On September 16, 2026, the Conference of State Bank Supervisors ("CSBS") released an Artificial Intelligence Supervisory Framework ("Framework") designed to help state financial regulators and financial institutions identify how institutions use artificial intelligence ("AI") and assess and manage associated risks. Although the Framework does not impose any new legal requirements, it serves as a critical tool that many state regulators are likely to integrate into their supervisory programs. Financial institutions are encouraged to utilize this Framework to evaluate their existing AI use, establish robust AI governance, and implement effective risk management strategies. This initiative addresses the rapid expansion of AI, including generative and agentic AI, across the financial sector by providing a consistent and risk-based methodology for supervision. It draws upon established risk management principles from various public resources, such as the National Institute of Standards and Technology's AI Risk Management Framework, the Cyber Risk Institute's Financial Services AI Risk Management Framework, and the US Department of Treasury's AI Lexicon. The Framework's broad applicability to state-chartered banks and state-licensed nonbank financial institutions, which constitute a significant majority of US banks, indicates its considerable practical reach and potential to influence broader regulatory standards. It also offers specific guidance through components like the Core Examiner Guide, Examiner Work Program, and Nonbank AI Supplements, which detail considerations for third-party and vendor risk, model risk, and consumer protection in AI applications. The introduction of this Framework highlights the evolving regulatory landscape for AI in finance, anticipating further guidance from federal banking regulators and urging institutions to proactive assess and manage their AI-related risks.
Key Takeaways This section outlines three crucial aspects of the new Framework. Firstly, it establishes a uniform, risk-based methodology for state regulators to supervise AI, recognizing the rapid growth of AI use, including generative and agentic AI, across financial institutions. Secondly, the Framework is built upon existing and familiar risk management standards, leveraging resources from the National Institute of Standards and Technology, the Cyber Risk Institute, and the US Department of Treasury. This ensures that the approach is consistent with established best practices in understanding and documenting AI risks, policies, procedures, and oversight. Finally, the Framework is anticipated to have significant influence across state legislatures and regulatory bodies. Historically, similar initiatives by the Conference of State Bank Supervisors (CSBS) have often served as blueprints for state model laws and regulatory standards, indicating a potential widespread adoption and integration into existing supervisory programs for various financial service providers. Framework Components The Framework is structured with several interconnected components designed to provide a comprehensive supervisory approach. The Core Examiner Guide is central, outlining the fundamental supervisory methodology, initial scoping questions for institutions, a list of required documents, and procedures to address AI governance, inventory of AI use cases, and emerging applications like generative AI. It helps examiners understand the nature of an institution's AI use and how risks are categorized. Complementing this, the Examiner Work Program provides more specific, actionable guidance for applying the Core Guide. Additionally, Nonbank AI Supplements offer specialized directives for reviewing third-party and vendor risks, model risks (including AI-enabled models, predictive tools, and machine learning systems), and consumer protection considerations within nonbank entities. These supplements guide examiners on specific AI-related questions concerning due diligence, contract terms, monitoring for confabulation and overreliance, and assessing potential for unfair consumer outcomes, especially for customer-facing AI and decision-support tools. AI Use Case Risk Tiering Worksheet ("Worksheet") The Worksheet is an optional but insightful tool developed by CSBS for financial institutions and examiners to assess the risk level of individual AI use cases. Institutions can classify their AI applications into three tiers: Low Risk, Moderate Risk, or High Risk, based on criteria such as the AI's impact on consumers, the degree of human oversight involved, the potential for harm from errors or outages, and the sensitivity of the data utilized. The Worksheet provides clear definitions for each tier: Low Risk involves internal AI use with human review, limited consumer impact, and low harm potential; Moderate Risk includes consumer-facing or decision-support AI with exception-based human oversight, moderate data sensitivity, and moderate harm potential; and High Risk entails AI directly influencing consumer outcomes, limited human review, sensitive personal data use, and significant operational reliance or material harm potential. Crucially, the Worksheet also suggests a cumulative set of controls, governance mechanisms, testing, monitoring, and managerial oversight processes, with increasingly stringent requirements for higher risk tiers, guiding institutions on expected risk management practices. The Framework in Context This section positions the CSBS Framework within the broader regulatory landscape, highlighting its role in filling gaps left by existing federal guidance. Notably, updated Supervisory Guidance on Model Risk Management from federal bodies like the Federal Reserve, OCC, and FDIC explicitly excluded generative and agentic AI models, a gap directly addressed by the CSBS Framework. Federal banking regulators have since indicated plans to issue their own requests for information on AI, suggesting that the CSBS Framework might inform future federal approaches. The Framework also bridges a void in federal third-party risk management guidance, as the 2023 Interagency Guidance on Third-Party Relationships took a broad, principles-based approach without specific AI considerations. The CSBS Framework’s Third-Party and Vendor Oversight supplement specifically directs examiners to inquire about AI-specific factors in vendor relationships, due diligence, contract terms, and monitoring. This comprehensive and timely release by CSBS underscores regulators' understanding of AI's rapid adoption and their commitment to ensuring responsible innovation within financial institutions. Next Steps Given the Framework's release and its potential impact, financial institutions, especially those operating across multiple states, are advised to take immediate proactive steps. Firstly, institutions should conduct a thorough AI inventory to identify all AI-based products, services, and tools currently in use or under development, including their business functions, development source (in-house or vendor), and data usage. Secondly, a comprehensive review of existing third-party and vendor arrangements is crucial to ensure that due diligence, contract terms, and ongoing monitoring adequately address AI-specific risks, particularly for embedded AI features and vendor-provided models. Thirdly, institutions should complete an AI risk assessment to identify and document AI-related risks, aligning their policies, procedures, and reporting structures with the Framework or other recognized AI risk management frameworks. Lastly, institutions with securities affiliates should coordinate these efforts, extending their AI inventory and governance programs to ensure compliance with applicable Securities and Exchange Commission, Financial Industry Regulatory Authority, and state securities requirements, recognizing that regulatory expectations may vary across different financial services sectors.
