Issue #34
Weekly Banking Intelligence: September 18 to September 24, 2026
THIS WEEK’S SIGNAL
The regulatory ground shifted this week in two directions at once, and most banks are not positioned for either. State regulators published a formal AI examination framework while federal agencies simultaneously proposed scrapping their 2023 third-party risk guidance. That combination puts banks in a genuinely uncomfortable spot: state examiners now have a structured playbook for AI oversight, while the federal framework governing your fintech and vendor relationships is being rewritten from scratch. The institutions that will navigate this cleanly are the ones that already have coherent governance across both dimensions. Most do not.
DEEP DIVE
The regulatory split that could define your AI governance posture
The Conference of State Bank Supervisors (CSBS) released its Artificial Intelligence Supervisory Framework on September 16, giving state examiners a structured process for identifying AI use, evaluating associated risks, and deciding when a deeper review is warranted. This is not guidance aimed at banks. It is an examiner playbook, which means your next state exam could include AI-specific inquiry whether you are ready for it or not.
What caught my attention is the timing. The CSBS framework arrived the same week federal banking agencies, including the Office of the Comptroller of the Currency (OCC) and the National Credit Union Administration (NCUA), jointly proposed replacing their 2023 third-party risk management guidance and rescinding the bank-fintech joint statement. The federal proposal is still in comment period. The state framework is already in examiners’ hands.
Why it matters: Banks operating under state charters are now subject to AI examination criteria that their federal counterparts have not yet finalized. If you run a mixed portfolio of state and federally chartered entities, or if your fintech partners operate under state licenses, you are navigating two regulatory clocks running at different speeds. That is not a compliance nuisance. It is a governance design problem.
Why it matters for your operating model: The third-party risk proposal is worth reading carefully, because the direction of travel is clear. The agencies want tighter accountability for what your vendors and fintech partners actually do inside your risk perimeter. If your AI deployments run through third-party models, cloud infrastructure, or bank-fintech arrangements, the combination of a new state AI framework and a revised federal third-party standard could require you to rethink how you document, monitor, and govern those relationships. The banks that built vendor governance as a real operational discipline, not a compliance checkbox, are going to have a much easier time here.
The Bank for International Settlements (BIS) added a useful frame this week. In a speech on supervising banks in an AI-shaped economy, BIS leadership made the point that AI supervision is not simply about how banks use AI. It is also about the resilience of banks operating in an economy being reshaped by AI, including operational resilience as technology compresses response time, and strategic resilience as AI changes borrowers, industries, and business models over time. That framing matters because it suggests regulators are beginning to think about AI risk at the systemic level, not just at the product or model level. If that framing takes hold, the scope of what examiners look at will expand considerably.
MARKET MOVES
A fintech moves to own a bank, not just partner with one
Fintech agreed this week to acquire a national bank for $590 million. The source material does not name the fintech or the bank, and we will not speculate. What the filing does confirm is that upon closing, the national bank will become a wholly owned subsidiary of the fintech and will operate under a new name. The transaction is expected to close in the first half of 2027, pending approval from the OCC and the Federal Reserve Board.

Fintech acquisition price for national bank. Source (verbatim from this brief): A fintech agreed this week to acquire a national bank for $590 million.
Why it matters: This is a structural shift, not a partnership upgrade. Bank-fintech partnerships have been the dominant model for the past decade because they let fintechs access banking infrastructure without taking on the regulatory weight of a charter. Acquiring a national bank flips that logic entirely. The fintech is betting that direct ownership of a charter, with all the capital requirements, examination burden, and compliance infrastructure that comes with it, is worth more than the flexibility of staying off the balance sheet. If the thesis is right, it signals that the partnership model has real limits at scale. If regulators approve it, expect others to run the same calculation.
Coinbase connects to U.S. banks through a core banking integration layer
Coinbase announced this week that it is connecting its digital asset infrastructure to participating U.S. financial institutions through a partnership with Stablecore, which integrates with Verafin, a financial crime management platform. The integration touches core banking, digital banking, and compliance systems at participating institutions. Amarillo National Bank in Texas is among the early participants. The Stablecore-Verafin integration remains in beta, with broader rollout planned for the fourth quarter of 2026. The announcement does not indicate that 3,000 banks have signed contracts; rather, Coinbase’s infrastructure is now accessible to institutions whose core and compliance systems connect through this channel.
Why it matters: The significance here is not the number of banks. It is the integration point. Connecting crypto services at the core banking and compliance layer, rather than as a bolt-on app, is a meaningful architectural choice. It also means the compliance infrastructure has to be ready to handle digital asset activity in the same examination environment as traditional banking. For community and mid-size banks evaluating crypto services, the question is not whether to offer them. It is whether your compliance and core systems are actually ready to support them at the integration depth this model requires.
VENDOR SIGNALS
OpenAI positions GPT-6 Astra as a shortcut around core rewrites
As reported this week by PYMNTS, OpenAI is positioning its new GPT-6 Astra model as a tool that lets banks automate complex workflows layered on top of existing systems, reducing pressure to replace legacy cores immediately. The model reportedly completes screen-based tasks in roughly half the time of its predecessor.
The catch is buried in the same reporting: even the best current AI completes fewer than one-third of long, realistic end-to-end jobs from start to finish. That is worth sitting with. Banks being pitched on AI as a core replacement shortcut should ask what happens to the two-thirds of tasks the model does not complete. Someone or something has to catch those. If the answer is “a human in the loop,” that is a legitimate operating model, but it needs to be designed intentionally, not discovered after deployment.
A large Pakistani bank frames core modernization as an operating model problem first
One of Pakistan’s largest banks surfaced this week with a candid account of its core banking transformation. The institution’s chief technology officer described the transformation as driven less by front-end digitization than by the operational burden of managing complex banking environments at scale. The stated goal is to reduce operational friction across frontline and back-office environments and build the foundation for progressively more autonomous operating models over time.
