On this page
The agents are already in your vendors' roadmaps
A community bank runs on a few dozen people, and most of what it spends pays them. A loan processor, a BSA analyst and a deposit operations specialist are often one person each, sometimes the same person, working from the core's reports, the imaging system and a shared inbox.
Its core vendor, its loan system and its monitoring tool are all adding agents. nCino's annual report describes "agentic AI that automates multi-step workflows through role-based digital agents"[3]. FIS says it is focused on "agentic capabilities"[4]. These arrive as features in releases the bank already pays for.
In April 2026 the Fed, OCC and FDIC rewrote model risk guidance and said generative and agentic AI models "are not within the scope"[13]. So when an agent tells a borrower something, proposes a provisional credit or drafts a SAR narrative, the controls an examiner will look at are the bank's own.
- 49
Full-time equivalent staff at the median community bank at the end of 2025, with $338 million in assets[1]
- 56.2%
Share of community bank noninterest expense that went to salaries and benefits in 2025, against 47.3% at other banks[1]
- 13% → 62%
Community bankers naming core processor responsiveness as a barrier to new technology, 2024 to 2025 survey[57]
Who this is for. US FDIC-insured community banks, the 3,911 institutions the FDIC flagged as community banks at the end of 2025, and regional banks of about $10 billion to $100 billion[1]. It covers operations: lending and loan administration, deposits and payments, BSA/AML and fraud, the contact center, and the compliance work behind them. Credit unions do much the same work under a different regulator and are mentioned only where a source covers them.
The short version
AI-enabled vs AI-native, for a bank
A loan officer pastes a tax return into a chatbot. The core vendor's bot answers balance questions. The BSA analyst reads an AI summary inside the monitoring tool. Each tool helps one person, and nobody can later show what the AI read, what it said, or who approved it.
Agents do the first pass on every loan file, condition request, annual review package, alert research packet, dispute intake, payoff letter and document exception. Named employees approve every credit decision, money movement, SAR decision and customer statement that is not from an approved template. Each agent acts on one employee's authority and sees no more than that employee could. Turnaround, errors and exceptions are measured per workflow.
The examiner test. If an examiner asked "show me what your AI told this borrower, what it relied on, and who approved it", could you answer from a record in a minute? An AI-enabled bank usually cannot. An AI-native bank can, for every workflow agents touch.
Most banks using generative AI today fit the first box. In Cornerstone Advisors' 2026 survey, about half of banks had deployed it[58], but a public count of banks running agents inside operations does not exist.
The missing layer: on whose authority the agent acts
A community bank will not replace its core to become AI-native, and most could not if they wanted to: 75% of CSBS respondents buy core services from an outside provider[57]. Agents will arrive from three directions: built into the core and the LOS, sold by point vendors for AML or the contact center, and assembled by the bank from general tools. Each one raises the same four questions. On whose authority does it act? What may it see? What waits for a person? What record does it leave?
The Fed is asking the same thing about payments: the question "shifts from proving that a buyer is an authorized payer to proving that an agent has the authority to pay on the buyer's behalf"[23]. Inside the bank it is a lending limit, an approval matrix and a field-level access rule. No single system answers it across the core, the LOS, imaging and email, and the core vendor controls what outside software may read and write. nCino's own 10-K says it lacks "formal arrangements" with many providers for access to their APIs, including "core processing systems"[3].
OrchKernel is built to be that layer. Agent actions the bank routes through it are checked against the rules, held when they need a named employee, limited by role and field, and recorded. It is not a core, an LOS or a monitoring system, and it does not replace any of them. The details are in the OrchKernel blueprint.
The bank's own, and the ones arriving inside the core, the loan system and the contact center. Each acts for a named employee, with no more access than that employee has.
- Approvals
- Rules
- Named-person authority
- Field-level access
- Human queue
- Audit log
Allows, holds for a named employee, or denies, and records which.
- Core
- Loan origination
- Document imaging
- BSA monitoring and cases
- Digital banking
- Email and phone
Where the hours and margin go
Revenue is spread; cost is people
Community banks earned 82.8% of their 2025 revenue as net interest income and 17.2% as fees and other noninterest income; for other banks the fee share was 33.5%[1]. Net interest margin was the top external risk for 88% of CSBS respondents[57]. A bank does not set the rate environment. It does control what it costs to serve a customer.
- 56.2%Salaries and benefits
- 9.9%Premises
- 33.0%Everything else: data processing, core fees, FDIC assessments, legal, audit, marketing
The efficiency ratio is the scoreboard. Community banks spent 62.9 cents to earn a dollar of revenue in 2025, against 55.5 cents at other banks. The middle half sat between 56.2% and 74.5%, with a median of 64.5%. The aggregate ratio has improved from 67.9% in 2015 to 61.5% in the first half of 2026, mostly as banks merged and cut staff: community banks fell from 5,733 to 3,818 and their staff from 439,030 to 347,003 full-time equivalents[1].
The scale gap is large. Community banks employ 126 people per $1 billion of assets; banks over $100 billion employ 73[1]. Some of that is the product: relationship lending, branches, farm and small-business loans need people. Much of it is the fixed work of running a chartered, examined institution at small scale. A typical $500 million to $2 billion community bank has about 111 staff, $20.8 million of annual noninterest expense and $12.2 million of salaries and benefits[1].
