Part of the AI Regulation News hub.
The CSBS Artificial Intelligence Supervisory Framework, approved by two CSBS committees on 13 August 2026 and released publicly on 16 September 2026, gives state examiners a discretionary set of AI scoping questions, review procedures and an optional risk-tiering worksheet, and states in its Core Examiner Guide that it does not create new legal obligations or supervisory requirements
The date on the page is 16 September. The date on every document footer is 13 August. Neither is an effective date, because the package has none: it is an examiner resource that each state agency may take up in whole, in part or not at all, and the one sentence that governs how to read the rest of it sits on page 2 of the Core Examiner Guide.
Bottom line: Non-binding. The Core Examiner Guide states on page 2 that it does not create new legal obligations or supervisory requirements, the framework page calls it a discretionary tool for state examiners, and both that page and the 16 September press release say each state agency will determine the extent to which the framework is incorporated into its supervisory programs. This is dated back-coverage: the documents carry an approval date of 13 August 2026, and CSBS says it released them publicly on 16 September 2026.
Who this affects: Compliance officers, general counsel, chief risk officers and model risk and vendor management leads at state-chartered banks and state-licensed nonbank financial institutions; internal auditors who may help assemble materials if an examiner requests them; outside counsel and CPAs who prepare clients for state examinations; and the state examiners the package is written for.
Issue date: The instrument's own date is 13 August 2026. The covers of the Core Examiner Guide and the Nonbank AI Supplements read Approval Date: August 13, 2026, and every page footer of the three PDFs, and the footer of both Word files, reads Version 1.0, Approval Date: 08/13/2026. The framework page on csbs.org is dated 16 September 2026, and a CSBS press release of the same date says CSBS today released the resource. We read the approval date in the documents and the release date in the press release.
What changed: A publicly available, CSBS-approved package now exists for state examiners: an eight-page Core Examiner Guide with eight scoping questions, a document request list and 21 numbered procedures; an Examiner Work Program with source tables and examiner focus notes for each question and procedure; an 11-page set of three nonbank overlays; an optional risk-tiering worksheet; and a one-page source list. CSBS says the public release came on 16 September; we make no claim about earlier distribution.
Analysis: The framework's practical weight comes from its Document Request List, not from any obligation. The guide says examiners may request, as applicable, AI policies, an inventory, risk tiering information, a list of vendor products with known or potential embedded AI, samples of AI-generated consumer-facing outputs such as chatbot transcripts, and contract terms on training AI systems on customer data. An institution that cannot produce those items will learn that from an examiner who has chosen to use the guide. Whether a given state examiner will use it is the question the package leaves to each agency.
Primary sources: CSBS AI Supervisory Framework page, dated 16 September 2026 · CSBS press release, CSBS Announces AI Supervisory Framework, 16 September 2026 · Core Examiner Guide, Version 1.0, approval date 13 August 2026 (PDF) · Examiner Work Program, Version 1.0 (Word) · Nonbank AI Supplements, Version 1.0 (PDF) · AI Use Case Risk Tiering Worksheet (Word) · Sources document (PDF)
- Instrument (EN)
- CSBS Artificial Intelligence Supervisory Framework, Version 1.0: Core Examiner Guide, Examiner Work Program, Nonbank AI Supplements, AI Use Case Risk Tiering Worksheet and a Sources document
- Authority
- Conference of State Bank Supervisors (CSBS). Approved by the CSBS State Supervisory Processes Committee (SSPC) and the CSBS NonDepository Supervisory Committee (NDSC). CSBS is a membership organisation of state financial regulators, not itself a regulator; its own site footer says it is not licensed or regulated by any state or federal bank authority
- Jurisdiction
- United States, state financial regulatory agencies. The guide is written for examiners of bank and nonbank institutions; the press release names state-chartered banks and state-licensed nonbank financial institutions. Use in any given state depends on that state's agency
- Status
- Approved 13 August 2026 (document covers and footers). Publicly released 16 September 2026 (CSBS press release and framework page date). No effective date exists
- Bindingness
