Getting your Trinity Audio player ready...

Authors: John Farley Eileen Yuen

null

Artificial intelligence ("AI"), including machine learning ("ML"), generative AI ("GenAI") and "agentic" workflow tools, is rapidly reshaping how financial institutions underwrite and price risk, detect fraud, screen for sanctions/AML, personalize customer interactions and optimize trading and treasury operations. Alongside clear upside, AI introduces amplified risk exposures: biased or non‑compliant decisions, opaque model failures, data leakage, IP infringement, third‑party risk concentration and heightened regulatory scrutiny.

This article highlights real-world case studies, emerging regulatory risk and a practical set of best practices tailored to banks, lenders, asset managers, insurers and fintechs.

Why AI is different in financial institutions

Financial services amplify AI risk due to several factors:

  • High-stakes decisions at scale. Credit, pricing, trading and fraud decisions can affect millions of consumers and markets.
  • Dense regulatory overlay. Financial institutions are heavily regulated and must satisfy fairness expectations while meeting consumer protection, market integrity and privacy obligations.
  • Model complexity and opacity. ML can be difficult to validate, explain and monitor.
  • Expanded attack surface. AI often relies on new data pipelines, cloud services and external models/APIs, increasing cyber and third‑party risk.

Case studies: AI/model use leading to losses

Emerging Regulatory Risk for Financial Institutions

United States: "No AI exemption," plus rising AI-specific expectations

  • Interagency enforcement posture: Federal agencies have explicitly stated that automated systems can violate existing consumer protection and civil rights laws, and they intend to enforce those laws in AI contexts.3,4
  • Model risk management baseline: US banking supervision has long expected robust model governance (development, validation and controls). Traditional guidance (SR 11‑7/OCC 2011‑12) remains influential, and the OCC recently issued updated interagency guidance emphasizing a risk‑based approach and vendor considerations (while noting certain novel GenAI systems may be out of scope).9
  • Market conduct: The SEC's proposal signals the potential for AI personalization and engagement tools to be regulated under conflicts-of-interest frameworks.5,6
  • Sector-specific AI governance tooling: Treasury announced a Financial Services AI Risk Management Framework (FS AI RMF) and an AI lexicon to drive consistent, risk-based governance across the sector (aligned to NIST AI RMF).8,10

European Union: EU AI Act "high-risk" obligations (credit scoring in scope)

The EU AI Act establishes a risk-based regime; in financial services, creditworthiness and credit scoring for natural persons are treated as high-risk use cases, triggering obligations around governance, data quality, transparency, oversight and conformity processes.11,12

New York: AI and cybersecurity expectations for regulated entities

NYDFS has issued guidance emphasizing AI-related cybersecurity risks and expectations under 23 NYCRR Part 500 (no new rule, but clear supervisory focus). In adjacent insurance contexts, NYDFS has also issued guidance on AI systems and external data in underwriting/pricing that illustrates the direction of travel on fairness, documentation and governance.13,14

Bottom line

Regulatory scrutiny is converging on the same demands: governance, explainability, testing, monitoring, third‑party oversight and documentation.10,11,15

Practical AI risk management strategies: The board level playbook for financial institutions

AI risk transfer: Insurance implications for financial institutions

AI-driven losses can implicate multiple coverage lines depending on facts and policy language. As claims develop, we expect more clarity to see whether they will affirmatively cover, explicitly exclude coverage or remain silent on AI loss exposures. Below are some but not all policies that may be impacted:

  • E&O/Professional liability: Claims of negligent advice, unsuitable recommendations, or misstatements derived from AI outputs (Particularly relevant where engagement tools influence investor behavior).5,6
  • Cyber/Privacy: Data leakage through GenAI use, AI pipeline breaches and operational disruption tied to AI dependencies.1,7
  • D&O/Securities: Governance failures or regulatory investigations tied to AI strategy, disclosure issues and controls.5,6
  • Crime/Social engineering: AI-enabled fraud and deepfake-driven payment diversion can intensify loss scenarios (often testing sublimits, definitions and authentication controls). NYDFS and banking research highlight external fraud as a key loss driver in AI contexts.1,13

As the AI risk landscape matures, the insurance marketplace is also beginning to develop standalone AI Liability products intended to respond more affirmatively to AI-specific failure modes that may not fit neatly within traditional Cyber, E&O, D&O, Crime or General Liability coverage grants. These products remain in an early stage of development, but emerging offerings are focused on exposures such as AI underperformance, hallucinations or inaccurate outputs, model drift, algorithmic error, intellectual property and privacy implications and third-party liability arising from the deployment or use of AI systems.

Practical takeaway: Insurance can help absorb AI-driven loss severity, but underwriters increasingly expect demonstrable AI governance aligned to model risk, cybersecurity and third‑party controls. We expect the insurance market to take various approaches to covering or not covering these exposures, and this may vary by insurance market and the type of insurance policy.

Conclusion

For financial institutions, these products should not be viewed as a substitute for strong enterprise AI governance or careful review of existing insurance wording. Rather, they may become a complementary risk transfer tool, particularly where an institution is deploying AI in customer-facing, decisioning, advisory, fraud detection or operational workflows that could create scaled legal, regulatory, reputational or financial harm. As the market continues to evolve, institutions should work with their insurance advisors to evaluate whether standalone AI Liability coverage, AI-specific endorsements or clarification of existing policy language provides the most effective approach to addressing these emerging exposures.

Author Information


Sources

1Mihov, Atanas and Ping McLemore. "Does AI Cause Higher Operational Losses at Banks?," Federal Reserve Bank of Richmond, accessed 27 Jul 2026.

2McLemore Ping and Atanas Mihov, "AI and Operational Losses: Evidence from U.S. Bank Holding Companies," Federal Reserve Bank of Boston, 3 Sept 2025. PDF file.

3"CFPB and Federal Partners Confirm Automated Systems and Advanced Technology Not an Excuse for Lawbreaking Behavior," Consumer Financial Protection Bureau, 25 Apr 2023.

4"Justice Department's Civil Rights Division Joins Officials from CFPB, EEOC and FTC Pledging to Confront Bias and Discrimination in Artificial Intelligence," United States Department of Justice, 25 Apr 2023.

5"Conflicts of Interest Associated with the Use of Predictive Data Analytics by Broker-Dealers and Investment Advisers," Securities and Exchange Commission, 26 July 2023. PDF file.

6"SEC Proposes Sweeping New Rules on Use of Data Analytics by Broker-Dealers and Investment Advisers," Sidley, 8 Aug 2023.

7"AI Risk Management Framework," NIST, accessed 27 July 2026.

8"Financial Services AI Risk Management Framework," Cyber Risk Institute, accessed 27 Jul 2026.

9"Model Risk Management: Revised Guidance," Office of the Comptroller of the Currency, 17 Apr 2026.

10"Treasury Releases Two New Resources to Guide AI Use in the Financial Sector," US Department of the Treasury, 19 Feb 2026.

11"AI Act: implications for the EU banking and payments sector," European Banking Authority, 21 Nov 2025.

12"Setting the ground rules: the EU AI Act," KPMG, May 2024.

13Alvarez, Daniel K et al. "NYDFS Issues Industry Guidance Letter on Artificial Intelligence Cybersecurity Risks," Willkie Farr & Gallagher LLP, 1 Nov 2024. PDF file.

14"Insurance Circular Letter No. 7: Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and Pricing," New York State Department of Financial Services, 11 Jul 2024. PDF file.

15"Supervisory Guidance on Model Risk Management," Board of Governors of the Federal Reserve System, 4 Apr 2011. PDF file.