Primary topic: AI in Banking: Digital Transformation, Cybersecurity, Privacy, and Governance
Research focus: AI in lending, fraud, and customer service; frontier AI cyber risk; model risk management rules; deepfake wire-fraud; third-party breach exposure; and practical governance for banks of every size
What “AI in Banking” Covers
AI sits in nearly every part of a bank. Risk grows with how directly a system touches money or a customer’s rights.
| Area | What AI does | Example |
|---|---|---|
| Lending and underwriting | Scores credit risk and sets loan terms | Automated approval and pricing models |
| Fraud and AML | Flags suspicious transactions and accounts | Real-time transaction monitoring |
| Customer service | Answers questions and processes requests | Chatbots and voice assistants |
| Collections and recovery | Decides who to contact and how | Agentic outreach and repayment plans |
| Software and security | Writes code and finds vulnerabilities | AI coding assistants and security scanners |
Visual: AI Across One Banking Relationship
AI scores the loan application
AI verifies identity and documents
AI watches every transaction
AI chatbot handles support
AI manages collections outreach
Five stages. Five places where an automated decision can help or hurt a real customer.
Why Governance Became Urgent in 2026
Four pressures hit banks at the same time. Each is documented. Together they explain why AI oversight jumped to the top of the risk list.
A single AI model’s exploit-finding power alarmed regulators
Most banks cannot confirm they can stop a malfunctioning AI
Voice and video clones are moving real money out the door
Third-party breaches keep exposing bank customer data
Visual: Key dates in the 2026 banking AI story
Massachusetts settles with a lender over discriminatory AI loan terms
Treasury and the Fed call an emergency meeting with major bank CEOs over Anthropic’s Mythos model
Fed, OCC, and FDIC issue SR 26-2, the first model risk overhaul in 15 years
Citizens Bank and Frost Bank disclose breaches tied to a shared vendor
Wolters Kluwer publishes its 230-banker AI readiness survey
The OCC has said the agencies plan to seek public input specifically on bank use of generative and agentic AI
Pressure 1: Regulators treated one AI model as a banking-sector risk
On April 7, 2026, Treasury Secretary Scott Bessent and Federal Reserve Chair Jerome Powell called an unannounced meeting. The attendees were CEOs of the country’s most systemically important banks. The subject was Claude Mythos Preview, a new AI model from Anthropic. During testing, the model found thousands of previously unknown security flaws. That list included a 27-year-old flaw in OpenBSD.
It also included a bug in the FFmpeg video library that automated tools had missed across five million prior scans. Anthropic said no specialized cybersecurity training produced this skill. It came from general gains in coding and reasoning.
CEOs from Citigroup, Morgan Stanley, Bank of America, Wells Fargo, and Goldman Sachs attended. JPMorgan’s CEO was invited but could not make it. Anthropic did not release Mythos widely, citing these same capabilities. It separately announced a project with other major tech companies to use the model for defense instead.
The lesson for every bank is direct. A single frontier AI model can find in hours what took researchers years to find by hand. That cuts both ways. It can defend a bank’s systems. Or it can hand an attacker a map of every weak point. It depends only on who holds the tool.
Sources: Powell, Bessent Discussed Anthropic’s Mythos AI Cyber Threat With Major US Banks, CNBC, April 2026, Treasury Secretary and Federal Reserve Chair Warn Bank CEOs, Sullivan and Cromwell, April 2026, and Fed Chair Powell, Treasury’s Bessent and Top Bank CEOs Met Over Anthropic’s Mythos Model, CBS News, April 2026
Pressure 2: Most banks admit they cannot control what they built
Ten days after the Mythos meeting, the Fed, OCC, and FDIC issued SR 26-2. That was April 17, 2026. It is the first full rewrite of US bank model risk guidance in 15 years. It replaces the 2011 framework known as SR 11-7. A footnote holds the detail that matters most.
The guidance excludes generative AI and agentic AI. It calls them too new and fast-moving to cover yet. It tells banks to apply their own judgment in the meantime. The regulators also said they plan to seek public input on these systems separately, though no date has been set yet.
That gap showed up fast. On June 10, 2026, Wolters Kluwer published survey results from 230 US banking professionals. Asked where their bank was least prepared, 72 percent pointed to one of two things. Regulatory reporting of an AI failure, named by 38 percent. Or a working kill switch, named by 34 percent.
The report called these two things minimum requirements, not advanced features. Respondents named lending and underwriting, at 33 percent, and collections and recovery, at 30 percent, as the riskiest functions for agentic AI.
A written policy exists. No one has pressed the button. No one knows how long it takes. No regulator has watched it happen.
The switch has been tested live. The shutdown time is measured and logged. A second team, not the model’s own vendor, can verify it works.
The same report points to a real case behind the warning. In July 2025, the Massachusetts Attorney General reached a 2.5 million dollar settlement with student lender Earnest Operations after finding its AI underwriting model produced racially discriminatory loan terms. That case predates SR 26-2, but it shows the exact failure mode regulators are now trying to prevent from recurring at larger scale.
Sources: Supervisory Letter SR 26-2, Revised Guidance on Model Risk Management, Federal Reserve, April 17, 2026, 72% of Banks Lack AI Model Kill Switches, Failure Reporting, American Banker, June 2026, Wolters Kluwer Survey Highlights AI Governance and Other Ongoing Needs, Wolters Kluwer, June 2026, and AG Campbell Announces 2.5 Million Dollar Settlement With Student Loan Lender, Massachusetts Attorney General, July 2025
Pressure 3: Deepfake calls are draining real accounts
Generative AI can now clone a voice from a few seconds of audio. It can clone a face from public video. Criminals use both to impersonate executives on live calls. In one widely reported case, a finance employee joined a video call with the company’s CFO and several colleagues.
Every person on that call, except the employee, was an AI-generated deepfake. The employee was told to process 15 wire transfers. The total came to roughly 25.6 million dollars.
Smaller cases are common too. US Bank describes a CFO who authorized a 243,000 dollar transfer after a call that perfectly mimicked the real CEO’s voice. It was an AI clone. The FBI’s Internet Crime Complaint Center logged over 22,000 reports of AI voice or video fraud in a single recent year.
Reported losses came close to 893 million dollars. The 2026 International AI Safety Report notes these tools are free. They need no technical skill. They can be used anonymously. That is why this fraud category is growing faster than most others.
A familiar voice or face on the call is proof enough. Urgency and authority get instant compliance.
A voice needs only seconds of audio to clone. A face needs only public video. A shared passphrase, not a face, is now the real proof.
Sources: AI Fraud: Protecting Your Business From Deepfakes, US Bank, 2026, Voice Cloning Is the New BEC: Deepfake CEO Fraud in the US, CybelAngel, April 2026, and International AI Safety Report 2026, arXiv
Pressure 4: Third-party vendors keep becoming the weak link
Banks rarely get breached through their own front door anymore. They get breached through a vendor. In April 2026, Citizens Bank and Frost Bank both disclosed breaches. Both traced back to one shared third-party vendor. The Everest ransomware group posted data from both banks the same day. Citizens Bank said most of the exposed data was masked test information. But a limited set of real customer data was involved too.
This pattern is not new, but it is speeding up. Bank of America customers were caught up in at least four separate vendor-linked incidents between 2023 and 2025. The bank’s own systems were never directly breached in any of them. In one case, a vendor’s own investigation later revised its count upward to over 6 million people across all its banking clients.
In another, a single software flaw in 2026 exposed data from roughly 1.35 million customers across 74 or more US institutions at once. This matters for AI governance directly. Every new AI vendor a bank adds is one more door into its data.