- Non-binding. Core Examiner Guide page 2: it does not create new legal obligations or supervisory requirements. Framework page: a discretionary tool for state examiners. The worksheet is described as an optional industry tool and says it should not be interpreted as official regulatory guidance from a state agency
- Issue date / next deadline
- Approval date 13 August 2026; public release 16 September 2026. The package sets no deadline, comment period, compliance date or transition period
- Legal basis
- None cited as authority. The Core Examiner Guide says it is based on existing public materials. The Sources document lists eight: NIST AI RMF 1.0, NIST AI 600-1, the U.S. Treasury / FSSCC AI Lexicon, the CRI Financial Services AI Risk Management Framework, SR 23-4, SR 26-2, ECOA / Regulation B at 12 CFR 1002.9, and the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, and says they are provided for context only
- Document
- Core Examiner Guide 8 pages; Nonbank AI Supplements 11 pages; Sources 1 page; the Work Program and the Worksheet are Word files whose page counts we did not verify. All five are linked from the framework page at csbs.org/node/584241, 584236, 584226, 584231 and 584246
- Primary source
- https://www.csbs.org/csbs-artificial-intelligence-supervisory-framework
Two dates, and neither is an effective date
The documents date themselves. The cover of the Core Examiner Guide reads Version 1.0, Approval Date: August 13, 2026, and the same line appears on the cover of the Nonbank AI Supplements and at the top of the Examiner Work Program. Every page footer of the three PDFs repeats it as Approval Date: 08/13/2026, and the footer stored inside both Word files carries the same version and date. The framework page on csbs.org says the framework was approved by the CSBS State Supervisory Processes Committee and the CSBS NonDepository Supervisory Committee in August 2026. So the instrument's own date is 13 August 2026, five weeks before this article.
The public release is a separate event. The framework page is dated 16 September 2026, and a CSBS press release of the same date, headed CSBS Announces AI Supervisory Framework, opens by saying that CSBS today released a new supervisory resource to support state examiners in assessing the use and risks of artificial intelligence at state-chartered banks and state-licensed nonbank financial institutions. That release is the source for the 16 September date. It is not the date anything was approved, and it is not a date on which anything took effect.
Nothing took effect on either date, because the package contains no effective-date clause, no comment period and no compliance deadline. What the release says instead is that each state agency will determine the extent to which this framework is incorporated into their supervisory programs, a sentence that also appears, with the words state financial regulatory agency, on the framework page. The release quotes CSBS President and CEO Brandon Milhorn describing the framework as "a principles-based approach to governance intended to help financial institutions explore and implement AI with additional confidence". That is CSBS's characterisation of its own resource.
A word on who CSBS is, since the package is easy to misread as a rule. The Conference of State Bank Supervisors is the membership organisation of state financial regulators; its press release boilerplate says it supports a network of state and financial regulators from all 50 states, the District of Columbia and four territories, and its site footer says CSBS itself is not licensed or regulated by any state or federal bank authority. Two of its committees approved a tool. No state agency adopted anything in the documents we read, and none is named.
Five documents, one disclaimer that governs them all
Five files hang off the framework page. The Core Examiner Guide is an eight-page PDF with six sections: Initial Scoping, Document Request List, Governance and Oversight, AI Inventory and Use Cases, Generative AI and Emerging Use, and Use of Existing Supervisory Resources. The Examiner Work Program is a Word file that, in its own words, supports the use of the Core Examiner Guide by providing source-based context, examiner focus points, and space for examiner notes for each scoping question and procedure; it covers four of those six sections, Initial Scoping, Governance and Oversight, AI Inventory and Use Cases, and Generative AI and Emerging Use, so it carries IS-1 to IS-8, GO-1 to GO-7, AI-1 to AI-6 and GE-1 to GE-8, and has no dedicated section for the Document Request List or for Use of Existing Supervisory Resources. The Nonbank AI Supplements are an 11-page PDF with three overlays. The AI Use Case Risk Tiering Worksheet is a Word form the page describes as an optional industry tool. The Sources document is a single page listing eight materials the framework drew on.
