Banks

Ally Financial Inc.

ALLY · MI · Large bank ($50B and above)
Total assets of FDIC-insured bank subsidiaries: $184.6B at the end of 2025

Filings on the SEC website · This bank on Bankgraph

In short. In its 2025 annual report, Ally Financial Inc. mentions AI in 13 passages. It lists AI as a risk and explains how AI is controlled.

Compare with peers

In the 2025 annual reportThe yearly report a listed company files with the SEC, called a 10-K. It describes the business, its risks and its results.

Mentions AI
Yes
13 passages
Highest detail levelHow specific a passage is about AI at this bank. General: could be in any bank's report. Names an area: says where AI is used or how it is controlled. Concrete example: names a tool or vendor, gives a number, a date or a result.
Names an area
What it says
Standard wording or passing mention; General statement about AI; Sees AI as a risk
Kinds of AI named
AI agents, Process automation, Generative AI, Machine learning
How AI is controlled
Model risk management, Policy or framework, Responsible AI, Vendor oversight

AI in its annual reports over time

What this shows
How many passages about AI each annual report contains, 2022 to 2025, by what they say.
What it means
0 passages in 2022, 13 passages in 2025.
How to read it
Each bar is a report year, split by what the passages say. Hover or tap a bar for the count.
Where it comes from
Banks' annual reports (10-K) filed with the SEC, up to 6 Oct 2026. How we did this
Passages about AI in Ally Financial Inc.'s annual reports, by report year.
Show as a table
Report yearUsing or planning AIExplains how AI is controlledSees AI as a riskOther mentions
2022
2022
2022
2022
2023
2023
2023
2023
2024
2024
2024
2024
2025
2025
2025
2025

Compared with banks of its size

What this shows
This bank's 2025 annual report next to all 43 banks of its size ($50B and above).
What it means
Its most specific passage is "Names an area"; for banks of its size the typical level is "Names an area".
How to read it
Yes or no for this bank; the share of banks of the same size for comparison.
Where it comes from
Banks' annual reports (10-K) filed with the SEC, up to 6 Oct 2026. How we did this
In the 2025 reportThis bankBanks of its size
Using AI nowNo12 of 43 (28%)
Explains how AI is controlledYes30 of 43 (70%)
Sees AI as a riskYes43 of 43 (100%)
Mentions generative AIYes33 of 43 (77%)
Mentions AI agentsYes10 of 43 (23%)

What changed from 2024

8 passages new in the 2025 report, 2 passages from the 2024 report no longer there.

Every passage about AI

What this shows
All 27 passages about AI in this bank's annual reports, quarterly reports and earnings materials since 2023, newest first.
What it means
0 passages say the bank is using AI now.
How to read it
Highlighted words are the terms that matched. Labels show what each passage says. Follow the link to read it in the filing.
Where it comes from
Banks' annual reports (10-K), quarterly reports (10-Q) and earnings materials (8-K) filed with the SEC. How we did this

Quarterly report, Q2 2026 filed 23 Jul 2026

Our operational and information technology/cybersecurity/data risks continue to evolve as technological innovation accelerates. For example, frontier and other emerging AI models are rapidly changing the risk landscape across the financial services industry, which is increasing the speed, scale, and complexity of cyber threats. As these technologies advance, organizations (including us), may be required to identify, assess, and respond to emerging risks more quickly, which may require prioritizing security over other business activities. The broad availability of increasingly capable open-source AI models and other emerging technologies increases the ability of threat actors to develop, scale, and automate cyberattacks and other malicious activities. We actively monitor advances in frontier and other emerging AI and evaluate how evolving AI capabilities may be incorporated into our risk management framework. Remaining vigilant with respect to these developments is an important component of maintaining an effective approach in managing cyber threats, and failure to do so could diminish our ability to identify and respond to cyber threats in a timely manner.
Sees AI as a riskDetail: GeneralMachine learningNew this periodNew since the annual report
Quarterly report, page 97Read it in the reportReport an error

