AI risk management banking is becoming a board level topic, not a side conversation for the IT department. You are already using AI to speed up onboarding, screen transactions and answer customer questions, and the risks that come with it, from biased credit decisions to opaque vendor dependencies, are moving just as fast.

Supervisors are watching this shift closely. Generative and agentic AI are moving fastest of all, and that speed is why banks need an AI risk management banking framework that treats governance as a starting requirement, not an afterthought.
For more on how AI improves customer support in banking, see AI in banking customer service. For AI’s role in fraud prevention, see AI in fraud detection.
Where banks are using AI today
Adoption has moved past isolated pilots. The European Central Bank’s supervisory arm tracks innovative technology use across large banks under its remit. Its latest survey found that more than 85% already use AI in some form, and adoption keeps climbing, according to ECB Banking Supervision.
The ECB groups deployment into three areas: IT operations, such as incident management and system maintenance; legal and document analysis, including contract reviews and regulatory interpretation; and front line applications, such as customer support and relationship management.
Map your own use cases against those three areas, and you get a fast read on your AI risk management banking coverage. Gaps tend to show up first in front line applications, since that is where customers notice them fastest.
Improving customer service with conversational AI
Conversational AI is one of the front line applications supervisors watch closest, because it sits directly in front of customers. Chatbots and virtual assistants handle account questions, payment disputes and basic servicing around the clock. That frees staff for calls that need judgment, not lookup work.
The upside only holds if the underlying AI risk management banking controls are in place. A support bot that mishandles a dispute turns into a customer complaint fast, and sometimes a conduct risk finding after that. Test it before launch, and keep a fast path for a human to take over.
Bank of America shows what that upside looks like at scale. In 2025, 20.6 million users interacted with its Erica assistant nearly 700 million times, and total interactions have passed 3.2 billion since Erica launched in 2018.
Numbers like that make a stronger case for AI risk management banking investment in conversational tools than any industry estimate, because they come from one bank’s own systems, not a survey.
AI data privacy and security risks in banking
Security is not a peripheral worry, it is the top one. The 15th EY and IIF Global Bank Risk Management Survey, based on 101 banks across 31 countries, found that cybersecurity remains banks’ top near term risk at 86%.
Part of the reason is that generative AI systems are trained on large datasets, and mishandling that data can expose customer information that was never meant to leave the bank’s walls. Chief risk officers are responding: the same survey found 41% are using AI to strengthen cyber and operational risk monitoring.
Encryption, access controls and documented data lineage are not optional extras. They are the baseline your AI risk management banking policy should require before any model touches customer data, generative or otherwise.
IBM’s 2025 Cost of a Data Breach research puts numbers on what happens when those controls are missing. Among organizations that had suffered a breach, 63% either had no AI governance policy or were still developing one, and 97% of that breached group lacked AI access controls entirely.
Organizations with high levels of shadow AI absorbed an average of $670,000 in extra breach costs compared with those using little or none. IBM also found that 13% of organizations reported breaches specifically of AI models or applications, meaning the AI itself was the target, not just the entry point.
Bias in AI decision-making for banking services
Bias in AI decision making for banking services is hard to prove and easy to deny, because the clearest cases are the ones nobody catches. Credit scoring and loan approval models can quietly weight a factor that correlates with a protected characteristic, and unless someone actively tests for it, that pattern stays invisible.
That is one reason regulators singled out credit scoring. Under the EU AI Act, credit scoring and creditworthiness systems are classified as high risk under Annex III, and the compliance obligations attached to that classification apply from 2 December 2027, after the Digital Omnibus amendment pushed the original deadline back from 2 August 2026. The classification itself did not change, only the timeline did.
Build fairness testing into your AI risk management banking process now, rather than waiting for the 2027 deadline. That gives your team time to find model behaviours that only show up once you go looking for them. Regular audits and a written definition of what fair means for each model are the starting point.
Governance and accountability, the three gaps supervisors keep finding
Most failures do not start with the model, they start with who owns it. In a February 2026 speech, ECB Banking Supervision representative Pedro Machado described three gaps supervisors keep finding across large banks under European supervision.
“First, they need to ensure clear and unambiguous accountability for AI-driven decisions. Second, there needs to be effective senior management oversight, reflecting the strategic importance of AI. And third, robust challenge mechanisms have to be in place, involving risk management, compliance and internal audit.”
The pattern behind those three gaps has a name too. Machado described it directly: “One supervisory concern we continue to encounter is fragmented ownership, with responsibility split across IT, data science teams, business lines and control functions, without a clear accountability framework.”
A written accountability structure is not optional for AI risk management banking. It should answer three questions: who owns the decision to deploy a model, who signs off on changes, and who is the escalation point when the model’s output looks wrong. If any of those three answers is “it depends,” that is the fragmented ownership the ECB is describing.