The sentence that governs how to read the rest is on page 2 of the Core Examiner Guide, under Considerations and Background: "The examiner guide is based on existing public materials, including supervisory guidance, regulator-issued materials, cross-sector risk management frameworks, and implementation resources. It does not create new legal obligations or supervisory requirements." The same page says the guide should be applied in a manner proportionate to an institution's size, complexity, risk profile and use of artificial intelligence, that not all sections will be relevant in every exam, and that examiner judgment remains important in determining the depth and focus of review.
Each of the other documents repeats the point in its own terms. The Work Program says it does not replace examiner judgment, existing supervisory resources, or applicable examination procedures. The Supplements say they are not standalone examination procedures and do not replace existing supervisory resources, examiner judgement, or applicable legal requirements. The Sources document says the sources are provided for context only and that the framework does not create new legal obligations or supervisory requirements. The worksheet closes by saying it should not be interpreted as official regulatory guidance from a state agency. The operative verbs throughout are may, should and consider; the only place obligation language appears is in the key-source tables, in language CSBS attributes to underlying materials such as Regulation B on adverse action notices. That is CSBS summarising existing law for context, not CSBS imposing anything, and we did not open those materials to check the tables against them.
Eight scoping questions, and a caution against taking no for an answer
Page 3 of the guide opens the examination with eight yes-or-no scoping questions, IS-1 to IS-8, each paired with the sections an examiner might prioritise if the answer is yes. IS-1 asks whether the institution uses artificial intelligence in any products, services, operations, compliance activities, or internal support functions. IS-3 asks whether AI is used in customer-facing activities or in activities that support or influence decisions. IS-4 and IS-5 ask about reliance on third parties for AI capabilities and whether the institution has sought to identify where AI is embedded in third-party products and services, and what information vendors have provided. IS-6 asks about generative AI and large language models, IS-7 whether the institution differentiates among its AI use cases based on risk, impact, or required level of review, and IS-8 whether customer, consumer, confidential or sensitive information is entered, processed or transmitted through AI systems, tools or third-party platforms.
The guide anticipates the answer no. Its scoping instruction says a negative or unclear response to IS-1 may warrant confirmation against the institution's vendor inventory, software inventory, approved tools, and recent product or platform changes before concluding that the framework does not apply. The Work Program's version is blunter: it says this is intended to help distinguish between institutions that do not use AI and institutions where AI use has not been fully identified, and its IS-1 focus note says AI use may be missed if it is embedded in software or treated as a feature rather than as a distinct system or use case. If no AI use is identified, the guide says, no further review under this framework may be necessary.
If AI use is identified, the examiner turns to the Document Request List on page 4, which the guide frames as materials examiners may request, as applicable. Four groups are listed. Governance and Oversight covers policies, committee materials, board reporting, monitoring dashboards and employee training. AI Inventory and Use Cases covers an inventory or list of AI systems, business-purpose documentation, risk assessments or tiering information, a list of vendor products or services with known or potential embedded AI capabilities, and change management records. Generative AI and Emerging Use covers policies or restrictions on generative AI, a list of approved or known tools, and documentation of data controls and output review. The fourth group, Additional Materials, is where the list reaches furthest: samples of recent AI-generated or AI-assisted consumer-facing outputs, where applicable, such as notices, chatbot transcripts, generated communications, or other customer-facing content, and contract terms, service terms, or vendor documentation addressing the use, retention, sharing, or training of AI systems on customer, consumer, confidential, or institutional data.
Twenty-one procedures, ending with a question about systems that act on their own
Pages 5 to 7 carry the numbered procedures: GO-1 to GO-7 on governance, AI-1 to AI-6 on inventory and use cases, and GE-1 to GE-8 on generative AI and emerging use. Two of the governance procedures decide how wide the review goes. GO-6 asks whether the institution has processes to test or monitor AI use, performance, limitations and related risks over time, including when AI systems, data, vendors, or operating conditions change. GO-7 asks whether governance and oversight apply to internally developed AI tools, externally sourced AI tools, and AI capabilities embedded in third-party products and services; the Work Program's focus note for it says governance that covers only internally developed tools may leave vendor-provided, purchased, embedded, or shadow AI outside the institution's oversight process.
