The Conference of State Bank Supervisors released an Artificial Intelligence Supervisory Framework on September 16 to give state examiners a common approach for evaluating how banks and nonbanks under their jurisdiction use artificial intelligence. The framework ships as five documents: a core examiner guide, a work program of examination procedures, a nonbank supplement, a risk tiering worksheet and a source list. CSBS chief executive Brandon Milhorn described it as “a principles-based approach…intended to help financial institutions explore and implement AI with additional confidence.”

The framework matters because state agencies supervise 3,355 of the country’s 4,233 FDIC-insured banks and savings institutions, meaning most US banks could face these questions at their next state exam. It sorts AI use into three risk tiers, from internal tools with human review at the low end to consumer facing systems with limited human oversight and material harm potential at the top, and it explicitly covers generative and agentic AI, the exact category the Federal Reserve, OCC and FDIC carved out of their own model risk guidance earlier this year.

The original insight is the gap it fills rather than closes: CSBS is explicit that the framework is discretionary and creates no new substantive requirement, leaving each state regulator to decide how much weight to give it. That leaves banks facing a fragmented outcome by design, one where a bank’s AI exam experience depends on which of the 3,355 state-chartered institutions’ home regulator it answers to, an unevenness that echoes how federal regulators have also rewritten oversight rules for bank-fintech partnerships without fully harmonizing them, at precisely the moment other regulators are widening the net for lighter exam schedules elsewhere in the system.

Source: Conference of State Bank Supervisors