Sources: Citizens Bank Customers Targeted in Third-Party Data Breach, PYMNTS, April 2026, Bank of America Data Breach: What Happened and What to Do, Security.org, July 2026, and 26 Biggest Data Breaches in Finance, UpGuard, July 2026
Research Study: SR 26-2 and the Governance Gap It Leaves Open
SR 26-2 replaces 15-year-old guidance with a more flexible, risk-based approach. It covers traditional statistical and quantitative models. It applies most directly to banks with over 30 billion dollars in assets. But examiners now ask about AI governance at banks of every size. Its most-discussed line is a footnote. Generative and agentic AI sit outside its scope, since they are too new and fast-moving. Analysts covering the guidance are clear this is not a green light. Examiners already ask every bank how it governs the systems this rule skips.
What banks can learn:
- Do not assume a system is safe just because no formal rule covers it yet
- Apply your existing model risk principles, materiality, monitoring, and independent challenge, to generative and agentic AI voluntarily
- Watch for the agencies’ promised follow-up request for public input on generative and agentic AI, and prepare comments in advance
- Document your reasoning for how you govern out-of-scope AI, since examiners will ask
Source: SR 26-2, Revised Guidance on Model Risk Management, Federal Reserve, OCC, and FDIC, April 2026
Research Study: The Wolters Kluwer US Banking AI Risk and Governance Index
This survey of 230 banking professionals is the clearest snapshot of real bank readiness available today. Beyond the headline 72 percent figure, it found two top human risks. Automation bias, named by 34 percent. Misaligned incentives, named by 27 percent. Risk mitigation, not regulatory compliance, was the leading driver of AI adoption. It scored 37 percent versus 30 percent for compliance.
What banks can learn:
- Treat kill-switch protocols and incident reporting as day-one requirements, not later add-ons
- Watch for automation bias, where staff trust an AI recommendation without checking it
- Frame AI governance as risk management first, since that is what is actually driving adoption at peer banks
- Prioritize oversight in lending, underwriting, and collections, the two areas bankers themselves flagged as highest risk
Research Study: The Sensorial Trust Problem in Financial Transactions
Academic research on speech deepfakes traces this threat back further than most people realize. In 2020, a Hong Kong bank manager got a call from a cloned voice. He knew the real executive being impersonated. He still authorized a partial transfer toward a fraudulent 35 million dollar request.
Researchers now argue that human senses are no longer reliable proof of identity. A familiar voice is not proof. A familiar face on video is not proof either.
What banks can learn:
- Never treat a voice or face alone as identity verification for a high-value transaction
- Adopt a shared, pre-agreed verification step, such as a code word, for wire authorization
- Require callback verification through a known, separately-dialed number before large transfers
- Train staff that urgency and confidentiality pressure are themselves warning signs, not just the content of a request
Source: The Age of Sensorial Zero Trust: Why We Can No Longer Trust Our Senses, arXiv, 2025
What the Experts Are Saying
Wolters Kluwer US Banking AI Risk and Governance Index, June 2026
Sultan Meghji, Frontier Foundry, June 2026
Elaine Duffus, Wolters Kluwer, June 2026
Notice what all four have in common. None of them argue AI should slow down in banking. They argue the control layer, kill switches, reporting, and human review, has to catch up to how fast banks are already deploying it.
Sources: American Banker, June 2026 and Sullivan and Cromwell, April 2026
Privacy: Customer Financial Data Is a Constant Target
Banks hold Social Security numbers, account numbers, income data, and full transaction histories. AI adds new paths for that data to move, and new places it can leak from.
Third-party tools and CRMs hold copies of records
Staff paste account details into public AI tools
Public appearances become raw material for deepfakes
Social engineers trick staff into confirming account access
Practical privacy rules for every bank:
- Use only approved AI tools, and block unapproved ones on staff devices
- Never let staff paste customer account numbers or balances into public AI tools
- Get written vendor terms on data storage, reuse, and no training on customer data
- Set short retention limits on AI chat logs, call recordings, and generated summaries
- Limit how much executive voice and video appears in public settings where it can be scraped for cloning
- Tell customers clearly when they are interacting with an AI system rather than a person
Governance Stack: Who Owns What
Sets AI risk appetite. Reviews the AI inventory. Owns the incident-reporting policy.
