Every Tier-1 risk function in Europe has an AI programme. Very few have an AI thesis. The programmes tend to start where the technology is most impressive rather than where the return is largest — which in practice means the credit-risk modelling team, because that is where the data scientists already sit.
That instinct is expensive. The single best predictor of whether an AI use case returns its investment inside a bank risk function is not model accuracy or data availability. It is how close the output sits to a regulatory capital number. The closer it sits, the more governance it attracts, the longer the approval cycle, and the smaller the net gain. The further away it sits, the faster it ships and the more of the benefit the bank keeps.
There are two AI questions inside a bank, and they are constantly confused. Question one: can AI improve a regulatory model? Question two: can AI reduce the cost of running the risk function? The first is a supervisory negotiation with a modest prize. The second is an operating-margin question with almost no supervisory friction — and it is where most of the value sits.
The supervisory gradient
Rank any candidate AI use case by the distance between its output and a Pillar 1 capital requirement. The gradient is remarkably consistent.
| Zone | Example use cases | Supervisory friction | Typical time to value |
|---|---|---|---|
| Zone 1 — Evidence & retrieval | OSI data-room search, findings-letter drafting support, policy and procedure lookup, regulatory-text change detection | None — no model output enters a return | Weeks |
| Zone 2 — Reconciliation & reporting | COREP/FINREP break investigation, AnaCredit data-quality triage, three-way reconciliation exception handling | Low — the numbers are unchanged; only the route to them is faster | One to two quarters |
| Zone 3 — Monitoring & early warning | Credit early-warning signals, portfolio concentration drift, collateral revaluation triggers | Moderate — feeds risk appetite and provisioning judgement, so it needs governance but not model approval | Two to four quarters |
| Zone 4 — Pillar 1 parameters | PD, LGD, CCF estimation; market-risk sensitivities | High — full model-change materiality assessment, supervisory approval, ongoing validation | Multi-year |
Most AI budgets in European risk functions are concentrated in Zone 4. Most of the recoverable cost sits in Zones 1 and 2.
Where the return actually is
Two of these zones deserve specific attention because they are systematically underinvested.
Evidence retrieval and the inspection file
An ECB on-site inspection on credit risk generates several hundred information requests over the investigation phase. The binding constraint is almost never analytical — it is retrieval: finding the right document version, the right committee minute, the right data lineage artefact, and doing it inside the inspector's response window.
This is a search-and-summarise problem over a controlled corpus the bank already owns. No model output reaches a regulatory return. No parameter changes. The governance requirement is document control and access management, which the data room needs regardless. A retrieval layer over a well-structured evidence vault is, in our view, the highest return-per-euro AI deployment available to a risk function today — and it is the one almost nobody funds, because it does not look like AI.
Reconciliation exception handling
The reporting rebuild under CRR3 has made the FINREP ↔ COREP ↔ Pillar 3 reconciliation a permanent operating cost rather than a quarterly project. Most of that cost is not producing numbers; it is investigating breaks — classifying an exception, tracing it to a source system, and deciding whether it is a data defect or a definitional difference.
That classification task is well suited to machine learning and carries no supervisory approval requirement, because the reported figures are unchanged. The bank is automating the investigation, not the number. Where we see this deployed, the gain shows up as headcount released from break-chasing into control design.
Before funding any AI use case in a risk function, ask one question: if this model were switched off tomorrow, would a regulatory return change? If the answer is no, the governance burden is manageable and the business case is probably real. If the answer is yes, price in the full model-change lifecycle before you approve the budget.
Zone 4: why the capital-model prize is smaller than it looks
None of this means machine learning has no place in Pillar 1 models. Supervisors have moved a long way from treating ML as inherently unacceptable. The ECB's revised Guide to internal models now contains a dedicated treatment of machine-learning techniques, updated to reflect CRR3, and it applies whether ML is the primary estimation method, a data-preparation step, or a supporting tool. The direction of travel is permissive, not prohibitive.
The EBA reached a similar place by a longer route. Its 2021 discussion paper on machine learning for IRB models asked how sophisticated techniques could coexist with CRR requirements; the 2023 follow-up report set out principle-based recommendations for prudent use alongside observed use cases. At Basel level, the BCBS has been explicit that its work in this area is analytical: its newsletter on AI and machine learning states plainly that it "does not constitute new supervisory guidance or expectations", and flags three continuing focus areas — explainability, governance and accountability, and resilience.
So the door is open. The question is what walking through it costs.
- Materiality assessment. A change of estimation technique on an IRB parameter is a model change. Under the final EBA RTS on the materiality of model changes and extensions (EBA/RTS/2026/05), a fundamental methodology shift is treated as material on qualitative grounds even where quantitative thresholds are not breached.
- Approval queue. Supervisory review of a material model change runs months, not weeks — and the CRR3 transition has already crowded the pipeline with competing submissions.
- Explainability burden. Transparency is expected to be commensurate with the risk of the activity supported. For a Pillar 1 credit parameter, that bar is high, and it is a permanent documentation and validation cost, not a one-off.
- Marginal accuracy. On well-specified retail portfolios with mature scorecards, the incremental discriminatory power from a more complex technique is often modest — and any gain that does materialise is partly absorbed by the conservatism margins a supervisor may attach.
The honest summary: Zone 4 is a legitimate multi-year investment for banks with a specific, evidenced accuracy problem on a material portfolio. It is a poor first AI project.
The 2026 compliance stack
Whatever zone a bank operates in, three regimes now sit over AI deployment and they do not have the same scope.
The EU AI Act
Under the AI Act's high-risk classification, AI systems used for creditworthiness assessment and credit scoring of natural persons are in scope — with a carve-out for systems used to detect financial fraud. That distinction matters operationally: the same modelling team may run one system inside the high-risk perimeter and one outside it.
Obligations for high-risk systems include conformity assessment and registration on the provider side, and on the deployer side human oversight, retention of automated logs, and a fundamental-rights impact assessment where required. Penalties for breach of the high-risk obligations reach €15 million or 3% of global annual turnover, whichever is higher.
The operative compliance date for high-risk obligations has been 2 August 2026. In November 2025 the European Commission proposed deferring certain deadlines into late 2027, and that proposal has attracted significant attention. As at the date of this article, that deferral has not been enacted. Planning to the later date is a bet on a legislative outcome that has not landed. We advise clients to build to the enacted deadline and treat any deferral as recovered contingency, not as budget.
DORA and the vendor question
Most bank AI is bought, not built. That places it inside the ICT third-party risk perimeter: contractual requirements, exit strategies, concentration analysis and audit rights. The practical exposure that supervisors are increasingly alert to is not model autonomy — it is concentration on a small number of model and infrastructure providers across an entire institution, and in some cases across an entire market.
Model risk governance
The unglamorous conclusion is that most AI governance questions a JST will ask are answerable from an existing model risk management framework, extended rather than rebuilt: inventory coverage, tiering by materiality, independent validation with genuine challenge, and named ownership. Banks with a credible MRM framework are substantially ready. Banks without one do not have an AI problem; they have a model-governance problem that AI has made visible.
What a CRO should do this quarter
- Inventory by zone, not by technology. Classify every AI use case — live, in flight, or proposed — by distance to a regulatory return. The inventory will usually show budget concentrated in Zone 4 and opportunity sitting untouched in Zones 1 and 2.
- Map the AI Act perimeter explicitly. Which systems touch creditworthiness assessment of natural persons? Which fall inside the fraud-detection carve-out? Get this documented before the classification is made for you.
- Run the switch-off test on every business case. If disabling the model would change a regulatory return, price the full model-change lifecycle into the approval.
- Fund one Zone 1 use case. Evidence retrieval over the inspection file is the fastest credible win available and it compounds — the same corpus discipline that makes retrieval work is what makes an OSI go well.
- Extend the MRM framework rather than writing an AI policy. A separate AI policy that does not tie into model inventory, tiering and validation creates a second governance surface for a supervisor to test.
AI will reduce the cost of running a European bank risk function materially over the next three years. Very little of that reduction will come from better capital models. Almost all of it will come from the unglamorous middle of the function — retrieval, reconciliation, exception handling, evidence discipline — where the supervisor is not watching because nothing they rely on is changing. The banks that understand the gradient will get there first and cheaper.
Sources
- ECB Banking Supervision — Guide to internal models (revised; machine-learning chapter, updated for CRR3)
- EBA — Discussion paper on machine learning for IRB models (November 2021)
- EBA — Follow-up report on machine learning for IRB models (August 2023, PDF)
- BCBS — Newsletter no. 27 on artificial intelligence and machine learning (16 March 2022)
- Regulation (EU) 2024/1689 (EU AI Act) — Article 6 and Annex III high-risk classification; Article 99 penalties
- Regulation (EU) 2022/2554 (DORA) — ICT third-party risk management
- Ezelman — EBA/RTS/2026/05 on the materiality of IRB model changes
Figures policy: this article contains no proprietary statistics. Regulatory positions are cited to primary sources above; the zone framework and the switch-off test are Ezelman methodology, offered as practitioner judgement rather than measured data.