Banks

Capital One Financial Corp

COF, COF-PI, COF-PJ, COF-PK, COF-PL, COF-PN · VA · Large bank ($50B and above)
Total assets of FDIC-insured bank subsidiaries: $658.5B at the end of 2025

Filings on the SEC website · This bank on Bankgraph

In short. In its 2025 annual report, Capital One Financial Corp mentions AI in 29 passages. It says it is using AI now, for credit and lending, fraud detection and marketing. It lists AI as a risk and explains how AI is controlled.

Compare with peers

In the 2025 annual reportThe yearly report a listed company files with the SEC, called a 10-K. It describes the business, its risks and its results.

Mentions AI
Yes
29 passages
Highest detail levelHow specific a passage is about AI at this bank. General: could be in any bank's report. Names an area: says where AI is used or how it is controlled. Concrete example: names a tool or vendor, gives a number, a date or a result.
Names an area
What it says
General statement about AI; Sees AI as a risk; Using AI now; Standard wording or passing mention
Kinds of AI named
AI agents, Process automation, Generative AI, Machine learning
How AI is controlled
Model risk management, Policy or framework, Vendor oversight

AI in its annual reports over time

What this shows
How many passages about AI each annual report contains, 2022 to 2025, by what they say.
What it means
2 passages in 2022, 29 passages in 2025.
How to read it
Each bar is a report year, split by what the passages say. Hover or tap a bar for the count.
Where it comes from
Banks' annual reports (10-K) filed with the SEC, up to 6 Oct 2026. How we did this
Passages about AI in Capital One Financial Corp's annual reports, by report year.
Show as a table
Report yearUsing or planning AIExplains how AI is controlledSees AI as a riskOther mentions
2022
2022
2022
2022
2023
2023
2023
2023
2024
2024
2024
2024
2025
2025
2025
2025

Compared with banks of its size

What this shows
This bank's 2025 annual report next to all 43 banks of its size ($50B and above).
What it means
Its most specific passage is "Names an area"; for banks of its size the typical level is "Names an area".
How to read it
Yes or no for this bank; the share of banks of the same size for comparison.
Where it comes from
Banks' annual reports (10-K) filed with the SEC, up to 6 Oct 2026. How we did this
In the 2025 reportThis bankBanks of its size
Using AI nowYes12 of 43 (28%)
Explains how AI is controlledYes30 of 43 (70%)
Sees AI as a riskYes43 of 43 (100%)
Mentions generative AIYes33 of 43 (77%)
Mentions AI agentsYes10 of 43 (23%)

What changed from 2024

21 passages new in the 2025 report, 9 passages from the 2024 report no longer there.

Every passage about AI

What this shows
All 85 passages about AI in this bank's annual reports, quarterly reports and earnings materials since 2023, newest first.
What it means
5 passages say the bank is using AI now.
How to read it
Highlighted words are the terms that matched. Labels show what each passage says. Follow the link to read it in the filing.
Where it comes from
Banks' annual reports (10-K), quarterly reports (10-Q) and earnings materials (8-K) filed with the SEC. How we did this