Where the hours go, by area
Public time data for bank operations barely exists. Where a row says so, measure your own.
What this means for the plan. The money sits in people assembling, checking and documenting work around the core, and compliance work is mostly people too. That is the work agents can draft. The same sources say the bank does not control its core, and that cybersecurity worries 94% of community bankers[57]. So the plan keeps the core, the LOS and the monitoring system, and puts controls around the agents that draft inside them.
What AI already does in bank operations, by system
The sources name example vendors; naming them is not a recommendation, and performance figures from vendors are their own claims.
Adoption, with caveats
About half of banks and nearly 60% of credit unions have deployed generative AI, in Cornerstone's survey of 416 executives at $250 million to $50 billion institutions[58]. It is a consultancy's sample, and "deployed" is not defined on the public page. Among community bankers, 46.7% see AI for customer interactions as a promising opportunity; 41% name cost and implementation as the main barrier, and 16% each name cybersecurity and the core provider[57].
The Fed has "seen a noticeable increase in the use of AI by banks of all sizes"[22], without a count. GAO found AI used for "automated trading, credit decisions, and customer service"[11]. Treasury recorded concern that generative AI could "increase smaller institutions' dependency" on a few large companies[12]. What nobody has published is an independent count of community banks using AI in operations, or outcome data for agents in lending or deposit operations outside vendor case studies.
Where the money went
Investment went to vendors that sell into banks: contact-center agents, document analysis, identity and fraud, AML investigation, and digital cores such as Nymbus, which raised $70 million in 2023[64]. The core vendors and nCino are building agents themselves. We found no AI-native community bank at scale: no de novo charter built around agents with a visibly lower cost base. So far, the AI-native entrants we found sell tools to banks.
The closest precedent went badly. From 2020 to 2024, fintechs ran customer-facing operations on top of small partner banks. When Synapse failed in 2024, $65 million to $95 million could not be reconciled[65], and its partner bank Evolve was already under a Fed enforcement action for its oversight of fintech partners[33]. Handing operations to software does not move the bank's responsibility: the 2023 third-party guidance says using a third party "does not diminish" it[15].
Who signs what
A borrower asks where the loan stands. An agent reads the file and drafts a reply. What happens next depends on what the draft would do, and the lanes are set by the bank's rules, not by the agent.
"Where are we on my loan? Do you need anything else from me?"
Reads the LOS conditions and the imaging index, sees what is missing, drafts a reply, and classifies the request.
- Goes out on a trusted template
No per-message approval. A sample is reviewed every week, and the template owner can switch it off.
- List of documents received and still missing
- Appointment and document reminders
- Branch hours and routing numbers
- Waits for the processor's approval
The processor sees the exact message and the file facts it used, then approves, edits or rejects.
- Condition request letter
- Payoff letter
- Free-text reply about loan status
- Reg E acknowledgment
- Goes to a person who decides
The agent can gather facts, but has no tool to act. A named owner gets the case with its deadline.
- Anything about approval or terms
- "I didn't make this charge"
- Any held or restricted account
- A change to payment instructions
What the agent read, what it drafted, which lane it took, who approved or decided, and what was sent. This is the record you hand an examiner.
The staged path
The stages follow regulatory weight: internal assembly first, customer-facing drafts second, narrow straight-through third, money and BSA only under dual control, and the operating model last. Timings are typical for a bank that starts with one workflow; different departments can sit on different rungs.
- 5AI-native operating modelOperations run as queues with clocks; the board sees the AI inventory
- 4Money and BSA paths, dual controlAgents first propose money movement and BSA filings
- 3Trusted templates; contact center with handoffCustomers first talk to an agent
- 2Customer-facing drafts, approved one by oneAgent output first leaves the bank, after approval
- 1Read and assemble, internal only
- 0Inventory and ground rules
- 0
Stage 0: Inventory and ground rules
About 1 to 2 months
What to do
- List every AI feature already switched on in the core, the loan origination system, digital banking, the BSA monitoring tool and staff productivity software.
- Find the shadow use: who pastes tax returns, account numbers or SAR facts into a public chatbot.
- Classify the data agents might touch: SSNs and account numbers, tax returns, SAR and case data, employee and insider accounts.
- Write a short AI policy for the board to approve, in three lists: what agents may draft, what needs a named approver, and what they may never do. Say what record is kept.
- Add AI questions to vendor due diligence: does the product contain an agent that acts in our systems, on whose authority, and what does it log?
- Measure a baseline for three workflows: hours per loan file, per commercial annual review, per alert, per dispute.
Why now
Generative and agentic AI are outside the revised model risk guidance[13], so the bank's own governance is what an examiner will read. About half of banks in Cornerstone's sample already use generative AI[58], mostly one person and one tool at a time.
In place first
- A named AI operations owner, often the COO or the digital banking officer.
- Sign-off from the compliance officer and the BSA officer on the never list.
What to measure
Share of AI features inventoried; share of staff covered by the AI use policy; baseline hours per file, review, alert and dispute.
Common mistakes
- Treating the core vendor's AI as already approved because the core is.
- A policy with no list of forbidden actions.
- No baseline, so every later saving is a guess.
- 1
Stage 1: Read and assemble, internal only
About 2 to 4 months
What to do
- Loan file assembly: index incoming documents to imaging and check them against the application.
