The most expensive belief in banking AI is that the fancier the AI, the more the rules care. Under this belief, a frontier model deserves a task force, and the models the bank has quietly run for twenty years are furniture.
The relationship runs exactly backward. Regulation follows the decision, not the technology. And it concentrates along what the decision can harm.
The rules in question are not new, and AI has not reset them. The rules that attend to a credit denial were written in the 1970s. The rules that attend to a trade date from the 1930s. The supervisory expectations for models were set a decade and a half ago and refreshed just this year. None of these texts mention your vendor's architecture, and none of them need to. They were addressed to the decision, so they transferred, intact, to whoever or whatever makes it. Even the statutes now arriving with artificial intelligence in their titles bend the same way, reserving their heaviest weight for consequential decisions about people rather than for the cleverness of the machinery.
The inversion is almost comic: a credit model built on decades-old arithmetic carries more regulatory weight than a frontier language model drafting internal emails, because one of them can deny a person a mortgage and the other cannot. The rules are indifferent to the math. They attend to what the output can do.
The same belief wears one more disguise: the more sensitive data a system touches, the more regulated it must be. Cash-flow forecasting for corporate clients breaks it. It swims in some of the most confidential information a bank holds, its clients' cash positions, and still summons a fraction of the apparatus, because it decides nothing about anyone. The data still carries duties; confidentiality does not lapse. But the expensive machinery, the kind that decisions trigger, never switches on. Data volume isn't the variable. Decision harm is.
What predicts the weight is a question a CFO can ask with no counsel in the room: what can this decision harm? Banking's rulebooks cluster around three answers.
Some decisions can harm a person. Deny them, price them, flag them, close their account, and the apparatus of explanation, fairness, and recourse attends: written explanations of adverse decisions, testing for whether the model treats protected groups fairly, documentation built to survive a dispute.
Some decisions can harm a market. This is where the algorithmic trading desk lives: no individual anywhere in the decision, and an apparatus of surveillance, pre-trade controls, kill switches, and audit trails at machine granularity, because the controls must run as fast as the harm.
And some decisions can harm the institution itself. The models that estimate loan losses, project liquidity, and stress the balance sheet have never met a customer, yet they draw some of the deepest validation, independent review, and standing supervisory attention in the building, because a bank that misreads its own risk is exactly what supervision exists to prevent. The same weight attends any model that shapes the bank's view of itself, however internal, however advisory.
The heaviest use cases stack. A credit decision can harm the applicant and the loan book in the same act, the person and the institution at once, which is why lending answers to more of the shelf than almost anything else a bank does.
Three things follow, all of them useful before any money moves.
First, the weight is legible at the desk. What a use case decides, about whom, with what autonomy: it all sits in the one-page description, long before the vendor demo. Locating regulatory weight is a desk exercise. Interpreting regulation is a legal one. The discipline described here is only ever the first.
Second, the weight predicts where compliance cost accumulates, and in what form. A use case on the people axis buys explanation machinery and fairness testing. One on the markets axis buys surveillance and controls. One on the institution axis buys validation depth. Different apparatus, different teams, different money.
Third, if the weight varies this much across a single portfolio, a flat "AI compliance" overhead rate misprices every use case in it, in both directions. Banks risk-weight every asset on the balance sheet. The AI portfolio deserves the same arithmetic. Call the measure regulatory intensity: how much attention and apparatus a decision summons. Some use cases must clear a far higher bar to earn their place, and the useful part is that the bar is visible before the commitment.
One more property makes the map worth keeping on the desk: a use case's position on it is a design outcome. What is the system allowed to decide, about whom, with how much autonomy? Narrow the decision and the weight recedes. Let an advisory tool begin executing, or point it at consumers, and it changes axes overnight, and the bill reprices with it. You don't inherit your regulatory intensity. You select it when you decide what the system may decide.
The question is not new either, and the CFO already owns it. It is the one banks have asked of every other exposure for a century: what can this harm, and what does carrying it cost? The rulebook was never waiting on the technology. It was filed under the decision.