Federal Reserve Acknowledges Outdated AI Guidance Amid Evolving Cybersecurity Landscape
UpGateNeutralRegulation & policy

Federal Reserve Acknowledges Outdated AI Guidance Amid Evolving Cybersecurity Landscape

Reading time: 4 min

Federal Reserve Vice Chair for Supervision Michelle Bowman highlighted that the central bank’s existing guidance for managing model risk in banking predates the widespread adoption of generative and agentic artificial intelligence, creating a gap in oversight. Speaking on May 1 at a Financial Stability Oversight Council roundtable, Bowman emphasized AI’s dual nature: it can serve as a powerful tool for cybersecurity but also presents significant risks when exploited by malicious actors.

Bowman acknowledged that current regulatory frameworks, including model risk management guidance, were established prior to the mainstream emergence of advanced AI technologies. This has coincided with a situation where AI’s capabilities are advancing faster than the industry’s defensive posture can adapt. This concern is shared at the highest levels; in April 2026, Treasury Secretary Scott Bessent and Fed Chair Jerome Powell met with CEOs of major banks to discuss these AI cybersecurity risks, underscoring the systemic nature of the issue.

AI’s dual role means that the same frontier models capable of detecting vulnerabilities in banking infrastructure could be repurposed by malicious entities to exploit those same systems. Existing model risk management guidelines were designed with traditional statistical models in mind, not large language models that can generate code, simulate social engineering attacks, or autonomously execute multi-step workflows. This presents a significant challenge for regulators seeking to ensure the stability and security of the financial system.

One of the sharpest points in Bowman’s address was the disparity in AI defense capabilities between large and small financial institutions. She noted that the Federal Financial Institutions Examination Council can provide support to smaller institutions that may lack the resources to independently develop advanced AI defenses. The Fed is also engaging with major payment networks, including Mastercard and Visa, to ensure that AI-driven security improvements do not leave the rest of the financial system exposed.

The advent of agentic AI, where models can take actions rather than just answer questions, poses a particularly thorny challenge for regulators. If an AI agent can independently initiate transactions, modify risk parameters, or interact with external systems, the traditional framework of human-in-the-loop oversight begins to break down. Bowman signaled that the Fed recognizes this gap and is working to address it, though she stopped short of proposing specific new rules.

The Federal Reserve has been tracking AI adoption across financial institutions for nearly a decade, indicating a long-standing awareness of its growing influence. However, the recent leap in generative and agentic AI capabilities has outpaced existing regulatory frameworks. While Bowman highlighted the need for modernized supervisory approaches, the specific timeline for the Fed to close this oversight gap and the exact nature of any new regulations remain uncertain. The Fed’s engagement with payment networks and its acknowledgment of institutional disparities suggest a comprehensive, albeit evolving, approach to managing AI risks in the financial sector.

Why This Matters

Federal Reserve Vice Chair Michelle Bowman’s remarks underscore the urgent need for updated regulatory frameworks to address the rapidly evolving capabilities of artificial intelligence in banking. The dual nature of AI, presenting both cybersecurity benefits and risks, coupled with the limitations of existing guidance, highlights a critical challenge for financial regulators. The Federal Reserve’s engagement with payment networks and its recognition of disparities between large and small institutions indicate a broad effort to adapt supervisory approaches, though specific new rules remain uncertain.

Broader Context

The Federal Reserve’s role in supervising financial institutions is central to this discussion. The increasing capabilities of generative and agentic AI, alongside existing regulatory frameworks for model risk management, form the backdrop against which Bowman’s concerns are situated. The challenges posed by AI to traditional cybersecurity and oversight models, particularly the differing concerns of large versus small financial institutions, are key elements shaping the current regulatory landscape.

Tags:UpGateNeutralRegulation & policy
Copied