Annual report, report year 2025 filed 25 Feb 2026

Our long-term strategic objectives are centered around (1) investing in our market-leading franchises and continuing to deliver a differentiated value proposition across Dealer Financial Services, Corporate Finance, and Ally Bank, (2) ensuring our culture remains aligned with relentless focus on customers, communities, employees, and shareholders, (3) accepting risks that we can understand and effectively manage, (4) maintaining one of the most relevant and creatively disruptive brands in banking, (5) advancing technology that powers dealer and consumer centric products and services leveraging our ongoing investment in data and AI, and (6) improving financial results and shareholder returns. Within our Automotive Finance operations, we are focused on enhancing our market-leading position and delivering long-term growth in annual originations by continuing to strengthen dealer engagement, deepen strategic partnerships, and evolve our expansion strategies, while maintaining an appropriate level of risk appetite. Within our Insurance operations, we seek to grow written premiums and deliver accretive returns by leveraging our automotive dealer network and driving efficiencies through process improvements and claims management, managing risk, and leveraging strategic reinsurance. Within Corporate Finance, we seek to expand our portfolio by deepening our preexisting relationships with private equity sponsors and asset managers, while also establishing new relationships and reviewing potential opportunities in other markets and industries. Within Ally Bank, we are focused on growing our base of customers who consider us their primary bank and prioritizing improvements to customer experiences and services. At Ally Invest, we are focused on providing investment solutions for our deposit customers that will help grow and diversify their portfolios while deepening our overall relationships and providing stability to our deposits portfolio. Across the organization, we intend to drive results by pursuing opportunities to improve operating efficiencies through the strategic implementation of AI and automation solutions.
General statement about AIDetail: Names an areaProcess automationOperationsOtherNew this year
•The development and use of AI is rapidly evolving and our failure to appropriately evaluate, adopt, govern, or effectively integrate AI where beneficial could adversely affect us.
Sees AI as a riskDetail: GeneralNew this year
Our ability to manage credit risk depends in part on the effectiveness of our loan and operating lease servicing activities, including payment processing, billing and collections, customer communications, collateral management, and loss mitigation. Failures, deficiencies, or delays in these servicing functions—whether due to process breakdowns, system limitations, human or AI-related errors, third-party service providers, or increases in servicing volumes—could impair our ability to identify, monitor, and remediate emerging credit issues in a timely manner. Inadequate servicing performance may also result in delayed collections, increased delinquencies, higher charge-offs, or diminished recoveries. Servicing failures may also negatively affect customer behavior, particularly during periods of economic stress. Any such developments could result in higher credit losses which could adversely affect our business and financial results.
Sees AI as a riskDetail: GeneralNew this year
successfully conduct our business and operations have been and, in the future, could be adversely affected. These risks are amplified to the extent that we or our third-party service providers make use of cloud computing, AI or other emerging technologies that may make our systems and those of our third-party service providers more susceptible to cyberattacks and other information technology risks, which in turn could have an adverse effect on our business and operations to the extent that they are not able to mitigate their cybersecurity or other information technology risks. In addition, we may need to incur substantial expenses to address issues of concern with a service provider, and if the issues cannot be acceptably resolved, we may not be able to timely or effectively replace the service provider due to contractual restrictions, the unavailability of acceptable alternative providers, or other reasons. Further, regardless of how much we can influence our service providers, issues of concern with them could result in supervisory actions and private litigation against us and could harm our reputation, business, and financial results. In these instances, we may be unable to enforce any indemnification or other rights we may have against such service providers.
Sees AI as a riskDetail: General
The markets for automotive financing, insurance, banking, brokerage, and investment advisory services are highly competitive, and we expect competitive pressures only to remain intense in the future, especially in light of the regulatory and supervisory environments in which we operate, innovations that alter the barriers to entry, current and evolving economic and market conditions, changing customer preferences and consumer and business sentiment, and monetary and fiscal policies. In addition, the emergence, adoption, and evolution of new technologies that affect intermediation, including distributed ledgers such as digital assets and blockchain, as well as advances in robotic process automation or AI could significantly affect the competition for financial services. Refer to the section above titled Industry and Competition in Part I, Item 1 of this report. The recent resurgence of ILCs could further heighten competitive pressures, as ILCs—often affiliated with fintech and technology-enabled companies—can offer bank-like products without being subject to the full scope of regulation and supervision applicable to bank holding companies. This could enable ILCs and similar institutions to compete more aggressively against us. Competitive pressures may drive us to take actions that we might otherwise eschew, such as lowering the interest rates or fees on loans, raising the interest rates on deposits, or adopting more liberal underwriting standards. These pressures also may accelerate actions that we might otherwise elect to defer, such as substantial investment in systems or infrastructure. Whatever the reason, actions that we take in response to competition may adversely affect our results of operations and financial condition. These consequences could be exacerbated if we are not successful in introducing new products and services, achieving market acceptance of our products and services, developing and maintaining a strong customer base, continuing to enhance our reputation, or prudently managing risks and expenses.