- Commercial annual review packages: pull financial statements and tax returns, draft the spread, list covenant results.
- Covenant, insurance and UCC continuation tracking lists, and document exception reports.
- Alert research packets for BSA: account history, customer profile, prior alerts and related parties, each with its source.
- A staff question-and-answer tool over the bank's own policies and procedures.
Why now
No customer sees the output, the hours are high, and the person who does the work today catches mistakes. One CSBS respondent said AI could do "80% to 90%" of commercial annual review work[57]: a banker's opinion, worth testing against your own baseline.
In place first
- Read-only connections to imaging, the LOS and core reports, or scheduled exports where the core vendor has not licensed API access.
- Field-level access rules from Stage 0 enforced in the connections themselves.
What to measure
Minutes per annual review package; alerts researched per analyst-day; reviewer agreement with agent packets; errors found per 100 files.
Common mistakes
- A service account that can see every customer, including employees and SAR flags.
- Skipping the reviewer agreement measure.
- Letting the packet reach a conclusion. Packets state facts and sources; the analyst concludes.
- 2
Stage 2: Customer-facing drafts, approved one by one
About 3 to 6 months
What to do
- Drafts of condition request letters, document reminders, loan status replies, payoff letters and incompleteness notices.
- Drafts of Reg E acknowledgment and resolution letters, dormant-account and deceased-customer letters, beneficial ownership requests.
- Dispute detection on every inbound channel: email, chat, secure message, call notes.
Why now
Stage 1 showed the agent reads the file correctly. Now the person who would have written each letter approves it, and the bank learns which templates can be trusted.
In place first
- Approved templates, owned by compliance.
- Dispute routing working before any customer-facing draft goes live.
- A record of what was sent, by whom, on whose approval.
What to measure
Approval-without-edit rate per template; time to first borrower request; days from conditions to clear-to-close; letters under Reg E sent within deadline.
Common mistakes
- Letting an agent choose the reasons on an adverse action notice, or send one. The loan officer records the reasons and sends.
- Free-text replies outside the templates.
- Going live without dispute routing.
- 3
Stage 3: Trusted templates; contact center with handoff
When Stage 2 numbers hold for a quarter
What to do
- Template replies whose approval-without-edit rate stayed high go out without per-message approval, with a weekly sample review and a kill switch.
- A contact-center agent answers from the file and the core, and hands off to staff on disputes, fraud, hardship and anything it cannot place.
Why now
The Stage 2 measure earns it. Chatbots are not new to customers: the CFPB estimated 37% of the US population used a bank chatbot in 2022, and documented the "doom loops" that follow when there is no way to reach a person[35].
In place first
- Consent for outbound calls and texts; AI voices count as artificial voices under the TCPA[56].
- A plain statement that the customer is talking to an AI, and how to reach a person.
- An escalation queue with people on it at the hours the agent answers.
What to measure
Handoff rate; complaints per 1,000 contacts; disputes detected against disputes missed, from a sample; after-hours requests resolved; sample error rate.
Common mistakes
- Letting templates drift without review.
- No human path out of the conversation.
- Treating chat transcripts as outside Reg E.
- 4
Stage 4: Money and BSA paths, under dual control
After a year of records from the earlier stages
What to do
- Agents propose provisional credits, ACH return and notification-of-change updates, fee reversals within limits, and loan boarding to the core.
- Agents draft CTRs and SAR narratives for the BSA officer.
- Agents built into the core and the LOS act through the same gate, with the same approvals and log.
Why now
Money and SAR decisions carry the most regulatory weight. The information security guidelines already call for "dual control procedures, segregation of duties"[45]. Agents should be held to the same standard.
In place first
- Approved actions run exactly once, and writes are checked against the live record.
- Amount tiers, and a rule that the approver differs from whoever asked.
- Callback verification for any change to payment instructions.
- SAR confidentiality rules applied to every customer-facing agent.
What to measure
Provisional credits on time; SARs filed within 30 days; CTR error rate; agent-proposed actions reversed; dollars moved per approval tier.
Common mistakes
- One person both proposing and approving, through the agent.
- Retry logic that posts twice.
- Any path, however indirect, for an agent to tell a customer about a SAR.
- 5
Stage 5: AI-native operating model
Ongoing
What to do
- Organize operations as queues with clocks: conditions, disputes, alerts, maintenance requests.
- The AI operations owner runs agent changes like policy changes: reviewed, tested, logged.
- The board gets a quarterly AI inventory with a materiality view; examiners get a walkthrough of the record.
Why now
Supervisors now ask whether AI use "is material to their business operations"[22]. And the efficiency ratio is public, so the result shows against peers.
In place first
- A year or more of records from Stages 1 to 4.
- Staffing plans that say what the freed hours will do.
What to measure
Efficiency ratio against peers; FTE per $1 billion of assets; noninterest expense growth against asset growth; exam findings on operations; turnaround per workflow.
Common mistakes
- Counting hours saved that were never put to other work.
- Letting a vendor's agent widen its scope through an update nobody reviewed.
Your first 90 days
Stage 0, one Stage 1 workflow, and the first Stage 2 template. The baseline you take in the first month is what tells you, and your board, whether it worked.
