still to come; a bank's assessment will need updating when they land.
The FS AI RMF is the practical template. It keeps NIST's four functions and adapts them to what a financial institution has to prove: under Govern, who is accountable for the AI use case and how it fits the risk appetite and existing regulatory obligations; under Map, what the system does, what data it uses, who is affected and what could go wrong; under Measure, how performance, robustness, bias, security and explainability are tested; under Manage, how the residual risk is accepted, monitored and retired. It is explicitly scalable — the AIEOG's stated aim was resources that small and mid-sized institutions can use — and explicitly non-binding. Binding expectations still arrive through the prudential regulators, which is why the requirement stack above pairs each Treasury document with the supervisory rule that examiners actually cite.
Inside a bank, the treasury function is where AI use cases and regulatory frameworks overlap most densely. Cash-flow and liquidity forecasting models are squarely inside the 2026 model risk definition and are among the most material models a bank runs, so they get full validation and outcomes analysis. Asset-liability and hedging models that reach into markets pick up the Fed's financial-stability concerns about correlated AI-driven strategies. Payments are the operational-resilience critical operation and the primary target of AI-enabled fraud — FinCEN's deepfake alert is addressed to exactly the controls a treasury team runs. Generative-AI assistants drafting funding memos or summarising counterparty documents sit outside model risk guidance and inside NIST AI 600-1's confabulation and data-leakage risks. And almost all of it arrives through vendors — treasury management systems, bank portals, cloud-hosted models — which makes SR 23-4 the first framework in the sequence, not the last.
A defensible AI treasury risk assessment therefore has five steps, each anchored to a document. Inventory every AI-enabled system in the function, including AI features switched on inside vendor platforms (SR 23-4; ESAs' July 2026 call for asset inventories that include AI components). Tier each by materiality — the FSB's Sound Practice 5 and the 2026 model risk guidance both make intensity of control follow materiality. Map each tier to its requirement stack: model risk, third-party, BCBS 239 data lineage, operational resilience, fraud and cyber, and consumer law where customers are affected. Measure against the FS AI RMF's Measure function — validation, robustness and adversarial testing, explainability for the decision-makers who rely on the output, drift monitoring. Manage: a named owner, a human able to override, thresholds at which automation stops, vendor exit plans and a re-assessment date, since the Treasury's December 2024 report asks for periodic re-evaluation rather than a one-time review.
What changes next is scheduled. The remaining AIEOG deliverables will add explainability and data-labelling expectations to the Map and Measure steps. The interagency request for information on AI and model risk management, promised in the April 2026 guidance, is the first federal document that will address generative and agentic AI in bank models directly. The FSB's final sound practices are due in October 2026 as a G20 deliverable, and FSOC's 2026 annual report in December will be the first full-year output of its AI Working Group. A treasury AI assessment written today should carry those three dates as review triggers.
WHAT THIS MEANS IN PRACTICE
- Start the assessment with the vendor inventory, not the model inventory: most AI in a bank treasury function arrives as a feature inside a treasury management system or bank portal, and SR 23-4 is the framework that reaches it.
- Use the FS AI RMF's four functions as the section headings of the assessment document. It is the template Treasury and the sector regulators wrote together, and it maps one-to-one onto NIST, which examiners and auditors already recognise.
- Classify liquidity and cash-flow forecasting models as high-materiality under the 2026 model risk guidance and validate them accordingly; a generative-AI assistant that drafts the commentary around them is a different tier with a different control set.
- Put deepfake-resistant payment controls in the AI risk assessment, not only in the fraud programme: FinCEN's red flags, phishing-resistant MFA and live re-verification of counterparties are the mitigations for the AI risk most likely to cost a treasury team money this year.
- Document data lineage for every input to an AI treasury model. BCBS 239 is the standard supervisors cite when they ask how the data feeding AI is controlled, and the Basel Committee said in January 2026 that lineage is where banks still fall short.
- Define the human override for every tier — who can stop an automated funding, hedging or payment action, on what evidence, and how fast — and test it, because the FSB, the OCC and the EU AI Act all treat human oversight as the control that scales with autonomy.
- Schedule the re-assessment now: the remaining AIEOG deliverables, the interagency AI and model risk RFI, the FSB final report (October 2026) and FSOC's 2026 annual report (December 2026) are the four events that will change the requirement stack.