Sees AI as a riskDetail: GeneralMachine learningProcess automation
The development and use of AI is rapidly evolving and our failure to appropriately evaluate, adopt, govern, or effectively integrate AI where beneficial could adversely affect us.
Sees AI as a riskDetail: GeneralNew this year
AI technologies are developing rapidly, and industry practices and regulatory expectations are still emerging. Our future competitiveness could depend in part on our ability to identify where AI can create value, prudently adopt and integrate AI-enabled tools and processes, and maintain appropriate governance, risk management, and controls over such technologies and the data we input into them. If we fail to keep pace with advances in AI, we may be slower or less effective than peers in realizing its benefits. Even where we determine AI adoption is appropriate, we may be unable to recruit or develop the necessary talent or successfully integrate AI into existing systems. Overly cautious adoption, or delays in deploying AI while peers advance, could result in missed opportunities, lower productivity, or loss of market share. The deployment and use of AI within our businesses and operations may present new or increased legal, regulatory, reputational, operational and other risks that further complicate model risk management, data security and privacy protection, data governance and management, and third-party risk management. AI models, including generative AI models and AI agents, may produce output that is incorrect, incomplete, misleading, or biased, or that inadvertently discloses proprietary or confidential information or infringes on the intellectual property of others, any of which could be difficult to detect, and the deployment of these models by us or our third-party service providers to produce output or perform tasks may lead to unintended consequences, the risks of which may vary depending on whether our AI use is internal or customer-facing, what systems an AI solution is integrated with, what data is being used by the AI solution, and what level of autonomy an AI solution is granted, and which our AI governance and risk management practices may not effectively mitigate. The complex nature of AI models may make it difficult to understand and explain their outputs or accurately and consistently measure model performance, particularly for frontier models developed, or fine-tuned or otherwise modified by, a third party. Our reliance on third-party service providers that develop, host, or operate AI solutions on our behalf introduces additional risks, including limited transparency into their models and dependence on their controls and monitoring activities. We may become overly reliant on the limited number of frontier model developers due to the great expense of developing such models. The legal and regulatory framework for AI—particularly in financial services—is increasingly complex, fragmented, and evolving rapidly, and there is no uniform regulatory regime for the development, deployment, and use of this technology. Multiple U.S. states, including Utah, Colorado, Texas, California, and New York, have enacted AI-specific regulations or frameworks or are
Sees AI as a riskDetail: Names an areaMachine learningGenerative AIAI agentsNew this year
considering how existing laws and regulations apply to these technologies, while the federal government in the United States has sought to establish a national standard for AI policy to spur innovation and sustain and enhance the United States’ global AI dominance, including by issuing a directive that seeks to limit state AI laws that are inconsistent with this policy. This fragmented regulatory landscape may impose new, inconsistent obligations or constraints, and meeting these requirements could increase costs and risk of noncompliance, limit certain AI applications, or necessitate changes to existing processes or controls. If we do not appropriately monitor developments in AI, invest selectively and responsibly in relevant capabilities, and implement effective controls commensurate with our risk profile, we could be subjected to regulatory scrutiny, and our business, financial results, and reputation could be adversely affected.
Sees AI as a riskDetail: GeneralNew this year
malicious or destructive code, social engineering (including phishing, spear phishing, or other attacks), deepfake-enabled attacks, denial-of-service or denial-of-information attacks, ransomware, account takeover or identity theft, fraudulent remote work schemes, access violations or other insider threats by employees or vendors, attacks on the personal email of employees, and ransom demands accompanied by extortion or other threats to expose security vulnerabilities. Cyberattacks and fraud targeting banking customers have increased in frequency and sophistication across the financial services industry. Customers who are victims of such schemes may incur financial losses or experience service disruptions and may attribute those losses or negative experiences to us, even where we are not at fault. These incidents could result in increased fraud-related losses, customer remediation and operational costs, regulatory scrutiny, and