State Examiners Now Have a Playbook for AI. Here Is What Is In It.
Artificial intelligence stopped being a technology question for financial institutions some time ago. It is now a governance question, and as of September 16, 2026, it is an examination question.
On that date the Conference of State Bank Supervisors announced an AI Supervisory Framework built to help state examiners evaluate how artificial intelligence is used, and what it puts at risk, at state chartered banks and state licensed nonbank financial institutions. CSBS did not keep it internal. The framework was published so that regulated institutions can see the questions examiners may ask and the information they may request.
That decision matters more than the announcement itself.
CSBS did not issue a regulation and did not create a separate AI examination program. The framework is a discretionary supervisory tool, and each state agency will decide whether and how far to fold it into its own program. It is also built to scale with the institution, taking into account size, complexity, risk profile, and actual AI use. Brandon Milhorn, CSBS President and Chief Executive Officer, described the approach as principles based, and framed it as a way for institutions to explore and implement AI with more confidence rather than less.
Discretionary is not the same as irrelevant.
Five documents came out of the release, not one. There is a core examiner guide, a work program of roughly twenty eight pages setting out procedures, a supplement for nonbank licensees, a risk tiering worksheet, and a list of source materials. Examiners are directed to open with eight threshold questions covering whether the institution uses AI, where it is deployed, whether it touches consumers or shapes decisions, whether it came from a vendor or was built internally, whether AI is already embedded in products the institution has bought, whether generative AI is in use, how AI uses are classified by risk, and what sensitive data moves through those systems.
Scale is the part most institutions underestimate. State agencies supervise 3,355 of the 4,233 FDIC insured banks in the country, close to 79 percent. Roughly 99 percent of state chartered institutions hold under thirty billion dollars in assets, which places them below the threshold where federal model risk management guidance applies. The framework also reaches into territory federal regulators left open, since generative and agentic AI were explicitly excluded from the April 2026 model risk guidance revisions issued by the Federal Reserve, the FDIC, and the OCC.
The practical question is no longer whether an institution uses AI.
It is whether management can identify where AI is being used, explain why, understand the risks, show appropriate oversight, and produce documentation that supports every one of those answers.
Cathedral CPAs and Advisors works with management teams on exactly that sequence. The policy is rarely the hard part. The first step is.
