Every Tier-1 risk function in Europe has an AI programme. Very few have an AI thesis. The programmes tend to start where the technology is most impressive rather than where the return is largest — which in practice means the credit-risk modelling team, because that is where the data scientists already sit.

That instinct is expensive. The single best predictor of whether an AI use case returns its investment inside a bank risk function is not model accuracy or data availability. It is how close the output sits to a regulatory capital number. The closer it sits, the more governance it attracts, the longer the approval cycle, and the smaller the net gain. The further away it sits, the faster it ships and the more of the benefit the bank keeps.

The frame

There are two AI questions inside a bank, and they are constantly confused. Question one: can AI improve a regulatory model? Question two: can AI reduce the cost of running the risk function? The first is a supervisory negotiation with a modest prize. The second is an operating-margin question with almost no supervisory friction — and it is where most of the value sits.

The supervisory gradient

Rank any candidate AI use case by the distance between its output and a Pillar 1 capital requirement. The gradient is remarkably consistent.

ZoneExample use casesSupervisory frictionTypical time to value
Zone 1 — Evidence & retrievalOSI data-room search, findings-letter drafting support, policy and procedure lookup, regulatory-text change detectionNone — no model output enters a returnWeeks
Zone 2 — Reconciliation & reportingCOREP/FINREP break investigation, AnaCredit data-quality triage, three-way reconciliation exception handlingLow — the numbers are unchanged; only the route to them is fasterOne to two quarters
Zone 3 — Monitoring & early warningCredit early-warning signals, portfolio concentration drift, collateral revaluation triggersModerate — feeds risk appetite and provisioning judgement, so it needs governance but not model approvalTwo to four quarters
Zone 4 — Pillar 1 parametersPD, LGD, CCF estimation; market-risk sensitivitiesHigh — full model-change materiality assessment, supervisory approval, ongoing validationMulti-year

Most AI budgets in European risk functions are concentrated in Zone 4. Most of the recoverable cost sits in Zones 1 and 2.

Where the return actually is

Two of these zones deserve specific attention because they are systematically underinvested.

Evidence retrieval and the inspection file

An ECB on-site inspection on credit risk generates several hundred information requests over the investigation phase. The binding constraint is almost never analytical — it is retrieval: finding the right document version, the right committee minute, the right data lineage artefact, and doing it inside the inspector's response window.

This is a search-and-summarise problem over a controlled corpus the bank already owns. No model output reaches a regulatory return. No parameter changes. The governance requirement is document control and access management, which the data room needs regardless. A retrieval layer over a well-structured evidence vault is, in our view, the highest return-per-euro AI deployment available to a risk function today — and it is the one almost nobody funds, because it does not look like AI.

Reconciliation exception handling

The reporting rebuild under CRR3 has made the FINREP ↔ COREP ↔ Pillar 3 reconciliation a permanent operating cost rather than a quarterly project. Most of that cost is not producing numbers; it is investigating breaks — classifying an exception, tracing it to a source system, and deciding whether it is a data defect or a definitional difference.

That classification task is well suited to machine learning and carries no supervisory approval requirement, because the reported figures are unchanged. The bank is automating the investigation, not the number. Where we see this deployed, the gain shows up as headcount released from break-chasing into control design.

The test we apply on mandates

Before funding any AI use case in a risk function, ask one question: if this model were switched off tomorrow, would a regulatory return change? If the answer is no, the governance burden is manageable and the business case is probably real. If the answer is yes, price in the full model-change lifecycle before you approve the budget.

Zone 4: why the capital-model prize is smaller than it looks

None of this means machine learning has no place in Pillar 1 models. Supervisors have moved a long way from treating ML as inherently unacceptable. The ECB's revised Guide to internal models now contains a dedicated treatment of machine-learning techniques, updated to reflect CRR3, and it applies whether ML is the primary estimation method, a data-preparation step, or a supporting tool. The direction of travel is permissive, not prohibitive.

The EBA reached a similar place by a longer route. Its 2021 discussion paper on machine learning for IRB models asked how sophisticated techniques could coexist with CRR requirements; the 2023 follow-up report set out principle-based recommendations for prudent use alongside observed use cases. At Basel level, the BCBS has been explicit that its work in this area is analytical: its newsletter on AI and machine learning states plainly that it "does not constitute new supervisory guidance or expectations", and flags three continuing focus areas — explainability, governance and accountability, and resilience.

So the door is open. The question is what walking through it costs.

The honest summary: Zone 4 is a legitimate multi-year investment for banks with a specific, evidenced accuracy problem on a material portfolio. It is a poor first AI project.

The 2026 compliance stack

Whatever zone a bank operates in, three regimes now sit over AI deployment and they do not have the same scope.

The EU AI Act

Under the AI Act's high-risk classification, AI systems used for creditworthiness assessment and credit scoring of natural persons are in scope — with a carve-out for systems used to detect financial fraud. That distinction matters operationally: the same modelling team may run one system inside the high-risk perimeter and one outside it.

Obligations for high-risk systems include conformity assessment and registration on the provider side, and on the deployer side human oversight, retention of automated logs, and a fundamental-rights impact assessment where required. Penalties for breach of the high-risk obligations reach €15 million or 3% of global annual turnover, whichever is higher.

A live timing caveat — read this before you plan around a date

The operative compliance date for high-risk obligations has been 2 August 2026. In November 2025 the European Commission proposed deferring certain deadlines into late 2027, and that proposal has attracted significant attention. As at the date of this article, that deferral has not been enacted. Planning to the later date is a bet on a legislative outcome that has not landed. We advise clients to build to the enacted deadline and treat any deferral as recovered contingency, not as budget.

DORA and the vendor question

Most bank AI is bought, not built. That places it inside the ICT third-party risk perimeter: contractual requirements, exit strategies, concentration analysis and audit rights. The practical exposure that supervisors are increasingly alert to is not model autonomy — it is concentration on a small number of model and infrastructure providers across an entire institution, and in some cases across an entire market.

Model risk governance

The unglamorous conclusion is that most AI governance questions a JST will ask are answerable from an existing model risk management framework, extended rather than rebuilt: inventory coverage, tiering by materiality, independent validation with genuine challenge, and named ownership. Banks with a credible MRM framework are substantially ready. Banks without one do not have an AI problem; they have a model-governance problem that AI has made visible.

What a CRO should do this quarter

The bottom line

AI will reduce the cost of running a European bank risk function materially over the next three years. Very little of that reduction will come from better capital models. Almost all of it will come from the unglamorous middle of the function — retrieval, reconciliation, exception handling, evidence discipline — where the supervisor is not watching because nothing they rely on is changing. The banks that understand the gradient will get there first and cheaper.

Sources

Figures policy: this article contains no proprietary statistics. Regulatory positions are cited to primary sources above; the zone framework and the switch-off test are Ezelman methodology, offered as practitioner judgement rather than measured data.