reputational harm. In addition, we are subject to additional risks as a result of the mishandling or misuse of personal information by our employees or third-party service providers. Data breaches at our third-party service providers have in the past and may in the future continue to expose confidential information about our company and customers to bad actors. We have been subject to litigation in the past in connection with data breaches and in the future could be subject to significant legal costs and damages, regulatory fines or penalties, reputational damage or other adverse effects as a result of data breaches. These risks, including the scope and consequences of any breach, may be amplified due to our and our third-party service providers use of AI, cloud-based services and other emerging technologies in connection with our governance, management, and use of data. Risks relating to cyberattacks on our service providers and other third-parties, including supply-chain attacks affecting our software and information-technology providers, have been rising as such attacks become increasingly frequent and severe. The development of new technologies, systems or processes, as well as the utilization of decentralized technology infrastructures (such as our increased utilization of cloud computing), software-defined networks and AI, could expose us to additional cybersecurity risks and could increase the spread and severity of any cyberattacks. Further, the use of AI by cybercriminals has and may continue to increase the frequency and severity of cybersecurity attacks against us or our service providers and others on whom we rely. All of these factors increase the susceptibility of our networks to unauthorized access and could increase the amount of information that may be available to cybercriminals in the event of a successful cybersecurity attack. We, our service providers, and others on whom we rely are also exposed to more traditional security threats to physical facilities and personnel.
Sees AI as a riskDetail: GeneralNew this year
As a digital financial-services company and a direct bank with no branch network, we significantly depend on technology to deliver our products and services and to otherwise conduct our business and operations. To remain technologically competitive and operationally efficient, we invest in system upgrades, new solutions, cloud-based services, AI, and other technology initiatives. Many of these initiatives take a significant amount of time to develop and implement, are tied to critical systems, and require substantial financial, human, and other resources. Further, our utilization of AI technologies could result in content, analyses, or automated tasks that are inaccurate, deficient, or otherwise erroneous. Although we take steps to mitigate the risks and uncertainties associated with these initiatives, they are not always implemented on time, within budget, or without negative financial, operational, or customer impact and do not always perform as we or our customers expect, and no assurance can be provided that initiatives in the future will be or will do so. We also may not succeed in anticipating or keeping pace with future technology needs, the technology demands of customers, or the competitive landscape for technology. For example, many of our competitors have begun utilizing AI to offer new products and services to their customers. If we are unable to meet evolving customer expectations and industry standards regarding the development and implementation of AI and emerging technologies, or if we were to misstep in any of these areas, our business, financial results, or reputation could be negatively impacted. Our use of systems and other technologies also depends on rights or interests in the underlying intellectual property, which we or our service providers may own or license. If we or a service provider were alleged or found to be infringing on the intellectual-property rights of another person or entity, we could be liable for significant damages for past infringement, substantial fees for continued use, and deprivation of access for limited or extended periods of time without the practical availability of an alternative.
Sees AI as a riskDetail: Names an area
The MRM function’s specific responsibility includes maintaining a centralized inventory of all models in production, under development, or recently retired; performing independent validation and annual review testing to verify that models are built as intended, conceptually sound, and appropriate for their intended use; monitoring ongoing model performance to identify potential model degradation; and producing risk appetite metrics and key risk indicators for consumption by Board-level and management-level risk committees. The MVG within the MRM function is a team of risk professionals with advanced degrees in the areas of economics, econometrics, mathematical finance, and statistics. MVG also has subject matter expertise in model validation, model development, analytics, data science, AI, and anti-money laundering and fraud detection.
Standard wording or passing mentionDetail: GeneralSame as last year
Cybersecurity and the continued enhancement of our controls, processes, and systems to protect our technology and data infrastructure, customer information, and other proprietary information or assets remain a critical and ongoing priority. We recognize that cyber-related risks continue to evolve, including through the emergence of AI, and have become increasingly sophisticated. As a result we continuously evaluate the adequacy of our preventive and detective measures. As a further protective measure, we maintain insurance coverage that, subject to terms and conditions, may cover certain aspects of cybersecurity and information risks. However, such insurance may not be sufficient to cover all losses, and there is no guarantee that such insurance will continue to be available to us on acceptable terms, if at all.
Sees AI as a riskDetail: General