Lending, collections, and service teams own how AI is used and who can override it.
Own kill switches, logging, vendor access, and frontier-AI threat monitoring.
Test for bias, review vendors, and prepare for examiner questions on out-of-scope AI.
Actionables: What Each Team Should Do, Why, and What It Changes
Use these tables as working checklists. Each row names the action, why it matters, and the result you should expect.
For Boards and Senior Leaders
| Action | Why it matters | Expected impact |
|---|---|---|
| Demand a live test of the AI kill switch, not a policy document | 72 percent of banks cannot confirm the switch actually works | The gap surfaces to you, not to an examiner or an incident |
| Name one executive who owns agentic AI oversight | SR 26-2 leaves these systems without a formal rulebook | Clear ownership instead of a gap nobody owns |
| Fund frontier-AI threat monitoring as a standing budget line | One model already alarmed regulators enough to summon CEOs | Faster response to the next capability jump |
| Require board reporting on vendor AI risk, not only internal AI risk | Recent bank breaches came through shared vendors, not direct hacks | Fewer blind spots in your real attack surface |
For Lending, Collections, and Frontline Business Leaders
| Action | Why it matters | Expected impact |
|---|---|---|
| Test lending models for outcome differences across protected groups | A real settlement already cost one lender 2.5 million dollars for this exact failure | Bias caught internally instead of by a regulator |
| Add human review before AI-driven collections escalate to legal action | Bankers themselves rank collections as a top agentic-AI risk area | Fewer wrongful escalations against vulnerable customers |
| Require a second verification channel for any wire request tied to urgency or secrecy | This exact pattern has already moved tens of millions of dollars via deepfakes | Fraud caught before the money leaves the building |
| Record a plain-language reason for every AI-assisted credit denial | Customers and regulators can both ask why a decision was made | Faster appeals and stronger legal defensibility |
For Developers and Security Engineers
| Action | Why it matters | Expected impact |
|---|---|---|
| Build and actually test a kill switch for every AI system touching money or credit | A policy that has never been tested is not a control | Confirmed, timed shutdown capability instead of an assumption |
| Log every AI decision with input, model version, and output attached | Examiners and courts will ask how a decision was reached | Fast, evidence-backed answers during any review |
| Restrict vendor and third-party AI access with least privilege | Recent major breaches all started at a shared vendor, not the bank itself | A compromised vendor reaches far less of your data |
| Track frontier-AI capability disclosures from major labs as threat intelligence | A model’s vulnerability-finding power can become an attacker’s tool overnight | Earlier patching before a new capability is exploited |
For Fintech and Banking-as-a-Service Startups
| Action | Why it matters | Expected impact |
|---|---|---|
| Build audit logs and reason codes into your product from day one | Your bank clients must justify your model’s decisions to their own examiners | Faster due diligence and stronger institutional trust |
| Offer a demonstrable, testable kill switch as a core feature | Banks are actively being asked whether their vendors have one | A real differentiator in procurement conversations |
| Publish clear data-handling terms, including no training on client data by default | Banks now screen AI vendors on data terms before anything else | Shorter sales cycles with regulated institutions |
| Avoid single-vendor dependency for any critical security or identity function | One vendor’s flaw already exposed 1.35 million customers across 74 institutions | Your product survives even if one dependency fails |
For Compliance, Risk, and Legal Teams
| Action | Why it matters | Expected impact |
|---|---|---|
| Build a written governance rationale for every AI system SR 26-2 does not cover | Examiners are already asking this question, rule or no rule | A defensible answer ready before the exam, not during it |
| Draft your incident-reporting playbook for an AI failure specifically | 38 percent of surveyed bankers say this is their weakest area | Minutes, not days, between detection and formal reporting |
| Prepare comments for the agencies’ promised request for input on generative and agentic AI | This is the rulemaking window that will shape the next several years | Your operational reality shapes the eventual rule, not just the largest banks’ |