The inventory procedures sort use cases. AI-3 asks whether AI use is internal, customer-facing, decision-support, or decision-making, and the Work Program adds that uses described as internal or support-only may still warrant review if they influence employees, consumers, decisions, communications, or institutional actions. AI-4 asks the examiner to review the institution's process for evaluating and tiering AI use cases based on risk, and points, in parentheses, to the risk tiering worksheet. AI-6 asks whether the institution is aware of AI capabilities embedded in third-party products, platforms, or services.
The generative AI section names its risks. GE-6 asks whether the institution has identified risks associated with generative AI use, including inaccuracy, hallucination, prompt injection, and data exposure. GE-3 distinguishes public, private, internally deployed and vendor-provided tools; GE-4 covers controls over data entered into or processed through them; GE-5 covers oversight of their outputs. GE-7 asks about processes for monitoring, updating, or restricting generative AI use as risks and capabilities evolve.
GE-8 is the procedure a reader running agents will want to know exists. In the guide's words: "Where AI systems can take actions with limited human direction, review how the institution defines the actions the system is permitted to take, human checkpoints, logging, reversibility, and the ability to restrict or halt the system." The section objective on page 7 names agentic tools, and the Work Program heads the procedure GE-8: Agentic AI Controls. The definition of agentic AI the Work Program supplies is not CSBS's own; it is attributed to the Treasury AI Lexicon, which the program describes, in language it attributes to that Lexicon, as covering AI systems capable of independently making decisions, interacting with their environment, and optimizing processes without direct human intervention. Page 8 of the guide adds that because some existing model risk resources may not fully address generative AI, agentic AI, or similar capabilities, examiners may use this framework and work program to identify AI-specific considerations that may warrant additional review.
The optional worksheet: three tiers, four factors, and the highest factor sets the starting tier
Institutions, not examiners, are the worksheet's first audience. Its instructions say it is intended to help financial institutions evaluate and document the relative risk of individual AI use cases, that state examiners may also use it to understand how an institution identifies, evaluates, and supports its AI risk-tiering decisions, and that an institution completes one worksheet per AI use case and retains completed worksheets as support for examination requests. The framework page calls it an optional industry tool. The Word file's stored footer carries Version 1.0 and the 13 August approval date, which the visible form does not display.
The method has three tiers and four factors. Tier 1, low risk, is described as internal use, human-reviewed outputs, limited consumer impact, limited data sensitivity, and low potential harm from errors or outages. Tier 2, moderate risk, is a consumer-facing or decision-support role, moderate data sensitivity, exception-based human oversight, or moderate potential harm. Tier 3, high risk, is use cases involving direct consumer outcomes, sensitive personal data, limited human review, significant operational reliance, or material potential harm from errors or outages. Section 3 rates four factors as low, moderate or high: consumer impact, from internal use only to directly determines consumer outcomes; human oversight, from every output reviewed to fully automated; harm potential from errors or outage; and data sensitivity, where the high rating covers nonpublic personal information, protected class data, biometric data, or data elements that could serve as proxies for protected characteristics.
The tier rule is one sentence with an escape hatch. The highest-rated risk factor should generally establish the preliminary tier assignment in Section 4; a different final tier may be assigned when supported by documented rationale, including relevant risk drivers, mitigating factors, and compensating controls; and any downward adjustment should be reviewed and approved consistent with the institution's governance process. Section 5 then lists suggested controls that are cumulative, so a Tier 3 use case is expected to have the Tier 1 and Tier 2 controls as well. The Tier 1 list, suggested for all AI use cases, runs to nine items, among them a documented inventory naming the business owner, a written policy on acceptable AI use, and vendor contracts that address AI-related risks. Tier 3 adds seven, including independent model validation completed by a qualified party, AI-specific incident response procedures, and consumer disclosures that address automated decision-making, as applicable.
None of that is a regulatory classification. The worksheet's last line says it is intended to assist an institution's risk assessment process and should not be interpreted as official regulatory guidance from a state agency. A Tier 3 label is a label the institution gives itself, on a form a state examiner may or may not ask to see.
