Artificial intelligence is already inside the banking environment.
It may be there through Microsoft Copilot, an AI-enabled vendor, a productivity platform, a browser-based chatbot, an employee experimenting with a personal AI account, or an AI feature added to software the bank has used for years.
For community and regional banks, that changes the AI conversation.
The question is no longer simply:
Does our bank have an AI policy?
The more important questions are:
Do we know which AI tools are actually being used?
Do we know what bank information employees are entering into them?
Can we enforce the rules in our AI policy?
Can we demonstrate what we are doing to manage AI risk?
Those questions have become especially relevant following the Conference of State Bank Supervisors' release of its Artificial Intelligence Supervisory Framework on September 16, 2026.
The framework is a discretionary resource for state examiners. It is not a new regulation or a universal examination requirement. Each state regulatory agency will determine how, or whether, it incorporates the framework into its supervisory program.
But the framework gives banks something valuable: greater visibility into the types of AI governance, inventory, use-case, and oversight information that may become part of supervisory conversations.
For bank leaders, that makes this a good time to look beyond the AI policy itself and ask whether the institution can actually demonstrate how AI is being governed.
What Is AI Governance for a Community Bank?
AI governance for a community bank is the combination of policies, oversight, technical controls, monitoring, and documentation used to determine how artificial intelligence can be used, what information it can access, who can use it, and how AI-related risk is managed.
A written acceptable-use policy is part of that program.
It is not the entire program.
Good AI governance should help bank leadership answer practical questions such as:
- Which AI applications are employees currently using?
- Which AI capabilities are embedded inside existing vendors?
- Who is using each tool?
- What business purpose does each AI use case support?
- What bank or customer information can an AI system access?
- What information should employees be prohibited from entering?
- Which AI applications are approved, restricted, or blocked?
- What happens when an AI agent can take an action instead of simply generating an answer?
- How is AI activity monitored?
- What evidence can the bank produce to demonstrate that its policies are being followed?
That last question is becoming increasingly important.
A bank can write a strong policy stating that confidential or regulated information should not be entered into an unapproved AI platform.
But if the bank cannot see what AI tools are being used or support that policy with appropriate controls, leadership may still have a visibility gap.
Why Is AI Governance Becoming More Important for Banks in 2026?
On September 16, 2026, CSBS released its Artificial Intelligence Supervisory Framework to help state examiners identify and understand AI use at financial institutions, assess associated risks, and determine when deeper review may be appropriate.
CSBS also made the framework available to financial institutions as a resource they can use to assess their own AI programs and prepare for examinations.
The framework's Core Examiner Guide includes examination procedures related to:
- Governance and oversight
- AI inventories and use cases
- Generative AI and emerging AI use
- Initial scoping and documentation
That does not mean every bank will face the same examination process or that every state examiner will use the framework in the same way.
It does mean that knowing where AI exists and being able to explain how the bank governs it is becoming a much more defensible position than simply pointing to an AI policy.
There is another important development happening at the same time.
Federal banking agencies have also proposed updated third-party risk management guidance, including a separate proposed guide for traditional community banking organizations. The proposals emphasize a risk-based approach to managing third-party relationships.
That matters because AI may enter a bank through both employees and vendors.
An institution may carefully control direct employee access to public AI tools while an existing software provider introduces an AI assistant, agent, model connection, or other AI-enabled capability.
AI governance and third-party risk management are increasingly connected.
The First AI Governance Problem: You Cannot Govern What You Cannot See
Before deciding which AI tools should be approved or blocked, a bank needs visibility into what is actually happening.
That sounds straightforward.
In practice, it may not be.
A bank may approve Microsoft Copilot while employees also experiment with ChatGPT, Claude, Gemini, browser-based AI tools, AI meeting assistants, writing tools, document platforms, or specialized applications.
Employees may access those systems using corporate accounts.
They may also use personal accounts.
They may work from the bank.
They may work remotely.
They may use different browsers.
That creates the problem commonly described as shadow AI: AI applications or services being used without the organization's full knowledge, approval, or oversight.
Wayne Hunter, CEO and Co-Founder of AvTek Solutions, recently described this challenge during AvTek's presentation on AI governance for banks.
The first question he asked was simple:
Do you have visibility into every AI application and agent your users are using?
That is where practical AI governance begins.
Before creating increasingly complex rules, the bank needs an accurate picture of its actual AI environment.
An AI Inventory Should Show More Than Which Tools You Purchased
A traditional software inventory may tell you which applications the bank intentionally licensed.
An AI governance inventory needs to go further.
It should help answer:
What AI applications are actually being used?
Who is using them?
How frequently are they being used?
Which AI agents are present?
What information is being submitted?
Which approved AI licenses are actually being used?
