The financial-services AI landscape
The categories of FS AI and their very different regulatory risk profiles.
The financial-services AI landscape spans the whole institution. Learn the categories and their regulatory-risk profiles — specific vendors and features change constantly (a 2026 snapshot; verify before relying on any specific tool, and naming a tool is not an endorsement).
The categories, roughly by regulatory risk:
Higher regulatory risk (they make or heavily influence consequential decisions about people or markets):
- Credit underwriting and scoring models — decide who gets credit and on what terms. Subject to fair-lending law and model risk management (Module 3). The highest-scrutiny category.
- Insurance underwriting and pricing — risk assessment and pricing, increasingly regulated (NAIC bulletin, Colorado's rules — Module 3), and "high-risk" under the EU AI Act.
- Investment and trading models / robo-advisers — algorithmic trading, portfolio construction, and automated advice, under securities regulation (SEC, FINRA — Module 3).
- AML/fraud models — transaction monitoring and fraud detection that trigger investigations and account actions; validated as models, with explainability expectations.
Lower regulatory risk (back-office and operational support):
- Process automation and document generation — automating workflows, drafting, summarizing. High value, lower risk.
- Customer-service chatbots — though these carry their own consumer-protection (UDAAP) considerations (Module 2).
- Internal copilots — coding, knowledge retrieval, research assistance.
The critical distinction — is it a "model" under supervisory expectations? In banking, anything that produces outputs used in decisions is generally treated as a model subject to model risk management (Module 3): development standards, independent validation, and governance. Traditional AI/ML decision models fall squarely under this expectation. (A 2026 wrinkle: revised interagency guidance now places generative and agentic AI outside the formal MRM framework, directing firms to apply existing risk practices instead — Module 3 covers this.) Either way, governance (not just accuracy) defines responsible FS AI.
Why think capabilities, not vendors: vendors and products change every quarter, but the categories and their regulatory-risk profiles are stable. A credit-underwriting capability carries fair-lending and model-risk exposure whether it's Tool A or Tool B; a back-office automation carries far less. Evaluate FS AI by what it does, what regulatory risk that creates, and whether it's a decision-driving model — not by brand.
The mindset: the financial-services AI stack ranges from lower-risk back-office and operational tools to higher-risk decision-driving models — credit, insurance, investment, and AML — that sit squarely under regulatory scrutiny and model risk management. Learn the categories and their risk profiles, evaluate tools by capability and regulatory exposure rather than brand, and recognize that anything driving consequential decisions is a "model" requiring governance. Knowing which category creates which risk is the foundation for deploying FS AI responsibly.
Map the FS AI you use or might use to these categories, and rate each by regulatory risk: does it make/influence consequential decisions (higher — credit, insurance, investment, AML) or support back-office operations (lower — automation, docs, internal copilots)? For the higher-risk ones, note that they're 'models' requiring Module 3's governance before deployment.
Enjoying the free lessons? Get an email when we publish new courses and updates — no spam, unsubscribe anytime.
Discussion (0)
Ask a question or share what worked for you. Comments are reviewed before they appear.
No comments yet. Be the first to start the discussion!