AI governance in financial services is evolving from a compliance burden to a business imperative, with regulators now focusing on whether controls work in practice rather than just existing on paper. The rapid pace, volume, and complexity introduced by AI challenge traditional compliance models, which were not designed to handle continuous and automated decision-making. This shift demands continuous assurance, where controls operate in real-time, adapt to changing conditions, and provide verifiable evidence under scrutiny, emphasizing resilience as a fundamental requirement.

The rise of "shadow AI"—unapproved generative AI tools used by employees—highlights the widespread and hard-to-detect risks. Regulators, such as FINRA, have clarified that existing rules apply to generative AI, requiring firms to supervise and retain records irrespective of how communications are generated. This indicates that firms cannot wait for new regulations and must instead integrate data, oversight, and accountability from the outset, moving beyond just building policies that might not hold under real conditions.

Regulatory scrutiny is increasingly centered on accountability, with questions not just about risk identification but about who is responsible for managing them. Andrew Mount, Counsel at Eversheds Sutherland, notes that regulators are inquiring about the existence of governance, documentation, and supervisory controls around AI tools. Fragmentation in oversight can lead to significant liabilities, as gaps in coordination become areas where risk accumulates.

While some financial firms view AI governance as a future problem, others are actively redesigning their systems to integrate it. Supervisors must balance a narrow technology governance perspective with a broader resilience perspective, acknowledging that model risk management guidelines, originally designed for transparent statistical models, need adjustment for the complexities of advanced AI like large language models. This includes re-evaluating governance, validation, and independent review expectations, recognizing potential trade-offs between explainability and performance, provided risks are properly managed.

Ultimately, supervision in the age of AI extends beyond merely overseeing banks' AI usage. It also involves ensuring the resilience of banks and the broader financial system within an AI-shaped economy. This encompasses operational resilience, given the compressed timeframes for responding to disruptions, and strategic resilience, as technology reshapes industries, borrowers, and business models over time. This holistic view is crucial for safeguarding financial stability and market integrity.