Three nonbank overlays, a routing table, and no fourth supplement
Narrow by design is how the Nonbank AI Supplements describe themselves. Page 2 says examiners should begin with the Core Examiner Guide and use the Examiner Work Program, and when that review indicates a relevant existing supervisory area, examiners may use the applicable supplement as an overlay to identify AI-specific issues that may warrant additional review. There are three: Third-Party and Vendor Oversight on pages 4 to 6, Model Risk Review on pages 7 to 9, and Consumer Protection on pages 10 to 11. Each has the same five parts: purpose, examiner use, a list of examiner considerations, a table of key sources with source-attributed language, and an examiner focus paragraph.
A routing table on pages 2 and 3 maps framework items to supplements. Third-party questions IS-4, IS-5, IS-8, GO-7, AI-6, GE-3 and GE-4 route to the vendor overlay; IS-3, IS-7, AI-2 to AI-5, GO-6, GE-5, GE-6 and GE-8 route to model risk; and a largely overlapping set routes to consumer protection. The document gives worked examples of overlap: a vendor-provided AI tool used to support underwriting or eligibility decisions may implicate all three, and an AI system that can take actions with limited human direction may implicate any of them depending on the action, system access, consumer impact, and vendor involvement.
The examiner focus paragraphs are the plainest statements of what the overlays look for. The vendor overlay tells examiners to focus on whether the institution treats vendor-provided AI as a managed dependency rather than a black box, and says that if AI is embedded in vendor tools but not identified, or the institution relies primarily on vendor representations, additional follow-up may be needed. The consumer protection overlay asks whether specific and accurate reasons can be identified and communicated where required, and flags the case where vague or inaccurate reasoning is used in place of actual factors. Its key sources table summarises adverse-action requirements it attributes to Regulation B, including the statement of specific reasons; whatever obligation applies there belongs to Regulation B, and the framework presents the summary as context, not as a CSBS requirement.
One structural point to hold onto. Section 6 of the Core Examiner Guide lists four existing supervisory areas: third-party and vendor review, model risk review, consumer protection review and operational risk review. The Supplements cover the first three. There is no operational-risk supplement, and the Work Program has no dedicated section 6; its closing next-steps note only refers examiners to the applicable existing supervisory resources and the Supplements where generative AI or emerging use raises third-party, model-related, consumer-facing or operational risk issues. For operational risk, the guide simply says examiners may use applicable safety and soundness or operational risk resources, as appropriate.
What we did not verify
What we opened: the framework page at csbs.org, saved as HTML and text and dated 16 September 2026; the CSBS press release of 16 September 2026, fetched by this desk and saved alongside the other evidence; the Core Examiner Guide (8 pages) and the Nonbank AI Supplements (11 pages) as PDFs with text extracted, read end to end; the Examiner Work Program and the AI Use Case Risk Tiering Worksheet as Word files with text extracted, read end to end, including the footer XML inside each file, which carries Version 1.0 and Approval Date: 08/13/2026; and the one-page Sources document. The PDF text layers render the letters fi as a single ligature glyph; where we quote or closely report those documents we have written the two letters, and the GE-8 quotation above contains one such word, defines. Where a quoted sentence crosses a line break in the PDF text layer, we have rendered the break as a space. The pull quote at the foot of this article is taken from the framework page, where no ligature occurs, and matches that page character for character.
What we did not open: any of the eight source materials the framework cites, including NIST AI RMF 1.0, NIST AI 600-1, the Treasury / FSSCC AI Lexicon, the CRI framework, SR 23-4, SR 26-2, Regulation B and the NAIC Model Bulletin, or the two Treasury reports the worksheet cites separately; we describe their content only as the CSBS documents describe it. We did not open any state agency's examination manual or any statement by a state agency about whether it will use the framework. We did not verify the page counts of the two Word files, and the cached page numbers in their footers are not evidence of them. We did not verify the boilerplate figure in the press release that state regulators supervise 79 percent of U.S. banks.
