Bank Director — 2026 Risk Survey “AI Exposes Threats, Knowledge Gaps”

Tag: S-2026-03-30-bank-director-risk-survey Type: report (industry survey) Author(s): Laura Alix (Director of Research, Bank Director); survey sponsored by Baker Tilly US, LLP Date of source: 2026-03-30 (article published 30 March 2026; PR Newswire release 31 March 2026) Date ingested: 2026-06-29 Authority weight: medium — credible bank-governance publisher’s annual board survey with a named sponsor, but self-reported, audience-limited to (predominantly US community and regional) bank CEOs, board members, CROs and senior executives, and the full results are gated behind Bank Services membership (only the high-level open report is public). Raw file: S-2026-03-30-bank-director-risk-survey. External URL: https://www.bankdirector.com/article/2026-risk-survey-ai-exposes-threats-knowledge-gaps/

What it claims

Bank Director’s 2026 Risk Survey (sponsored by Baker Tilly) reports that AI adoption by banks ramped up through 2025 — assisting functions from loan processing to customer service to compliance — but that it introduces new threats and exposes knowledge gaps among bank leadership [S-2026-03-30-bank-director-risk-survey].

Headline points:

  • Fraud dominates AI concern. 79% of respondents (CEOs, board members, CROs and senior executives) are concerned about fraud generally. On AI specifically, leaders are most concerned about fraud and scams targeting their customers (84%) and their employees and organisation (77%); the competitive threat from other financial institutions and nonbanks (38%) ranks a distant third. 20% believe their bank or its customers had been impacted by fraud involving AI or deepfake media over the prior 18 months [S-2026-03-30-bank-director-risk-survey].
  • Agentic-AI knowledge gap. Respondents report at least baseline understanding of many AI topics (machine learning, AI use cases, data governance), but a third say they do not understand agentic AI — autonomous decision-making AI — at all. Bank Director and Baker Tilly frame this as a governance problem: a basic understanding is needed so management can, for example, explain why staff should not use un-vetted public AI tools for bank business [S-2026-03-30-bank-director-risk-survey].
  • “Governance from the very beginning.” Baker Tilly’s financial-services risk advisory leader Mark Wuchte is quoted: “Banks need a baseline level of understanding so everyone knows what’s in play. Without that foundation, you risk people inadvertently using tools outside of the bank’s oversight. Governance needs to be part of the conversation from the very beginning.” [S-2026-03-30-bank-director-risk-survey]
  • Strategic risk rising, regulatory risk receding. 42% rank strategic risk a top concern for 2026, up from 30% a year earlier (attributed partly to AI-driven competitive change and fintechs seeking bank charters); 53% believe their bank could take more strategic risk. Regulatory risk fell to 28% (from 55% last year), attributed to a friendlier US regulatory posture under the second Trump administration [S-2026-03-30-bank-director-risk-survey].
  • Examiner capacity signals. 44% saw heightened regulatory-exam attention to liquidity planning; 37% to cybersecurity (up from 30% in 2025). 35% felt their last examiner was inexperienced versus previous exams; 38% believed their primary regulator was understaffed or under-resourced [S-2026-03-30-bank-director-risk-survey].
  • Cybersecurity oversight. 79% of board chairs/independent directors say the board reviews and approves a management-set cybersecurity strategy, but under half (47%) invited outside cyber experts to the board in the past 12 months. 89% of CEOs/tech executives ran a cyber incident-response tabletop in the prior 12 months; the most common gaps surfaced were overreliance on one individual or function (36%) and internal communications (35%) [S-2026-03-30-bank-director-risk-survey].
  • Credit risk. 60% name credit a top risk (up from 51%), with commercial real estate emphasised — credit-quality concern (27%) and loan-portfolio concentration (38%) [S-2026-03-30-bank-director-risk-survey].
  • Risk responsibility / CRO. 54% say their bank employs a chief risk officer; among those, 81% say the CRO reports directly to the CEO and almost two-thirds say the CRO interacts with directors at every board meeting [S-2026-03-30-bank-director-risk-survey].

Notable quotes

“Banks need a baseline level of understanding so everyone knows what’s in play. Without that foundation, you risk people inadvertently using tools outside of the bank’s oversight. Governance needs to be part of the conversation from the very beginning.” — Mark Wuchte, financial services risk advisory leader, Baker Tilly (in Bank Director, 30 March 2026)

What’s speculative vs. asserted

  • Asserted (survey results / fact): all percentage figures above are reported survey results (84% / 77% / 38% AI-fraud concern; 20% AI/deepfake fraud impact; “a third” not understanding agentic AI; 42% vs 30% strategic risk; 28% vs 55% regulatory risk; 53% could take more strategic risk; exam-attention and examiner-capacity figures; cyber-oversight figures; 60% credit; CRO-structure figures).
  • Interpretive / commentary (Bank Director and Baker Tilly framing, not survey data points): that the agentic-AI knowledge gap is primarily a governance problem; that AI-driven competition and fintech charters are feeding the rise in strategic-risk concern; that smaller banks must “get more agile … make decisions more quickly”; that the regulatory-risk decline is driven by the administration’s posture.
  • Caveat in source: only high-level findings are public; complete results (broken out by asset category) are gated behind Bank Services membership, so sub-segment figures cannot be independently verified from the public article. Respondent base skews to US community/regional banks.

Topics this feeds

  • AI Governance Maturity Gap — adds a US bank-board datapoint to the 2026 adoption-outpaces-governance convergence and, specifically, sources the previously-untagged “a third do not understand agentic AI” claim already on that page; reinforces the board-AI-literacy-as-binding-constraint and “governance from the start” framings.

Open questions raised

  • Does the US-community-bank emphasis (fraud-first AI concern; receding regulatory risk under a friendlier US posture) transfer to UK/EU regulated firms, where the supervisory direction is the opposite (FCA/EBA tightening expectations)? The regulatory-risk-receding finding is the inverse of the UK/EU signal on this topic.
  • Is the “a third do not understand agentic AI” figure consistent with the McKinsey finding that only ~one-third of firms reach maturity level 3+ on agentic-AI governance — i.e. are board literacy and organisational governance maturity measuring the same underlying gap from two ends?
  • How much weight to place on the figures given the full results are gated and the sample skews to US community/regional banks.

Ingestion note

Located via WebSearch (no regulator/source landing page lists this item; it is an industry survey) and confirmed by direct WebFetch of the Bank Director article page (HTML article:modified_time 2026-03-30; visible byline date “03/30/2026”; PR Newswire release dated 31 March 2026). All figures are taken verbatim from the public high-level article; the full survey report is gated behind Bank Services membership and was not accessed. This source is dated 30 March 2026 and is therefore not a “past-7-days” practitioner signal; it was captured on the 29 June daily run because (a) no genuinely new past-7-days practitioner item existed beyond sources already in the corpus, and (b) its “a third do not understand agentic AI” figure already appeared untagged on AI Governance Maturity Gap and required a proper source under the schema’s attribution rule.