Overview
On September 16, 2026, the Conference of State Bank Supervisors (CSBS) announced the release of its Artificial Intelligence (AI) Supervisory Framework (Framework), which provides state examiners with a detailed roadmap for identifying and assessing AI use at supervised financial institutions—including the questions they may ask and documents they may request. Because the Framework is discretionary and does not itself create new legal or supervisory requirements, each state financial regulator will determine whether and how to incorporate it into its supervisory program. Financial institutions subject to state supervision therefore should consider using the Framework now to assess their AI governance, inventories, controls, and examination readiness.
Scope and Applicability
The Framework is designed principally for examinations of state-chartered banks and state-licensed nonbank financial institutions. It therefore does not itself establish an examination framework for national banks or other federally chartered institutions, although many of its risk-management concepts may be relevant beyond the institutions directly supervised by state financial regulators. While the Framework is designed to aid state examiners, it may also be used by interested financial institutions "to assess their own AI programs, establish sound AI governance and risk management, and prepare for examinations."[1]
Overview
The Framework has several components: the Core Examiner Guide; the Examiner Work Program; the Nonbank AI Supplements; and the AI Use Case Risk-Tiering Worksheet. While the Guide is the central document of the Framework, all of the documents are meant to be used by a state examiner together (including, if applicable, the Nonbank AI Supplements). As a whole, the Framework "is designed to consider each institution’s size, complexity, risk profile, and use of AI."[2]
Core Examiner Guide
The Core Examiner Guide organizes an examiner’s review into six sections: (1) Initial Scoping; (2) a Document Request List; (3) Governance and Oversight; (4) AI Inventory and Use Cases; (5) Generative AI and Emerging Use; and (6) Use of Existing Supervisory Resources.[3] The structure is deliberately risk-based: not every section is expected to apply in every examination, and the Guide directs examiners to tailor the depth and focus of review to the institution’s size, complexity, risk profile, and AI use.
The Initial Scoping section directs examiners to identify whether and how an institution uses AI and, based on the answers, which areas warrant further review. For example, customer-facing AI may trigger heightened attention to model risk and consumer protection. Notably, an institution’s initial representation that it does not use AI may not end the inquiry. If AI use is denied or unclear, the Guide instructs examiners to consider checking the institution’s vendor inventory, software inventory, approved tools, and recent product or platform changes before concluding that further AI-focused review is unnecessary. The Guide thus makes clear that institutions may need visibility not only into internally developed AI, but also into AI capabilities embedded in third-party products and services.
The Document Request List provides a useful examination-readiness checklist. Among other things, the Framework identifies materials examiners may request, including AI policies and procedures; governance and board or management reporting; inventories of AI systems, tools, models, and use cases; risk assessments and tiering information; lists of vendor products with known or potential embedded AI; generative-AI policies and approved-tool lists; vendor oversight materials; testing and validation materials; consumer-facing AI outputs; and contracts addressing the use of institutional or customer data by AI systems.
The Framework gives particular attention to generative AI and other emerging uses, including increasingly autonomous AI. For systems capable of taking actions with limited human direction, examiners are instructed to consider permission boundaries, human checkpoints, logging, reversibility, and the institution’s ability to restrict or halt the system. This focus is particularly notable as financial institutions begin evaluating agentic AI applications.
Guidance Documents
The Examiner Work Program supplements the Core Examiner Guide with additional context and examination considerations for Initial Scoping, Governance and Oversight, AI Inventory and Use Cases, and Generative AI and Emerging Use. It draws on existing supervisory and risk-management resources, including the Treasury AI Lexicon and National Institute of Standards and Technology’s AI Risk Management Framework (NIST AI RMF), and identifies considerations for examiners assessing each area.
The Nonbank AI Supplements are intended to help examiners apply AI-specific considerations when using existing supervisory resources addressing third-party and vendor oversight, model risk, and consumer protection. They operate as AI-specific overlays to those existing resources rather than as standalone examination procedures. A single AI use case may implicate multiple Supplements. For example, CSBS notes that a vendor-provided AI underwriting tool may raise third-party oversight, model-risk, and consumer-protection considerations simultaneously.
