State Regulators Enter AI Chat: CSBS Releases AI Supervisory Framework

The Conference of State Bank Supervisors (CSBS) released an AI Supervisory Framework to help state examiners assess artificial intelligence (AI) use by state-chartered banks and state-licensed nonbank financial institutions. Although the framework is discretionary and creates no new legal obligations, it signals what examiners may expect of an institution’s AI program as institutions increasingly integrate AI into their operations.

Background

CSBS supports the nationwide network of state financial regulators, who collectively supervise the substantial majority of state-chartered banks and a range of nonbank financial services providers – including money transmitters, consumer and mortgage lenders and servicers, and debt collectors. CSBS established an AI Advisory Group in August 2024, demonstrating an interest in the development and use of AI in the financial services industry. The AI Supervisory Framework, approved in August 2026, builds on that initiative and fills a regulatory guidance gap left by federal banking agencies.

CSBS President and CEO Brandon Milhorn described the framework as “a principles-based approach to governance intended to help financial institutions explore and implement [generative and agentic] AI with additional confidence.” Importantly, each state agency may independently decide how much, if any, of the framework to incorporate into its own exam program. However, because it offers a common set of questions and procedures that any examiner can adopt, entities operating across multiple states can likely expect meaningful consistency in how AI use and integration in financial institutions will be examined.

Overview of the framework

CSBS released the framework in five components built on established resources, including NIST’s AI Risk Management Framework and generative AI profile, the Cyber Risk Institute’s Financial Services AI Risk Management Framework, the US Treasury’s AI Lexicon, and existing prudential guidance (SR 23-4 on third-party risk and SR 26-2 on model risk):

Core examiner guide

This foundation of the framework sets out:

  1. An eight-question initial scoping questionnaire for examiners to use during examinations – covering, among other things, customer-facing AI use, reliance on third parties for AI use and handling of sensitive data with respect to AI processing.
  2. A document request list to provide to examinees.
  3. Procedures that examiners may use to evaluate an entity’s governance and oversight, AI inventory and use cases, and use of generative AI and other emerging forms and uses of AI.

Examiner work program

This 28-page companion document expands each scoping question and procedure with additional guidance, source citations and specific areas of supervisory focus, and provides guidance on how examiners should evaluate agentic AI systems’ permission boundaries, human checkpoints, logging, reversibility and capability to halt actions when needed.

Nonbank AI supplements

These supplements serve as overlays that apply AI-specific considerations to three existing nonbank review areas:

  1. Third-party and vendor oversight.
  2. Model risk management.
  3. Consumer protection.

CSBS notes a single AI use case may implicate more than one supplement.

AI use case risk tiering worksheet

This optional, institution-completed tool assigns each AI use case a risk tier from 1 (lowest) to 3 (highest) based on consumer impact, human oversight, potential harm from errors or outages, and data sensitivity. Expected controls escalate by tier – from maintaining basic inventories and acceptable-use policies for Tier 1 use cases to independent model validation and AI-specific incident response procedures for Tier 3 use cases.

Source support document

This document provides a reference list of the regulatory and technical materials underlying the framework, including the:

  • National Institute of Standards and Technology AI Risk Management Framework 1.0/AI 600-1
  • Treasury/ Financial Services Sector Coordinating Council AI Lexicon, SR 23-4, SR 26-2
  • Equal Credit Opportunity Act (ECOA)/Regulation B
  • National Association of Insurance Commissioners Model Bulletin on AI

Key themes: Third-party risk management and data privacy implications

The framework’s third-party and vendor oversight expectations may be some of the most consequential features, particularly for entities using AI-enabled tools, such as underwriting, servicing, fraud detection or document-generation programs. The framework treats reliance on third-party AI providers as a supervisory focal point and reiterates that the responsibility for AI use, even when using service providers, remains with the supervised entity. Reliance on third parties for AI tools is particularly salient when these providers will process or have access to personal or other regulated information. Certain states have already expressly identified this as a supervisory priority.