Key Takeaways
This section outlines three crucial aspects of the new Framework. Firstly, it establishes a uniform, risk-based methodology for state regulators to supervise AI, recognizing the rapid growth of AI use, including generative and agentic AI, across financial institutions. Secondly, the Framework is built upon existing and familiar risk management standards, leveraging resources from the National Institute of Standards and Technology, the Cyber Risk Institute, and the US Department of Treasury. This ensures that the approach is consistent with established best practices in understanding and documenting AI risks, policies, procedures, and oversight. Finally, the Framework is anticipated to have significant influence across state legislatures and regulatory bodies. Historically, similar initiatives by the Conference of State Bank Supervisors (CSBS) have often served as blueprints for state model laws and regulatory standards, indicating a potential widespread adoption and integration into existing supervisory programs for various financial service providers.
Framework Components
The Framework is structured with several interconnected components designed to provide a comprehensive supervisory approach. The Core Examiner Guide is central, outlining the fundamental supervisory methodology, initial scoping questions for institutions, a list of required documents, and procedures to address AI governance, inventory of AI use cases, and emerging applications like generative AI. It helps examiners understand the nature of an institution's AI use and how risks are categorized. Complementing this, the Examiner Work Program provides more specific, actionable guidance for applying the Core Guide. Additionally, Nonbank AI Supplements offer specialized directives for reviewing third-party and vendor risks, model risks (including AI-enabled models, predictive tools, and machine learning systems), and consumer protection considerations within nonbank entities. These supplements guide examiners on specific AI-related questions concerning due diligence, contract terms, monitoring for confabulation and overreliance, and assessing potential for unfair consumer outcomes, especially for customer-facing AI and decision-support tools.
AI Use Case Risk Tiering Worksheet ("Worksheet")
The Worksheet is an optional but insightful tool developed by CSBS for financial institutions and examiners to assess the risk level of individual AI use cases. Institutions can classify their AI applications into three tiers: Low Risk, Moderate Risk, or High Risk, based on criteria such as the AI's impact on consumers, the degree of human oversight involved, the potential for harm from errors or outages, and the sensitivity of the data utilized. The Worksheet provides clear definitions for each tier: Low Risk involves internal AI use with human review, limited consumer impact, and low harm potential; Moderate Risk includes consumer-facing or decision-support AI with exception-based human oversight, moderate data sensitivity, and moderate harm potential; and High Risk entails AI directly influencing consumer outcomes, limited human review, sensitive personal data use, and significant operational reliance or material harm potential. Crucially, the Worksheet also suggests a cumulative set of controls, governance mechanisms, testing, monitoring, and managerial oversight processes, with increasingly stringent requirements for higher risk tiers, guiding institutions on expected risk management practices.
The Framework in Context
This section positions the CSBS Framework within the broader regulatory landscape, highlighting its role in filling gaps left by existing federal guidance. Notably, updated Supervisory Guidance on Model Risk Management from federal bodies like the Federal Reserve, OCC, and FDIC explicitly excluded generative and agentic AI models, a gap directly addressed by the CSBS Framework. Federal banking regulators have since indicated plans to issue their own requests for information on AI, suggesting that the CSBS Framework might inform future federal approaches. The Framework also bridges a void in federal third-party risk management guidance, as the 2023 Interagency Guidance on Third-Party Relationships took a broad, principles-based approach without specific AI considerations. The CSBS Framework’s Third-Party and Vendor Oversight supplement specifically directs examiners to inquire about AI-specific factors in vendor relationships, due diligence, contract terms, and monitoring. This comprehensive and timely release by CSBS underscores regulators' understanding of AI's rapid adoption and their commitment to ensuring responsible innovation within financial institutions.
Next Steps
Given the Framework's release and its potential impact, financial institutions, especially those operating across multiple states, are advised to take immediate proactive steps. Firstly, institutions should conduct a thorough AI inventory to identify all AI-based products, services, and tools currently in use or under development, including their business functions, development source (in-house or vendor), and data usage. Secondly, a comprehensive review of existing third-party and vendor arrangements is crucial to ensure that due diligence, contract terms, and ongoing monitoring adequately address AI-specific risks, particularly for embedded AI features and vendor-provided models. Thirdly, institutions should complete an AI risk assessment to identify and document AI-related risks, aligning their policies, procedures, and reporting structures with the Framework or other recognized AI risk management frameworks. Lastly, institutions with securities affiliates should coordinate these efforts, extending their AI inventory and governance programs to ensure compliance with applicable Securities and Exchange Commission, Financial Industry Regulatory Authority, and state securities requirements, recognizing that regulatory expectations may vary across different financial services sectors.