You Are Already Using More AI Than You Think: Why the AI Inventory Comes First
When management hears the words “AI risk,” the first thing that usually comes to mind is something big. An automated underwriting platform. An internally developed AI model. A major generative AI project with a sizeable budget and a steering committee.
That view is too narrow, and it’s why so many organizational AI inventories come back short.
Key Takeaways
- Most financial institutions never made one deliberate decision to adopt AI. It arrived through many smaller decisions, several of them made by vendors.
- AI exposure comes from three sources: the systems you run, the tools your employees use, and the vendors who add AI to products you already own.
- A 2026 survey of community banks with $750 million to $25 billion in assets found that every respondent had adopted AI in some form, while only about 5% had a scaled, governed AI program.
- Two of the eight CSBS examiner questions ask about vendor-embedded AI and generative AI use.
- Fannie Mae and Freddie Mac now require mortgage lenders and servicers to inventory both internally built and vendor-provided AI.
Where Is AI Already Hiding in a Community Bank?
A community bank may have no data scientists, no proprietary AI models, no formal AI strategy, and a boilerplate AI policy, and still have meaningful AI exposure.
AI is probably already present in:
- Fraud detection and transaction monitoring
- Cybersecurity software
- Credit and loan origination systems
- Loan servicing platforms
- Marketing and customer engagement software
- Customer service, chatbots, and helpdesk systems
- Document processing and data extraction tools
- Compliance and BSA/AML tools
- Analytics and reporting tools
- Everyday productivity tools, such as Microsoft Copilot
Very little of this shows up as “AI” on an IT asset list. It shows up as a fraud system, a CRM, or a productivity license.
What Are the Three Sources of AI Exposure?
1. Systems the institution runs
These are the core and ancillary systems listed above. Some were purchased with AI features. Others gained them later.
2. Employees using generative AI
Staff are likely using public or enterprise generative AI tools to summarize documents, draft correspondence, analyze information, prepare presentations, research questions, and get routine work done faster. The most consequential use is when that output starts informing business decisions. Very little of this activity appears on an IT asset list.
3. Vendors adding AI to products you already own
Vendors are usually the largest of the three sources. An institution bought a system years ago for fraud monitoring, customer engagement, underwriting, or cybersecurity, and later learns, often much later, that the vendor added AI functionality through a normal software update. Change management is one of the few controls positioned to catch this, which is why IT general controls reviews should ask whether a release introduced AI features.
Put simply, most institutions never made a single deliberate decision to adopt AI. AI arrived through twenty smaller decisions. Some were made outside the organization, and none of them felt like an AI decision at the time.
How Widespread Is AI Adoption in Community Banks?
The numbers back this up. A 2026 survey of community banks between $750 million and $25 billion in assets found:
- 100% of respondents had adopted AI in some form.
- 30% relied entirely on ad hoc or vendor-embedded tools.
- About 5% had a scaled, governed AI program in production.
The gap between those numbers is the exposure. AI is everywhere; governance over it is not.
Why Do Examiners Care About Vendor-Embedded AI?
This is not just an opinion about how examiners think. It is written into the framework. Two of the eight CSBS examiner questions, the ones the framework tells examiners to start with, are:
- Is AI already embedded in products the institution has purchased?
- Is generative AI in use?
An institution that only inventories the AI it built itself will miss both, and both are on the examiner’s opening list.
Why the AI Inventory Comes Before the AI Policy
This is why the inventory comes before the policy, not the other way around.
Before management can govern AI risk, it has to know:
- Where the technology is being used.
- What it is doing.
- What information it can access.
- Who relies on its output.
- What could happen if that output is wrong.
A governance program built on an incomplete inventory is a governance program that documents the wrong things.
What This Means for Mortgage Lenders and Servicers
Mortgage origination and servicing businesses are typically more outsourced than most banks, which makes the vendor channel the one that matters most.
Both Fannie Mae and Freddie Mac now require an AI inventory that covers internally built and vendor-provided AI, documented across the AI lifecycle.
Fannie Mae goes a step further. Under Lender Letter LL-2026-04, effective August 6, 2026, a seller or servicer must promptly provide, on request, the types of AI and machine learning it has deployed, the purpose and method of use, and the safeguards in place. There is no notice period. Either the inventory exists on the day someone asks for it, or it does not.
How Cathedral Starts Every AI Readiness Engagement
At Cathedral, we start every AI readiness engagement with the inventory, because it determines the quality of everything that follows. Our inventory work typically covers:
- Interviews with business lines, IT, compliance, and vendor management.
- A review of vendor contracts, release notes, and due diligence files for AI functionality.
- Identification of employee generative AI use, approved and unapproved.
- A record of each AI use: owner, purpose, data accessed, who relies on the output, and potential impact of error.
If you are not sure your inventory would hold up on the day someone asks for it, talk to Cathedral CPAs & Advisors about building one that will.