- Days 1 to 30
Name an AI operations owner. Inventory the AI already switched on in vendor systems and in staff use. Classify the data. Get a one-page AI policy approved by the board, in three lists: allowed, needs approval, never. Pick one internal workflow: commercial annual review packages, document exceptions, or alert research packets. Start four weeks of baseline measurement.
- Days 31 to 60
Connect read-only to imaging, the LOS and core reports, or to scheduled exports where the core vendor has not licensed API access. Run the agent beside the team on the chosen workflow; people still do the work and compare. Record reviewer agreement and errors. Add AI questions to vendor reviews. Turn the never list into rules the agents are checked against.
- Days 61 to 90
Move one customer-facing template to Stage 2: condition request letters or payoff letters, each approved by the processor before it goes. Walk the compliance officer and the BSA officer through the record of every read, draft and approval. Report to the board against the baseline, and decide the next workflow.
What not to fully automate
An agent can prepare every one of these. A named, authorized employee makes the call.
When it goes wrong
Real cases first. None of them involved an AI agent, but each failed at a point an agent would touch: an approval nobody understood, a dispute path that was not ready, monitoring nobody revisited, a record the bank did not own.
Citibank's mistaken Revlon payment, August 2020
Acting as loan agent, Citi sent nearly $900 million of its own money to Revlon's lenders by mistake, then sued to get it back[67]. The payment had passed Citi's multi-person check, which the Second Circuit's opinion refers to as a "six-eye" process[27]. Two months later the OCC fined Citibank $400 million for long-standing risk management, data governance and internal control failures[26].
To be confirmed: How the loan system's screen misled the approvers is to be confirmed against the opinion text.
The control: Approvals show the exact payload and its effect, not a form to tick (control 3).
Apple Card disputes, 2024 orders
The CFPB ordered Goldman Sachs to pay a $45 million penalty and $19.8 million in redress for failing to send dispute acknowledgments and resolution letters on time, investigating poorly, and holding consumers liable before investigating. The board was told on 16 August 2019 that the disputes system was "not fully ready"; the card launched four days later[28]. Apple was separately ordered to pay $25 million[29].
The control: A dispute is a dispute whatever channel it arrives through; clocks and human decisions are enforced, and nothing goes live before the dispute path works (control 4).
TD Bank transaction monitoring, 2024
The OCC found "significant, systemic breakdowns in its transaction monitoring program" and a pattern of failing to file SARs, and imposed a $450 million penalty and a growth restriction[30]. FinCEN assessed a record $1.3 billion[31] and the Fed $123.5 million[32], alongside a Justice Department action.
To be confirmed: The combined total across all agencies, often reported as about $3 billion, is to be confirmed.
The control: Automation that nobody revisits becomes the failure. Coverage and every rule change are reviewed and logged (controls 5 and 15).
Evolve Bank & Trust and Synapse, 2024
The Fed took action against Evolve over risk management of its fintech partners, AML and consumer compliance[33]. A ransomware breach exposed data on at least 7.6 million people, including partner fintechs' customers[66]. When Synapse failed, $65 million to $95 million could not be reconciled and nearly $160 million was frozen for end users[65].
The control: The bank's record of who did what must be its own. A vendor's ledger or log is not enough (controls 12 and 16).
Hello Digit, 2022
An automated savings tool promised it "never transfers more than you can afford", caused overdrafts, and the company "did not always reimburse" them. CFPB penalty: $2.7 million[34].
The control: Software that moves customer money needs limits, a check against the live balance, and a person on exceptions (control 3).
Impersonation and deepfake payment fraud
An Arup employee in Hong Kong sent about $25 million after a video call with deepfaked executives, a case Governor Barr cited[24,69]. The community bank version, from the CSBS survey: callers posing as the bank talked a business customer into giving up online banking credentials, and $16,000 left the account within the hour[57].
The control: Changes to payment instructions or login credentials need out-of-band verification; voice or video alone never authorizes (control 7).
Earnest AI underwriting, Massachusetts, July 2025
A reported $2.5 million settlement with the Massachusetts Attorney General over a student lender's AI underwriting, requiring written AI lending policies and dropping certain variables. The company denied wrongdoing[68].
To be confirmed: Read in a secondary source; the terms are to be confirmed against the Attorney General's release.
The control: Write down what an AI may use, and review outcomes by borrower group (control 18).
Chatbots that miss disputes
From a complaint the CFPB quoted: "The chat agent confirmed that the agent from the prior week did NOT open a dispute"[35].
The control: Dispute language is classified and routed to a human queue with the Reg E clock started (controls 4 and 13).
Agent failures to design against (scenarios)
These are scenarios, not reported cases: what an agent with too much access or too little routing could do in a community bank. Each maps to a control point.
Rules that apply
Across all of these, the same few controls keep recurring: a named person decides, the customer can reach a person, a clock is tracked, confidential facts stay confidential, and a record is kept. Build those five once, for every agent, and each rule below becomes a question of settings and wording rather than a new project.
Supervision of AI
- Model risk guidance leaves agents out
- SR 26-2, issued by the Fed, OCC and FDIC in April 2026, replaced SR 11-7. It is "expected to be most relevant" to banks over $30 billion, and footnote 3 says generative and agentic AI models "are not within the scope of this guidance", while the bank's risk management and governance "should guide the determination of appropriate governance and controls"[13]. The OCC separately said its guidance does not require community banks to validate models every year[14]. So there is no safe harbor, and no checklist either: your own controls are the standard.
