The Fed Just Told You the Price of the Light Touch. Pay It Now.
What Governor Bowman’s FSB remarks mean for your bank, and the six things to do before your next exam cycle
Last Tuesday, Vice Chair for Supervision Michelle Bowman delivered opening remarks at an FSB outreach event on the consultation report she initiated: Sound Practices for the Responsible Adoption of Artificial Intelligence in Finance. Six minutes of remarks. Most of the industry will skim the headline and move on, and that would be a mistake.
Produced with the Treasury and the SEC, Bowman’s report gets finalized as a U.S. G-20 deliverable later this year. This is America’s latest supervisory doctrine being packaged for export. When your examiners show up in 2027 asking about AI governance, this document is what they’ll be working from. I spent enough time inside a federal banking agency to tell you exactly how this goes:
Consultation Report → Final Report → Interagency Guidance → Examination Procedures
The clock started last Tuesday.
The Deal on the Table
Strip away the diplomatic language and Bowman is offering banks a bargain: governance intensity scaled to materiality. Low-risk AI use cases get a lighter supervisory touch. Complex, material deployments get scrutiny proportionate to their impact. Community banks explicitly get a different standard than the money centers.
This is the most adoption-friendly posture a U.S. banking regulator has taken on AI — but it’s conditional. The light touch is only available to institutions that can demonstrate, not assert, which of their AI deployments are material and which aren’t. If you can’t produce that evidence, everything defaults to the heavy tier.
Explainability just became the price of admission. Here’s how to pay it.
The Cookbook
1. Build the AI Inventory this Quarter
You cannot tier by materiality if you don’t know what you’re running. Inventory every AI and ML deployment in the bank, including the ones buried inside vendor products (this is where most of them live). For each entry: what it does, what decisions it touches, what data it consumes, who owns it, and whether a human sits between the model output and the customer.
Most banks I talk to think this list has five items on it. It usually has fifty. Your fraud stack, your call center, your loan pricing tool, your marketing platform, and half your fintech partnerships are all running models you’ve never inventoried.
2. Assign a Materiality Tier to Every Entry
Three tiers is enough.
High: Touches credit decisions, BSA/AML, capital, or customer outcomes directly.
Medium: Informs human decisions with material consequences.
Low: Productivity, drafting, summarization, and internal tooling.
Write down the criteria before you classify, so the classification is defensible when an examiner asks why your chatbot is low-tier and your underwriting model is high-tier.
This tiering document is the single artifact that unlocks the lighter touch. It’s also a one-day exercise for a bank that has already completed Step 1.
3. Extend SR 11-7 But Don’t Reinvent It
Your model risk management framework already exists. The mistake banks make is treating AI as a new category requiring a new committee, a new policy, and eighteen months of consultants.
It isn’t.
Map your high-tier AI deployments into your existing MRM program: validation, ongoing monitoring, change management, documentation. Identify where the framework strains (non-deterministic outputs, foundation models you didn’t train, continuous vendor updates), and document the gap and the compensating control. Examiners reward honest gap analysis far more than pretend completeness.
4. Interrogate Your Vendor Stack, Including the Ones You’ve Trusted for Decades
Look at what just happened in the space of a few weeks.
On May 4, FIS announced it’s bringing agentic AI into banking with Anthropic, starting with a financial crimes agent that compresses AML investigations from hours to minutes. BMO and Amalgamated are already in development, with broader availability planned for the second half of this year and a roadmap into credit decisioning, onboarding, and fraud. Less than two weeks later, on May 14, Fiserv announced a strategic collaboration with OpenAI, building first-party agents on its new agentOS platform. Fiserv is also deploying Cognition’s Devin to rewrite its core banking code and has rolled out Microsoft Copilot across its entire workforce.
Your core provider now has a frontier AI lab wired into the systems that run your bank. That may turn out to be a very good thing — these are serious efforts, and FIS in particular is saying the right words about traceability and auditability. But saying the right words in a press release is not the same as handing you the evidence your examiner will want. So ask:
When the agent flags, or fails to flag, a SAR, whose model documentation do I produce? FIS’s? Anthropic’s? Mine?
Can I get case-level decision traces, or just a marketing deck about “governed AI”?
What happens to my materiality tiering when my vendor pushes a model update I didn’t request, didn’t test, and may not have been told about?
And for the dozens of thinner “AI-powered” vendors, like the wrapper companies putting a workflow skin on someone else’s model: What exactly is their layer adding to my defensibility? A wrapper around a black box is still a black box, now with an extra party in the accountability chain.
The hard truth in Bowman’s framework is that materiality-based governance is your obligation. Your core provider’s partnership with an AI lab doesn’t discharge it, and neither does a startup’s SOC 2 badge. The banks that ask these questions now will get real answers written into contracts. The banks that don’t will be forced to wait until someone gets around to them next year. That is precisely the wrong side of an examiner’s attention to be on.
5. Put AI on the Board Agenda with a One-Page Dashboard
Not a 40-slide deck. One page, quarterly, with the inventory count, the tier distribution, the top three material deployments, the validation status of each, and the open gaps. Board minutes showing informed oversight of AI risk will be worth more in your next exam than any policy binder.
6. File a Comment Letter Before July 22
The consultation closes July 22, and Bowman explicitly asked for pushback on where the practices are too prescriptive and where material risks were missed. Community and regional banks are chronically absent from these processes, and then live for a decade with rules written around JPMorgan’s operating model. If proportionality matters to your institution, say so on the record now, while the document is still wet. Your trade association filing does not count as your voice.
The Bottom Line
Build the inventory, tier it honestly, and be ready to walk an examiner through why each model does what it does. Do that and the light touch is yours, along with the strategic freedom that comes with it. Skip it and you land in the heavy tier by default.
The Fed just told you the rules of the game eighteen months early. That’s a gift. Most of your competitors will leave it unopened.
Sultan Meghji is the founder and CEO of Frontier Foundry and served as the first Chief Innovation Officer of the FDIC.