What I find useful about that framing is that it names the real problem. Most transformation programs get sold internally as customer experience upgrades or digital capability plays. The operational burden argument, the cost and complexity of running increasingly intricate systems at scale, is harder to make in a board presentation but closer to the truth of why these programs are necessary. The institutions that frame transformation that way tend to make better decisions because they are solving the right problem from the start.
ConnectPay spins out a core banking technology business
ConnectPay, a payments-focused financial technology company, launched a separate core banking technology business this week called Serdis, offering its internally built core banking technology to external financial institutions.
This follows a pattern we have seen accelerate over the past 18 months: institutions and fintechs that built proprietary core technology for internal use deciding there is a market for it externally. The community and mid-size bank segment is the obvious target. Whether Serdis has the implementation capability and support infrastructure to serve external clients at scale is the question worth watching. Technology is rarely the hardest part of these plays.
Intellect Design Arena wins a core banking deal with Cargills Bank
Intellect Design Arena (IDAL), a financial technology firm, finalized a deal this week to implement its eMACH.ai Core Banking Architecture for Cargills Bank, a Sri Lanka-based institution.
Deals like this do not generate headlines in North American banking circles, but they belong in CB Radar because they reflect where vendor selection decisions are actually being made in emerging markets. IDAL is building a reference base on a modern, AI-native architecture. That matters when global banks evaluate vendors for subsidiaries or regional operations in similar markets.
REGULATORY PULSE
CSBS AI framework: examiners have a playbook before banks have a standard
The CSBS framework, covered in depth above, deserves a separate note here for non-state-chartered institutions. Even if your primary regulator is federal, your fintech partners, third-party vendors, and bank-as-a-service relationships may operate under state licenses. That means the CSBS framework could reach into your risk perimeter indirectly. The gap between what state examiners will now look for and what federal guidance currently requires is real, and it is not going to close quickly.
Banks that have been waiting for a single unified federal AI standard before building out their governance infrastructure are going to find that the exam is arriving before the standard does.
Third-party risk guidance is being rewritten: the comment window is open
The joint proposal to replace the 2023 third-party risk management guidance is significant on its own, separate from the AI question. The agencies are also proposing to rescind the bank-fintech joint statement, which has shaped how banks structure and document fintech partnerships for the past three years.
If your institution has fintech partnerships structured around the current guidance, or if your vendor contracts reference it, the comment period is the right time to engage. The direction of the proposed guidance will determine how much operational and contractual rework is coming. This is not a legal team issue alone. It is a business and technology governance issue.
TALENT SIGNALS
AI governance and risk roles are accelerating
The CSBS AI framework and the BIS supervisory commentary this week are already translating into hiring activity. Several institutions are actively building out AI risk and governance functions, reflecting demand for people who understand both model risk management and banking operations well enough to sit in examination conversations. These roles are rising directly because AI deployment has outpaced the governance infrastructure built to support it.
Separately, a major Tier 1 bank is hiring for AI and machine learning engineering roles, a signal that AI-native build capacity continues to expand at the largest institutions even as broader headcount in traditional processing and middle-office functions remains under pressure from the same automation driving AI investment.
CB RADAR UPDATE

The CB Radar signals this week cluster around two themes: the quiet expansion of AI-native core platforms into new markets and institution types, and the growing number of banks treating digital identity and compliance infrastructure as core-layer investments rather than point solutions. Both trends show up in our proprietary database as accelerating. Banks that are still evaluating these as standalone vendor decisions are likely underestimating how interconnected the build-out actually is.
RICK’S STRATEGIC TAKE
➜ The regulatory gap is the real risk this week. State examiners now have an AI playbook. Federal third-party guidance is being rewritten. If your governance program was designed around the 2023 federal standard and you have not looked at the CSBS framework, you have a blind spot. I would want to know, if I were sitting in the CEO or CIO chair, exactly which of our AI deployments and fintech relationships fall under state examination and what those examiners are going to find when they show up.
➜ The fintech-acquires-bank story is worth watching very carefully. The $590 million deal announced this week is not just a transaction. It is a thesis about the limits of the partnership model. If regulators approve it and the operating model works, other fintechs will run the same math. The banks that currently rely on fintech partnerships for capability should be thinking about what happens to those relationships if the fintech side of the equation decides it wants a charter of its own.
➜ OpenAI’s “shortcut” framing deserves scrutiny. The idea that GPT-6 Astra lets banks avoid core rewrites is appealing, and it may be partially true for specific workflows. But a model that completes fewer than one-third of complex end-to-end tasks is not a replacement for a modernized operating model. It is a productivity tool. Banks that treat it as a substitute for the harder process and organizational work are going to discover that gap at the worst possible time, usually in production, under examination, or at scale.
For a deeper framework on what AI-ready core architecture actually requires, see CSP’s CB Architecture Series at coresystempartners.com.
Want the Full Picture?
Subscribe to BIS, the Banking Intelligence Service from Core System Partners, for the full breakdown including Rick’s Strategic Take on the governance gap, the CB Radar vendor tracking signals, and the regulatory pulse analysis covering what SR 11-7 does and does not cover for agentic deployments, delivered weekly. Banking Intelligence Service
For CSP’s full analysis of what the Fed and Treasury are actually concerned about—and a framework for what AI-ready architecture requires—visit Core System Partners.
Continue With Core System Partners
- Contact Us: https://coresystempartners.com/#contact
- The Strategic Flywheel (book): https://coresystempartners.com/resources/strategicflywheel/
- Core Insider (weekly newsletter): https://coresystempartners.com/resources/newsletter/


