I'll be asked about AI and I have nothing to show
Author
Audrey
NobleCloak's AI Correspondent · AI-drafted, fact-checked against our sourced evidence before publishing.
Date Published
There's a specific quiet dread that shows up in compliance officers around now, and it doesn't have a clean name yet. It's not fear of a rule. It's the opposite. It's the feeling of an obligation with no paperwork attached — a question you can see coming down the hallway, and no folder in the drawer that answers it.
You know the question. Some version of "So, how are you managing the AI your institution and your vendors are using?" It might come from an examiner. It might come from your board, your supervisory committee, a nervous member of your credit union, or a client's attorney during a diligence request. And you already know, in the part of your brain that's been assembling exam binders for years, that when it comes you will not have a good answer sitting ready. You'll have a shrug, a promise to "look into it," and a mental note that turns into a bad week.
I want to name that feeling plainly, because naming it is the first useful thing anyone has done with it. You will be asked about AI, and you have nothing to show. That's the real 2026 problem. Not a mandate. A vacuum with your name on it.
The obligation is real even though the rule isn't
Here's the trap that makes this so disorienting. If you go looking for the regulation that says "financial institutions must inventory and assess their AI vendors," you won't find it. There isn't one. And the absence gets read, understandably, as "then I don't have to do anything yet."
That reading is exactly backwards, and the structure of 2026 is what makes it backwards.
If you're a credit union, the vendor-diligence burden doesn't sit with your regulator — it sits with you, by design. The GAO confirmed in May 2025 (GAO-25-107197) that the NCUA has no authority to examine third-party technology vendors, including the ones delivering AI-driven services. GAO has recommended Congress fix that gap since 2015. It hasn't. So there is no examiner walking into your vendor's office to check their AI on your behalf. The diligence is yours to run and yours to evidence. The good news buried in that: NCUA's own framework (07-CU-13 / SL 07-01) has always been explicitly proportional — "reasonable alternative procedures," less analysis for non-complex vendors. Nobody expects a SOC-team's worth of output from you. They expect something, applied sensibly. Right now most institutions have nothing.
If you're an RIA or broker-dealer, the obligation isn't even ambient — it's live and dated. The amended Reg S-P safeguards rule (17 CFR 248.30(a)(5)) already requires written policies mandating ongoing "oversight, including through due diligence and monitoring, of service providers." Larger firms hit compliance December 3, 2025; every smaller firm's deadline was June 3, 2026. The industry asked for an extension; the SEC denied it. And Reg S-P compliance is a named Division of Examinations priority for FY2026. AI isn't singled out in the rule. It doesn't have to be. Your AI vendors are service providers, and "ongoing monitoring of service providers" is the sentence you'll be asked to produce evidence for.
And the one place a regulator did speak directly to generative AI, it stepped back. SR 26-2, effective April 17, 2026, explicitly carved generative and agentic AI out of model-risk management scope (footnote 3), and it's aimed at banks over $30 billion anyway. That's not relief. That's a regulator publicly declining to fill the space — which leaves the space, and the question, sitting with you.
The feeling has data behind it
If you think this dread is a personal failing — that everyone else has this handled and you're the one who's behind — the incumbent's own numbers say otherwise. In Ncontracts' 2026 State of TPRM survey (n=173), AI risk tied cybersecurity as institutions' top third-party concern for the first time ever. In the same survey, 72% of institutions were only partially aware of which of their vendors even use AI. And the share who called themselves "extremely confident" managing AI-related third-party risk was zero percent. Not low. Zero.
Read that as company, not as an alarm. The reason nobody feels ready is that the tooling and the muscle memory for this genuinely don't exist yet in most shops — especially the ones running their whole compliance function on one or two people, which the same survey found is most of them. You're not behind the field. The field is here, in the hallway, with you.
What "having something to show" actually looks like
The antidote to "nothing to show" is embarrassingly concrete, which is the good part. It's not a strategy deck. It's a small stack of paper (or its PDF) that answers three plain questions an examiner or a board member actually asks:
- What AI is in use here — ours and our vendors'? A real inventory. Not "we think a few tools use it." A list, with names, dated. Our How to run an AI data call playbook walks the internal side; the harder half is the vendors, which brings us to the next post in this series, Your vendors are adding AI without telling you.
- What can each of those AI tools reach? Which data, which systems, through what access. This is the part everyone skips and the part that turns a vague worry into a governable list. It lives in your OAuth grants and connectors, not your network logs — see Shadow AI is an access problem not a traffic problem.
- What did we conclude, and what did we do about the risky ones? The findings, the questions we asked the vendor, and the decision. This is the section that reads as governance rather than anxiety.
That's the whole shape of "something to show." An inventory, an access map, and a documented judgment. Assembled once, kept current, and formatted the way an examiner reads. If you want the full table of contents, it's in What an examiner-ready AI evidence binder contains.
The honest part
I'm not going to tell you a report makes the dread disappear, because a point-in-time assessment has real edges and pretending otherwise is how trust brands die.
A report is a snapshot. It tells you what's true the week it's run, and vendors change what their AI does between snapshots — that's the whole reason the next post in this series exists. It's read-only: it inventories what access exists and what vendors say they do, but it can't watch every keystroke or catch a colleague pasting member data into a personal chatbot account. And even where you'd want the receipts, you may not be able to get them — audit-log export for the ChatGPT product line, for instance, is gated to Enterprise and Edu tiers with 30-day retention; a team on ChatGPT Business can't export it at all. A report names that gap. It doesn't close it.
What it does do is turn "I have nothing to show" into "here's what we found, here's what we asked, here's what's still open." At an exam, and in your own head at 11pm, that sentence is worth a great deal more than its length suggests.
That's the deliverable we build: a Discover scan, produced with you — not a login you have to figure out alone, but a concierge scan we run alongside your team, proportional to your risk profile. If the dread in this piece is familiar, that's the thing that answers it.
Request your Discover scan — we run it with you. Or if you'd rather see the shape of it first, see what a Discover scan finds.