Summary AI governance in financial services has moved from conference-panel abstraction to daily supervisory reality. In the United States, the OCC and Federal Reserve now raise artificial intelligence in every routine bank examination, state insurance regulators are piloting a standardised AI evaluation tool, and state attorneys general are widening enforcement audits. In Europe, the EU AI Act's next major compliance milestone for high-risk systems lands on 2 August 2026, with EIOPA having already told national supervisors how existing insurance law applies to AI. Meanwhile the insurance market itself is repricing the technology, as carriers weigh new AI exclusions against the opportunity to underwrite AI risk.
The ten pieces below — drawn from regulators, law firms and trade press over the past year — map where the pressure is building and what boards, risk officers and compliance teams in insurance and banking should be doing about it. Each entry carries a short note on why it matters for governance practice rather than for headlines.
Why AI governance became a supervisory priority in 2026 Three forces converged. Adoption reached near-universality across underwriting, claims, credit decisioning and financial crime detection, so supervisors could no longer treat AI as a pilot-stage curiosity. Legacy model risk management guidance — written for statistical models with stable specifications — proved a poor fit for generative and agentic systems, and regulators have started to say so explicitly rather than stretch existing text. And the control gap became measurable: adoption surveys and litigation both point to firms deploying models faster than they can evidence bias testing, human review and vendor oversight.
The practical consequence for a risk function is that AI governance is now examined through the ordinary supervisory machinery — exams, thematic reviews, market conduct examinations — rather than through a dedicated AI rulebook that does not yet exist in most jurisdictions.
United States banking supervision: AI in every examination Bank supervisors have moved first, and they have moved through examination practice rather than rulemaking.
1. US bank regulators make AI a standing topic in routine exams
Quartz / Reuters · 12 June 2026 · read the article
The OCC and Federal Reserve have made AI oversight a standing topic in every routine bank examination. Examiners are probing technical limits on model behaviour, how human review is structured, whether emergency shutdown capability exists, vendor risk management, and whether AI systems respect data boundaries. Three banking regulators issued updated model risk management guidance on 17 April 2026 — while noting that generative and agentic AI fall outside its current scope — and JPMorgan plans to deploy autonomous AI agents later this year.
Why it matters: even without an AI rulebook, supervisory expectations are being set examination by examination. Institutions that cannot answer the questions above in writing are already behind.
2. OCC report signals AI governance guidance is on the horizon
Consumer Finance Insights (Goodwin) · 19 May 2026 · read the article
The OCC's Semiannual Risk Perspective warns that AI is significantly transforming the cybersecurity threat landscape — facilitating fraud and lowering barriers for attackers — while flagging explainability gaps, data poisoning and model validation challenges. The three federal banking regulators plan a request for information on model risk management for AI, and the OCC endorses a measured approach to generative and agentic AI with human oversight and guardrails.
Why it matters: the request for information is the clearest signal yet that formal US AI governance guidance for banks is coming. Institutions strengthening frameworks now are effectively pre-positioning for it.
3. Fed Vice Chair Bowman on artificial intelligence in the financial system
Federal Reserve Board speech · 27 April 2026 · read the article
Speaking at the FSOC roundtable on AI, cybersecurity and risk management, Vice Chair for Supervision Michelle Bowman called AI a force multiplier for the financial system and explained the Federal Reserve's recalibration of oversight — including amending model risk management guidance to exclude generative and agentic AI, on the view that rapidly evolving technologies may require a technology-specific approach. She also pointed to Financial Stability Board work on sound practices for AI adoption, with a consultation draft expected in the third quarter of 2026.
Why it matters: excluding generative AI from legacy model risk guidance is a deliberate fork in the road. New frameworks are being drafted rather than old ones stretched, and firms that mapped generative AI into SR 11-7 style validation should expect to rework that mapping.
4. Banks get new federal guidance on AI cyber risks
American Banker · 17 December 2025 · read the article
NIST released a preliminary draft of its Cybersecurity Framework Profile for Artificial Intelligence, organising AI security into three areas: securing AI system components, using AI for cyber defence, and defending against AI-enabled attacks. The profile complements the NIST AI risk management framework and aims to give banks a common language for AI security, with a full draft expected during 2026.
