Filling the Regulatory Void: State Regulators Step In as AI Moves Beyond Federal Oversight

In the rapidly shifting landscape of financial technology, a quiet but profound transformation is taking place. As the transition toward a second Trump administration looms—bringing with it widespread expectations of federal deregulation—state-level agencies are positioning themselves as the new frontline of financial oversight. By moving to fill the perceived gaps left by federal regulators who have been hesitant to provide firm guardrails for emerging technologies, state agencies are asserting their authority in the digital age.

This strategic pivot became strikingly apparent this week when the Conference of State Bank Supervisors (CSBS) released a comprehensive, discretionary supervisory framework designed to help state examiners assess how financial institutions are deploying artificial intelligence. While not compulsory, the move signals a proactive effort by state regulators to ensure that the adoption of AI—ranging from generative models to autonomous agents—does not outpace the industry’s ability to manage its inherent risks.

The Federal Reluctance: A Technological "No-Go" Zone

The urgency of the CSBS framework is underscored by the notable absence of federal guidance on AI. In April, the "Big Three" of federal banking oversight—the Federal Reserve, the Office of the Comptroller of the Currency (OCC), and the Federal Deposit Insurance Corp. (FDIC)—updated their joint guidance regarding model risk management.

While this guidance provided a rigorous roadmap for how banks should test and oversee the models governing lending, pricing, and risk decisions, it conspicuously omitted artificial intelligence. The agencies offered a blunt rationale for this exclusion: "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance."

For many in the industry, this statement was interpreted as a sign that federal regulators were not yet ready to commit to a formal supervisory posture regarding AI. By effectively drawing a line in the sand, the federal agencies created a regulatory "grey zone," leaving banks in a state of uncertainty. While the April federal guidance was not technically intended for state-chartered banks, the lack of a clear national standard left a vacuum that state supervisors, who oversee nearly 80% of the nation’s 4,233 FDIC-insured institutions, felt compelled to address.

A Principles-Based Approach: The CSBS Strategy

Recognizing that the genie cannot be put back in the bottle, the CSBS has opted for a "principles-based" framework. During the launch of the initiative, CSBS CEO Brandon Milhorn emphasized that the goal is not to stifle innovation, but to provide a structured environment for it to thrive.

"This is intended to help financial institutions explore and implement AI with additional confidence," Milhorn stated in a press release. "We know that any new technology can present risks, but we also recognize the potential for AI to drive efficiency and consumer value. Our framework provides the necessary guardrails to ensure that this implementation is done safely."

The framework is expansive, consisting of five core documents designed to assist examiners in navigating the complexities of modern software:

  1. A Core Examiner Guide: The foundational document outlining the philosophy of AI oversight.
  2. A Work Program: A step-by-step procedure for conducting examinations.
  3. A Nonbank Supplement: A specific guide for entities outside of traditional banking that nonetheless participate in the financial ecosystem.
  4. An AI Tiering Worksheet: A mechanism for classifying the risk level of specific AI use cases.
  5. A Source List: A comprehensive bibliography of the research and data informing the framework.

The Tiering System: Quantifying the Unquantifiable

Perhaps the most impactful innovation within the CSBS framework is its risk-tiering system. By categorizing AI deployments into three distinct tiers, the CSBS provides a clear rubric for both banks and examiners to determine the intensity of oversight required.

Tier 1: Low-Risk Internal Operations

The CSBS defines Tier 1 as the lowest level of risk. This typically applies to AI applications that are limited to internal bank operations. Characteristics include human-reviewed outputs, minimal impact on consumers, low data sensitivity, and a negligible potential for harm if the system experiences an error or outage. In these cases, examiners are encouraged to take a light-touch approach, focusing on basic internal controls.

Tier 2: Moderate-Risk Support Systems

A bank enters Tier 2 when AI is deployed in a consumer-facing role or acts as a primary decision-support tool. According to the CSBS, this tier is characterized by moderate data sensitivity and "exception-based" human oversight. If an AI tool is used to help a loan officer make a decision, or if it manages customer interactions that could lead to moderate operational harm, it falls into this category.

Tier 3: High-Risk Consumer Outcomes

Tier 3 represents the highest level of scrutiny. This is reserved for AI use cases that involve direct consumer outcomes, process sensitive personal data, or operate with limited human oversight. Because significant operational reliance or the potential for material harm exists, these systems require rigorous, frequent testing, and robust governance documentation. If an AI model is autonomously approving mortgages or managing high-volume trading accounts, it is almost certainly a Tier 3 application.

Implications for the Financial Industry

The CSBS framework is not intended to be a siloed tool for government agents; rather, the organization explicitly framed it as a "resource for industry." By making the framework public, the CSBS is encouraging banks to engage in "self-examination."

"Financial institutions can use the framework to assess their own AI programs, establish sound AI governance and risk management, and prepare for examinations," the CSBS noted. This dual-purpose nature is a strategic move to foster transparency. By showing banks exactly how they will be measured, the CSBS hopes to lower the barrier to entry for AI adoption, provided that institutions are willing to document their processes and maintain clear lines of accountability.

However, the framework arrives at a time of significant political flux. As the incoming administration prepares to take office, the promise of "perceived deregulation" is top of mind for many financial executives. If the federal government moves toward a hands-off approach to AI in the banking sector, the CSBS framework may inadvertently become the de facto national standard. This creates a fascinating dynamic: state agencies, traditionally seen as the secondary tier of regulation, are now setting the pace for the federal government.

Supporting Data: Why State Regulation Matters

The importance of this initiative is highlighted by the sheer volume of assets under state supervision. With over 3,300 FDIC-insured institutions falling under the jurisdiction of state regulators, the CSBS framework covers the majority of the community banking sector in the United States.

Community banks often lack the internal resources to develop complex, proprietary AI risk-assessment models from scratch. By providing a pre-built framework, the CSBS is effectively leveling the playing field, allowing smaller, state-chartered banks to compete with larger, national institutions that have massive compliance budgets.

Challenges and Future Outlook

Despite the optimism surrounding the CSBS framework, significant challenges remain. The rapid evolution of "agentic" AI—systems capable of autonomous decision-making and task execution—continues to outpace even the most well-intentioned regulatory guidelines.

Furthermore, the discretionary nature of the CSBS framework leaves room for variability. Because individual states may interpret or implement these guidelines differently, the industry could face a fragmented regulatory landscape. A bank operating in multiple states might find itself answering to different sets of AI oversight standards, creating a "patchwork" compliance burden that many bankers have long feared.

Nevertheless, the move by the CSBS marks a definitive shift in the philosophy of financial supervision. It acknowledges that the future of banking is intrinsically linked to artificial intelligence, and that the duty to protect the financial system cannot wait for a federal consensus that may never arrive.

As the industry moves forward, the CSBS framework will serve as a litmus test. If it succeeds in guiding banks toward safe and transparent AI integration, it may provide a model for how decentralized regulatory bodies can lead in the face of technological disruption. If it fails, or if it becomes overly burdensome, it could spark a new wave of lobbying for federal preemption.

For now, the message to state-chartered banks is clear: The age of unregulated AI experimentation is coming to a close. Whether through federal mandate or state-led guidance, the era of "AI accountability" has officially begun. The institutions that adapt early—by building strong governance, rigorous testing protocols, and a clear understanding of their risk tiers—will likely be the ones to thrive in the complex, algorithm-driven financial world of tomorrow.