Annual report, report year 2024 filed 19 Feb 2025

We seek to distinguish ourselves as a customer-centric company that delivers passionate customer service and innovative financial solutions and that is relentlessly focused on “Doing it Right.” Third-party service providers, however, are key to much of our business and operations, including online and mobile banking, brokerage, customer service, and operating systems and infrastructure. We rely on our third-party service providers to provide critical products and services to facilitate our business activities, including by providing data and information, technology, security and other infrastructure services. While we have implemented a supplier-risk-management program and can exert varying degrees of influence over our service providers, we do not control them, their actions, or their businesses. Our contracts with service providers, moreover, may not require or sufficiently incent them to perform at levels and in ways that we would choose to act on our own. Despite our supplier-risk-management program, there can be no assurance that our third-party service providers will notify us of any potential risks or incidents in a timely manner or that our risk-management procedures will be effective in mitigating the impact of actions by third-party service providers on our business. Service providers have not always met our requirements and expectations, and no assurance can be provided that in the future they will perform to our standards, adequately represent our brand, comply with applicable law, appropriately manage their own risks (including cybersecurity), remain financially or operationally viable, abide by their contractual obligations, or continue to provide us with the services that we require. In such a circumstance, our ability to deliver products and services to customers, to satisfy customer expectations, and to otherwise successfully conduct our business and operations have been and, in the future, could be adversely affected. These risks are amplified to the extent that we or our third-party service providers make use of cloud computing, artificial intelligence or other emerging technologies that may make our systems and those of our third-party service providers more susceptible to cyberattacks, which in turn could have an adverse effect on our business and operations to the extent that they are not able to mitigate their cybersecurity risks. In addition, we may need to incur substantial expenses to address issues of concern with a service provider, and if the issues cannot be acceptably resolved, we may not be able to timely or effectively replace the service provider due to contractual restrictions, the unavailability of acceptable alternative providers, or other reasons. Further, regardless of how much we can influence our service providers, issues of concern with them could result in supervisory actions and private litigation against us and could harm our reputation, business, and financial results.
Sees AI as a riskDetail: GeneralNew this year
The markets for automotive financing, insurance, banking, brokerage, and investment-advisory services are highly competitive, and we expect competitive pressures only to remain intense in the future, especially in light of the regulatory and supervisory environments in which we operate, innovations that alter the barriers to entry, current and evolving economic and market conditions, changing customer preferences and consumer and business sentiment, and monetary and fiscal policies. In addition, the emergence, adoption, and evolution of new technologies that affect intermediation, including distributed ledgers such as digital assets and blockchain, as well as advances in robotic process automation or artificial intelligence could significantly affect the competition for financial services. Refer to the section above titled Industry and Competition in Part I, Item 1 of this report. Competitive pressures may drive us to take actions that we might otherwise eschew, such as lowering the interest rates or fees on loans, raising the interest rates on deposits, or adopting more liberal underwriting standards. These pressures also may accelerate actions that we might otherwise elect to defer, such as substantial investment in systems or infrastructure. Whatever the reason, actions that we take in response to competition may adversely affect our results of operations and financial condition. These consequences could be exacerbated if we are not successful in introducing new products and services, achieving market acceptance of our products and services, developing and maintaining a strong customer base, continuing to enhance our reputation, or prudently managing risks and expenses.
Sees AI as a riskDetail: GeneralMachine learningProcess automationSame as last year
technologies, the continued expansion of the use of internet and telecommunications technologies (including mobile devices) to conduct financial and other business transactions, and the increased sophistication and activities of hostile state-sponsored actors, organized crime, perpetrators of fraud, hackers, terrorists, and others. We, along with other financial institutions, our service providers, and others on whom we rely, have been and are expected to continue to be the target of cyberattacks and fraud, which could include computer viruses, malware, malicious or destructive code, social engineering (including phishing, spear phishing, or other attacks), denial-of-service or denial-of-information attacks, ransomware, account takeover or identity theft, fraudulent remote work schemes, access violations or other insider threats by employees or vendors, attacks on the personal email of employees, and ransom