top of page

Innovation at Risk: AI Banking Regulation Must Not Leave Community Banks Behind

  • Writer: SC Undergraduate Law Journal
    SC Undergraduate Law Journal
  • Jul 29
  • 6 min read

Writer: Somers Kirk

Editors: Andrew Lehnhardt, Steven Carredano Mendez


Abstract

This blog argues that federal AI banking regulations should protect consumers without imposing uniform compliance burdens on community banks and credit unions. While existing laws such as the Gramm-Leach-Bliley Act and fair lending rules already address some risks, AI creates new gaps involving data inference, vendor oversight, and institutional capacity. Rather than adopting a sweeping federal AI statute modeled around large banks, regulators should pursue targeted reform: modernized privacy disclosures, clearer AI vendor contract standards, and tiered compliance duties based on institutional size and risk. This approach would protect customer information while allowing smaller financial institutions to adopt useful technology responsibly.


I. Introduction


Artificial intelligence no longer counts as a distant banking issue. Banks already use AI to flag fraud, evaluate loans, answer customer questions, manage risk, and process large amounts  of financial data.1 These uses can make banking faster and more efficient, but they also place sensitive customer information inside systems that many consumers do not see or understand. That risk became concrete in May 2026, when CB Financial Services disclosed that nonpublic customer information had been handled through an unauthorized AI-based software application.2 That filing identified the exposed data as customer names, Social Security numbers, and dates of birth.3 This incident did not involve a dramatic cyberattack or a failed lending algorithm; it involved a data-handling failure tied to new technology. For some lawmakers, incidents like this  support broad federal AI regulation for banking. Consumers deserve protection when banks use automated systems and outside technology vendors, but a sweeping federal AI statute could also create a second problem: rules designed around the largest banks may overwhelm community banks and credit unions. Federal AI banking reform should address the risks created by customer data use and outside technology vendors while avoiding a uniform compliance structure that treats community banks like national banks. 




II. Existing Law Already Does Some Work, but AI Creates New Gaps



AI risk in banking extends beyond the algorithm itself. In lending, regulators have  already warned that creditors using AI or complex models must still give specific and accurate reasons when denying credit.4 Calling a tool “AI” does not create an exception to existing consumer protection law.5 Privacy law also matters. Gramm-Leach-Bliley Act (GLBA) provisions require covered financial institutions to tell customers about certain information sharing practices and, in some circumstances, provide opt-out rights.6

The Safeguards Rule also requires reasonable administrative and technical protections for customer information.7 These requirements show that current law already carries real substance. Still, AI exposes gaps in that older framework. GLBA was written around a more traditional idea of information sharing: a bank gives customer information to a third party, then provides notice or an opt-out right. AI does not always work that simply. GLBA may regulate disclosure of customer information, but AI can transform existing information into new risk profiles without a customer ever realizing that a new form of sensitive information has effectively been created. A customer may know that a bank has transaction history without realizing that the same data could generate behavioral or credit-related risk predictions. Reform  should begin there.

Banks should explain, in plain language, when customer data feeds AI systems that meaningfully affect important financial decisions or generate new conclusions about the customer. Privacy notices require modernization for AI-driven inference, not expansion into unreadable consent forms for every ordinary fraud-detection tool. 



III. Vendor Oversight as the Practical Pressure Point


For many institutions, the most realistic AI risk will not come from a model built inside the bank. It will come from a third-party vendor. Federal banking regulators have already made clear that using a third party does not reduce a bank’s responsibility to operate safely and comply  with law.8 Their 2023 interagency guidance also states that third-party oversight should match the bank’s size, risk profile, and the nature of the vendor relationship.9 That principle should apply directly to AI tools. AI vendor contracts should specify whether customer data may be retained after service ends, whether that data may be used to train future models, who may access the data, and how quickly the bank must be notified after an incident. Treasury Department analysis has recognized that financial firms may depend heavily on externally developed AI tools and that these relationships can create privacy and incident response risks.10

A stronger vendor framework would address a likely source of harm without  forcing every small bank to become its own technology company. Not every AI use requires a new federal bureaucracy, but the need for clearer internal controls, employee training, and enforceable vendor rules remains evident. Governance problems come first, and targeted supervisory guidance can address them more directly than a broad, one-size-fits-all statute. 