- Third-party risk covers every AI vendor
- Using a third party "does not diminish" the bank's responsibility to meet its obligations[15], with a community bank guide in SR 24-2[16]. New tailored guidance and a guide for traditional community banks were proposed on 15 September 2026, with comments due 16 November 2026[17]. The final text may differ.
Information security and incidents
- Access, dual control and service providers
- The interagency security guidelines call for access controls that "permit access only to authorized individuals", "dual control procedures, segregation of duties", monitoring, and oversight of service providers[45]. An agent is a new kind of user and should be held to the same lines.
- 36 hours to tell your regulator
- A bank must notify its primary federal regulator "no later than 36 hours after" it determines a notification incident occurred, under parallel FDIC, OCC and Fed rules. A bank service provider must tell the bank as soon as possible when an incident disrupts services for four hours or more[46,47]. An agent vendor can be that provider.
- Notice of new service relationships
- The Bank Service Company Act requires a bank to notify its regulator of a service relationship within 30 days of the contract or the first service[48]. Whether a given AI vendor falls under it depends on the services; ask your regulator.
- New York state charters
- NYDFS has explained how Part 500 applies to AI: deepfake social engineering, third-party AI, data minimization, and authentication that does not rely on SMS, voice or video. It "clarifies existing Part 500 obligations" rather than adding new ones[25].
Lending
- Regulation B: notice and specific reasons
- Notice of action within 30 days of a completed application, and a statement of reasons that is "specific" and indicates "the principal reason(s)"[37]. Records kept 25 months for consumer credit and 12 months for business credit[38]. The CFPB withdrew its 2022 circular on complex algorithms in May 2025[36]; the regulation it interpreted did not change.
- Fair lending after EO 14281
- The OCC stopped examining for disparate impact in July 2025 but still examines for disparate treatment and analyzes HMDA data[18]. ECOA and the Fair Housing Act are unchanged, and private suits continue. How the FDIC and the Fed now examine for disparate impact is to be confirmed. Different agent wording for similar borrowers is what disparate treatment looks like in a file.
- Mortgage timing, valuations and flood
- The Closing Disclosure must reach the borrower "no later than three business days before consummation"[40]. Quality control standards for automated valuation models took effect on 1 October 2025[51]. Flood insurance violations in a pattern or practice carry mandatory civil money penalties: the statute says up to $2,000 per violation[49], which the FDIC adjusted for inflation to $2,730 in January 2025, its latest adjustment we found[50]. Other regulators publish their own adjusted figures.
- Colorado from 2027To be confirmed
- SB26-189, signed on 14 May 2026, covers "consequential decisions" including lending: notice at the point of interaction, a plain-language explanation within 30 days of an adverse outcome, a right to "meaningful human review", and records for three years[53]. It exempts entities "to the extent the entities comply with other legal obligations". How that applies to a federally examined bank is to be confirmed: we could not open the signed text.
Deposits and payments
- Regulation E error resolution
- Notice within 60 days of the statement; investigate within 10 business days or provisionally credit; up to 45 days, or 90 for point-of-sale, foreign-initiated and new-account transfers[39]. The rule covers "any oral or written notice of error", so in our reading a dispute typed into a chat window counts; confirm with counsel how your channels are covered.
- Chatbots
- The CFPB's 2023 issue spotlight documents chatbots that fail to recognize disputes and trap customers in loops. It says it is "not intended to impose any obligations"[35], so the duty comes from Reg E and UDAAP law, and the spotlight shows how examiners have seen the failure.
- Outbound AI calls
- AI-generated voices are "artificial" voices under the TCPA, so consent rules apply to AI voice calls for collections and service[56].
BSA, AML and fraud
- SARs and their confidentiality
- File within 30 calendar days of initial detection, up to 60 if no suspect is identified; keep five years; and do not "disclose a SAR or any information that would reveal the existence of a SAR"[41]. The September 2026 joint statement allows talking to customers about suspicious transactions "so long as that communication does not reveal the existence of a SAR"[19].
- CTRs
- A report for each "transaction in currency of more than $10,000"[42], filed within 15 days and kept five years[44]. Cash transactions the bank knows are by or for one person in a business day count as one[43], across branches.
- AML program reformTo be confirmed
- FinCEN and the OCC, FDIC and NCUA proposed new AML/CFT program rules on 10 April 2026, and the Fed followed on 9 July 2026[52]. As of 5 October 2026 we found no final rule in the Federal Register. The final text is to be confirmed.
- Digital IDs and deepfakes
- Verifiable digital credentials such as mobile driver's licenses may be used for CIP; they "do not alter existing BSA legal or regulatory requirements"[20]. FinCEN has seen more SARs describing deepfake media used to get past identity checks[10]. In 2018 the agencies already encouraged banks to try new technology, naming "artificial intelligence", for BSA work[21].
The dispute clock
- 1Day 0
The customer says a transfer was wrong, by chat, email, phone or at a branch. The clock starts when the bank receives the notice, not when someone opens a case.
Agent recognizes the dispute and opens the case with the deadline
- 210 business days
Finish the investigation, or provisionally credit the account and keep investigating. 20 business days for new accounts.
Deposit operations decides; a second person approves the credit
- 345 days (90 in some cases)
Longest investigation once provisionally credited. 90 days for point-of-sale, foreign-initiated and new-account transfers.