Regulatory compliance challenges with AI systems
Compliance teams are tracking two different clocks. The EU AI Act’s prohibited practices and AI literacy requirements have applied since 2 February 2025, and its governance duties and penalty regime since 2 August 2025. From 2 August 2026 the Regulation becomes generally applicable, Article 50 transparency rules start, and the Commission gains its power to fine general-purpose AI model providers. The high risk obligations specific to credit scoring, under Annex III, do not apply until 2 December 2027. AI risk management banking that only tracks one of those dates will miss obligations already in force.
Compliance risk is not limited to AI specific rules. The Basel Committee’s June 2026 report on information and communication technology risk management covers how banks handle ICT incidents affecting critical operations. It is not an AI specific report, but its practices, incident response, resilience testing, vendor oversight, apply directly to the infrastructure your AI systems run on.
The supervisory gap for generative AI
In April 2026 the Federal Reserve, the OCC and the FDIC jointly issued SR 26-2, which supersedes and replaces SR letter 11-7 on model risk management, issued in 2011, and SR letter 21-8 on model risk management for Bank Secrecy Act and anti money laundering systems, issued in 2021. Fifteen years of guidance, replaced in one letter.
But SR 26-2 draws a boundary around itself. Its attachment states plainly: “Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance.” The next sentence confirms what is still covered: “However, the principles described in this guidance apply to traditional statistical and quantitative models and non-generative, non-agentic AI models.” The generative tools your bank is rolling out fastest fall outside it.
That does not mean you are free to skip governance for them. SR 26-2 itself says: “Nonetheless, a banking organization’s risk management and governance practices should guide the determination of appropriate governance and controls for any tools, processes, or systems not covered in this document.” You are asked to build that control framework yourself.
SR 26-2 is expected to matter most for banking organizations with over $30 billion in total assets regulated by the Federal Reserve, though smaller organizations may still find it relevant where their own model risk exposure is significant.
Meanwhile the EU AI Act’s high risk credit scoring obligations still do not bite until 2 December 2027. So for close to two years, banks are governing their fastest growing AI in a gap between a US letter that excludes it and EU rules that have not started.
The practical answer is to adopt a framework voluntarily rather than wait for one. NIST released the AI Risk Management Framework, AI RMF 1.0, on 26 January 2023, built on four functions: Govern, Map, Measure and Manage. It followed with a Generative AI Profile, NIST AI 600-1, on 26 July 2024. That profile extends the same four functions to generative systems specifically.
Use it to structure your AI risk management banking programme, and you get a documented basis for oversight before either regulator requires one. The framework is under revision, with no successor version published, so treat it as the reference point available, not a finished target.
AI-based fraud detection in financial systems
Fraud is where chief risk officers report the deepest AI adoption. The 15th EY and IIF Global Bank Risk Management Survey, published February 2026 and based on 101 banks across 31 countries, found 61% of CROs using AI most extensively to detect fraud and financial crime.
The threat side is moving too. The same survey found digital fraud risk rising to 59% and financial crime risk rising to 43%, both up from a shared 23% baseline in the prior year, though these are two separate trends that happened to share a starting point.
Generative AI cuts both ways. The Financial Stability Board’s October 2025 report noted that generative AI could increase financial fraud and expand the ability of malicious actors to spread disinformation in financial markets. The FSB first raised that same warning in November 2024.
Signicat’s own fraud detection platform shows how fast generative tools are reshaping the threat. Deepfake attempts rose from 0.1% of the fraud attempts it detected three years earlier to about 6.5%, a 2,137% increase over that period. Signicat also attributes 42.5% of the fraud attempts detected in the financial sector to AI.
Deloitte projects that generative AI could push fraud losses in the United States to $40 billion by 2027, up from $12.3 billion in 2023, a compound annual growth rate of 32%. That figure is a forward looking projection for the US market, not a measured loss or a global estimate.
Treat fraud detection and threat monitoring as one continuous system inside your AI risk management banking function, not two tools that never talk to each other.
Concentration risk and third-party dependency
Generative AI compounds concentration risk because so much of it flows through a small number of vendors. The Financial Stability Board’s October 2025 report identifies four vulnerabilities to watch: third party dependencies and service provider concentration, market correlations, cyber risks, and model risk, data quality and governance.
These numbers come from a 2024 Bank of England and FCA survey of UK financial services, quoted inside the FSB report, so treat them as UK figures, not global ones. That survey found 33% of AI use cases in UK financial services were implemented by third parties, up from 17% in 2022.
The top three cloud providers account for about three quarters of cloud usage, and the top three model providers accounted for 44% of named providers in 2024, up from 18% in 2022. Foundation model use cases, which necessarily involve third party dependence because the underlying models are pre-trained, account for 17% of AI use cases.