What has the U.S. Treasury actually published on AI?
| Date | Document | Status |
|---|---|---|
| Jun 24, 2026 | FSOC AI Innovation Series (Mar–May 2026) — Artificial Intelligence Innovation Series — FSOC and Treasury AI Transformation Office roundtables | Final |
| Feb 19, 2026 | Treasury FS AI RMF and AI Lexicon (Feb 2026) — Financial Services AI Risk Management Framework (FS AI RMF) and Artificial Intelligence Lexicon | Final |
| Dec 11, 2025 | FSOC 2025 Annual Report — Financial Stability Oversight Council 2025 Annual Report — Section 3.4, Harnessing Artificial Intelligence to Promote Financial Stability | Final |
| Dec 19, 2024 | Treasury AI in Financial Services report (Dec 2024) — Artificial Intelligence in Financial Services — Report on the Uses, Opportunities, and Risks of AI in the Financial Services Sector | Final |
| Dec 6, 2024 | FSOC 2024 Annual Report — Financial Stability Oversight Council 2024 Annual Report — Section 3.3.3, The Use of Artificial Intelligence in Financial Services | Superseded |
| Oct 17, 2024 | Treasury $4B AI fraud-prevention announcement (Oct 2024) — Treasury Announces Enhanced Fraud Detection Processes, Including Machine Learning AI, Prevented and Recovered Over $4 Billion in Fiscal Year 2024 | Final |
| Jun 12, 2024 | Treasury AI RFI (June 2024) — Request for Information on Uses, Opportunities, and Risks of Artificial Intelligence in the Financial Services Sector | Final |
| Mar 27, 2024 | Treasury AI cybersecurity risks report (Mar 2024) — Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector | Final |
| Dec 14, 2023 | FSOC 2023 Annual Report — Financial Stability Oversight Council 2023 Annual Report — Section 3.3.3, The Use of Artificial Intelligence in Financial Services | Superseded |
| Date | Type | Document / event |
|---|---|---|
| Jun 24, 2026 | Report | FSOC AI Innovation Series (Mar–May 2026) — Artificial Intelligence Innovation Series — FSOC and Treasury AI Transformation Office roundtables. Announced by Secretary Bessent at the December 11, 2025 FSOC meeting, the AI Innovation Series was four public-private roundtables run by the Office of FSOC and Treasury's AI Transformation Office: Strategy and Governance (March 4, 2026), Value Generation and Efficiency (April 7), Cybersecurity and Risk Management (April 27), and Financial Stability and Economic Security (May 19). source ↗ |
| Feb 19, 2026 | Framework | Treasury FS AI RMF and AI Lexicon (Feb 2026) — Financial Services AI Risk Management Framework (FS AI RMF) and Artificial Intelligence Lexicon. On February 19, 2026 Treasury released a shared Artificial Intelligence Lexicon and the Financial Services AI Risk Management Framework (FS AI RMF), the first two of six deliverables from the Artificial Intelligence Executive Oversight Group (AIEOG), a public-private partnership of the FBIIC and the Financial Services Sector Coordinating Council. source ↗ |
| Feb 18, 2026 | Milestone | Treasury announces completion of the AIEOG public-private AI initiative. Treasury said six AIEOG deliverables — covering governance, data practices, transparency, fraud, and digital identity — would be released in stages during February 2026, aimed particularly at small and mid-sized institutions. |
| Dec 11, 2025 | Report | FSOC 2025 Annual Report — Financial Stability Oversight Council 2025 Annual Report — Section 3.4, Harnessing Artificial Intelligence to Promote Financial Stability. FSOC's 2025 annual report, unanimously approved December 11, 2025, made 'harnessing AI to promote financial stability' one of four priority areas and formalized an FSOC Artificial Intelligence Working Group. source ↗ |
| Jul 23, 2025 | Milestone | White House releases America's AI Action Plan. The Action Plan calls for clear standards, shared understanding, and risk-based governance; Treasury's February 2026 AIEOG resources and AI Innovation Series are framed as implementing it in the financial sector. |
| Jan 23, 2025 | Milestone | Executive Order 14179 'Removing Barriers to American Leadership in Artificial Intelligence' signed. Revoked EO 14110 (under which Treasury's March 2024 AI cybersecurity report was written) and set the deregulatory frame that Treasury's 2026 AI resources and FSOC's AI Innovation Series cite as their mandate. |
| Dec 19, 2024 | Report | Treasury AI in Financial Services report (Dec 2024) — Artificial Intelligence in Financial Services — Report on the Uses, Opportunities, and Risks of AI in the Financial Services Sector. On December 19, 2024 Treasury published its report on the uses, opportunities, and risks of AI in financial services, summarizing 103 responses to its June 2024 RFI. source ↗ |