Why it matters: cyber and AI governance are converging. The NIST profile is likely to become the reference vocabulary examiners and internal auditors use when they ask how AI systems are secured.
United States insurance regulation: a state-by-state patchwork Insurance supervision is fragmented by design, and AI has made that fragmentation expensive.
5. AI governance expectations rise for insurers amid new regulatory activity
Hinshaw & Culbertson LLP · 5 June 2026 · read the article
A roundup of accelerating oversight: the New York Department of Financial Services warned that frontier AI models may amplify cybersecurity threats; Colorado enacted SB26-189, narrowing its high-risk AI framework into an automated decision-making approach effective January 2027; twelve states are piloting the NAIC AI Systems Evaluation Tool during 2026; and California CCPA regulations phase in risk assessments, ADMT compliance and cyber audit certifications through 2028.
Why it matters: for US insurers the compliance map is a patchwork of state regimes moving at different speeds — a strong argument for one enterprise AI governance programme built to the strictest common denominator rather than fifty local variants.
6. The NAIC 2026 AI evaluation pilot moves ahead as industry balks
InsuranceNewsNet · 12 December 2025 · read the article
State insurance regulators are pressing ahead with a 2026 pilot of an AI systems evaluation tool involving ten insurers, over trade-group objections that the pilot is voluntary for regulators while compulsory for companies, with no defined duration. The article also captures federal-versus-state tension after a December 2025 executive order pursuing a single national AI regulation framework, which Iowa Commissioner Doug Ommen argued would undercut 150 years of state regulatory authority.
Why it matters: the pilot will shape what a standardised state AI examination of insurers actually looks like, and the preemption fight will determine who ultimately gets to run it.
7. Tracking the evolution of AI insurance regulation
Fenwick · 11 December 2025 · read the article
A wide-angle survey: between 58% and 92% of insurers across sectors report current or planned AI use, agentic AI is the newest frontier, and the NAIC 2023 Model Bulletin has been adopted by 23 states plus the District of Columbia — yet nearly a third of health insurers do not regularly test models for bias. Litigation alleging discriminatory AI in claims processing is emerging, and a model law on third-party AI vendors is anticipated during 2026.
Why it matters: the gap between adoption, which is near-universal, and control maturity in bias testing and vendor oversight is exactly where enforcement and litigation risk will concentrate.
Europe: the EU AI Act and the supervisory bridge from Solvency II ### 8. EIOPA opinion on artificial intelligence governance and risk management
EIOPA · 6 August 2025 · read the article
The European insurance supervisor's opinion clarifies how existing insurance-sector legislation applies to AI systems, directing national supervisors toward a risk-based and proportionate approach that balances benefits and risks rather than imposing blanket restrictions. It arrives alongside an impact assessment and followed a public consultation.
Why it matters: for European insurers this is the supervisory bridge between Solvency II-era governance requirements and the EU AI Act — the document national regulators will reach for when reviewing AI use, and the reason an AI control framework should be anchored in the existing system of governance rather than built beside it.
Market response: exclusions, pricing and data foundations Where supervision sets expectations, the insurance market sets prices — and pricing is what usually forces control maturity.
9. Insurer interest in AI exclusions grows as risk becomes omnipresent
Claims Journal · 20 July 2026 · read the article
Carriers are showing growing interest in three new ISO exclusions targeting generative AI risks in commercial general liability policies, against a backdrop of AI-related lawsuits that surged 978% between 2021 and 2025. The leading claim types are patent infringement, copyright infringement and privacy violations, and the market is split between insurers who would exclude AI exposure outright and those who would rather underwrite and price it as a premium opportunity.
Why it matters: coverage language is where AI governance debates become money. Whether AI risk is excluded or priced will shape how quickly corporate policyholders formalise their own AI controls.
