Congress and regulators are eyeing both the promise and the pitfalls of artificial intelligence, with a new Government Accountability Office (GAO) report showing how deeply AI has penetrated the industry and how uneven the oversight remains.
Driving the news: In its report, the GAO detailed how financial institutions are using AI for everything from customer service to fraud detection, but found that the National Credit Union Administration (NCUA) lacks two key oversight tools to monitor AI’s use among credit unions.
Why it matters: While AI promises faster credit decisions, lower operational costs, and personalized services, it also brings risks of biased lending, hallucinated chatbot outputs, privacy violations, and system vulnerabilities. Regulators are relying heavily on existing frameworks to supervise AI, which raises questions about whether more targeted oversight is needed.
Key findings:
- Widespread Use: Banks, credit unions, and fintechs are deploying AI for credit underwriting, customer chatbots, fraud detection, and investment strategies.
- Regulatory Gap at NCUA: Unlike other banking regulators, NCUA lacks detailed model risk management guidance and the authority to examine third-party tech providers that credit unions depend on for AI services.
- GAO’s Recommendation: GAO reiterated its 2015 call for Congress to give NCUA examination authority over tech vendors. It also advised NCUA to update its model risk guidance to reflect modern AI use.
- Enforcement Action Snapshot: The Consumer Financial Protection Bureau has brought six AI-related enforcement actions since 2020. The Securities and Exchange Commission took at least eight in 2023–2024, many involving misleading AI claims. The Office of the Comptroller of the Currency has issued 17 AI-related “matters requiring attention” to banks since 2020.
Between the lines: While federal regulators say current rules apply to both traditional and AI-enabled tools, many institutions remain wary. The SEC, CFPB, and OCC have launched AI-focused examinations, with some firms misrepresenting their use of AI in public disclosures.
What’s next: Some agencies are reviewing whether current guidance is sufficient. Meanwhile, many financial institutions are treading carefully, especially with generative AI, due to hallucination risks and explainability concerns.
The bottom line: As AI evolves, so too must the frameworks that oversee it. But for now, regulators are largely relying on old tools to police new tech—and that may not be enough.
.