| Dec 6, 2024 | Report | FSOC 2024 Annual Report — Financial Stability Oversight Council 2024 Annual Report — Section 3.3.3, The Use of Artificial Intelligence in Financial Services. FSOC's 2024 annual report, approved December 6, 2024, sharpened its AI analysis, warning that lack of explainability and high complexity could heighten instability beyond individual firms and that concentration in a few models or providers could create interconnection, herding, and contagion. source ↗ |
| Oct 17, 2024 | Report | Treasury $4B AI fraud-prevention announcement (Oct 2024) — Treasury Announces Enhanced Fraud Detection Processes, Including Machine Learning AI, Prevented and Recovered Over $4 Billion in Fiscal Year 2024. On October 17, 2024 Treasury announced that its Office of Payment Integrity, within the Bureau of the Fiscal Service, prevented and recovered over $4 billion in fraud and improper payments in fiscal 2024 (October 2023 to September 2024), up from $652.7 million in FY2023. source ↗ |
| Jun 12, 2024 | Consultation | Treasury AI RFI (June 2024) — Request for Information on Uses, Opportunities, and Risks of Artificial Intelligence in the Financial Services Sector. Treasury announced its Request for Information on the uses, opportunities and risks of AI in financial services on June 6, 2024 and published it in the Federal Register on June 12, 2024 with a 60-day comment period. source ↗ |
| Mar 27, 2024 | Report | Treasury AI cybersecurity risks report (Mar 2024) — Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector. On March 27, 2024 the Treasury released 'Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector', written under Executive Order 14110 and led by its Office of Cybersecurity and Critical Infrastructure Protection. source ↗ |
| Dec 14, 2023 | Report | FSOC 2023 Annual Report — Financial Stability Oversight Council 2023 Annual Report — Section 3.3.3, The Use of Artificial Intelligence in Financial Services. FSOC's 2023 annual report, approved December 14, 2023, was the first to identify the use of AI in financial services as an emerging vulnerability to U.S. source ↗ |
Which of the 100 largest US banks answer to the U.S. Treasury on AI?
2 of the 100 bank pages on this site name the U.S. Treasury among the authorities their AI programme answers to. Each page lists the documents that apply and why.
- Publication and uptake of the remaining AIEOG deliverables (explainability, data nutrition labeling, AI-enhanced fraud, identity and authentication) and whether examiners begin referencing the FS AI RMF
- FSOC's 2026 annual report (expected December 2026): the first full-year output of the AI Working Group and any follow-through on the 'regulatory impediments' identified in the AI Innovation Series
- Whether Treasury or FSOC translate Innovation Series feedback into concrete asks of the banking agencies — e.g., harmonized AI guidance or safe harbors for AI-enabled fraud and cyber defense
- Treasury's own AI deployment (AI Transformation Office, Chief AI Officer appointed June 2025) and updated fraud-prevention figures from the Bureau of the Fiscal Service
Is the Treasury FS AI RMF mandatory for banks?
No. The Financial Services AI Risk Management Framework and the AI Lexicon released on February 19, 2026 are voluntary, non-binding resources developed through the AIEOG public-private partnership. They adapt the NIST AI Risk Management Framework to financial services and are meant to be scalable for institutions of any size; binding expectations still come from the prudential regulators' model-risk, third-party, and consumer-protection rules.
What did FSOC say about AI in its 2025 annual report?
FSOC's December 11, 2025 report reframed AI as an opportunity as well as a risk, creating an Artificial Intelligence Working Group to identify high-value AI use cases for member agencies, monitor financial-stability risks from AI adoption inside and outside finance, and provide a public-private forum on regulatory impediments to responsible adoption.
Does Treasury regulate AI in financial services?
Not directly. Treasury publishes reports, voluntary frameworks, and FSOC recommendations, and it houses the OCC and FinCEN, which do have supervisory and enforcement powers. Its December 2024 RFI report recommended that regulators clarify supervisory expectations and that firms review AI use cases for compliance with existing laws before deployment.
Follow every move these regulators make
the daily brief · six sourced stories · in your inbox by 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning