Industry surveys published in the first half of 2026, including the WealthTech adoption survey reported in early May, put the share of advisor firms using at least one production artificial intelligence tool at approximately 98 per cent. The figure includes large wirehouses, independent broker-dealers, registered investment advisers and the wealth management arms of the principal commercial banks. The figure does not include the many internal artificial intelligence applications used by the same firms in back-office, compliance and risk functions. The institutional reading is that artificial intelligence has now reached the saturation point in financial advice as a category, and that the question is no longer whether to adopt but how to govern.
The governance question, in the United States banking context, runs through Federal Reserve Supervision and Regulation Letter 11-7 on model risk management, as supplemented by the Office of the Comptroller of the Currency Bulletin 2011-12 and the Federal Deposit Insurance Corporation Financial Institution Letter 22-2017. In the Canadian context, the question runs through Office of the Superintendent of Financial Institutions Guideline E-23 on model risk management for federally regulated financial institutions, updated in 2024 to address artificial intelligence and machine learning specifically. In the European context, the question runs through the European Banking Authority guidelines on internal governance and the European Union Artificial Intelligence Act. In each case, the regulatory expectation is that a model, defined broadly to include any quantitative method that produces a numerical output used in decision-making, must be subject to independent validation, ongoing monitoring, documented governance of change and clear executive accountability.
The difficulty is that the model-risk management functions at the major financial institutions were sized, staffed and processed-designed for a population of models drawn from credit scoring, market risk, asset-liability management, capital calculation and a handful of other established applications. The population was measured in the hundreds at a large bank and in the low thousands at the very largest. The artificial intelligence adoption of the past three years has increased the model population by approximately one order of magnitude at most large institutions. The model-risk management function has not increased its capacity by anywhere near the same factor. The resulting backlog is now a quantitative supervisory question.
A representative large institution disclosed at an industry conference in March 2026 that its model-risk inventory had grown from approximately 1,200 models in 2022 to approximately 11,000 in early 2026, with the increase concentrated in machine learning and generative artificial intelligence applications. The institution's model validation function had grown over the same period from approximately 80 to approximately 140 staff. The implied per-validator workload had increased by a factor of approximately five. The institution had introduced tiered validation, automated documentation generation and risk-based scheduling, but acknowledged that the tier-three population of lower-risk models was experiencing validation cycle times of more than eighteen months. The acknowledgement, which the supervisor required to be on the record, is illustrative of the broader industry condition.
The supervisory response has been firm but constructive. The Federal Reserve and the Office of the Comptroller of the Currency have, through a series of supervisory letters and informal guidance throughout 2025 and the first half of 2026, made clear that the existing model risk management framework remains the operative standard and that the introduction of artificial intelligence does not, in itself, justify a relaxation of the validation expectation. The supervisors have, however, indicated openness to risk-based prioritisation, to the use of artificial intelligence within the validation function itself, and to the development of additional industry-wide guidance to support the application of the existing framework to the new model population.
The institutional implications begin with the inventory. An institution that does not have a complete, current and accurate inventory of its artificial intelligence applications cannot manage the model risk arising from them. The institutional reading is that the inventory exercise is, in practice, more difficult than it appears. Artificial intelligence is increasingly embedded in commercial software, in third-party services and in workflow tools that the model-risk management function has historically not regarded as in scope. A reliable inventory requires coordination across procurement, information technology, business lines and the model-risk management function itself, with named accountability for each category of artificial intelligence application.
The second implication concerns the validation methodology. Traditional model validation relies on a combination of conceptual review, data and assumption testing, outcomes analysis and ongoing monitoring. Each of these components must be adapted for artificial intelligence applications, particularly for generative models whose outputs are not directly numerical and whose behaviour can drift in ways that traditional outcomes analysis does not capture. The institutional reading is that validation methodologies for artificial intelligence are still maturing, with substantial work being done by the principal industry consortia and by the supervisors themselves.
The third implication concerns the use of artificial intelligence within the validation function. A number of the largest institutions have begun to use artificial intelligence to assist with documentation generation, with data and assumption testing, and with ongoing monitoring. The use is itself a model risk management question, and the supervisors have made clear that the application of artificial intelligence to the validation function is subject to the same standards as its application elsewhere. The institutional reading is that the productivity gains available from this approach are real but bounded, and that the principal constraint on the capacity of the validation function remains the availability of skilled validators with both quantitative and domain expertise.
The fourth implication concerns the staffing of the model-risk management function. The traditional model-risk management profile combines quantitative training, financial domain expertise and supervisory awareness. The expanded model population requires additional expertise in machine learning, natural language processing and software engineering. The labour market for this combined profile is tight, and several of the largest institutions have published growth targets for the function that exceed the available recruitment in any reasonable time horizon. The institutional reading is that the staffing question will, for most institutions, be solved through a combination of recruitment, training of existing staff and selective outsourcing to specialised providers, with each component subject to its own constraints.