demands accompanied by extortion or other threats to expose security vulnerabilities. In addition, we are subject to additional risks as a result of the mishandling or misuse of personal information by our employees or third-party service providers. Data breaches at our third-party service providers have in the past and may in the future continue to expose confidential information about our company and customers to bad actors. We have been subject to litigation in the past in connection with data breaches and in the future could be subject to significant legal costs and damages, regulatory fines or penalties, reputational damage or other adverse effects as a result of data breaches. These risks may be amplified due to our and our third-party service providers use of cloud-based services and other emerging technologies in connection with our data governance activities. Risks relating to cyberattacks on our service providers and other third-parties, including supply-chain attacks affecting our software and information-technology providers, have been rising as such attacks become increasingly frequent and severe. The development of new technologies, systems or processes, as well as the utilization of decentralized technology infrastructures (such as our increased utilization of cloud computing), software-defined networks and artificial intelligence, could expose us to additional cybersecurity risks. Further, the use of artificial intelligence by cybercriminals may increase the frequency and severity of cybersecurity attacks against us or our service providers and others on whom we rely. All of these factors increase the susceptibility of our networks to unauthorized access and could increase the amount of information that may be available to cybercriminals in the event of a successful cybersecurity attack. We, our service providers, and others on whom we rely are also exposed to more traditional security threats to physical facilities and personnel.
Sees AI as a riskDetail: GeneralNew this year
As a digital financial-services company and a direct bank with no branch network, we significantly depend on technology to deliver our products and services and to otherwise conduct our business and operations. To remain technologically competitive and operationally efficient, we invest in system upgrades, new solutions, cloud-based services, artificial intelligence, and other technology initiatives. Many of these initiatives take a significant amount of time to develop and implement, are tied to critical systems, and require substantial financial, human, and other resources. Further, our utilization of artificial intelligence technologies could result in content or analyses that are inaccurate or deficient. Although we take steps to mitigate the risks and uncertainties associated with these initiatives, they are not always implemented on time, within budget, or without negative financial, operational, or customer impact and do not always perform as we or our customers expect, and no assurance can be provided that initiatives in the future will be or will do so. We also may not succeed in anticipating or keeping pace with future technology needs, the technology demands of customers, or the competitive landscape for technology. If we were to misstep in any of these areas, our business, financial results, or reputation could be negatively impacted. Our use of systems and other technologies also depends on rights or interests in the underlying intellectual property, which we or our service providers may own or license. If we or a service provider were alleged or found to be infringing on the intellectual-property rights of another person or entity, we could be liable for significant damages for past infringement, substantial fees for continued use, and deprivation of access for limited or extended periods of time without the practical availability of an alternative.
Sees AI as a riskDetail: Names an area
The MRM function’s specific responsibility includes maintaining a centralized inventory of all models in production, under development, or recently retired; performing independent validation and annual review testing to verify that models are built as intended, conceptually sound, and appropriate for their intended use; monitoring ongoing model performance to identify potential model degradation; and producing risk appetite metrics and key risk indicators for consumption by Board-level and management-level risk committees. The MVG within the MRM function is a team of risk professionals with advanced degrees in the areas of economics, econometrics, mathematical finance, and statistics. MVG also has subject matter expertise in model validation, model development, analytics, data science, artificial intelligence, and anti-money laundering and fraud detection.
Standard wording or passing mentionDetail: GeneralSame as last year
Cybersecurity and the continued enhancement of our controls, processes, and systems to protect our technology and data infrastructure, customer information, and other proprietary information or assets remain a critical and ongoing priority. We recognize that cyber-related risks continue to evolve, including through the emergence of artificial intelligence, and have become increasingly sophisticated. As a result we continuously evaluate the adequacy of our preventive and detective measures. As a further protective measure, we maintain insurance coverage that, subject to terms and conditions, may cover certain aspects of cybersecurity and information risks. However, such insurance may not be sufficient to cover all losses, and there is no guarantee that such insurance will continue to be available to us on acceptable terms, if at all.
Sees AI as a riskDetail: General

