We use cookies to understand how this site is used. Privacy policy

    Skip to main content
    Kriv AI

    Financial Services AI Governance

    Why Can't Compliance Keep Up With AI Adoption in Financial Services?

    The gap between how fast banks deploy AI and how fast compliance functions can govern it is now measurable, and it is widening.

    Compliance can't keep up because AI adoption is outrunning three things at once: regulatory guidance (federal model risk rules explicitly exclude generative and agentic AI), state by state rule fragmentation, and internal governance maturity. Surveys show under 20% active compliance function AI use versus 84% organization wide use, with governance still ad hoc.

    cause

    Three Reasons Compliance Is Structurally Behind

    Regulators themselves haven't finished the rulebook

    In April 2026 the OCC, Federal Reserve, and FDIC issued SR 26-2, a revised interagency model risk management guidance that replaced the 2011-era SR 11-7. According to a Sullivan & Cromwell client memo analyzing the guidance, the agencies explicitly excluded generative and agentic AI models from its scope, describing them as 'novel and rapidly evolving.' Banks are told to apply their 'broader risk management and governance practices' to these systems instead of a specific framework, and the agencies have said they plan to issue a request for information on AI model risk in the near future. That leaves compliance teams building governance for the fastest-growing category of models without a finished rulebook to build against.

    This is not a hypothetical gap. It means the single most-cited compliance reference document in U.S. banking, model risk guidance, does not yet formally cover the AI systems banks are deploying fastest. Compliance officers are left applying general enterprise risk principles by analogy, which is slower and more contested internally than working from a specific supervisory standard.

    Regulatory fragmentation multiplies the compliance workload

    Even where federal guidance exists, it is split across agencies with no unified standard. A Goodwin Procter legal alert on the evolving AI regulatory landscape in financial services notes that the Federal Housing Finance Agency and Consumer Financial Protection Bureau began issuing AI compliance directives as early as September 2022, and that the Federal Trade Commission, Department of Justice, OCC, Federal Reserve, and Equal Employment Opportunity Commission have each issued their own separate AI oversight statements, with neither a consensus nor a binding law on AI regulation at the federal level forming. States have filled the vacuum with their own rules: Goodwin cites California consumer protection advisories applied to AI, a Colorado law requiring disclosure of AI-driven lending decisions effective February 2026, an Illinois law expanding oversight of AI used in creditworthiness determinations effective January 2026, and New York City's independent audit mandate for automated employment decision tools.

    For a bank operating in multiple states, this means the compliance function has to track and reconcile a different, moving set of AI-specific obligations in every jurisdiction it serves, on top of federal guidance that is itself unsettled. Fragmented internal data compounds the problem: an AscentAI 2026 RegTech Benchmark Survey, reported by fintech.global, found that 39% of respondents cited fragmented compliance data and the absence of a single source of truth as a major challenge, rising to 67% among Tier 1 banks specifically.

    Internal governance maturity hasn't caught up with usage

    Adoption inside banks has simply outpaced the internal machinery meant to govern it. Deloitte's banking-sector AI governance research found that 63% of bank employees now use AI on a weekly basis, yet only 13% of banks have reached a leading maturity stage for AI governance, and 87% of banks could significantly improve their governance frameworks. On training specifically, Deloitte found only 15% of banks provide regularly refreshed AI governance training to all staff, while a third of global banks rely on ad hoc training or provide none at all.

    A separate ACA Group survey of over 200 U.S. financial firms, conducted around the GAIM Ops conference in April 2026, quantifies the same gap from the usage side: 84% of firms report using AI somewhere in the organization, but active AI use inside the compliance function itself is under 20%, and inside operations it is around 5%. ACA's Jody Kochansky, Head of Product and Engineering, summarized it this way: 'Most firms are still in the experimentation phase, relying on desktop tools that sit outside of their core workflows. The real opportunity, and the real challenge, is moving from informal use to embedded, governed, auditable deployment.'

    evidence

    What the Numbers Show

    The Investment Adviser Association's 2026 Investment Management Compliance Testing Survey, now in its 21st year, found that 85% of investment adviser firms named AI their top compliance priority in 2026, a 28-percentage-point jump from 2025 that the survey's authors called the largest single-topic margin in the survey's history. 72% of firms reported increasing compliance testing specifically around AI, the largest year-over-year increase recorded for any topic. Firms are also moving on policy: 80% have formally implemented AI tools and 86% now maintain AI acceptable-use policies, up from roughly 64% in fall 2025. But the harder controls lag well behind the easier ones. Only 48% of firms have human-in-the-loop oversight policies for AI, and just 37% have output validation procedures in place.

    That same pattern, easy governance in place, hard governance still missing, shows up in how AI is actually used day to day. Employees are using AI tools their compliance functions never approved, often with sensitive data. Reporting on the shadow AI problem at Tearsheet quotes Corey Gross, VP and Head of Data & AI at Q2 Holdings, arguing that the root cause usually is not a policy failure at all: 'When employees bypass a sanctioned tool, they're telling leadership teams that the approved option isn't getting the job done.' He added that 'it's rarely a governance or compliance issue' in the sense most institutions assume, pointing instead to workflow mismatches that push employees toward unapproved tools. That dynamic played out concretely in May 2026, when an employee at Pennsylvania-based CB Financial Services uploaded a file containing customer names, Social Security numbers, and dates of birth into an unauthorized AI application while preparing a presentation, bypassing the bank's own approved AI tool.

