Banks are outsourcing their AI strategies to their vendors

  • Key insight: As banks integrate AI into their systems, they are becoming accountable for decision-making architectures that they did not design and have no real insight into. That means they need to ask their vendors some hard questions.
  • What’s at stake: A good vendor can make risk legible, but it can never make it someone else’s responsibility. 
  • Forward look: With technology this new and unregulated, there’s no such thing as being overly cautious or asking too many questions.

Bank-fintech relationships are responsible for some of the most popular financial innovations of our time. We have these relationships to thank for neobanking, an innovation that has lowered the barrier to entry for banking and improved financial inclusion.

Processing Content

Despite all of the progress these relationships have provided, one problem remains: A good vendor can make risk legible, but it can never make it someone else’s responsibility. 

For the last 15 years, SR 11-7 has been the framework U.S. banks use to manage model risk, including from models they buy rather than build. In April 2026, regulators introduced SR 26-2 which replaced SR 11-7 and SR 21-8 alongside it, a new set of guidance for a new era in banking. 

But there’s one glaring topic missing, and it’s the fastest moving, but the least understood.

Advanced AI.

This omission is deliberate. In a footnote, the regulators said they purposefully carved out generative and agentic AI because these are “novel and rapidly evolving, and as a result are not within the scope of the guidance.” So, the 15 years of validation machinery banks built under SR 11-7 does not, by the regulators’ own words, reach the one class of technology their vendors are shipping fastest. Eventually, they’ll release a separate request for information that will gather input intel from companies leading in AI and financial services.

Most banks don’t build their own AI, they buy it from a few large infrastructure providers, and for good reason. The technology is moving at a pace that’s difficult for any organization to keep up with, let alone traditional financial institutions with strict legal and compliance parameters. And almost nobody is building the models themselves. A bank’s own AI tooling still sits on top of an OpenAI or Anthropic model. A bank layering a client insights dashboard onto a third-party model will spend months moving it through internal approvals, and in that time the model underneath will have been replaced more than once.

Banks carry full accountability for advanced AI decisions. But most of the time, it’s actually a vendor that’s setting the tone. Fintechs are able to move faster and are generally more willing to take on that risk than banks, which is why these bank-fintech relationships are so critical. 

However, accountability to its customers and its regulator is the one thing no vendor can take off a bank’s plate. If a bank isn’t deliberate, those providers’ choices become the bank’s AI strategy by default.

Read more:

This puts banks in a genuinely hard spot. Boards want visible AI progress, competitors are already shipping the next best AI product, and yet there is no regulatory checklist or rulebook to follow.
Banks are left to define and manage responsible AI use themselves, even where the AI isn’t theirs, and to answer for it when it fails. So, while innovation can flourish in these bank and fintech relationships, the accountability for them is almost entirely concentrated on the bank.

Picture this scenario: A bank partners with a vendor to deploy AI fraud detection. The tech flags a legitimate small business as fraudulent based on a spurious pattern, like an unusual but honest cash flow shape. The business is denied credit. Now the bank faces fair-lending exposure, a discrimination complaint, and reputational damage, for a decision its own staff can’t reconcile because the vendor won’t expose the model’s logic.

So, where do banks go from here? Well, the FDIC is aware of this issue and has been working toward a solution. It floated working with fintechs to create an independent standard-setting body to make it easier for banks to evaluate risk when partnering with vendors, although this is currently at a very early meeting stage. It’s a good idea that I support, in theory. 

In practice, I don’t see this working the way it’s intended. It’s hard to see a new body commanding enough trust that banks will accept the certification at face-value. Conditions will be different for every deployment, therefore, banks will still need to follow their own set of standards and vetting procedures. Plus, American Banker’s reporting on this matter states that obliging these standards would be completely voluntary for both banks and fintechs, so the likelihood of full participation is low.

When it comes down to it, accountability for AI can’t be bought from anyone — hyperscaler, core provider or fintech.

Until regulators provide clear guidance on advanced AI, it’s up to banks to ask the right questions and understand their deal breakers before entering any vendor partnerships. 

With technology this new and unregulated, there’s no such thing as being overly cautious or asking too many questions. Any vendor who flinches has already told you where they stand.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *