The Conference of State Bank Supervisors (CSBS) on September 16, 2026 released an Artificial Intelligence Supervisory Framework designed to help state financial examiners identify and understand how the bank and non-bank institutions they regulate are using artificial intelligence, assess the associated risks, and determine when a more in-depth review may be appropriate. The framework is significant because it provides state examiners with a common approach to AI supervision at a time when banks and nonbanks are rapidly expanding their use of AI, including generative and agentic AI. CSBS emphasizes that the framework is a discretionary supervisory tool and does not establish new substantive requirements governing the use of AI. The American Association of Residential Mortgage Regulators (AARMR) also surveyed mortgage companies on AI deployment for consumer protection, and widespread adoption of this framework in the non-bank mortgage industry is anticipated.
This section explains that the CSBS framework is a risk-based approach tailored to an institution's characteristics and AI use. It integrates existing AI risk-management resources, including those from the National Institute of Standards and Technology, the Cyber Risk Institute, and the U.S. Department of the Treasury. The framework comprises a Core Examiner Guide for basic examination, an Examiner Work Program for detailed guidance, and Nonbank AI Supplements specifically addressing third-party and vendor risk, model risk, and consumer protection for non-bank institutions. An optional AI Use Case Risk Tiering Worksheet is also provided to help assess individual AI applications. While approved by CSBS committees, individual state agencies will determine the extent of its incorporation into their supervisory programs.
The framework is crucial because it acts as a structured supervisory tool for state examiners, enabling them to inquire into an institution’s use of AI and evaluate whether its existing governance, risk-management, and compliance processes adequately address AI-related risks. It is important to note that the framework does not impose new legal requirements. CSBS explicitly labels it a “discretionary tool” and stresses that the supervisory approach should be flexible, reflecting the institution’s size, complexity, risk profile, and specific AI usage. This design aims to avoid a rigid, one-size-fits-all methodology, distinguishing between varying levels of risk posed by different AI applications, such as an employee using generative AI for document summarization versus an AI system influencing credit decisions.
A significant consequence of the framework is the expectation for financial institutions to maintain comprehensive AI inventories, identifying all material AI use cases, business functions employing AI, whether the technology is internal or third-party, and the associated risks. Institutions must also be prepared to explain their AI governance and how AI risks are integrated into existing risk-management and compliance programs. The framework places particular emphasis on third-party and vendor risk, especially for nonbanks that frequently rely on external AI solutions. State examiners will likely scrutinize how institutions evaluate and monitor these vendors to ensure their AI-related practices do not create undue risks for the institution or its customers. This focus on third-party AI risk management addresses a gap in federal banking regulators' guidance, which has generally taken a broad, principles-based approach without specific AI-related directives. Consequently, this framework offers tangible governance measures and sets clear supervisory expectations for deploying various AI tools.
This section highlights the framework's distinct treatment of generative AI and other emerging AI applications, acknowledging that traditional model-risk-management concepts may not be fully applicable to these advanced technologies. Financial institutions are increasingly leveraging these AI types for a wide range of functions, including customer service, fraud detection, document review, coding, marketing, and underwriting support, many of which do not align with conventional model structures. Therefore, supervisory inquiries cannot be limited solely to traditional model validation. The primary challenge for both regulators and financial institutions is to develop effective control mechanisms that adequately address the genuine risks posed by these technologies, without imposing excessive or disproportionate burdens on AI uses that present relatively lower risk.
Although the CSBS framework does not introduce new regulatory mandates, financial institutions subject to state supervision should proactively utilize it as a preparatory guide for upcoming examinations. Specifically, institutions should ensure they can readily address fundamental questions regarding their AI inventory, governance structure, risk assessments, interactions with third-party providers, consumer-protection controls, and the deployment of generative and other emerging AI technologies. The ultimate impact of the framework will be contingent on individual state regulators’ implementation decisions, as each agency will determine its integration into their supervisory program. While this doesn't guarantee immediate, separate AI examinations for every state, the framework provides state regulators with a consistent set of tools and questions that will be incorporated into existing examinations, signifying a shift of AI supervision from a theoretical concept to a concrete component of state supervisory reviews.