AI Use Case Risk-Tiering Worksheet
The final component of the Framework is the AI Use Case Risk-Tiering Worksheet, which is intended to help financial institutions evaluate and document the risks associated with specific AI use cases. State examiners may also use the Worksheet "to understand how an institution identifies, evaluates, and supports its AI risk-tiering decisions."[4]
The AI Use Case Risk-Tiering Worksheet begins by identifying the AI use case as well as its business purpose and role. After the use case is identified, a financial institution assesses the use case for four distinct risk factors: (1) consumer impact; (2) human oversight; (3) harm potential from errors or outage; and (4) data sensitivity. Based on this assessment, an institution may assign a low risk, moderate risk, or high risk rating to the AI use case. The final section of the AI Use Case Risk-Tiering Worksheet includes controls suggested based on the specific assigned risk tier, ranging from maintaining a written policy or procedure governing acceptable AI use to having independent model validation completed by a qualified party.
The Worksheet therefore provides institutions with a potential common vocabulary for documenting why particular AI applications receive different levels of governance and control. Even where a regulator does not formally require use of the Worksheet, institutions should be prepared for examiners using the Framework to ask how AI use cases are differentiated by risk and how the resulting risk classifications affect approval, monitoring, testing, and oversight.
Regulatory Context
The Framework builds on existing AI risk-management resources, including the Treasury AI Lexicon, NIST AI RMF, the Cyber Risk Institute’s Financial Services AI Risk Management Framework, and existing federal supervisory materials. Its significance lies in translating those and other resources into a broadly applicable, AI-specific examination methodology for state bank and nonbank financial supervisors.
The Framework will also operate against an increasingly varied state-law backdrop. For example, New York DFS has issued AI-related guidance addressing cybersecurity risks across DFS-regulated entities and specific AI uses in insurance and virtual-currency activities.[5] Colorado, meanwhile, recently enacted revised legislation governing automated decision-making technologies used in consequential decisions, including financial and lending decisions, with new requirements taking effect January 1, 2027, and implementing rulemaking currently underway. Institutions operating across multiple states therefore may face both CSBS-inspired supervisory expectations and separate substantive state-law requirements.
At the federal level, the banking agencies have not adopted a comparable AI-specific supervisory framework. Instead, federal banking regulators have generally addressed AI through existing risk-management and compliance frameworks while considering whether additional AI-specific guidance is warranted. In April 2026, the OCC, Federal Reserve, and FDIC revised their interagency model risk management guidance and expressly excluded generative and agentic AI from the revised guidance’s scope because those technologies are "novel and rapidly evolving." The agencies nevertheless stated that they expect to consider additional measures addressing model risk and banks’ use of AI. Federal Reserve Vice Chair for Supervision Michelle Bowman likewise has stated that banks currently rely on existing risk-management frameworks for AI and that regulators should assess whether existing supervisory guidance is "fit for the future."
The federal agencies’ September 2026 proposal to revise their third-party risk management guidance likewise takes a technology-neutral, risk-based approach rather than establishing AI-specific requirements. The proposal emphasizes tailoring oversight to the risks presented by particular third-party relationships and does not specifically establish an AI governance framework. Comments are due November 16, 2026.
Takeaways
Although adoption and implementation will vary by state, the Framework provides regulated institutions with a common roadmap for the AI questions state examiners may ask, the documents they may request, and the circumstances that may trigger deeper review under existing supervisory authorities. Institutions therefore need not—and likely should not—wait for their primary state regulator to formally announce adoption. Instead, they should consider using the Framework itself to test whether they can respond to the Initial Scoping questions, produce the materials identified in the Document Request List, and explain the governance and risk-tiering decisions associated with material AI use cases.
As a practical matter, state-regulated financial institutions should consider (1) identifying AI use across the enterprise, including AI embedded in vendor products; (2) maintaining an inventory that identifies the business purpose, owner, risk level, and customer or decision-making impact of material AI use cases; (3) documenting a risk-based process for approving, monitoring, and periodically reassessing those use cases; (4) reviewing vendor diligence and contracts for AI-specific issues, including data use, model changes, monitoring, audit access, and contingency rights; and (5) establishing enhanced controls for generative and agentic AI, particularly where customer information, consumer-facing outputs, or autonomous actions are involved.
[1] The CSBS Artificial Intelligence Supervisory Framework, CONF. OF STATE BANK SUPERVISORS (Sep. 16, 2026), https://www.csbs.org/csbs-artificial-intelligence-supervisory-framework.
[2] Id.
[3] Conf. of State Bank Supervisors, Artificial Intelligence Supervisory Framework Core Examiner Guide at 2 (2026).
[4] Conf. of State Bank Supervisors, AI Use Case Risk-Tiering Worksheet at 1 (2026).
[5] See, e.g., Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks, N.Y. Dep’t of Fin. Servs. (Oct. 16, 2024), https://www.dfs.ny.gov/industry-guidance/industry-letters/il20241016-cyber-risks-ai-and-strategies-combat-related-risks.