This distinction matters.
The bank's procurement records may say it has one AI environment.
Actual user behavior may reveal another.
AvTek's AI governance approach starts with visibility into AI tools and agents being used across managed endpoints. The service Wayne demonstrated is designed to identify AI applications and agents, understand who is using them, observe usage, and provide reporting that can support governance and audit documentation.
That visibility gives leadership a factual starting point for deciding what should be allowed, restricted, monitored, or blocked.
An AI Policy Is Stronger When Technical Controls Support It
Consider a simple policy:
Employees may not enter certain sensitive bank information into an unapproved large language model.
That rule makes sense.
But what happens when someone accidentally does it?
Or when an employee has legitimate access to sensitive information but uses that information in an AI application that is not approved for it?
Traditional access control answers one question:
Is this employee allowed to access this information?
AI governance introduces another:
Is this employee allowed to send that information to this AI system?
Those are not always the same thing.
An employee may properly have access to financial reports, customer information, internal documentation, or other sensitive data as part of their job.
That does not automatically mean every piece of that information should be submitted to every AI platform the employee can reach.
This is why AI governance has to connect written policies to technical controls.
In Wayne's presentation, AvTek demonstrated the ability to apply policies at the managed device level and configure AI activity as allow, warn, or block.
If an action violates the bank's defined policy, the user can receive a customized warning or be prevented from submitting the information.
The objective is not to make AI unusable.
It is to turn the bank's written expectations into controls that can actually support those expectations.
Banks Need Evidence, Not Just Intent
Another major difference between an AI policy and an AI governance program is documentation.
Imagine an examiner, auditor, board member, or risk committee asking:
How do you know your AI policy is being enforced?
A copy of the policy explains what should happen.
Evidence helps demonstrate what is happening.
Wayne's presentation describes AI governance reporting that can capture information including:
- The user involved
- The AI application being used
- When activity occurred
- The managed system involved
- Policy-related activity
- AI application and agent usage
That gives the bank a stronger foundation for monitoring, policy refinement, and audit support.
It also creates a feedback loop.
Instead of guessing which AI rules employees need, leadership can use actual usage information to determine where policies may need to change.
Maybe an application should be approved.
Maybe a particular type of data should trigger a warning.
Maybe a use case should be blocked.
Maybe the bank purchased AI licenses that employees are barely using.
Governance becomes an ongoing process rather than a document created once and revisited at the next annual review.
AI Agents Raise a Different Governance Question
Generative AI introduced the question:
What can employees tell AI?
AI agents introduce another:
What can AI do?
An AI assistant might summarize a document.
An AI agent may be designed to perform multiple steps, interact with systems, retrieve information, or initiate actions.
That creates a different level of governance.
Banks should understand:
- Which AI agents exist in the environment
- What systems an agent can access
- What information the agent can retrieve
- What actions it is authorized to perform
- Where human approval is required
- How activity is logged
- How an agent can be restricted or stopped
Human verification is especially important when an AI-supported workflow moves beyond analysis or drafting into actions that could affect data, systems, customers, compliance, or bank operations.
The goal is not to require a human click simply for appearances.
The goal is to place meaningful oversight at the points where the consequences justify it.
What Should a Community Bank's AI Governance Program Include?
There is no single AI governance model that fits every institution.
A community bank with a small number of controlled AI use cases will have a different risk profile from a larger institution deploying AI across multiple departments and vendors.
A practical program should reflect the bank's size, complexity, risk profile, and actual use of AI.
That aligns with the principles-based approach described in the CSBS framework.
At a practical level, banks should consider whether their governance program addresses several core areas.
1. AI Discovery and Inventory
Know which AI applications and agents are actually being used, not merely which ones have been purchased.
2. Approved Use Cases
Define where AI provides a legitimate business benefit and what the bank expects employees to accomplish with it.
3. Data Governance and Classification
Understand which information employees can access and which information should or should not be submitted to particular AI systems.
4. Acceptable-Use Policies
Give employees clear rules about approved applications, acceptable uses, prohibited data, and escalation procedures.
5. Technical Policy Enforcement
Where appropriate, support written policies with controls that can allow, warn, restrict, or block activity.
6. Monitoring and Evidence
Maintain appropriate records that help management understand how AI is being used and demonstrate how policies are being applied.
7. AI Agent Oversight
Understand what agents can access and do, and determine where human verification should remain part of the workflow.
8. Third-Party Risk
Identify AI capabilities introduced through existing vendors and determine whether those changes affect data access, subprocessors, permissions, operations, security, or the bank's overall risk profile.
9. Ongoing Review
AI changes quickly. The governance program needs a process for evaluating new applications, new features, changing use cases, policy exceptions, and emerging risks.