Deposit operations decides whether an error occurred
- 4After the decision
Tell the customer the result. If no error, explain, and give notice before reversing a provisional credit.
Agent drafts from the case; staff approve the letter
Keeping records: one setting will not fit
How roles change
Our recommendations, inferred from the work rather than from a survey. Community bank staff already fell 21% from 2015 to mid-2026 while assets grew[1]. With staff retention still a top internal risk for 68% of CSBS respondents[57], the likelier near-term effect is absorbing growth and retirements without rehiring, not layoffs. Nobody has measured that yet.
- Loan processor
- Owns the exceptions. Agents request documents, index them to imaging, check them against the application and track conditions. The processor handles what does not match and releases files to closing. No public benchmark exists for files per processor, so measure your own.
- Credit analyst
- Becomes the reviewer. Agents spread statements and assemble annual review packages; the analyst checks the figures and writes the judgment. The banker's "80% to 90%" is a claim to test against your baseline.
- BSA analyst
- Investigates and recommends. Agents gather account history, the customer profile and prior alerts into a case packet and draft the narrative. The analyst and the BSA officer decide.
- Deposit operations
- Works a queue with clocks. Reg E disputes, ACH returns, deceased-customer files and maintenance requests arrive as cases with deadlines computed, and staff approve each step that touches money.
- Contact center and universal bankers
- Change first and fastest. Teller jobs are projected to fall 13% from 2025 to 2035[6], while loan officer jobs grow 1%, with the BLS citing "productivity-enhancing technology in loan processing"[7]. Staff shift to handoffs, exceptions, vulnerable customers and fraud calls.
- AI operations owner (new)
- Often the COO or the digital banking officer. Owns agent playbooks, templates, the list of what each agent may do, and the change log.
- Compliance and BSA officers
- Own the rules: which notices need a person, which templates may go out alone, what agents may never see.
- Vendor management
- Asks every vendor a new question: does your product contain an agent that acts in our systems, and on whose authority?
- The board
- Gets an AI inventory and a materiality view each quarter, because supervisors now ask whether AI use "is material to their business operations"[22].
Acquisitions. Banks that buy other banks convert them to one core. Agents built against one core and one set of templates can run in every acquired branch, which makes the record and the rules part of the integration plan.
The OrchKernel blueprint for a community bank
OrchKernel sits between AI agents and the systems a bank runs on, as drawn in the missing layer. Agents ask it before they act; it checks the rules, holds what needs a named employee, and records what happened.
What it is not. The core stays the system of record for deposits, loans, the general ledger and the customer file. OrchKernel does not replace the core, the LOS, imaging or the BSA monitoring system.
The mechanisms
- Approvals
- The action waits for a named employee, who sees the exact payload: the letter as it will be sent, the credit with its amount and account. On approval it runs once.
- Rules
- Argument checks, deny lists and thresholds, checked before every action. A rule allows, holds or denies, and says why.
- Acting on a named person's authority
- Each agent acts for a named employee, with no more access than that person. Lending limits and the approval matrix come from board policy. When the employee leaves, their agents stop.
- Data access by role and field
- Sensitive fields are visible only where the job needs them; customer-facing agents never see case data. Each AI model is cleared for a data class before use.
- Tamper-evident audit log
- Every read, draft, rule result, approval and write, hash-chained so an edited or deleted entry shows. Any run can be replayed.
- Human queue
- Work only a person may do lands with an owner and a deadline, such as a dispute with its Reg E date.
- Kill switches and budgets
- Stop one agent, one workflow or all of them at once; cap what an agent may do in a period.
- Connections to the bank's systems
- The core (Fiserv, Jack Henry, FIS and others), the LOS (nCino, MeridianLink, Encompass), imaging, BSA tools, digital banking, email and phone, through MCP servers, REST adapters, or reports and exports where the core vendor has not licensed API access. OrchKernel holds the credentials, so agents never hold core passwords.
Twenty control points
Where a community bank needs a control whatever tools it uses, who owns it, how OrchKernel enforces it, and what stays in another system.
Lending
Deposits, payments and customers
BSA and fraud
Access, vendors and the record
Running and governing the agents
What belongs elsewhere
The last column of the table names what stays in other systems. Two points sit outside it: board policy, lending authority and regulator notices are the bank's decisions, which OrchKernel enforces but does not make; and API access to the core is a commercial matter between the bank and its core provider.
OrchKernel is source-available under the Business Source License and runs on the bank's own infrastructure, so the bank and its examiners can read the code that enforces these controls. A bank running it for itself is within the license. A core vendor, bankers' bank or service bureau running one deployment for many separately chartered banks needs a commercial license.
Scorecard by stage
Take the baseline in Stage 0, then track the same numbers at each stage. Only the bank-wide ratios have public benchmarks, from the FDIC's call reports. Everything else is measured against your own baseline.
What we don't know yet
- Time per task in community bank operations (loan processing, annual reviews, alert research, disputes). We found no public data.
- How many community banks use AI inside operations, as opposed to chat or fraud scoring. Survey figures measure sentiment or loosely defined deployment.
- Several rules are moving: final AML/CFT program rules, final third-party risk guidance and Colorado's reach into banks. Each is marked in the rules section.
- Whether a lower-cost, agent-run community bank charter is possible. Nobody has built one yet.