The ECB has flagged the same problem from the supervisory side: generative AI is often sourced from a small number of major third party providers, built on large general purpose models that are not fully transparent to users, which raises concentration risk, vendor lock-in, and exit strategy questions.
None of this means avoiding third party AI. It means your AI risk management banking due diligence needs a documented answer for what happens if your primary model provider changes terms, has an outage, or exits the market. Write that answer down before you need it, not after an incident forces the question.
Data quality, scalability and cost
Cost pressure on AI programmes rarely shows up as a training bill. It shows up as a data problem. The EY and IIF survey found that 80% of CROs identify data quality and availability as the primary barrier to AI adoption, ahead of budget or talent.
Scaling is slower than the marketing suggests, too. The same survey found that 72% of CROs say AI adoption in the risk function remains in early stages, a pace the survey describes as having changed little since 2024.
Cost pressure is also changing headcount planning. 30% of CROs expect smaller risk teams over the next three years, almost double the prior year’s figure of 16%. That means your AI risk management banking budget needs to plan for fewer people doing more oversight, not the same headcount with a new tool. Build that assumption in before the next budget cycle forces the question.
Employee adaptation to AI-driven workflows
Staff are not wrong to feel uneasy about AI headcount plans. The way to make an AI risk management banking rollout land well is to be direct about what is changing and what is not.
Skills are the more immediate gap than headcount. The EY and IIF survey found that 79% of CROs emphasize the importance of data and AI skills for their teams, and 71% cite digital acumen as the most important skill set for risk teams.
Training that builds those skills does double duty. It gives staff a stake in how the tools are evaluated, and it gives your bank people who can question a model’s output rather than accept it. Include risk and compliance staff in testing new tools before rollout, not after.
Ethical concerns over AI-generated outputs in finance
Generative AI can produce a summary, a customer response or a risk assessment that reads confident and is wrong. In finance, a confidently wrong output is not a minor bug, it is a decision a customer or examiner may rely on.
The ECB’s supervisory position is direct: using AI does not reduce a bank’s accountability for an outcome, it raises the standard the bank is expected to meet, because the technology is new but the responsibility is not.
Building that expectation into your AI risk management banking framework means writing down, for each generative AI use case, who reviews the output before a customer sees it, and what happens when the review catches something wrong. Treat that review step as part of the product, not an afterthought.
Artificial Intelligence Services
Banking leaders face growing pressure to balance innovation with risk management as large language models and generative AI reshape the industry. The right AI services can cut operational inefficiencies, improve customer interactions and close the governance gaps supervisors keep raising.
Here are 3 AI services banks should prioritize:
1. Operational efficiency from AI in banking
Supervisors are asking banks for documented accountability, not just a working model. That means each automated process, whether it is data entry, client onboarding or compliance reporting, needs a named owner and a record of who approved it for production. Getting that documentation in place is most of the work behind an AI risk management banking programme that can survive an examiner’s questions.
See how AI services can help you build that operational efficiency without losing track of who is accountable for each system.
2. Improving customer service with conversational AI
Conversational AI gives customers a fast, always available channel, but every generative response it produces needs to sit inside your model inventory, even though SR 26-2 explicitly places generative and agentic models outside its own scope. That gap is exactly where banks are being asked to build their own governance rather than borrow a regulator’s.
Learn how AI email replies and lead nurturing flows can scale customer engagement while keeping that governance visible.
3. AI data privacy and security risks in banking
The FSB treats third party concentration as a named supervisory vulnerability, not a footnote. Before adding another vendor to your generative AI stack, assess what happens if that provider’s terms change, its service degrades, or it exits the market, and document that assessment as part of your AI risk management banking due diligence.
Explore artificial intelligence consulting services to strengthen your bank’s approach to AI security and vendor risk.
Ready to put these AI services to work in your bank? Check out our Artificial Intelligence Services to get insights tailored to your goals.
For more on AI’s impact on fraud detection in financial systems, see AI-based fraud detection enhancements.
Transform your banking operations with AI
You have seen where AI is already working and where the ECB and the Federal Reserve are finding gaps. Two concrete steps turn that into action.
First, map every generative and agentic AI system your bank runs against NIST’s AI Risk Management Framework. Use its four functions, Govern, Map, Measure and Manage, as the checklist. This gives you a documented governance basis for exactly the systems regulation has not caught up with yet.
Second, if you operate in the United States, re-baseline your model risk governance against SR 26-2. Mark which systems in your model inventory are generative or agentic, because those are the ones the letter excludes from its scope and the ones that need your own governance most.
Neither step requires a new regulation. Both are things an AI risk management banking team can start without waiting for a rule to force the issue.
If you’re ready to take the next step in AI implementation, we’re here to guide you. Contact us to explore solutions tailored to your bank’s specific needs.

