AI Governance

The OCC Risk Perspective and the coming AI guidance for banks

The OCC's Semiannual Risk Perspective flags AI-driven cyber threats, explainability gaps and validation challenges, while regulators plan a request for information on AI model risk management.

By Jonas Osman AbdelghafourPublished May 19, 2026

Summary The OCC's Semiannual Risk Perspective is a useful forward indicator: what appears there as an emerging risk tends to appear later as examination emphasis. Its treatment of artificial intelligence is the clearest signal yet that formal US guidance for banks is being prepared.

Source: Consumer Finance Insights (Goodwin) · 19 May 2026 · read the original article

What the report flags Three themes stand out. Artificial intelligence is significantly transforming the cybersecurity threat landscape by facilitating fraud and lowering barriers to entry for attackers. Explainability gaps and data poisoning are named as specific control concerns. And model validation is identified as challenged by systems whose behaviour is not fully specified.

Alongside these, the three federal banking regulators plan a request for information on model risk management for artificial intelligence, and the OCC endorses a measured approach to generative and agentic deployment supported by human oversight and guardrails.

Reading a request for information as a planning signal An RFI is normally the first step in a sequence that ends in guidance. It also tells firms what the agencies are uncertain about, which is where a well-argued response can shape the outcome. Institutions with material AI deployment should treat the response as a governance exercise rather than a public affairs one: the internal work of describing how the firm validates systems without stable specifications is exactly the documentation an examiner will later request.

The practical planning assumption is that guidance arrives after the RFI closes and that firms strengthening frameworks now are pre-positioning rather than gold-plating.

Data poisoning belongs on the risk register Data poisoning deserves specific attention because it falls between teams. Model risk functions typically test for bias and drift, not for adversarial manipulation of training or retrieval data. Security functions monitor infrastructure, not feature stores. The control is joint: integrity monitoring on training and retrieval corpora, provenance requirements for external data, and detection thresholds tied to unexpected shifts in model behaviour.

Methodology and limitations This summarises a law firm analysis of a public supervisory report as at the date shown and links to the original. The request for information was pending at the time of writing, and its eventual scope may differ from what is described here.

Related reading See [Banking Risk](/expertise/banking-risk), [Model Risk](/expertise/model-risk), [Enterprise Risk](/expertise/enterprise-risk) and the overview in [AI governance in insurance and banking](/insights/ai-governance-insurance-banking-2026).

Frequently asked questions

What the report flags?

Three themes stand out. Artificial intelligence is significantly transforming the cybersecurity threat landscape by facilitating fraud and lowering barriers to entry for attackers. Explainability gaps and data poisoning are named as specific control concerns. And model validation is identified as challenged by systems whose behaviour is not fully specified.

What should risk leaders know about reading a request for information as a planning signal?

An RFI is normally the first step in a sequence that ends in guidance. It also tells firms what the agencies are uncertain about, which is where a well-argued response can shape the outcome. Institutions with material AI deployment should treat the response as a governance exercise rather than a public affairs one: the internal work of describing how the firm validates systems without stable specifications is exactly the documentation an examiner will later request.

What should risk leaders know about data poisoning belongs on the risk register?

Data poisoning deserves specific attention because it falls between teams. Model risk functions typically test for bias and drift, not for adversarial manipulation of training or retrieval data. Security functions monitor infrastructure, not feature stores. The control is joint: integrity monitoring on training and retrieval corpora, provenance requirements for external data, and detection thresholds tied to unexpected shifts in model behaviour.

What should risk leaders know about methodology and limitations?

This summarises a law firm analysis of a public supervisory report as at the date shown and links to the original. The request for information was pending at the time of writing, and its eventual scope may differ from what is described here.

What should risk leaders know about related reading?

See [Banking Risk](/expertise/banking-risk), [Model Risk](/expertise/model-risk), [Enterprise Risk](/expertise/enterprise-risk) and the overview in [AI governance in insurance and banking](/insights/ai-governance-insurance-banking-2026).