    A KPMG analysis of scaling agentic AI in financial-crime compliance identifies why even well-resourced compliance teams struggle to close this gap quickly: data sensitivity rules slow vendor approvals for AI tools that touch personally identifiable information, human-in-the-loop requirements mean a model cannot legally be the final decision-maker on something like a suspicious activity report, and continuously learning models conflict with regulatory frameworks that expect static, reproducible validation testing. As one compliance specialist quoted in the piece put it, 'a computer cannot be the last actor on an audit log for an SAR decision. This is a regulatory reality, not cultural preference.'

    framework

    Closing the Gap Requires Sequencing, Not Just Policy

    The evidence points to a consistent order of operations for institutions trying to close this gap: first, inventory where AI is actually being used, including unapproved tools, since ungoverned use is what creates GLBA, BSA/AML, and fair-lending exposure before anyone in compliance even knows a model is running. Second, map governance obligations against the specific federal guidance that exists (including where it explicitly stops, as SR 26-2 does for generative and agentic AI) and the state rules that apply in every jurisdiction the institution serves. Third, build human-in-the-loop and output validation controls before scaling any AI tool into production workflows, because the survey data above shows institutions are consistently completing the easy steps (policies, committees) well ahead of the hard ones (oversight, validation). Fourth, redesign the underlying workflow the AI is meant to support rather than layering monitoring on top of a tool employees are already avoiding, which is the fix Q2 Holdings' Corey Gross points to as more durable than stricter policy alone.

    differentiation

    How Kriv AI Helps

    Kriv AI works with regulated and mid-market financial institutions to close exactly this gap: building AI governance frameworks that map to existing federal guidance where it exists, flag where it doesn't (like the SR 26-2 gap for generative and agentic AI), and account for state-level fragmentation across the jurisdictions a firm operates in. Enterprise and regulated-industry engagements are billed at a $200 per hour floor, fractional AI governance leadership at $300 to $400 per hour, and specialized regulatory advisory at $400 to $700 per hour, with an $8,000 minimum engagement so scoping reflects the actual complexity of a bank's regulatory footprint rather than a flat fee.

    Because the data above shows most institutions have policies and committees in place but lack human-in-the-loop oversight and output validation, Kriv AI's engagements typically start with a shadow AI and vendor inventory, move to a governance framework aligned to current federal and state obligations, and end with the operational controls (validation testing, audit trails, escalation paths) that examiners actually test for. Firms that want a structured starting point can review the AI governance framework approach or book a discovery call to scope the work against their specific regulatory exposure.

    Straight answers

    Frequently asked questions about Why Can't Compliance Keep Up With AI Adoption in Financial Services?

    Is there a specific regulation that governs generative AI at banks?

    Not yet in a comprehensive way. The April 2026 interagency model risk management guidance (SR 26-2) issued by the OCC, Federal Reserve, and FDIC explicitly excludes generative and agentic AI models from its scope, calling them 'novel and rapidly evolving,' and directs banks to apply broader risk management and governance practices instead. The agencies have said they plan to issue a request for information specifically addressing AI model risk.

    How much of the gap is a state-versus-federal regulation problem?

    A significant part of it. Federal agencies including the FHFA, CFPB, FTC, DOJ, OCC, Federal Reserve, and EEOC have each issued separate AI-related guidance without forming a single binding federal standard, according to a Goodwin Procter legal alert. States have filled that gap with their own rules, including a Colorado law requiring disclosure of AI-driven lending decisions effective February 2026 and an Illinois law on AI in creditworthiness determinations effective January 2026, so multi-state institutions face a growing patchwork rather than one rulebook.

    What percentage of banks actually have mature AI governance?

    Deloitte's banking-sector AI governance research found only 13% of banks have reached a leading maturity stage for AI governance, while 87% of banks could significantly improve their governance frameworks. The same research found 63% of bank employees already use AI weekly, meaning usage has scaled well ahead of governance maturity.

    Is shadow AI really a compliance problem or a workflow problem?

    Both, but the root cause is often workflow. Corey Gross, VP and Head of Data & AI at Q2 Holdings, has argued that when employees bypass a sanctioned AI tool, it usually signals the approved option isn't meeting their actual workflow needs, not that governance itself failed. That said, the compliance exposure is real: a documented May 2026 incident involved a CB Financial Services employee uploading customer names, Social Security numbers, and dates of birth into an unauthorized AI application while bypassing the bank's approved tool.

    Are compliance teams actually testing AI systems, or just writing policies?

    Mostly writing policies so far. The 2026 Investment Management Compliance Testing Survey found 86% of firms now have AI acceptable-use policies and 80% have formally implemented AI tools, but only 48% have human-in-the-loop oversight policies and just 37% have output validation procedures, showing the harder operational controls still lag behind the easier policy work.

    Why can't compliance teams just move faster to match AI adoption?

    Because the constraint isn't effort, it's that the reference points compliance normally relies on (finished federal guidance, a single regulatory standard, mature internal governance processes) are themselves incomplete or immature right now. An ACA Group survey found 84% of financial firms use AI somewhere in the organization, but active AI use inside the compliance function itself is under 20%, reflecting that compliance is still building the governed, auditable processes needed to use AI safely rather than lacking the will to adopt it.

    Talk to the team that would do the work

    Bring your requirements to a working session with the person who'll actually deliver.

    Book a Discovery Call