From the start of the second Trump administration, with perceived deregulation incoming, some state agencies took the position that they’d have to fill gaps in areas where federal regulators de-emphasized supervision.
Perhaps through that lens, the Conference of State Bank Supervisors on Wednesday released a discretionary (read: not compulsory) framework that examiners of state-chartered banks could employ to assess financial institutions’ use of artificial intelligence.
The Federal Reserve, Office of the Comptroller of the Currency and Federal Deposit Insurance Corp. in April updated guidance on how banks test and oversee the models that govern lending, pricing and risk decisions.
But they left AI largely out.
"Generative AI and agentic AI models are novel and rapidly evolving,” the agencies noted at the time. “As such, they are not within the scope of this guidance.”
In a press release introducing five suggested documents for examiners, CSBS CEO Brandon Milhorn called his organization’s framework “a principles-based approach … intended to help financial institutions explore and implement AI with additional confidence” because “any new technology can present risks.”
To be clear, state-chartered banks weren’t the intended audience of the April federal guidance that did not address AI.
But nearly 80% of the nation’s 4,233 FDIC-insured institutions are supervised by state regulators.
The CSBS guidance includes a core examiner guide, a work program that outlines suggested procedures for examiners, a supplement for nonbanks, a worksheet that tiers banks’ AI use and a list of sources from which the framework is derived.
Of particular note are eight questions the CSBS proposes examiners should consider when evaluating AI use at supervised banks:
- Does the bank use AI?
- Has it identified where?
- How does AI touch customers or shape decisions?
- Does the banks’ AI stem from vendors or outside platforms?
- Has the bank looked for AI embedded in vendor products it’s currently running?
- Does the bank use generative AI?
- Does the bank classify its AI uses by risk?
- Does sensitive information (customer, bank or otherwise) pass through AI?
The framework’s other arguably most impactful piece is the tiering system through which the CSBS suggests examiners view AI risk. There are three tiers, ranked lowest- to highest-risk.
The CSBS deems a bank to be “Tier 1” when AI is limited to “internal use, human-reviewed outputs, limited consumer impact, limited data sensitivity, and low potential harm from errors or outages,” according to the framework.
A bank reaches Tier 2, or moderate risk, when it gives AI a “consumer-facing or decision-support role,” or has “moderate data sensitivity, exception-based human oversight, or moderate potential harm from errors or outages,” the CSBS said.
Tier 3, meanwhile, occurs when “use cases involv[e] direct consumer outcomes, sensitive personal data, limited human review, significant operational reliance, or material potential harm from errors or outages,” according to the CSBS.
The AI framework isn’t just for regulators, the CSBS noted. It “doubles as a resource for industry,” the organization said.
“Financial institutions can use the framework to assess their own AI programs, establish sound AI governance and risk management, and prepare for examinations,” the CSBS said.