NEWJoin 2M+ software buyers|Get Weekly Insights, Trends & Expert PicksSubscribe free →

AI Software

AI in Banking (2026): 8 Use Cases, Controls and Where to Start

Rajat Gupta

Written by

Rajat Gupta

Published September 13, 2026

Updated September 28, 2026

The short answer: banks use AI most in fraud detection, anti-money laundering (AML) alert triage, customer onboarding and KYC, credit decisioning, customer service assistants, relationship manager copilots, collections and back-office document processing. The mature uses, fraud and AML, rely on machine learning models that have run for years; generative AI is newer and is mostly deployed internally first, helping staff search policies, summarise cases and draft communications. In every case, model risk management, fair lending and explainability rules apply, so banks that succeed treat governance as part of the build, not an afterthought.

This guide is for bank and credit union leaders in operations, risk, compliance, lending, digital and IT. Tool names are examples of each category, not endorsements. Most banking AI is sold by quote, often priced by transaction volume, accounts, users or assets, so check each vendor’s current pricing directly.

AI use cases in banking at a glance

Use case What the AI does Tool examples Effort Payback signal
Payments and card fraud detection Scores every transaction and login in real time for fraud and account takeover Feedzai, NICE Actimize, SAS High: real-time data, model validation Fraud losses, false positive rate, customer friction
AML alert triage and investigations Prioritises monitoring alerts, links related entities and drafts case narratives Hawk AI, Quantexa, NICE Actimize High Alerts closed per investigator, time per case, quality findings
Onboarding, KYC and screening Verifies ID documents, extracts ownership data, screens against sanctions and PEP lists ComplyAdvantage, identity verification tools Medium Time to open an account, abandonment, manual review rate
Credit decisioning Predicts default risk using bureau and cash-flow data; automates decisions within policy Zest AI, loan origination platforms High: fair lending and model validation Approval rate at the same loss rate, time to decision
Lending document processing Reads bank statements, pay stubs, tax returns and financial statements Ocrolus, document AI platforms Medium Underwriter hours per file, time to close
Customer service assistants Answers balance, transaction, card and dispute questions in app, chat and voice Kasisto, interface.ai, in-house assistants Medium: authentication and core integration Contained conversations, CSAT, cost per contact
Relationship manager and staff copilots Summarises client history, prepares meetings, answers policy and product questions Enterprise AI assistants, CRM AI features Low to medium Prep time per meeting, time to answer policy questions
Collections Prioritises accounts and recommends contact timing and channel Collections platforms with ML scoring Medium Roll rates, cure rates, complaints

How can AI be used in banking?

1. Fraud detection

The job: stop card fraud, account takeover and authorised push payment scams in real time without blocking good customers.

  • Input: transaction details, device and login signals, customer behaviour history, merchant and payee data.
  • AI step: machine learning models score each event in milliseconds against the customer’s normal behaviour and known fraud patterns; rules and scores decide whether to approve, step up authentication or hold.
  • Human review: fraud analysts work queues of held payments and alerts, and tune rules and thresholds.
  • Output: blocked fraud, step-up challenges and customer notifications.

What it needs: real-time data from cards, payments and digital banking channels, labelled fraud outcomes to train on, and integration with the payment flow. Examples include Feedzai, NICE Actimize and SAS. Compare tools in fraud protection software. Measure it by: fraud losses in basis points of volume, false positive rate (good transactions declined) and customer complaints about blocks. Risks: fraud patterns change quickly, so models need monitoring and frequent retraining.

2. AML alert triage and investigations

The job: transaction monitoring systems generate large volumes of alerts, most of which turn out not to be suspicious. Investigators spend their time clearing noise.

  • Input: monitoring alerts, customer due diligence data, transaction history and external data.
  • AI step: models score alerts by likelihood of being suspicious; entity resolution links accounts, people and companies into networks (Quantexa is known for this); generative AI drafts a case summary and a first version of the narrative.
  • Human review: investigators review every case and decide whether to file a suspicious activity report. The decision and the filing stay with people.
  • Output: prioritised queues, better-documented cases and faster closure of low-risk alerts.

Examples include Hawk AI, Quantexa and NICE Actimize; see anti-money laundering software. Measure it by: alerts handled per investigator, time per case, and quality assurance findings on closed cases. Risks: regulators expect you to show that deprioritised alerts are not hiding real risk. Validate the model, sample closed alerts and keep the audit trail.

3. Onboarding, KYC and sanctions screening

AI checks identity documents and selfies for tampering, extracts beneficial ownership from company documents for business accounts, and screens names against sanctions, politically exposed persons and adverse media lists, using fuzzy matching to cut false hits. Analysts review potential matches and higher-risk customers. It needs integration with the onboarding flow and the core banking system. ComplyAdvantage is one example of an AI-driven screening provider. Measure time to open an account, application abandonment and the share of applications needing manual review. The risk is a missed true match, so tune thresholds with compliance and test regularly.

4. Credit decisioning

The job: approve more creditworthy applicants, especially thin-file borrowers, without raising losses, and decide faster.

  • Input: application data, credit bureau data and, with consent, bank transaction data for cash-flow underwriting.
  • AI step: machine learning models estimate default risk, and the decision engine approves, declines or refers within credit policy.
  • Human review: underwriters handle referrals and exceptions; model risk and fair lending teams validate the model before use and monitor it after.
  • Output: a decision with the principal reasons recorded, ready for adverse action notices.

Zest AI is a known example of ML underwriting for banks and credit unions. The rules here are strict. In the US, the Equal Credit Opportunity Act and Regulation B require specific reasons when credit is denied, and the Consumer Financial Protection Bureau said in Circular 2022-03 that this applies even when a complex algorithm makes the decision. In the EU, the AI Act treats AI used to evaluate the creditworthiness of individuals as high risk. Measure approval rate at a constant loss rate, time to decision and fair lending test results. See loan origination software and loan servicing software.

5. Lending and operations document processing

Loan files, business account openings, trade finance and disputes all involve reading documents. Document AI extracts data from bank statements, pay stubs, tax returns and financial statements, flags signs of document tampering, and spreads financials into the bank’s templates. Underwriters and operations staff verify flagged fields. Ocrolus is an example focused on lending documents. Measure underwriter hours per file, time to close and error rates found in QA. See OCR software and document management software.

6. Customer service assistants

Virtual assistants in the app, chat and phone answer balance and transaction questions, freeze cards, explain fees, start disputes and route complex issues to agents with context. Large banks have built their own; Bank of America’s Erica is a widely known example. Specialist vendors such as Kasisto and interface.ai serve banks and credit unions. They need secure authentication, access to core banking and card systems, and careful scope: the assistant should not give financial advice or make promises about disputes. Measure the share of conversations resolved without an agent, CSAT and cost per contact. See AI customer support agents, AI voice agents and our guide to AI chatbots for business.

7. Relationship manager and staff copilots

This is where most banks start with generative AI, because it stays internal. Copilots summarise a client’s accounts, recent interactions and news before a meeting, draft follow-up emails, and answer staff questions from policy manuals, product guides and procedures with citations. Staff check every output before it reaches a customer, and communications with clients still go through required compliance review. Measure preparation time per meeting and time to answer policy questions. Pair it with your CRM; see our guide to CRM for banking and speech analytics for call review.

8. Collections

Models predict which delinquent accounts are likely to cure on their own, which need early contact, and which channel and time work best, and AI can draft personalised, compliant messages. Collectors handle hardship conversations and payment plans. In the US, the Fair Debt Collection Practices Act and Regulation F limit contact frequency and content, so rules must be built into the tool. Measure roll rates, cure rates and complaints.

Model risk and compliance requirements

  • Model risk management: in the US, supervisory guidance SR 11-7 from the Federal Reserve (issued with the OCC) sets expectations for model development, validation and governance, and banks generally apply it to AI and machine learning models, including vendor models.
  • Third-party risk: US banking regulators’ interagency guidance on third-party relationships applies to AI vendors. Due diligence, contract terms and ongoing monitoring are required.
  • Fair lending and adverse action: ECOA, Regulation B and fair lending testing for any model touching credit.
  • Explainability: be able to explain decisions to customers, examiners and auditors.
  • Data use and training: ask vendors whether customer data trains models used for other institutions, and get the vendor’s policy in the contract. Many banks require it does not.
  • Privacy and security: GLBA in the US, GDPR in Europe, PCI DSS for card data, and in the EU the Digital Operational Resilience Act (DORA) for ICT and third-party risk.
  • Data residency: where data is stored and processed, including where a model provider runs inference.
  • Access and audit: SSO, SCIM provisioning, role-based access and full audit logs of prompts, outputs and human decisions for generative AI tools.
  • Certifications: SOC 2 Type II and ISO 27001 as the vendor states them.

For tooling, see AI governance software.

Where should a bank start with AI?