Sources
Last reviewed October 2026. Sources were read in October 2026 unless the entry says otherwise; dates are publication or data dates. FDIC ratios were computed by us from call reports for every institution, using the FDIC's own community bank flag.
Primary sources
Regulators, statutes and regulations, court records, government statistics and SEC filings. Regulations are read in the Cornell LII copy unless the entry says otherwise. FDIC call-report ratios were computed by us from the FDIC's own data.
- 1BankFind Suite API, institution financials (call reports for 2015-12-31, 2020-12-31, 2025-12-31 and 2026-06-30). Federal Deposit Insurance Corporation, data as filed; pulled October 2026.Ratios computed by us, aggregated by the FDIC's community bank flag. Use the Quarterly Banking Profile for institution counts
- 2Jack Henry & Associates, annual report on Form 10-K, fiscal 2026. US Securities and Exchange Commission, EDGAR, filed 28 August 2026.
- 3nCino, annual report on Form 10-K, fiscal 2026. US Securities and Exchange Commission, EDGAR, filed 31 March 2026.
- 4Fidelity National Information Services (FIS), annual report on Form 10-K, fiscal 2025. US Securities and Exchange Commission, EDGAR, filed 24 February 2026.
- 5Fiserv, annual report on Form 10-K, fiscal 2025. US Securities and Exchange Commission, EDGAR, filed 19 February 2026.
- 6Occupational Outlook Handbook: tellers. US Bureau of Labor Statistics, read October 2026.
- 7Occupational Outlook Handbook: loan officers. US Bureau of Labor Statistics, read October 2026.
- 8FinCEN Year in Review, fiscal year 2025. Financial Crimes Enforcement Network, read October 2026.
- 9FinCEN Alert on nationwide surge in mail theft-related check fraud schemes (FIN-2023-Alert003). Financial Crimes Enforcement Network, 27 February 2023.
- 10FinCEN Alert on fraud schemes involving deepfake media targeting financial institutions (FIN-2024-Alert004). Financial Crimes Enforcement Network, 13 November 2024.
- 11Artificial Intelligence: use and oversight in financial services (GAO-25-107197). US Government Accountability Office, 19 May 2025.
- 12Artificial Intelligence in Financial Services. US Department of the Treasury, 19 December 2024.
- 13SR 26-2: Revised guidance on model risk management, with attachment. Board of Governors of the Federal Reserve System, with the OCC and FDIC, 17 April 2026.Scope and footnote 3 read in the attachment (SR2602a1.pdf)
- 14OCC Bulletin 2025-26: model risk management, clarification for community banks. Office of the Comptroller of the Currency, 6 October 2025.
- 15Interagency guidance on third-party relationships: risk management (88 FR 37920). Federal Reserve, FDIC and OCC, Federal Register, 9 June 2023.
- 16SR 24-2: Third-party risk management, a guide for community banks. Board of Governors of the Federal Reserve System, 7 May 2024.
- 17Proposed third-party risk management guidance, and proposed guide for traditional community banking organizations. Federal Register, 15 September 2026; comments close 16 November 2026.Community bank guide: federalregister.gov document 2026-18852
- 18OCC Bulletin 2025-16: removing references to disparate impact. Office of the Comptroller of the Currency, 14 July 2025.
- 19SR 26-5: Joint statement on SAR confidentiality and communications with customers. Board of Governors of the Federal Reserve System and other agencies, 2 September 2026.
- 20SR 26-6: FAQs on verifiable digital credentials under the customer identification program rule. Board of Governors of the Federal Reserve System and other agencies, 8 September 2026.
- 21Joint statement encouraging innovative approaches to BSA/AML compliance. Board of Governors of the Federal Reserve System and four other agencies, 3 December 2018.
- 22Speech by Vice Chair for Supervision Bowman. Board of Governors of the Federal Reserve System, 7 July 2026.
- 23Speech by Governor Waller on payments. Board of Governors of the Federal Reserve System, 28 September 2026.
- 24Deepfakes and the AI arms race in bank cybersecurity, speech by Governor Barr. Board of Governors of the Federal Reserve System, 17 April 2025.The 2,137% deepfake figure in the speech comes from an identity-verification vendor's study
- 25Industry letter: cybersecurity risks arising from artificial intelligence and strategies to combat related risks. New York State Department of Financial Services, 16 October 2024.
- 26OCC assesses $400 million civil money penalty against Citibank. Office of the Comptroller of the Currency, 7 October 2020.
- 27In re Citibank August 11, 2020 Wire Transfers, No. 21-487. US Court of Appeals for the Second Circuit, via CourtListener, 8 September 2022.We confirmed by full-text search that the opinion uses the term "six-eye"; we could not open the text
- 28Enforcement action: Goldman Sachs Bank USA (Apple Card). Consumer Financial Protection Bureau, 23 October 2024.
- 29Enforcement action: Apple Inc.. Consumer Financial Protection Bureau, 23 October 2024.
- 30OCC issues cease and desist order, assesses $450 million civil money penalty, and imposes asset restriction on TD Bank. Office of the Comptroller of the Currency, 10 October 2024.
- 31FinCEN assesses record $1.3 billion penalty against TD Bank. Financial Crimes Enforcement Network, 10 October 2024.