Should Banks Ban Public AI Tools?
A blanket prohibition may look simple on paper, but it does not answer the larger governance problem.
Employees may still encounter AI through vendor platforms, embedded software features, personal accounts, browser tools, or new capabilities introduced into applications they already use.
The more useful question is:
What AI use should the bank permit, under what conditions, and with what controls?
Responsible governance gives the bank a way to make those decisions deliberately.
That may mean approving one application for a particular use case.
It may mean blocking another.
It may mean allowing a tool while preventing certain categories of data from being submitted.
It may mean requiring human review before an agent completes a higher-risk action.
AI governance should help the bank use AI deliberately, not simply say yes or no to the technology as a whole.
How Can a Bank Prepare for AI Questions During an Examination?
Start by asking whether the bank can clearly explain its current AI environment.
Could you provide an inventory of AI applications and use cases?
Could you identify which departments and users are using them?
Could you explain how applications are approved?
Could you show how sensitive information is protected?
Could you demonstrate how the bank monitors compliance with its AI policies?
Could you explain how vendor AI capabilities are evaluated?
Could you identify where AI agents exist and what they are permitted to do?
Could you provide evidence supporting those answers?
The CSBS framework does not create a single mandatory checklist for every bank. But its focus on governance and oversight, AI inventory and use cases, and generative and emerging AI use makes these useful questions for banks to ask themselves now.
You do not have to wait for an examiner to ask them.
Frequently Asked Questions About AI Governance for Banks
Do community banks need an AI governance program?
If a bank is using AI or AI-enabled systems, a structured governance process can help leadership understand those uses, evaluate risk, establish policies, protect sensitive information, monitor activity, and document oversight.
The appropriate program should reflect the bank's size, complexity, risk profile, and actual use of AI.
Is an AI policy enough for a bank?
An AI policy is an important foundation, but a policy alone does not provide visibility into actual AI use or automatically enforce data-handling rules.
Banks should also consider inventory, data governance, application controls, monitoring, employee education, third-party risk, documentation, and oversight.
What is shadow AI in banking?
Shadow AI refers to AI applications or services being used without the bank's full knowledge, approval, or governance.
Examples can include employees using personal AI accounts, unapproved browser-based tools, AI extensions, or new AI features introduced through existing software.
What should banks include in an AI inventory?
An AI inventory should identify the applications and AI agents being used, their business purpose, who uses them, the information they can access, and the controls surrounding their use.
Banks should also account for AI embedded inside third-party platforms rather than limiting the inventory to products explicitly purchased as AI tools.
How does AI governance relate to bank examinations?
CSBS released an AI Supervisory Framework in September 2026 that state examiners may use at their discretion to help identify AI use, assess associated risks, and determine whether deeper review is appropriate.
The framework also gives financial institutions a resource for assessing their own AI programs and preparing for examinations.
Because individual state agencies determine how they use the framework, banks should not treat it as a universal new examination requirement.
How does AI governance relate to vendor risk management?
AI can enter the bank through vendors as well as direct employee use.
When a vendor adds AI, the change may affect what information the service can access, which outside providers are involved, what actions the technology can perform, or how the bank depends on that service.
AI governance and third-party risk management therefore need to work together.
Can banks technically prevent sensitive information from being entered into AI?
Depending on the environment and controls being used, policies can be supported with technical restrictions that warn users or prevent defined information from being submitted to certain AI applications.
AvTek's AI governance service includes device-level visibility and policy enforcement capabilities designed to support these types of controls across managed endpoints.
Move From an AI Policy to an AI Governance Program You Can Demonstrate
If your bank already has an AI policy, that is a good starting point.
Now ask the harder question:
Can you prove that the bank is operating according to it?
Can you see the AI tools and agents employees are actually using?
Can you identify what information is being submitted?
Can you apply controls when a use violates policy?
Can you produce evidence showing how AI is being managed?
Can you tell which AI investments employees are actually using?
Can you explain your AI governance approach clearly to management, the board, auditors, and examiners?
AvTek Solutions' AI governance services are designed to help community and regional banks move from assumptions to visibility.
AvTek can perform a two-week AI governance assessment to identify AI applications and agents being used across the environment, evaluate usage, and provide a clearer picture of the bank's current AI activity. From there, AvTek can help apply policies that allow, warn, or block defined AI activity and provide reporting that supports ongoing governance and audit evidence.
If your bank has an AI policy but cannot yet demonstrate what is happening behind it, now is the time to find out.
Talk with AvTek Solutions about an AI governance assessment and get a clear view of the AI applications, agents, usage, and data activity already present in your environment. Don't wait until an examiner, auditor, or incident forces the question. Know what your bank is using, establish the right controls, and build the evidence to support your AI governance program.