Earnings release, Q1 2024 filed 27 Mar 2024

Prior to Discover, Rhodes spent over 12 years at TD Bank, most recently as Group Head, Canadian Personal Banking, where he oversaw the division dedicated to retail products and serving customers through mobile, online, telephone, and a branch network over one thousand strong. During his tenure at TD Bank, Rhodes also led North American Credit Card and Merchant Services and served as Head of Innovation, Technology, and Shared Services. In this role, Rhodes strengthened operational resilience, security, and efficiency while improving the bank’s capability to support emerging technologies, such as artificial intelligence and cloud migration. He has also held senior positions at Bank of America and MBNA America Bank.
Standard wording or passing mentionDetail: GeneralNew this periodNew since the annual report

Annual report, report year 2023 filed 20 Feb 2024

The markets for automotive financing, insurance, banking (including corporate finance, mortgage finance, and credit-card products), brokerage, and investment-advisory services are highly competitive, and we expect competitive pressures only to intensify in the future, especially in light of the regulatory and supervisory environments in which we operate, innovations that alter the barriers to entry, current and evolving economic and market conditions, changing customer preferences and consumer and business sentiment, and monetary and fiscal policies. In addition, the emergence, adoption, and evolution of new technologies that affect intermediation, including distributed ledgers such as digital assets and blockchain, as well as advances in robotic process automation or artificial intelligence could significantly affect the competition for financial services. Refer to the section above titled Industry and Competition in Part I, Item 1 of this report. Competitive pressures may drive us to take actions that we might otherwise eschew, such as lowering the interest rates or fees on loans, raising the interest rates on deposits, or adopting more liberal underwriting standards. These pressures also may accelerate actions that we might otherwise elect to defer, such as substantial investment in systems or infrastructure. Whatever the reason, actions that we take in response to competition may adversely affect our results of operations and financial condition. These consequences could be exacerbated if we are not successful in introducing new products and services, achieving market acceptance of our products and services, developing and maintaining a strong customer base, continuing to enhance our reputation, or prudently managing risks and expenses.
Sees AI as a riskDetail: GeneralProcess automationSame as last year
Our operating systems and infrastructure, as well as those of our service providers or others on whom we rely, are subject to security risks that are rapidly evolving and increasing in scope, complexity, and frequency. This is due, in part, to the introduction of new technologies, the continued expansion of the use of internet and telecommunications technologies (including mobile devices) to conduct financial and other business transactions, and the increased sophistication and activities of hostile state-sponsored actors, organized crime, perpetrators of fraud, hackers, terrorists, and others. We, along with other financial institutions, our service providers, and others on whom we rely, have been and are expected to continue to be the target of cyberattacks, which could include computer viruses, malware, malicious or destructive code, social engineering (including phishing or spear phishing attacks), denial-of-service or denial-of-information attacks, ransomware, identity theft, access violations by employees or vendors, attacks on the personal email of employees, and ransom demands accompanied by threats to expose security vulnerabilities. Risks relating to cyberattacks on our service providers and other third parties, including supply-chain attacks affecting our software and information-technology providers, have been rising as such attacks become increasingly frequent and severe. The development of new technologies, as well as the utilization of decentralized technology infrastructures (such as our increased utilization of cloud computing) and software-defined networks, could expose us to additional cybersecurity risks. Further, the use of artificial intelligence by cybercriminals may increase the frequency and severity of cybersecurity attacks against us or our service providers and others on whom we rely. We, our service providers, and others on whom we rely are also exposed to more traditional security threats to physical facilities and personnel.
Sees AI as a riskDetail: GeneralNew this year
As a digital financial-services company and a direct bank with no branch network, we significantly depend on technology to deliver our products and services and to otherwise conduct our business and operations. To remain technologically competitive and operationally efficient, we invest in system upgrades, new solutions, cloud-based services, and other technology initiatives. Many of these initiatives take a significant amount of time to develop and implement, are tied to critical systems, and require substantial financial, human, and other resources, and our utilization of artificial intelligence technologies could result in content or analyses that are inaccurate or deficient. Although we take steps to mitigate the risks and uncertainties associated with these initiatives, they are not always implemented on time, within budget, or without negative financial, operational, or customer impact and do not always perform as we or our customers expect, and no assurance can be provided that initiatives in the future will be or will do so. We also may not succeed in anticipating or keeping pace with future technology needs, the technology demands of customers, or the competitive landscape for technology. If we were to misstep in any of these areas, our business, financial results, or reputation could be negatively impacted. Our use of systems and other technologies also depends on rights or interests in the underlying intellectual property, which we or our service providers may own or license. If we or a service provider were alleged or found to be infringing on the intellectual-property rights of another person or entity, we could be liable for significant damages for past infringement, substantial fees for continued use, and deprivation of access for limited or extended periods of time without the practical availability of an alternative.