What we refuse to claim: we do not say the framework was approved, issued or took effect on 16 September, because the documents date their approval to 13 August and nothing in the package takes effect at all. We do not say any state has adopted it, that every state examiner will use it, or that completing the worksheet or producing the Document Request List items is compulsory for any institution, because the guide says it creates no new legal obligations or supervisory requirements and each state agency decides how far to incorporate it. We do not say the framework applies to national banks, federal savings associations, credit unions or all U.S. financial institutions; the guide speaks of bank and nonbank institutions and the release of state-chartered banks and state-licensed nonbank financial institutions, and we go no further. We do not say the framework changes SR 26-2, Regulation B or the NAIC bulletin, or that any federal agency endorsed it. We do not say it is the first such framework, and we make no claim about whether anyone had the documents before 16 September. We attach no number to the institutions affected, because CSBS gives none. The only obligation verbs in the package sit in the key-source tables, in language CSBS attributes to underlying materials such as Regulation B; we did not open those materials, we do not certify the tables as verbatim quotations of them, and we have not repeated their obligation verbs in our own voice.
Informational analysis for working professionals, not legal advice. Confirm how any rule applies to your situation with qualified counsel.
Treat this as a preview of the questions a state examiner may now choose to ask, not as a rule. If your institution is state-chartered or state-licensed, the cheapest preparation is to walk the eight scoping questions and the Document Request List against what you could actually produce this week: an AI inventory that includes embedded vendor features, a written basis for how each use case was risk-rated, samples of consumer-facing AI output, and the contract clauses on whether vendors train on your customers' data. If you run anything that acts with limited human direction, GE-8 tells you the five things an examiner using this guide would look for: permitted actions, human checkpoints, logging, reversibility and the ability to halt the system.
Source File
https://www.csbs.org/csbs-artificial-intelligence-supervisory-framework
Open the framework page and confirm four things: the 16 September 2026 page date and the sentence saying each state financial regulatory agency will determine the extent to which the framework is incorporated; the Approval Date: August 13, 2026 line on the cover of the Core Examiner Guide at node 584241; the disclaimer on page 2 of that guide that it does not create new legal obligations or supervisory requirements; and procedure GE-8 on page 7. Then open the press release of 16 September 2026 for the release event.
The CSBS Artificial Intelligence Supervisory Framework is a discretionary tool for state examiners to identify and understand AI at financial institutions, assess associated risks, and determine when a deeper review may be appropriate using existing supervisory resources. ยท CSBS framework page, first body paragraph, csbs.org, page dated 16 September 2026
FAQ
Is the CSBS AI Supervisory Framework binding on my institution?
No. Page 2 of the Core Examiner Guide states that it does not create new legal obligations or supervisory requirements, the framework page calls it a discretionary tool for state examiners, and both the page and the 16 September press release say each state agency will determine the extent to which it is incorporated into its supervisory programs. What it does do is set out the questions and document requests an examiner who chooses to use it may bring to an examination.
Which date matters, 13 August or 16 September 2026?
Both, for different purposes. The documents themselves carry Version 1.0 and Approval Date: August 13, 2026 on their covers and footers, and the framework page attributes the approval to two CSBS committees in August 2026. The 16 September date is the date of the framework page and of the CSBS press release saying the resource was released that day. Neither is an effective date; the package has none.
Does a Tier 3 rating on the worksheet mean a regulator has classified my use case as high risk?
No. The worksheet is described on the framework page as an optional industry tool, it is completed by the institution, and its final line says it should not be interpreted as official regulatory guidance from a state agency. The tier is the institution's own preliminary assessment, generally established by the highest-rated of four factors, and the worksheet allows a different final tier when supported by documented rationale, with downward adjustments reviewed under the institution's governance process.
Does the framework apply to national banks, credit unions or fintechs without a state licence?
The documents do not say so and we do not claim it. The Core Examiner Guide describes itself as a practical tool for examiners of bank and nonbank institutions, and the press release names state-chartered banks and state-licensed nonbank financial institutions. Nothing in the five documents addresses federally chartered institutions or unlicensed firms, and whether any examiner uses the framework at all depends on the state agency employing that examiner.
Related briefings
Sponsored Training
Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.