The fifth implication concerns the role of the third line of defence. Internal audit is responsible for independent assurance over the model-risk management function itself. The expanded model population, the maturing validation methodologies and the use of artificial intelligence within the function all increase the demands on internal audit. The institutional reading is that internal audit functions at the major institutions are themselves investing in artificial intelligence expertise, and that the principal supervisors expect to see evidence of this investment in the audit committee reports they receive.
The sixth implication concerns the documentation. Regulatory expectations on model documentation predate the artificial intelligence transition by several decades. The expectations have not been relaxed, and in some respects have been strengthened, by the introduction of artificial intelligence. The institutional reading is that documentation generation is one of the most acute productivity constraints in the validation function, and that the use of artificial intelligence to assist with documentation, subject to appropriate validation and review, is among the most defensible productivity investments available.
The seventh implication concerns the integration with broader risk management. Model risk is one component of operational risk under the Basel framework, with capital implications that flow through the standardised measurement approach. The expanded model population implies an expansion of the operational risk profile that, depending on the institution's loss experience and the supervisor's calibration, may flow through to higher capital requirements. The institutional reading is that the link between model population, model risk and operational risk capital is becoming an explicit supervisory dialogue at the major institutions.
The eighth implication concerns the strategic posture. An institution that treats the artificial intelligence model risk question as a compliance burden is likely to under-invest, to fall further behind its peers in capability terms and to attract increasing supervisory attention. An institution that treats the question as a strategic investment in operational quality is likely to over-invest, to gain a relative competitive advantage and to attract favourable supervisory attention. The choice between the two postures is among the most consequential strategic decisions facing financial institutions in 2026.
The ninth implication concerns the smaller institutions. Community banks, credit unions and smaller broker-dealers face the same model risk management expectations as the largest institutions, scaled to their size and complexity. The institutional reading is that the proportionality principle applies but that the absolute capability requirements are significant, and that smaller institutions are increasingly relying on shared infrastructure, industry utilities and specialised third-party providers to meet the expectations. The supervisors have indicated openness to this approach subject to documented oversight of the third-party arrangements.
The tenth implication concerns the European context. The European Union Artificial Intelligence Act, applicable in stages through 2026 and 2027, introduces additional governance, transparency and oversight requirements for high-risk artificial intelligence systems, which include many of the applications used by financial institutions. The institutional reading is that institutions operating in the European Union must address both the model risk management framework and the Artificial Intelligence Act in parallel, with overlap and gap that must be deliberately documented and managed. The European Banking Authority and the European Securities and Markets Authority have published joint guidance on the overlap, with further detail expected in the second half of 2026.
The Cabier Consulting institutional brief Governance Above the Rail addresses the model risk question for embedded artificial intelligence applications in its Cluster B treatment, including the practical implications of SR 11-7, OSFI E-23 and the European Union Artificial Intelligence Act. The brief recommends that the model-risk management function be elevated to a strategic capability with board-level accountability, and that the capacity question be addressed through a documented multi-year investment plan rather than as a series of project commitments.
Readers responsible for institutional implementation are directed to the FinanceTrackerIQ model-risk inventory dashboard, the CALCULATORiQ operational risk capital workbench and the institutional reading list maintained by Cabier Consulting.
Board questions to ask now.
Has the management body received, within the last six months, a quantitative report on the institution's model inventory, the validation cycle times by tier and the resulting backlog by risk category? Has the audit committee received independent assurance over the adequacy of the model-risk management function for the expanded artificial intelligence population? Has the institution documented its strategic posture on model risk management for artificial intelligence and aligned its multi-year investment plan accordingly?
Operating model implications.
The model-risk management function must be reorganised to address the expanded model population, with named accountability for inventory completeness, validation methodology, capacity planning and supervisory dialogue. The function must be resourced for sustained growth rather than episodic remediation, because the underlying model population will continue to grow for the foreseeable future. The reliance on external providers and shared industry infrastructure must be deliberately chosen and documented, with oversight equivalent to that applied to internal capability.
Twelve-month implementation plan.
In the first quarter, complete the inventory of artificial intelligence applications across the institution, with named accountability for each category. In the second quarter, refresh the validation methodology to address the expanded model population, with documented tiers and risk-based scheduling. In the third quarter, present the resulting capacity plan and resource implications to the board, and align the investment plan to the chosen strategic posture. In the fourth quarter, complete the integration of the model-risk management framework with the broader operational risk and governance frameworks, with documented evidence for supervisory review.
Cabier Consulting's 2026 institutional brief, Governance Above the Rail, sets the architectural context within which this question is best understood. Reciprocal reading at https://cabierconsulting.com/insights/governance-above-the-rail-2026 is recommended for institutions building their model-risk management capability for the artificial intelligence era.