IV. Community Banks Differ from Wall Street Banks


Any AI regulation must recognize that banks differ sharply in capacity. Large national banks have compliance departments and cybersecurity teams, plus technical staff that can absorb complicated new mandates. If federal law requires model audits, algorithmic impact assessments, plus specialized testing, large banks may object, but many can comply. Community  banks and credit unions operate differently. They often rely on vendors because they cannot build advanced AI systems internally. They also play a distinct role in local economies. FDIC research reported that community banks held only 12 percent of banking industry assets in 2019, but 36 percent of small business loans and a much larger share of agricultural lending.11

If  regulation causes those institutions to delay technology adoption or exit certain services, local  borrowers bear the cost. For states with rural communities and relationship-based lending markets, such as South Carolina, that cost would not remain inside the banking industry; it would reach small businesses, farmers, and local borrowers. Compliance costs already fall unevenly. A Federal Reserve Bank of St. Louis analysis found that banks under $100 million in assets spent 8.7 percent of noninterest expenses on compliance, compared with 2.9 percent for banks between $1 billion and $10 billion.12 More recent CSBS research similarly concludes that smaller community banks consistently devote a higher share of resources to compliance.13 New legal duties become staff time, consultant fees, and legal review. For a small institution, those costs can determine whether a tool gets adopted at all. 



V. A Better Model: Targeted and Tiered Reform 


The European Union (EU) AI Act offers a useful warning. Its risk-based structure treats certain creditworthiness and credit-scoring systems as high-risk, showing how financial AI can trigger heightened legal duties. That instinct is reasonable, but scale matters. United States regulators should borrow the EU AI Act’s risk-tiering concept without importing a compliance heavy model that smaller institutions cannot realistically manage. A more workable approach would tie legal duties to actual institutional risk. Regulators should ask whether a bank can map its AI uses, supervise outside vendors, explain consequential automated decisions, and respond quickly when customer data is mishandled. Modernized GLBA disclosures, clearer AI vendor  standards, and scaled compliance obligations would protect consumers without treating a local lender like a national bank. 



VI. Conclusion


Each month that banks adopt new tools without clearer guardrails shifts risk onto  customers least able to see it coming. Sensible reform should draw one firm line: when financial institutions profit from powerful automated systems, accountability must travel with the data. That standard would move banking law beyond panic over new technology and toward  accountability customers can recognize.


  1. “Artificial Intelligence in Financial Services.” U.S. Department of the Treasury, December 2024.

    https://home.treasury.gov/system/files/136/Artificial-Intelligence-in-Financial-Services.pdf.

  2. “CB Fin. Servs., Inc., Current Report (Form 8-K) (May 7, 2026).” United States Securities and Exchange Commission, May 7, 2026. https://www.sec.gov/Archives/edgar/data/1605301/000160530126000021/cbfv-20260507.htm.

  3. Id.

  4. “CFPB Issues Guidance on Credit Denials by Lenders Using Artificial Intelligence.” Consumer Financial Protection Bureau, September 19, 2023. https://www.consumerfinance.gov/archive/newsroom/cfpb-issues-guidance-on-credit-denials-by-lenders-using-artificial-intelligence/.

  5.  Id.

  6. “Gramm-Leach-Bliley Act.” Federal Trade Commission. Accessed July 6, 2026. https://www.ftc.gov/legal-library/browse/statutes/gramm-leach-bliley-act.

  7. “16 CFR Part 314: Standards for Safeguarding Customer Information.” Federal Trade Commission. Accessed July 6, 2026. https://www.ecfr.gov/current/title-16/chapterI/subchapter-C/part-314.

  8. “Interagency Guidance on Third-Party Relationships: Risk Management.” Federal Register, June 6, 2023.

    https://www.federalregister.gov/documents/2023/06/09/2023-12340/interagency-guidance-on-third-party-relationships-risk-management.

  9.  Id.

  10. “Artificial Intelligence in Financial Services.” U.S. Department of the Treasury, December 2024.

    https://home.treasury.gov/system/files/136/Artificial-Intelligence-in-Financial-Services.pdf.

  11. “FDIC Community Banking Study.” Federal Deposit Insurance Corporation, December 2020.

    https://www.fdic.gov/resources/community-banking/report/2020/2020-cbi-study-full.pdf.

  12. Dahl, Drew, Andrew P. Meyer, and Michelle Clark Neely. “Scale Matters: Community Banks and Compliance Costs.” Federal Reserve Bank of St. Louis, July 14, 2016. https://www.stlouisfed.org/publications/regional-economist/july-2016/scale-matters-community-banks-and-compliance-costs.

  13. Siems, Thomas F., and Nathan Ross. “Too Small to Scale: What 10 Years of Data Say About Community Bank Compliance Costs.” Conference of State Bank Supervisors, November 13, 2025. https://www.csbs.org/too-small-scale-what-10-years-data-say-about-community-bank-compliance-costs.

Uof SC
ULJ

  • Instagram
  • LinkedIn

Although this organization has members who are University of South Carolina students and may have University employees associated or engaged in its activities and affairs, the organization is not a part of or an agency of the University. It is a separate and independent organization, which is responsible for and manages its own activities and affairs. The University nor Law School directs, supervises or controls the organization and is not responsible for the organization’s contracts, acts or omissions. For any questions or business inquiries, please reach out to us at ulj.uofsc@gmail.com.

bottom of page