Collections and recovery is the banking function where artificial intelligence poses the greatest risk of customer harm or regulatory exposure, according to a new survey of 230 banking professionals from Wolters Kluwer, which found the function outpacing credit risk and underwriting by 10 percentage points.
The finding, part of the company’s H1 2026 US Banking AI Risk and Governance Index, should get the attention of anyone running a collection operation. More than 35% of respondents named collections as the highest-risk function, compared with 25% for credit and underwriting. The report attributes the gap to where collections sits: at the intersection of financial distress, behavioral AI, and a thinner consumer disclosure framework than the adverse action regime that governs lending decisions.
The concern compounds when autonomous AI enters the picture. Asked where agentic AI introduces the greatest risk due to automation without sufficient human-in-the-loop controls, respondents pointed to lending and underwriting workflows (33%) and collections and recovery (30%), together accounting for nearly two-thirds of the concern. Only 12.6% of respondents said their institution has no agentic AI deployment yet, meaning the vast majority are already running or planning autonomous systems in the functions they themselves identify as the most dangerous places to run them.
The survey, which drew responses from community banks under $1 billion in assets up to institutions above $50 billion, found governance lagging deployment across the board. Model governance and validation was cited as the top barrier to safely scaling AI by 36% of respondents, more than double the share who named fairness and non-discrimination. Synthetic data misrepresentation topped the list of data risks as banks increasingly use AI to generate and clean the data that other AI systems train on.
The starkest numbers came on incident response. More than 72% of respondents said their institution is least prepared in either regulatory reporting for AI failures or model kill-switch protocols, the two capabilities regulators are likely to demand first when a system causes harm. And the leading human-side risk was automation bias, the tendency of human reviewers to defer to algorithmic outputs rather than exercise independent judgment, cited by 34% of respondents.
Notably, respondents said the primary driver of safe AI adoption at their institutions is internal risk mitigation, not regulatory compliance. For collection shops using AI to optimize contact strategies, generate settlement offers, or determine payment plan eligibility, the report’s implication is direct: the time to pressure-test governance and human oversight is before examiners ask to see it.




