Read NCUA’s 2026 Supervisory Priorities letter looking for the word “artificial intelligence” and you will not find it. No AI section, no AI priority, no AI checklist. Some executives read that absence as a pass. What it actually means is that the AI questions arrive with no heading of their own, inside the exam areas you already face: third-party risk, fraud, payment systems, information security, and internal controls.
We covered the regulatory foundation in what NCUA expects before you deploy AI on member data. This is the exam-season sequel: the questions examiners are equipped to ask under the 2026 priorities, and the file to have ready when they do.
What the 2026 letter prioritizes
The 2026 letter names four supervisory priorities: credit risk in lending portfolios, interest rate and liquidity risk, earnings and capital adequacy, and operational risk with a focus on payment systems and fraud, plus BSA compliance. The AI questions live inside payment systems, fraud, and third-party risk.
Payment systems. The letter states that examiners will assess whether credit unions have effective governance, risk assessments, vendor management, and security frameworks supporting payment operations. Every one of those four words applies directly to any AI tool touching payments, disputes, or transaction monitoring.
Fraud. The letter commits NCUA to reviewing its own examination procedures so internal control reviews keep pace with what it calls the ever-changing fraud landscape. Fraudsters use AI, and your detection stack increasingly runs on it.
Third-party risk. The lending section notes that when functions are outsourced, examiners will assess third-party risk-management practices. AI in a credit union is overwhelmingly delivered by vendors, so this is where most AI scrutiny lands.
NCUA’s stated AI posture, in its own words
NCUA maintains an AI resource page with a supervision FAQ that is more direct than most commentary about it. The load-bearing statements:
Credit unions may use AI. The FAQ answers this question with a flat yes. NCUA supports adoption of AI when implemented in a safe, sound, and compliant manner.
There is no AI regulation. NCUA has issued no AI-specific rules. Existing regulations are technology-neutral and apply to AI use the same way they apply to email or a phone system.
Supervision runs through the existing framework. The FAQ lists exactly what examiners evaluate: safety and soundness practices, compliance with applicable laws, internal controls around the AI tool, ongoing monitoring of risks, and third-party due diligence when using vendors. The FAQ also states plainly that the supervisory focus is on risk management rather than the tool itself.
Vendor due diligence has a defined shape. For third-party AI, NCUA expects the credit union to understand how the product functions, what risks the AI introduces, how it fits the business model, and the vendor’s safeguards, reliability, and controls, with board and management oversight on top.
It is the standard new-product playbook applied to a new category of product.
The questions to expect, by exam area
Combining the 2026 priorities with the supervision FAQ, here is what a prepared examiner can reasonably ask a credit union with AI in production. Treat this as a self-exam to run this quarter.
Inventory. What AI tools are in use across the institution, including AI features inside existing vendor products? This is the question most institutions fail first, because the honest answer includes capabilities their core provider, loan origination system, or fraud platform switched on without a separate contract. If your core vendor shipped AI features this year, they are on your exam surface whether you deployed them deliberately or not.
Third-party due diligence. Show the due diligence file for each AI vendor. Does it document how the product works, what data it touches, whether the vendor trains models on your member data, who the underlying model provider is, and what happens to your data at termination? Get the training answer in writing; a vendor that will not commit to one on paper is a due diligence finding in itself.
Internal controls. What controls sit around each tool’s output? Where does human review happen, what triggers escalation, and how are overrides recorded? An override log, where staff decisions that reject the system’s output get captured with timestamps, is the single most persuasive control artifact you can produce.
Ongoing monitoring. How do you know the tool still performs the way it did at deployment? What gets measured, how often, and who sees the numbers? If the only accuracy figure on file dates from the pilot, expect that to come up.
Board oversight. What does the board see, and how often? The FAQ puts board and management oversight explicitly inside the vendor due diligence expectation. A short standing agenda item with the inventory and the monitoring numbers clears this bar.
Fraud and identity. What has the institution done about AI-enabled fraud, specifically deepfake media in identity verification? NCUA’s AI page points credit unions to FinCEN’s alert on deepfake schemes targeting financial institutions. Expect the question in the fraud review even if you have zero AI deployed.
Information security. What member data leaves your environment through AI tools, and under what protections? Technology-neutral means your existing information security obligations followed the data into the vendor’s model. A one-page data map per tool answers this cleanly.
The examiner file
In the 90-day pilot plan we recommended opening an examiner file on day 15 of any AI pilot. Here is the full contents list for an institution with AI in production:
- The AI inventory, one line per tool, including vendor-embedded AI features
- Third-party due diligence per vendor: financial condition, SOC 2 or equivalent, subcontractor and model-provider disclosure, the data-training answer in writing
- The data map per tool: what member data goes where, retention, deletion at termination
- The control description: where human review sits, escalation triggers, the override log
- Monitoring records: what is measured, the cadence, the last three readings
- Board minutes or packet excerpts showing AI oversight on the agenda
- For any tool touching lending decisions: the fair lending analysis
Once assembled, the file takes maybe an hour a quarter to maintain. Trying to build it during exam week is a much worse experience, and examiners can usually tell.
What examiners are not asking
Over-preparation is a failure mode too; it blocks useful projects for years. Grounded in what NCUA has published:
Nothing gets filed before deployment. You do not submit anything to NCUA before turning on an AI tool. The FAQ says AI is not treated differently than any other innovative technology.
Frameworks are optional reference material. Nothing requires a bank holding company’s model risk management apparatus for a document-routing tool with human review. NCUA’s own resource page points to NIST and COSO materials as resources that may help, not as adopted requirements. Proportionate documentation, sized to the risk of the workflow, is the standard.
Member data can go into AI systems. The obligation is that existing information security and vendor management requirements follow the data wherever it goes. A vendor with the right contractual safeguards and a clean data map satisfies the same rules that governed your imaging system.
The exam conversation goes badly when the answer to “what AI is in use here” is a shrug. A folder fixes that, provided the readings inside are current; a thick file of stale numbers helps less than a thin one from last quarter.
More on the compliance-safe adoption path lives in the NCUA and compliance pillar.
If you want a second set of eyes on your AI inventory and examiner file before your next exam cycle, Advisor Labs runs a 45-minute readiness review: book a conversation.
Get one substantive analysis like this every Tuesday: subscribe to the AiForCU newsletter.