Back to homepage

Fed’s Bowman flags AI-driven cyber threats to community banks

October 2, 2026

On September 29, Fed Vice Chair for Supervision Michelle W. Bowman delivered opening remarks at the annual Community Bank Cyber Workshop. She said several community banks experienced significant cyber events over the past year, underscoring the importance of cyber hygiene and resiliency. Bowman said threat actors’ growing use of AI complicates a risk environment that already includes ransomware, business email compromise and vendor data breaches. She warned that AI can speed vulnerability identification, power sophisticated social engineering campaigns, lower the barrier to entry for cyber criminals, and adapt attacks in real time. She said defense begins with strong cyber hygiene, including current asset inventories, phishing-resistant multifactor authentication, strong identity and access controls, and robust vulnerability and patch management, along with employee training and periodic incident response testing. AI, she added, is becoming a critical part of these measures as both a defensive tool and an evolving risk.

Bowman said many banks are already exploring how to deploy AI safely and strategically for cyber defense, and that understanding when, where and how to use it is key to balancing innovation with sound risk management. She pointed to the Financial Stability Board’s consultation report on sound practices for responsible AI adoption, published in June under her leadership of its Standing Committee on Supervisory and Regulatory Cooperation (previously covered by InfoBytes here). Noting that some of the report’s case studies target smaller institutions, she invited community banks to offer feedback on how regulators can clarify their expectations for smaller banks. Bowman said cybersecurity requires proactive risk management by boards and senior management, as well as investments in people, processes and technology matched to an institution’s risk and complexity. She said regulators recognize that this can be burdensome for community banks and that the Fed continues to tailor its approach to IT examinations to consider each bank’s risk profile and emerging threats and risks.