Vendor AI as a managed dependency

Examiners may probe whether an institution has:

  • Identified which vendor relationships involve AI (including vendors that embed AI features in their offerings, even though the institution is not specifically procuring an AI product from that vendor).
  • Built AI-specific factors into due diligence – data provenance, privacy, security, explainability limitations and vendor dependency.
  • Demonstrated an understanding of the shared-responsibility boundary for oversight, monitoring and incident response between the institution and its vendor.

Examiners are likely to focus specifically on contract terms – including data rights, usage restrictions, security requirements, incident disclosure, access to testing or audit information, change notification, and termination or fallback planning – to demonstrate how much oversight and protection the institution has over a particular vendor and service. Institutions relying on legacy vendor contracts negotiated before AI functionality was added should expect these gaps to surface in an AI-focused exam.

Data use, retention and training rights

The framework emphasizes whether customer, consumer or institutional data may be used, retained, shared or used to train AI systems. Nonbanks should inventory their data flows underlying each AI use case and vendor to determine what data is processed by each vendor, whether that data is used to train a vendor’s model (and/or could be used to inform outputs delivered to that vendor’s other customers), and how long the vendor retains the institution’s data after the engagement ends. Where AI systems process personal information, nonbanks subject to state and industry-specific privacy laws and rules should separately assess their respective privacy compliance obligations.

Consumer protection overlay

Where AI informs adverse actions, pricing, valuations or servicing decisions, examiners may test whether the institution – not just its vendor – can identify and communicate specific, accurate reasons for those outcomes, consistent with ECOA/Regulation B adverse action principles. The Nonbank AI Supplements indicate that examinations will also focus on potential proxy effects, automation bias and overreliance on vendor outputs without independent challenge. Nonbanks should accordingly seek sufficient vendor transparency to explain consequential outcomes, monitor independently for disparate impact across products or segments, and build meaningful human review into consumer-facing AI workflows rather than treating vendor outputs as final.

AI program considerations

The framework’s structure and key focus areas telegraph what examiners may expect a mature AI program to look like. Based on the inventory, tiered risk-rating practices and key focal points described above, examiners are likely to expect an AI program to address:

Governance and accountability

The framework encourages examiners to look for clear ownership over AI oversight, documented governance policies (including for generative AI use specifically), a defined process for evaluating risk and approving new use cases, and reporting to management and, where appropriate, the board. Institutions are expected to apply governance oversight equally to internally built tools and externally sourced or vendor-embedded AI tools.

Generative and agentic AI-specific controls

Because generative and agentic tools raise risks that traditional model risk frameworks do not fully capture – including hallucination, prompt injection, nonrepeatable outputs and autonomous action – institutions should expect scrutiny of controls over inputs and outputs and, for agentic systems, the permission boundaries and human checkpoints described in the Examiner Work Program.

Documentation and demonstrable oversight

Across every area, institutions must be able to show their work, including through risk assessments, documented rationales for tiering decisions, testing and monitoring records, and internal audit or compliance review of AI governance. An institution that believes its AI use is well managed but cannot document that fact should expect follow-up questions.

What’s next: Practical takeaways

It remains to be seen whether states will adopt the framework and to what extent, particularly as states are increasingly passing legislation governing the use of AI – for example, Colorado recently finalized its novel AI legislation in May 2026, which is largely applicable to financial institutions.

State-regulated financial services companies may treat the framework as a preview of future state examinations and thus may consider completing a self-assessment against the Core Examiner Guide’s scoping questions. These institutions may also consider building or updating an AI inventory that captures embedded and vendor-provided AI, applying a risk-tiering methodology with written support for each classification, revisiting vendor contracts for AI-specific data use and incident-disclosure terms, and confirming that consumer-facing AI outputs can be explained in the terms existing consumer protection laws require.

State-regulated entities should also consider how the framework intersects with AI-specific guidance issued by applicable federal and international regulators and agencies, such as the US Treasury, Fannie Mae and the UK Financial Conduct Authority, as well as executive orders issued by the current administration, which we covered in this June 8 post and this December 18, 2025, post. We will continue to monitor both federal AI developments and state-level adoption of the framework as individual regulators clarify how they intend to apply it.