State Regulators Propose AI Framework for Banks
The Conference of State Bank Supervisors has released a voluntary framework to help examiners assess AI use and risk at state-chartered banks, filling a

The Conference of State Bank Supervisors has issued a new, voluntary framework for examiners to assess how state-chartered banks use artificial intelligence. This move comes after federal regulators updated model risk management guidance in April but explicitly left AI out of its scope.
Brandon Milhorn, CEO of the CSBS, described the framework as "a principles-based approach." He said it is intended to help financial institutions explore and implement AI with additional confidence, noting that "any new technology can present risks." The framework is discretionary and not a compulsory rule for the nearly 80% of the nation's 4,233 FDIC-insured institutions that are supervised by state regulators.
Core Components of the Framework
The CSBS guidance consists of five suggested documents for examiners. These include a core examiner guide, a work program outlining suggested procedures, a supplement for nonbanks, a worksheet for tiering banks' AI use, and a list of source materials. A central feature is a list of eight questions examiners should consider when evaluating a bank's AI deployment.
Examiners are prompted to ask if the bank uses AI and if it has identified where. They should determine how AI touches customers or shapes decisions and whether the technology stems from vendors or outside platforms. The questions also probe if a bank has looked for AI embedded in existing vendor products, if it uses generative AI, if it classifies its AI uses by risk, and if sensitive information passes through AI systems.
A Three-Tier Risk System
Perhaps the most impactful element is a proposed tiering system for categorizing AI risk. The CSBS framework outlines three distinct tiers, from lowest to highest risk.
| Tier | Risk Level | Key Characteristics |
|---|---|---|
| Tier 1 | Low | Internal use, human-reviewed outputs, limited consumer impact, limited data sensitivity, low potential harm from errors or outages. |
| Tier 2 | Moderate | Consumer-facing or decision-support role, moderate data sensitivity, exception-based human oversight, moderate potential harm from errors or outages. |
| Tier 3 | High | Direct consumer outcomes, sensitive personal data, limited human review, significant operational reliance, material potential harm from errors or outages. |
This structure is designed to help examiners tailor their scrutiny based on the complexity and potential impact of a bank's AI applications.
A Dual-Purpose Resource
The CSBS emphasized that the framework is not solely for regulators. The organization stated it doubles as a resource for industry. Financial institutions can use the documents to assess their own AI programs, establish governance and risk management practices, and prepare for upcoming examinations. The release follows a period where some state agencies anticipated needing to fill supervisory gaps, a perspective that may have been shaped by expectations of federal deregulation. The framework provides a structured, yet flexible, tool for handling the novel and rapidly evolving landscape of AI in banking.