| Write AI-specific verification steps into your wire-transfer policy | Deepfake fraud already defeats voice and video recognition alone | A documented control that actually matches the current threat |
For Customers and Small Businesses Banking With AI-Enabled Institutions
| Action | Why it matters | Expected impact |
|---|---|---|
| Set up a verbal passphrase with your own finance team for wire requests | A familiar voice or face is no longer proof of identity | A deepfake call fails the check even if it sounds perfect |
| Ask your bank for a plain-language reason behind any automated denial | You are entitled to understand why an AI-assisted decision was made | A faster, more informed appeal if the decision was wrong |
| Monitor for breach notifications, even from vendors you never directly dealt with | Most bank breaches now start at a third party, not the bank itself | Faster response if your data is exposed through a partner you never chose |
Risk Tiers: Matching Oversight to Impact
| Tier | Example | Required control |
|---|---|---|
| Assist | Chatbot answers a balance or hours question | Clear AI labeling and an easy path to a human |
| Recommend | AI suggests a credit limit or repayment plan | Human sign-off with a documented reason code |
| Execute bounded tasks | Auto-approve small, low-risk loans | Fixed approval ceiling and regular bias testing |
| High-impact decision | Deny a loan, freeze an account, or authorize a large wire | Mandatory human review and a tested, working kill switch |
Implementation Roadmap
List every AI system, including vendor tools, touching money or credit decisions
Actually activate your kill switch and time how long it takes
Add second-channel checks for wires and bias tests for lending
Keep audit evidence ready and rehearse an AI incident report
KPIs to Track
| KPI | What it tells you |
|---|---|
| Kill-switch activation time | How fast you can actually stop a malfunctioning AI system |
| Lending outcome gap | Differences in approval or pricing across groups that need explaining |
| Wire fraud caught before transfer | Whether verification steps are actually stopping deepfake attempts |
| Vendor AI risk coverage | Share of AI vendors formally reviewed for security and data terms |
| AI incident reporting time | Minutes or hours from detection to formal internal or regulatory report |
Future Predictions: 2027 to 2030
2027: Generative and Agentic AI Get Their Own Rulebook
The OCC has already said the agencies plan a request for input on bank use of generative and agentic AI. If that process moves at a typical regulatory pace, expect a formal proposal in this window.
2028: Verified Voice and Video Become Standard for High-Value Transfers
As deepfake losses keep climbing, expect banks to require cryptographic or passphrase-based verification for large wires as a default, not an opt-in.
2029: Frontier-AI Threat Sharing Becomes Formalized
Following the Mythos meeting’s precedent, expect a standing channel between AI labs, regulators, and systemically important banks for disclosing dangerous new capabilities before public release.
2030: Vendor AI Risk Gets Its Own Supervisory Category
Given how many major breaches now originate at shared vendors, expect regulators to treat AI vendor concentration as its own supervised risk category, similar to how cloud concentration risk is already discussed today.
Startup and Product Opportunities
- Tested kill-switch infrastructure: Provides banks a provable, auditable way to halt any AI system instantly
- Deepfake-resistant transaction verification: Adds passphrase or cryptographic checks to high-value wire approvals
- AI vendor concentration mapper: Tracks how many critical functions depend on a single AI or cloud vendor
- Lending fairness monitor: Continuously tests credit models for outcome gaps across customer groups
- AI incident reporting platform: Turns a detected AI failure into a regulator-ready report in minutes
- Frontier-AI threat intelligence feed: Tracks new model capabilities that could become attack tools
Frequently Asked Questions
What actually happened with Anthropic’s Mythos model and US banks?
In April 2026, the US Treasury Secretary and Federal Reserve Chair called an emergency meeting with major bank CEOs after Anthropic’s new Mythos AI model showed an unprecedented ability to find serious, previously unknown software vulnerabilities.
Does SR 26-2 regulate generative and agentic AI in banks?
No. The April 2026 guidance explicitly excludes those systems from its scope, calling them too new to cover yet, while directing banks to apply their existing risk principles voluntarily in the meantime.