  1. Build governance first: an AI use policy, an inventory of models and AI tools, and a review path through model risk, compliance and security.
  2. Start internal with generative AI: a staff assistant over policies and procedures, or case summaries for investigators. Customer exposure is low and value is quick to see.
  3. Improve existing ML use cases: if fraud or AML models are rules-heavy, pilot ML alert scoring alongside current systems before switching.
  4. Move to customer-facing and credit use cases once validation, fair lending testing and monitoring are routine.
  5. Run pilots in parallel with existing processes for at least one full cycle, and compare outcomes.

For community banks and credit unions, the most practical path is often AI features from existing vendors (core, digital banking, fraud and loan origination providers) instead of building models in-house. Compare digital banking platforms with that in mind.

How to measure AI ROI in banking

Separate three kinds of value. Loss avoidance: fraud and credit losses avoided against a control or champion model. Efficiency: hours saved per alert, case, file or contact x volume x loaded cost. Revenue: extra approvals at the same risk level x average balance x margin. Subtract licences, data, integration, validation and monitoring costs; model governance is a real, recurring cost in banking. Use champion and challenger testing wherever possible, since banks already have the discipline for it.

Risks and failure modes

  • Bias and fair lending violations from proxy variables in credit or marketing models.
  • Unexplainable decisions that cannot support adverse action notices or examiner questions.
  • Hallucinated answers from generative assistants on fees, rates or policies.
  • Data leakage through staff pasting customer data into unapproved AI tools. Provide an approved tool and block others.
  • Model drift as fraud patterns and economic conditions change.
  • Vendor concentration: reliance on a small number of model providers is a resilience issue regulators are watching.

Which banks are leading in AI?

Large banks such as JPMorgan Chase, Capital One and RBC speak publicly about their AI programmes and talent investment, and the Evident AI Index publishes a ranking of large banks’ AI maturity based on public information; check its latest edition for the current order. For most mid-sized banks and credit unions, the better benchmark is peers of similar size using the same core and fraud vendors.

Is AI going to take over banking?

No. AI is taking over high-volume analysis and routine service: scoring transactions, clearing low-risk alerts, reading documents and answering simple questions. Banking decisions carry legal accountability, so regulators expect people to own credit, compliance and customer outcomes. Roles are shifting toward investigation, relationship management, model oversight and data work. The bigger competitive risk is banks that move too slowly while peers cut costs and improve service.

How to choose an AI tool for banking

  • Start with use cases your existing vendors already support; integration with core systems is the hardest part.
  • Ask for model documentation that your model risk team can validate.
  • Check references at institutions of similar size and regulator.
  • Confirm data residency, training terms and exit rights in the contract.
  • Price at full volume, including validation and monitoring effort.

Related reading: AI sales tools for commercial banking teams, and our workflow automation software guide for operations teams.

More on enterprise AI: for other industries, see our guides to AI in manufacturing, retail, real estate, construction and insurance. For the cross-functional view, read enterprise AI use cases by function and how to implement AI in business. Related guides: AI in finance, intelligent document processing, AI customer service, AI voice agents and AI governance tools.

Frequently asked questions

What is the most common use of AI in banking?

Fraud detection. Banks have used machine learning to score card and payment transactions for years, and it remains the most established AI use case in the industry.

Is banking at risk from AI?

Banks face two risks: criminals using AI for scams and deepfake fraud, and falling behind peers that use AI to cut costs and improve service. The response is better fraud controls and a governed AI programme, not avoiding AI.

Can banks use AI to make credit decisions?

Yes, within fair lending and model risk rules. In the US, lenders must still give specific reasons for denials under ECOA and Regulation B, and the CFPB has said complex models are no exception.

How do banks use generative AI?

Mostly internally first: staff assistants that answer questions from policies and procedures, case summaries for investigators, meeting prep for relationship managers and code help for developers. Customer-facing uses follow once controls are proven.

Should a community bank build or buy AI?

Usually buy, through existing core, digital banking, fraud and lending vendors. Building needs data science and model validation capacity that most smaller institutions do not have.

What is SR 11-7 and does it apply to AI?

SR 11-7 is US supervisory guidance on model risk management. It covers model development, validation and governance, and banks generally apply it to AI and machine learning models, including models bought from vendors.

Can bank employees use public AI chatbots?

Only under a clear policy. Most banks block unapproved tools and provide an approved assistant with enterprise controls, so customer and confidential data is not sent to services that may retain it.

Spotsaas advisor
Find the best Billing & Invoicing Software for your team
  • Independent picks for exactly what you just read about
  • Matched to your team size & needs
  • Vendors don't pay for placement

Step 1 of 4

How big is your team?

We tailor recommendations to companies your size.

Trusted by teams at

Related Articles