Two state financial regulators issued new guidance for bank examiners on artificial intelligence within a week of each other in September 2026. The New York State Department of Financial Services (NYDFS) published cybersecurity guidance on September 10, and the Conference of State Bank Supervisors (CSBS) released an AI supervisory framework for state examiners on September 16.
What changed
NYDFS’s September 10 guidance covers the cybersecurity risk assessments required under its Cybersecurity Regulation. It names AI, including “frontier AI model developments,” as an emerging risk entities must account for, and a trigger for updating that assessment when adoption changes materially.
CSBS’s September 16 release gives state examiners a discretionary tool for reviewing AI use at state-chartered banks and nonbank financial companies. According to CSBS, it helps examiners “identify and understand AI at financial institutions, assess associated risks, and determine when a deeper review may be appropriate.” Examiners can look at AI in products, operations, compliance and vendor software, and review chatbot transcripts. It flags agentic AI—systems acting with limited human oversight—for extra scrutiny. Adoption is left to each state, so there is no single uniform mandate.
What it means for you
Neither document creates a new law or customer right. What changes is visibility: examiners now have an explicit basis to ask a bank or fintech how it governs its AI, including chatbots, and to pull transcripts during a routine exam. If you rely on a bank’s AI chatbot or an AI-driven credit product, this is part of why your bank may be updating its AI risk assessments and vendor contracts. For what these tools can see and share, see our privacy walkthrough on AI assistants and bank data. Examiner attention doesn’t mean the AI’s answers are always right, so check our guide to common AI money mistakes before acting on financial advice from an AI assistant.



