The CSBS guide, described as a principles‑based approach to AI governance, directs examiners to probe AI deployment across products, operations, compliance, internal support functions and third‑party software, and to request inventories of AI use‑cases, risk assessments, policies, vendor contracts and testing records.

Brandon Milhorn, CSBS President and CEO, said the framework aims to make AI use visible within existing examination practices while leaving each state agency discretion over adoption, noting that AI can improve services, protect consumers and boost efficiency.

Institutions that cannot readily confirm whether they employ AI may face follow‑up inquiries about their software and vendor inventories before an examiner can close the review, and firms using customer‑facing AI such as chatbots could be asked to provide sample transcripts and notices.

The framework also emphasizes governance of “agentic” AI—systems that can act with limited human direction—by requiring examiners to assess human checkpoints, logging, reversibility and the ability to stop the system.

AI‑driven tools that affect consumers, such as underwriting algorithms, could be examined under existing fair‑lending, disclosure, privacy and unfair‑practice standards, potentially raising vendor, model‑risk and consumer‑protection concerns.

While the guide does not create new legal obligations, it signals a state‑led push toward clearer AI oversight. A Sept. 17 advisory from law firm Sheppard Mullin advises firms to maintain robust AI inventories, clear ownership and vendor oversight as states incorporate the framework into their examination programs.

New York’s Department of Financial Services issued a Sept. 10 letter reminding regulated entities to keep cybersecurity risk assessments up to date when business or technology changes materially, specifically flagging AI—including frontier models—as a technology that may trigger a fresh assessment.

In California, Business and Consumer Services Agency Secretary Rohit Chopra announced in an Aug. 31 blog post that the newly formed agency will examine whether chatbots and other automated tools harm consumers or undermine licensing requirements, a move echoed by a Sept. 10 Sheppard advisory that, while not imposing new rules, signals heightened scrutiny of AI in consumer interactions.

Together, these actions illustrate a patchwork of state initiatives that rely on existing authority to bring AI use into the regulatory spotlight, setting the stage for how financial institutions will need to demonstrate accountability, risk controls and transparency before a comprehensive federal AI framework emerges.