Federal banking regulators drew a line this spring. Their revised model-risk guidance, issued in April, applied to institutions with more than $30 billion in assets, leaving the vast majority of American banks outside the new framework for how artificial intelligence gets scrutinized. This week, the states erased the line.

The Conference of State Bank Supervisors, the association of state banking regulators, released its AI Supervisory Framework, a five-document playbook state examiners can use when they walk into a state-chartered bank and ask what the AI is doing. The reach is the headline: state regulators supervise 3,355 of the country's 4,233 FDIC-insured banks, about 79 percent of the industry, and the framework applies to state-chartered institutions of all sizes. Roughly 99 percent of those banks hold $30 billion or less in assets. The population the federal guidance deliberately excluded is the population the state framework explicitly covers.

What the playbook contains

The framework is five documents: a core examiner guide, a 28-page examiner work program, supplements for nonbank AI use, a risk-tiering worksheet for AI use cases, and a source support document. It is explicitly drawn from the NIST AI Risk Management Framework, the Cyber Risk Institute's Financial Services AI RMF, and the Treasury Department's AI Lexicon, which means the states are not inventing a new vocabulary. They are applying the existing one at a scale nobody has applied it before.

The scope covers generative and agentic AI, the two technologies the federal agencies explicitly placed outside their revised model-risk guidance. That choice by the feds was the source of the gap: banks adopting chatbots, document-processing models, and agentic systems that take actions were told the federal guidance did not reach them. The state framework closes the gap at the state level, which is where most of the affected banks are chartered anyway.

The examiner work program starts with eight questions that read like triage: Does the bank use AI at all? Where? Does it touch customers or shape decisions? Is AI embedded in vendor products? From there examiners may request AI policies, inventories, board reporting, chatbot transcripts, and vendor contract terms on data use and training. For agentic AI, they look at defined actions, human intervention checkpoints, logging, reversibility, and whether the system can be halted. The questions escalate from "do you have this" to "can you prove it, and can you stop it."

The tiering worksheet is the enforcement mechanism

The framework's risk-tiering worksheet scores each AI use case across three tiers by consumer impact, human oversight, potential harm, and data sensitivity. Tier 1 gets basic governance. Tier 3, where the model makes credit decisions or handles sensitive data with little human intervention, escalates to independent model validation and AI-specific incident response requirements.

The tiering approach matters because it answers the community-bank objection before it is made. A small bank using a vendor's fraud-detection product should not face the same examination burden as a large bank training its own underwriting models, and under this framework it will not. The controls follow the use case, not the asset size, which is the design feature that lets the framework cover institutions of every size without imposing the federal regime's compliance weight on a bank with three branches and a chatbot.

What the federal guidance left open

The April federal guidance was a revision of the model-risk management framework that has governed bank models for years, and it drew its line for a reason. The agencies calibrated the new requirements to the institutions where model risk is concentrated, the roughly two dozen banks above $30 billion that run large in-house model inventories. A $3 billion community bank using a vendor product, the argument ran, does not need the same apparatus, and imposing it would price small banks out of useful technology.

The calibration had a second consequence the agencies may not have intended. By drawing the line at $30 billion, the federal guidance left the majority of the banking system without any federal AI examination framework, at exactly the moment when AI products aimed at community banks were proliferating. Every vendor now sells a chatbot, a document-processing model, or an underwriting assistant to banks that the federal guidance does not reach. The state framework is the answer to that gap, and it is built for the gap's scale: a tiering system that lets a small bank's single vendor chatbot be examined without imposing large-bank model-validation requirements, while still putting agentic systems under real scrutiny.

The federal agencies have not objected to the state framework, and they will see its work product through the alternating examination cycle that already divides bank exams between state and federal supervisors. A framework adopted unevenly by fifty states may not have the uniformity of a federal rule, but for the banks it covers, it is the only framework there is.

