BankThink

Bank examiners already have a good template for regulating AI

  • Key insight: Recent federal guidance stopped short of issuing rules for banks' artificial intelligence use, but bank examiners already have some tools they can deploy to make sure these systems operate safely.
  • Supporting data: On April 17, the Fed, the OCC and the FDIC published the replacement for SR 11-7.
  • Forward look: While the original supervisory letter, published on April 4, 2011, does not mention the words "artificial intelligence," it is essentially the country's oldest working AI governance regime.

Having spent a decade running the Federal Reserve Bank of Philadelphia, I know what bank supervision looks like from the inside and how supervisory guidance is written. So, consider the supervisory letter numbered SR 11-7, issued on April 4, 2011. In all 21 pages, the words "artificial intelligence" never appeared. It did say that any quantitative model a bank uses had to be documented, carefully tested, and capable of being challenged by people who are not the same as those who built the model. And finally, it required that bank examiners would be able to check that all of this was done.

Processing Content

While that letter never mentions AI, it is essentially the country's oldest working AI governance regime. All the various quantitative models deployed in credit scoring, fraud detection, stress models, etc. all fell under this guidance, and as the models became more complex, the guidance stood.

Fast forward 15 years. On April 17, the Fed, the OCC and the FDIC published the replacement for SR 11-7. In looking at the revised version, there's much to like, including stating that it is most relevant to banks with more than $30 billion in assets. The new version also adds a section on vendor models, stating that the principles of SR 11-7 apply even when a bank lacks full visibility into the underlying model.

But then the regulators added this exception: "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance." Furthermore, it states: "non-compliance will not result in supervisory criticism." In fairness, the agencies do understand that they will need to deal with AI and promised a request for information on AI in banking "in the near future."

I understand the reasons behind the strategy, since it's very difficult to write guidance around a target you can't clearly pin down. That said, I am sympathetic to both the bank examiners and bank management in not having clear guidance on this issue.

Obviously, banks cannot wait for this guidance. Fraud detection models, customer service systems, underwriting support, and document review are all actively deploying AI tools provided by a small number of vendors. Now, interagency guidance issued in June 2023 still holds a bank responsible for the models provided by these vendors. This clearly puts bank leadership in a tough spot because they are accountable for models that they don't have full visibility into. And since the guidance says that the models using this technology are out of scope, they receive no help from their regulators.

In addition, the providers of these technologies are highly concentrated. Three companies supply most of cloud computing, and a few supply most of the frontier AI models. If multiple banks are using essentially the same model from one of the few choices, and that model creates a problem for one type of transaction, that's not just a problem with a single bank. This leads to correlated exposure across the banking system. Regulators do have a tool for such correlated exposure: horizontal review, but it's never been applied to AI vendors.

While Congress and all of us debate how to govern AI, let's recognize that bank examiners have essentially been governing quantitative models since 2011. They have a 15-year head start in thinking about these issues, so the country should lean on their expertise.

Read more:

So, what do we do right now? Here's what I would do, and none of it requires Congress to act.

First, make sure that this request for information gets turned into a supervisory letter on the use of foundational models within 12 months. It just needs to say what a bank needs to know about any model it licenses, what an examiner would need to see to demonstrate the bank's prudence in the use of these models, and what a bank should do if a vendor does not disclose the information the bank requires. And as technology evolves, the letter can be revised, just as SR 11-7 finally was this year.

Second, use the authority under the Bank Service Company Act to examine the models provided by AI firms, as this 1962 statute allows agencies to examine any company that performs services for a bank, including core processors. The Richmond Fed has used this already to examine an Amazon facility in Virginia. The firm supplying the frontier AI model for bank fraud is clearly providing a bank service and should fall under this act.

Third, conduct a horizontal review of AI vendors across the largest banks and then publish those results. The names of banks and vendors are not important to disclose publicly; it's the understanding of where the risks are in this system, risks that are growing each day.

So, what is the pushback? Some may object to the use of a 1962 statute written with check-processing companies in mind and question its applicability to these technology firms. While it is true that such a use of this act has never been fully tested in court, the Richmond Fed's examination of Amazon argues that it is appropriate. And while there will be lots of complaints about using an obscure banking law to examine today's technology companies, the bank examiners I know are used to getting complaints. That's not a reason not to do this.

What about the argument that it is impossible to explain the inner workings of these AI models? I would bet that if the OCC decided that it would not let a bank deploy a model it could not explain, the vendors would figure out how to build in the explainability. Banks are too important as customers of these firms to simply ignore.

Artificial intelligence was never mentioned in a 21-page letter issued 15 years ago, but it governed this technology before anyone called it that. The new guidance should move briskly to govern it as well.


For reprint and licensing requests for this article, click here.
Artificial Intelligence Regulation and compliance Bank technology
MORE FROM AMERICAN BANKER
Load More