- 32Federal Reserve Board fines Toronto-Dominion Bank $123.5 million for violations related to anti-money laundering laws. Board of Governors of the Federal Reserve System, 10 October 2024.
- 33Enforcement action against Evolve Bancorp and Evolve Bank & Trust. Board of Governors of the Federal Reserve System, 14 June 2024.
- 34Enforcement action: Hello Digit, LLC. Consumer Financial Protection Bureau, 10 August 2022.
- 35Chatbots in consumer finance (issue spotlight). Consumer Financial Protection Bureau, 6 June 2023.
- 36Interpretive rules, policy statements and advisory opinions; withdrawal (including Circulars 2022-03 and 2023-03). Consumer Financial Protection Bureau, Federal Register, 12 May 2025.
- 3712 CFR 1002.9: notifications (Regulation B). Legal Information Institute, Cornell Law School.
- 3812 CFR 1002.12: record retention (Regulation B). Legal Information Institute, Cornell Law School.
- 3912 CFR 1005.11: procedures for resolving errors (Regulation E). Legal Information Institute, Cornell Law School.
- 4012 CFR 1026.19: certain mortgage and variable-rate transactions (Regulation Z, TRID timing). Legal Information Institute, Cornell Law School.
- 4131 CFR 1020.320: reports by banks of suspicious transactions. Legal Information Institute, Cornell Law School.
- 4231 CFR 1010.311: filing obligations for reports of transactions in currency. Legal Information Institute, Cornell Law School.
- 4331 CFR 1010.313: aggregation of multiple currency transactions. Legal Information Institute, Cornell Law School.
- 4431 CFR 1010.306: filing of reports. Legal Information Institute, Cornell Law School.
- 4512 CFR Part 364, Appendix B: Interagency guidelines establishing information security standards. Legal Information Institute, Cornell Law School.Parallel OCC and Federal Reserve appendices apply to their banks
- 4612 CFR 304.23 and 304.24: computer-security incident notification (FDIC). Legal Information Institute, Cornell Law School.Service provider duty: 12 CFR 304.24
- 4712 CFR 53.3 (OCC) and 12 CFR 225.302 (Federal Reserve): notification incident, 36 hours. Legal Information Institute, Cornell Law School.Federal Reserve text: law.cornell.edu/cfr/text/12/225.302
- 4812 U.S.C. 1867: regulation and examination of bank service companies. Legal Information Institute, Cornell Law School.
- 4942 U.S.C. 4012a: flood insurance purchase and compliance requirements. Legal Information Institute, Cornell Law School.
- 50Notice of inflation adjustments for civil money penalties. Federal Deposit Insurance Corporation, Federal Register, 14 January 2025.The most recent FDIC adjustment we found in the Federal Register
- 51Quality control standards for automated valuation models (final rule). Federal Register, 7 August 2024; effective 1 October 2025.
- 52Anti-money laundering and countering the financing of terrorism programs (proposed rules by FinCEN, and by the OCC, FDIC and NCUA). Federal Register, 10 April 2026; Federal Reserve proposal 9 July 2026.Agencies' proposal: document 2026-06948; Federal Reserve: document 2026-13919
- 53SB26-189: consumer protections for automated decision-making technology. Colorado General Assembly, signed 14 May 2026.Read on the bill page; the signed text refused access
- 54Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI). Official Journal of the European Union, via EUR-Lex, 8 July 2026.
- 55EU AI Act, Annex III: high-risk AI systems. artificialintelligenceact.eu (unofficial copy).
- 56Declaratory ruling: AI-generated voices are artificial voices under the TCPA. Federal Communications Commission, 8 February 2024.
Industry bodies and independent research
State supervisors' survey of community bankers, a banking consultancy's executive survey, and the community bankers' trade association.
- 572025 CSBS Annual Survey of Community Banks (n=268, fielded April to July 2025). Conference of State Bank Supervisors, 2025.Self-selected sample; banker quotes are opinions
- 58What's Going On in Banking 2026 (n=416 executives at $250 million to $50 billion institutions). Cornerstone Advisors, 2026.Consultancy sample; "deployed" is not defined on the public page
Vendor sources
Published by companies that sell AI to banks. Directional, not an industry benchmark.
- 59AI-native operations for back-office workflows (formerly Greenlite). Bretton AI, read October 2026.Vendor source
- 60
Company and press
News coverage and encyclopedia summaries, used for funding rounds, the Synapse collapse and cases where no primary text was reachable.
- 61Interface.ai raises $30M to help banks field customer requests. TechCrunch, 22 October 2024.
- 62Fintech Alloy raises to fight fraud at a $1.55B valuation. TechCrunch, 1 September 2022.
- 63Hummingbird lands $30 million to bring design thinking to anti-money laundering investigations. TechCrunch, 7 December 2021.
- 64Nymbus lands $70M to help banks digitally transform. TechCrunch, 25 May 2023.
- 65Synapse's collapse has frozen nearly $160M from fintech users. TechCrunch, 22 August 2024.
- 66Evolve Bank says ransomware gang stole personal data on millions of customers. TechCrunch, 9 July 2024.
- 67Brigade Capital (section on the Citibank Revlon payment). Wikipedia, read October 2026.
- 68Earnest (company). Wikipedia, read October 2026.Secondary; the Massachusetts Attorney General's release refused access
- 69Arup Group (2024 deepfake fraud). Wikipedia, read October 2026.