Urgent.News

What's breaking now, across thousands of outlets.

AI

State Bank Regulators Give Examiners a Road Map for AI Oversight

State financial regulators are beginning to define what artificial intelligence oversight looks like inside banks and FinTech companies, even without a comprehensive federal rule governing the technology’s use across financial services. The Conference of State Bank Supervisors (CSBS) released an AI supervisory framework for examiners reviewing state-chartered banks and state-licensed nonbank…

State Bank Regulators Give Examiners a Road Map for AI Oversight

State financial regulators are establishing a framework for artificial intelligence oversight within banks and FinTech companies, despite the absence of comprehensive federal regulations governing the technology's use across the financial sector. The Conference of State Bank Supervisors (CSBS) unveiled an AI supervisory framework for examining state-chartered banks and state-licensed nonbank financial institutions on September 16, according to a press release.

The guide provides examiners with questions to ask, documents to request, and methods to determine when an AI system requires closer scrutiny. Individual state agencies will decide whether to implement the framework and how to apply it, though it offers institutions a glimpse into potential examination areas. CSBS President and CEO Brandon Milhorn emphasized that AI offers financial institutions a powerful tool to enhance services, protect consumers, and boost efficiency.

The examiner guide directs examiners to identify AI usage across institutions, covering products, operations, compliance, and internal support functions, as well as AI embedded in third-party software. If uncertain about AI usage, institutions may face follow-up questions about vendor and software inventories before the examination concludes.

During the examination, examiners could request AI policies, use-case inventories, risk assessments, management reports, vendor contracts, and testing records. For customer-facing systems, the scope includes samples of chatbot transcripts, notices, and other AI-assisted communications. The framework also probes whether firms designate AI use owners, rank them by risk, and reassess controls as systems evolve.

Notably, the treatment of agentic AI, which can operate with limited human direction, is particularly relevant given the increasing adoption of autonomous systems in commerce and financial institutions. Examiners are prompted to examine the boundaries of such systems, including human checkpoints, logs, reversibility, and the ability to halt them.

AI affecting consumers may also be subject to review under existing fair lending, disclosure, privacy, and unfair practices standards. The framework does not impose new legal obligations, but its significance lies in making AI use visible within established examination practices while preserving state discretion over adoption. Financial firms should maintain clear AI governance, inventories, and vendor oversight while staying vigilant to how state agencies incorporate the framework into their programs, according to Sheppard.

Meanwhile, the New York State Department of Financial Services (NYDFS) issued a Sept. 10 letter stating that regulated entities must maintain current cybersecurity risk assessments when changes to their business or technology materially affect cyber risk. The letter identified AI, including frontier models, as a technology that may necessitate updated assessments, noting no new obligations but stressing that firms should demonstrate how identified risks shaped their cybersecurity controls and risk acceptance decisions.

California is taking a different approach, with its newly formed Business and Consumer Services Agency Secretary Rohit Chopra announcing plans to examine whether chatbots and other automated tools harm consumers or violate licensing and consumer protection requirements. While the announcement does not impose new requirements, it signals increased scrutiny of AI use in consumer interactions and licensed activities within the state.

Together, these developments suggest a state-led approach to AI oversight largely relying on existing regulatory authority. The practical challenge for financial institutions is demonstrating to examiners where AI operates, who is accountable for it, what risks it generates, and how those risks are controlled. This record may become crucial as state regulators define the scope of AI supervision before a comprehensive federal framework emerges.

Written by urgent.news from PYMNTS's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at pymnts.com →

More in AI

AIoT in Practice: Bridging IoT Data and AI Insights for Industrial Use Cases

The Internet of Things has enabled information gathering at a level previously unseen. We can apply sensors to equipment, RFID systems to tagged assets, and other means to create a connected digital…

  • AIoT combines IoT data with AI insights for industrial use cases.
  • Data flows through sensor, connectivity, IoT platform, and AI/ML model in typical IoT architecture.
  • Data pipelines are crucial for accurate AI predictions in AIoT systems.

More from Wednesday 23 September →