Can most banks actually shut down a malfunctioning AI system?
Not confidently. A June 2026 survey of 230 bankers found 72 percent named either kill-switch protocols or failure reporting as their weakest area of AI preparedness.
How much money has deepfake fraud actually cost companies?
Individual cases range from hundreds of thousands to tens of millions of dollars. The FBI received over 22,000 reports involving AI-generated voice or video fraud in a single recent year, with reported losses approaching 893 million dollars.
Are recent bank data breaches caused by AI?
Mostly no. Recent major incidents at banks like Citizens Bank, Frost Bank, and Bank of America involved third-party vendors, not AI failures directly. They matter for AI governance because every new AI vendor adds another potential entry point.
What should a bank do first if it has no formal AI governance program yet?
Build a complete inventory of every AI system touching money or credit decisions, then actually test whether you can shut each one down and how long that takes.
Final Perspective
Banking runs on trust that money is safe and decisions are fair. AI can make both promises faster and cheaper to keep. It can also break them quietly, at a scale no single fraud investigator could match.
The 2026 record is now clear. Regulators treated one AI model’s capabilities as a banking-sector emergency. A rewrite of model risk rules left the fastest-growing AI systems without a formal rulebook. Most banks admitted they could not confidently stop a malfunctioning AI system. And deepfake calls have already moved tens of millions of real dollars out the door.
None of this argues for slowing down. It argues for catching up. Test your kill switch. Verify every high-value wire through a second channel. Watch your vendors as closely as your own systems. Document why every automated decision was made. Banks that build this discipline now will be the ones regulators, customers, and their own boards trust with the next wave of AI capability.
For sector-specific playbooks that apply the same discipline elsewhere in finance, see our related guides on AI Security and Governance in Insurance, AI Security and Governance in FinTech, AI Security and Governance in Investment and Asset Management, AI Security and Governance in Healthcare, and our earlier guides on AI in Capital Markets, AI in Trading, and AI in Crypto.
For deeper coverage of the banking topics above, see our reporting on AI in real-time fraud detection in banking, AI in credit scoring and underwriting, AI in anti-money laundering, the 2026 AI safety hack affecting a bank, Anthropic’s mandatory kill switch proposal, and the AI Kill Switch Act and regulation risks.
Sources
- Powell, Bessent Discussed Anthropic’s Mythos AI Cyber Threat With Major US Banks, CNBC, April 2026
- Treasury Secretary and Federal Reserve Chair Warn Bank CEOs About Cybersecurity Risks Posed by Anthropic’s New AI Model, Sullivan and Cromwell, April 2026
- Fed Chair Jerome Powell, Treasury’s Bessent and Top Bank CEOs Met Over Anthropic’s Mythos Model, CBS News, April 2026
- Supervisory Letter SR 26-2, Revised Guidance on Model Risk Management, Federal Reserve, April 17, 2026
- SR 26-2 Regulates Your Models, Not Your AI Agents, CIMCON Software, August 2026
- 72% of Banks Lack AI Model Kill Switches, Failure Reporting, American Banker, June 2026
- Wolters Kluwer Survey Highlights AI Governance and Other Ongoing Needs for Banking Institutions, Wolters Kluwer, June 2026
- AG Campbell Announces 2.5 Million Dollar Settlement With Student Loan Lender, Massachusetts Attorney General, July 2025
- AI Fraud: Protecting Your Business From Deepfakes, US Bank, 2026
- Voice Cloning Is the New BEC: Deepfake CEO Fraud in the US, CybelAngel, April 2026
- International AI Safety Report 2026, arXiv
- The Age of Sensorial Zero Trust: Why We Can No Longer Trust Our Senses, arXiv, 2025
- Citizens Bank Customers Targeted in Third-Party Data Breach, PYMNTS, April 2026
- Bank of America Data Breach: What Happened and What to Do, Security.org, July 2026
- 26 Biggest Data Breaches in Finance, UpGuard, July 2026


Leave a Reply