Why Banks and Regulators Are Rethinking AI Governance From the Ground Up
Financial institutions are discovering that AI governance cannot be bolted on after the fact; it must be woven into the architecture of AI systems from inception. This insight emerged from the 2026 New York Fed Innovation Conference, where regulators, banks, and fintech leaders gathered to discuss how to responsibly scale artificial intelligence across the financial system while maintaining human oversight and institutional trust.
What Does AI Governance Actually Mean in Finance?
The term "governance" in the context of AI has evolved beyond traditional compliance frameworks. At the conference, speakers defined it as the processes, standards, and frameworks needed to ensure AI systems operate ethically, responsibly, and securely. But the definition carries a critical caveat: governance demands more nuanced and comprehensive oversight than any technology that came before it.
Closely related to governance is what conference speakers called "coherence," a concept that ties together operating models, governance structures, risk frameworks, and human judgment. The goal is to create AI capabilities that institutions can trust enough to move from experimental pilots into wider, production-level adoption. Without coherence, even well-intentioned governance frameworks fall apart under real-world pressure.
"The real question for us is how can we make this acceleration responsible, the governance scalable, and human judgment more integrated, not less integrated, as this technology becomes more powerful?" said Leigh-Ann Russell, chief information officer and global head of engineering at Bank of New York Mellon.
Leigh-Ann Russell, Chief Information Officer and Global Head of Engineering at Bank of New York Mellon
Why Are Traditional Risk Frameworks Failing?
AI systems introduce entirely new categories of risks, threats, and potential fragility that traditional financial risk models were never designed to handle. The pace of AI adoption has outstripped the ability of legacy risk frameworks to keep up, creating a dangerous gap between technological capability and institutional readiness.
This challenge is compounded by the fact that large language models (LLMs), which are AI systems trained on vast amounts of text data to understand and generate human language, have developed rapidly outside any formal legal or regulatory framework. Across industries, participants at the conference agreed that coordinated regulations are urgently needed to strengthen safeguards while still encouraging responsible AI adoption.
How to Build AI Governance Into Your Institution
Based on insights from financial leaders and regulators, several core principles emerged for embedding governance into AI systems:
- Observability and Transparency: Implement audit trails and logging mechanisms that create a complete record of how AI systems make decisions, what data they use, and when they change behavior. This allows institutions to trace problems back to their source.
- Human Accountability Integration: Design AI systems as partners or "digital employees" that augment human judgment rather than replace it. Governance models must clearly define where human decision-makers remain responsible and where AI provides recommendations.
- Architecture-First Approach: Embed governance requirements into system design from the beginning rather than retrofitting compliance measures after deployment. This prevents costly redesigns and security vulnerabilities.
- Defensive Evolution: Develop defensive strategies and threat models that evolve in parallel with AI capabilities, recognizing that new technologies create new attack surfaces and failure modes.
The conference emphasized that AI adoption increases institutional capacity but does not eliminate the need for human judgment. Some firms have begun thinking of AI as a "partner" or "digital employee," an approach that requires governance models integrating human accountability at critical decision points.
What Role Will Regulation Play?
Industry participants acknowledged that regulation, when thoughtfully designed, can actually encourage safer incorporation of AI into daily workflows. Rather than viewing regulation as purely restrictive, speakers framed it as a backstop that protects institutions if something goes wrong and creates a level playing field across competitors.
The challenge lies in coordinating these regulations across different nations and jurisdictions. Different legal frameworks create friction for institutions operating globally, making international coordination essential. The conference highlighted that technical capability, oversight, and operational coordination are advancing at different rates across global financial systems, creating both opportunities and risks.
Looking ahead, stakeholders see public-private partnerships as a foundational element that could shape long-term outcomes. These partnerships would allow regulators to understand emerging risks while giving industry input into practical, implementable standards. The goal is to align around shared principles before fragmented regulations create costly compliance burdens.