Sees AI as a riskDetail: GeneralNew this year
The model risk management function’s specific responsibility includes maintaining a centralized inventory of all models in production, under development, or recently retired; performing independent validation and annual review testing to verify that models are built as intended, conceptually sound, and appropriate for their intended use; monitoring ongoing model performance to identify potential model degradation; and producing risk appetite metrics and key risk indicators for consumption by Board-level and management-level risk committees. The MVG within the MRM function is a team of risk professionals with advanced degrees in the areas of economics, econometrics, mathematical finance, and statistics. MVG also has subject matter expertise in model validation, model development, analytics, data science, artificial intelligence, and anti-money laundering and fraud detection.
Standard wording or passing mentionDetail: GeneralNew this year
Cybersecurity and the continued enhancement of our controls, processes, and systems to protect our technology infrastructure, customer information, and other proprietary information or assets remain a critical and ongoing priority. We recognize that cyber-related risks continue to evolve, including through the emergence of artificial intelligence, and have become increasingly sophisticated. As a result we continuously evaluate the adequacy of our preventive and detective measures. As a further protective measure, we maintain insurance coverage that, subject to terms and conditions, may cover certain aspects of cybersecurity and information risks. However, such insurance may not be sufficient to cover all losses.
Sees AI as a riskDetail: GeneralNew this year
11 passages in legal noticesThe forward-looking statements notice at the start or end of a filing. It often lists AI among many risks. It is never counted., not counted
•our ability to keep pace with changes in technology, such as AI, that affect us or our customers, counterparties, service providers, or competitors or to maintain rights or interests in associated intellectual property;
Same as last period
Quarterly report, page 72Read it in the reportReport an error
•our ability to keep pace with changes in technology, such as AI, that affect us or our customers, counterparties, service providers, or competitors or to maintain rights or interests in associated intellectual property;
Same as last period
Quarterly report, page 63Read it in the reportReport an error
•our ability to keep pace with changes in technology, such as AI, that affect us or our customers, counterparties, service providers, or competitors or to maintain rights or interests in associated intellectual property;
Same as last year
•our ability to keep pace with changes in technology, such as artificial intelligence, that affect us or our customers, counterparties, service providers, or competitors or to maintain rights or interests in associated intellectual property;
Same as last period
Quarterly report, page 73Read it in the reportReport an error
•our ability to keep pace with changes in technology, such as artificial intelligence, that affect us or our customers, counterparties, service providers, or competitors or to maintain rights or interests in associated intellectual property;
Same as last period
Quarterly report, page 70Read it in the reportReport an error
•our ability to keep pace with changes in technology, such as artificial intelligence, that affect us or our customers, counterparties, service providers, or competitors or to maintain rights or interests in associated intellectual property;
Same as last period
Quarterly report, page 63Read it in the reportReport an error
•our ability to keep pace with changes in technology, such as artificial intelligence, that affect us or our customers, counterparties, service providers, or competitors or to maintain rights or interests in associated intellectual property;
Same as last year
•our ability to keep pace with changes in technology, such as artificial intelligence, that affect us or our customers, counterparties, service providers, or competitors or to maintain rights or interests in associated intellectual property;
Same as last period
Quarterly report, page 77Read it in the reportReport an error
•our ability to keep pace with changes in technology, such as artificial intelligence, that affect us or our customers, counterparties, service providers, or competitors or to maintain rights or interests in associated intellectual property;
Same as last period
Quarterly report, page 77Read it in the reportReport an error
•our ability to keep pace with changes in technology, such as artificial intelligence, that affect us or our customers, counterparties, service providers, or competitors or to maintain rights or interests in associated intellectual property;
New this period
Quarterly report, page 66Read it in the reportReport an error
•our ability to keep pace with changes in technology, such as artificial intelligence, that affect us or our customers, counterparties, service providers, or competitors or to maintain rights or interests in associated intellectual property;
New this year