10. Could AI become the insurance industry's next compliance crisis?
Insurance Edge (Alastair Walker) · 14 July 2026 · read the article
This piece argues that insurers are deploying AI in underwriting, claims and customer service before putting information governance foundations in place. With data scattered across disconnected systems and regulators demanding transparency and explainability, flawed inputs risk turning AI programmes into compliance liabilities; the UK Financial Conduct Authority has warned that AI will reshape financial services by 2030.
Why it matters: most AI governance failures are really data governance failures. Trusted information, not model sophistication, is the first control.
What boards and risk committees should do now The supervisory questions converging across jurisdictions are consistent enough to be turned into a standing agenda:
- Maintain a complete inventory of deployed and planned AI systems, including embedded vendor functionality, with a named accountable owner for each
- Classify systems by decision impact — pricing, underwriting, claims, credit, financial crime, customer communication — rather than by technology type
- Evidence human review: who can override, on what basis, within what timeframe, and where the override is recorded
- Test for bias and drift on a defined cycle for any system affecting customer outcomes, and retain the results
- Extend third-party risk management to model providers, including change notification, evaluation access and exit arrangements
- Confirm an emergency stop exists for autonomous and agentic systems, and that it has been tested
- Align AI security controls with the NIST profile vocabulary so that internal audit and examiners are reading the same map
Methodology and limitations This is a curated reading list, not a legal analysis. Each entry summarises a publicly available source as at the date shown and links to the original; regulatory positions described here are moving quickly and several — the federal request for information, the NAIC model law on third-party AI vendors, the FSB consultation — were pending at the time of writing. Jurisdictional interpretation should be confirmed with qualified counsel, and views expressed in the linked pieces belong to their authors.
The thread that ties them together Read together, these pieces describe an industry crossing a threshold: adoption is no longer the story, accountability is. Supervisors on both sides of the Atlantic are converging on the same five questions — where is AI deployed, what data feeds it, who reviewed the model, can a human intervene, and can you prove all of it. Institutions that can answer from an actual governance programme, rather than a slideware one, will find the next two years of examinations, audits and information requests far less eventful.
Full analysis of each source Each entry above has a dedicated analysis:
- AI exclusions in general liability: how carriers are repricing artificial intelligence risk
- Data governance is the first AI control for insurers
- AI oversight in US bank examinations: what examiners are asking
- The US state AI patchwork facing insurers
- The OCC Risk Perspective and the coming AI guidance for banks
- Recalibrating model risk guidance for generative AI: reading the Bowman speech
- The NIST AI cybersecurity profile and why banks should adopt its vocabulary
- The NAIC AI evaluation pilot and the federal preemption question
- Adoption without control maturity: tracking AI regulation across insurance
- The EIOPA opinion: a supervisory bridge between Solvency II and the EU AI Act
Related reading See [Model Risk](/expertise/model-risk), [Governance, Risk and Compliance](/expertise/grc), [Regulatory Compliance](/expertise/regulatory-compliance), [Insurance Risk](/expertise/insurance-risk), [Banking Risk](/expertise/banking-risk) and [Board risk governance](/governance).
Frequently asked questions
Why AI governance became a supervisory priority in 2026?
Three forces converged. Adoption reached near-universality across underwriting, claims, credit decisioning and financial crime detection, so supervisors could no longer treat AI as a pilot-stage curiosity. Legacy model risk management guidance — written for statistical models with stable specifications — proved a poor fit for generative and agentic systems, and regulators have started to say so explicitly rather than stretch existing text. And the control gap became measurable: adoption surve...
What should risk leaders know about united States banking supervision: AI in every examination?
Bank supervisors have moved first, and they have moved through examination practice rather than rulemaking.
What should risk leaders know about united States insurance regulation: a state-by-state patchwork?
Insurance supervision is fragmented by design, and AI has made that fragmentation expensive.
What should risk leaders know about europe: the EU AI Act and the supervisory bridge from Solvency II?
EIOPA · 6 August 2025 · [read the article](https://www.eiopa.europa.eu/publications/opinion-artificial-intelligence-governance-and-risk-management_en)
What should risk leaders know about market response: exclusions, pricing and data foundations?
Where supervision sets expectations, the insurance market sets prices — and pricing is what usually forces control maturity.