Why agentic AI changed the question

The framework's treatment of agentic AI is the sharpest part of the document, and it reflects a real shift in what a bank's AI does. A traditional model scores: it estimates default risk, detects fraud patterns, prices a product. An agentic system acts: it moves money, communicates with customers, adjusts parameters, and chains decisions together without a human at each step. The failure modes are different, and so are the controls. A scoring model that is wrong produces a bad number, which a human can catch. An agentic system that is wrong produces actions, which may be unrecoverable by the time anyone looks.

The examiner work program's agentic-AI questions read like a checklist for the failure modes: what actions can the system take, where are the human checkpoints, what is logged, can actions be reversed, and can the system be halted. The kill-switch question is the one the banker survey says the industry is least prepared to answer, and it is the one with the most direct operational meaning. A bank that cannot stop its own agent is a bank with an open-ended liability, because every action the agent takes after it should have stopped is an action the bank must explain to a customer, a regulator, or a court.

The tiering worksheet folds this into the tier system: agentic systems with consumer impact and limited human oversight score into the higher tiers, where the controls, independent validation and incident response among them, are mandatory. The framework does not ban agentic banking. It makes the capacity to control the agent a condition of using it, which is the only sustainable position for a system where the technology is moving faster than the supervision.

The framework also reaches beyond banks. The Nonbank AI Supplements apply the same examination logic to the state-licensed nonbank institutions the states supervise, the mortgage companies, money transmitters, and fintech lenders whose AI use has grown at least as fast as the banks'. That extension matters because the nonbank sector is where a large share of AI-driven financial decisions are now made, and it has historically sat at the edge of the supervisory perimeter. A state examiner with the same five documents can now walk into a nonbank licensee and ask the same eight questions, which makes the framework's effective reach considerably larger than the 3,355 bank figure suggests. The states, in other words, did not just erase the asset-size line. They extended the examination playbook to the institutions the federal guidance never contemplated covering.

Discretionary, for now

The framework "does not create new legal obligations or supervisory requirements." Each state agency decides whether and how much to adopt it. That sentence is the framework's weakest point and its most honest one: CSBS cannot bind its members, and adoption will vary from California to Wyoming.

The history of state supervisory frameworks suggests adoption will be uneven but directionally uniform. When states get a common examination tool, examiners use it, because using the common tool means findings hold up across state lines and compare cleanly in interagency conversations. The federal agencies participate in state examinations through the alternating exam cycle, and they will see the framework's work product. A community bank's AI controls, or lack of them, are now something an examiner can walk in with a checklist to assess.

CSBS president and chief executive Brandon Milhorn framed the framework as a "principles-based approach to governance" meant to help institutions adopt AI with confidence. The confidence argument is worth noting because it inverts the usual regulatory framing: the playbook is presented as something that lets banks deploy AI knowing what will be examined, rather than as a restraint. For banks that have hesitated over compliance uncertainty, that framing is the intended nudge.

The preparedness gap the framework walks into

The timing matters. A Wolters Kluwer survey of 230 bankers found that 72 percent named model kill-switch protocols or regulatory reporting of AI failures as the areas where they were least prepared. The state framework makes both subjects of examination. Kill-switch capability, the ability to halt an AI system when it misbehaves, and failure reporting are exactly the agentic-AI controls the work program requests.

A bank that cannot stop its own AI system is now a bank with an examination finding waiting to happen, in any state that adopts the framework. The 72 percent figure suggests the first examination cycle will find the industry where the survey found it: aware of the requirement, short of the capability, and about to spend real money closing the gap. For the vendors who sell AI to community banks, the framework is also a product roadmap: whatever the worksheet scores at Tier 3, the vendor market will start building into their offerings. State examination has a way of becoming the de facto national standard for anything the federal guidance does not reach. In bank AI, that is now most of the industry.

Primary sources

  1. CSBS for the framework, its five documents, and its stated scope and basis.
  2. National Mortgage News for the supervisory reach figures, the tiering structure, and the examiner questions.