Annual report, report year 2025 filed 19 Feb 2026

We leverage information and technology to achieve our business objectives and to develop and deliver products and services. A key part of our strategic focus is the development and use of efficient, flexible computer and operational systems, such as cloud or artificial intelligence (“AI”) technologies. We believe that the continued adoption, development and integration of these technologies is an important part of our efforts to reduce costs, improve quality and security and provide faster, more flexible technology services. Consequently, we frequently consider our capabilities and develop or acquire systems, processes and competencies to meet our business requirements or objectives.
General statement about AIDetail: GeneralNew this year
•We face risks resulting from the extensive use of models and data, as well as from our evolving use of AI.
Sees AI as a riskDetail: GeneralSame as last year
•Technology-driven disruption of certain industries, such as those due to advances in AI, robotics and cryptocurrency;
Label being checked, not counted yetSame as last year
Decreases in overall business activity and changes in customer behavior (such as the increased use of debt settlement companies) may lead to increases in our charge-off rate caused by bankruptcies and may reduce our ability to recover debt that we have previously charged off. Such changes may also decrease the reliability of our internal processes and models, including those we use to estimate our allowance for credit losses, particularly if unexpected variations in key inputs and assumptions cause actual losses to diverge from the projections of our models and our estimates become increasingly subject to management’s judgment. See “We face risks resulting from the extensive use of models and data, as well as from our evolving use of AI.”
Sees AI as a riskDetail: GeneralNew this year
•Incorrect Estimates of Expected Credit Losses: The credit quality of our loan portfolios can have a significant impact on our earnings. We allow for and reserve against credit risks based on our assessment of expected credit losses in our loan portfolios. This process, which is critical to our financial condition and results of operations, requires complex judgments, including forecasts of economic conditions. We may underestimate our expected credit losses and fail to hold an allowance for credit losses sufficient to account for these credit losses. Incorrect assumptions could lead to material underestimations of expected credit losses and an inadequate allowance for credit losses. See “We face risks resulting from the extensive use of models and data, as well as from our evolving use of AI.”
Sees AI as a riskDetail: GeneralSame as last year
Similar to other large corporations in our industry, we are exposed to operational risk that can manifest itself in many ways, such as errors in execution, inadequate processes, inaccurate models, faulty or disabled technological infrastructure, malicious disruption and fraud by employees or persons outside of our company, whether through attacks on Capital One directly, or on our third-party service providers or customers. In addition, the increased use of near real-time money movement solutions and the use of AI, as well as other emerging technologies, increases the complexity of preventing, detecting and recovering fraudulent transactions. We are also heavily dependent on the security, capability, integrity and continuous availability of the technology systems and networks that we use to manage our internal financial and other systems, monitor risk and compliance with regulatory requirements, provide services to our customers, develop and offer new products and communicate with stakeholders. In addition, our employees, service providers, partners and other third parties with whom we interact may expose us to certain risks as a result of human error or misconduct. For example, errors in processing wire transfers may result in the inadvertent release of funds in incorrect amounts or to incorrect recipients, and we may be unable to recover such funds. In addition, in connection with the integration of Discover, we may experience increased risks associated with processing a large volume of transactions in multiple currencies and in jurisdictions where we have not historically operated.
Sees AI as a riskDetail: Names an areaNew this year
For example, on July 29, 2019, we announced that on March 22 and 23, 2019 an outside individual gained unauthorized access to our systems (the “2019 Cybersecurity Incident”). This individual obtained certain types of personal information relating to people who had applied for our credit card products and to our credit card customers. While the 2019 Cybersecurity Incident has been remediated, it resulted in fines, litigation, consent orders, settlements, government investigations and other regulatory enforcement inquiries. Cyber and information security risks for large financial institutions like us continue to increase due to the proliferation of new technologies, the industry-wide shift to reliance upon the internet to conduct financial transactions, the increased sophistication and activities of malicious actors, organized crime, perpetrators of fraud, hackers, terrorists, activists, extremist parties, formal and informal instrumentalities of foreign governments, state-sponsored or nation-state actors and other external parties and the growing use of AI by threat actors.
Sees AI as a riskDetail: GeneralSame as last year
In addition, our customers access our products and services using personal devices that are necessarily external to our security control systems. There has also been a significant proliferation of consumer information available on the internet resulting from breaches of third-party entities, including personal information, log-in credentials and authentication data. These third-party breach events could create a threat for our customers if their Capital One log-in credentials are the same as or similar to the credentials that have been compromised on other internet sites. This threat could include the risk of unauthorized account access, data loss and fraud. The use of AI, “bots” or other automation software can increase the velocity and efficacy of these types of attacks and such use by companies has resulted in, and may continue to result in, cyber-attacks and other security incidents that implicate the sensitive and confidential information, including personal information, of AI users. As our employees and contractors are operating under our hybrid work model, our remote interaction with employees, service providers, partners and other third parties on systems, networks and environments over which we have less control (such as through employees’ personal devices) increases our cybersecurity risk exposure. We will likely face an increasing number of attempted cyber-attacks as we expand our mobile and other internet-based products and services, expand our usage of mobile, cloud and other internet-based technologies, increase international merchant acceptance of credit cards issued on the Discover Network, acquire new business operations or outsource certain business operations and otherwise attempt to keep pace with rapid technological changes in the financial services industry.
Sees AI as a riskDetail: GeneralProcess automation
The methods and techniques employed by malicious actors continue to develop and evolve rapidly, including from emerging technologies, such as AI and quantum computing, are increasingly sophisticated and often are not fully recognized or understood until after they have occurred, and some techniques could occur and enable persistent access for an extended period of time before being detected and remediated, if at all. We and our service providers and other third parties with which we interact may be unable to anticipate or identify certain attack methods or techniques in order to implement effective
Sees AI as a riskDetail: General
We face risks resulting from the extensive use of models and data, as well as from our evolving use of AI.
Sees AI as a riskDetail: GeneralSame as last year
We rely on quantitative models and, in some cases, the use of AI. We also rely on our ability to manage and aggregate data in an accurate and timely manner, to assess and manage our various risk exposures, to create estimates and forecasts, and to manage compliance with regulatory capital requirements. In particular, we use models and AI in certain processes and may expand our use of AI in additional processes in the future. Some examples may include determining the pricing of products, identifying potentially fraudulent transactions, grading loans, extending credit, measuring market and interest rate risks, predicting deposit levels or loan losses, assessing capital adequacy, estimating the value of financial instruments and balance sheet items, software development, personalizing customer experiences and other operational functions. We continue to invest in building new capabilities that use new AI technologies, such as generative AI, and we expect our use of these technologies to increase over time.
Using AI nowDetail: Names an areaMachine learningGenerative AIFraud detectionCredit and lendingMarketingSoftware developmentOperationsRisk managementNew this year
However, there are significant risks involved in using models and AI, and we cannot assure that our use will enhance our businesses or produce only the intended or beneficial results. For example, generative AI has been known to produce false or “hallucinatory” inferences or output. Certain generative AI tools use machine learning and predictive analytics, which can create inaccurate, incomplete or misleading outputs; unexpected results; or errors or inadequacies, any of which may not be easily detectable. In addition, models and AI that are based on historical data sets might not be accurate predictors of future outcomes. The ability of models and AI to appropriately predict future outcomes may degrade over time due to limited historical patterns, extreme or unanticipated market movements, or customer behavior and liquidity, especially during severe market downturns or stress events (e.g., geopolitical or pandemic events). Consequently, our use of models and AI could result in inaccurate forecasts, ineffective risk management practices, inaccurate risk reporting and other negative or unexpected consequences.
Sees AI as a riskDetail: GeneralMachine learningGenerative AINew this year
AI may subject us to new or heightened legal, regulatory, ethical or other challenges, and a negative public opinion of AI could impede the acceptance of AI solutions. If the models or AI solutions that we or a third party create and use or the data inputs, formulas, or algorithms on which such models or AI solutions rely – or if the content, analyses or recommendations that the models or AI solutions produce are (or are perceived to be) deficient, inaccurate, biased, unethical or controversial – we could incur operational inefficiencies, competitive harm, legal liability, or brand or reputational harm. We could also incur other adverse impacts on our businesses and financial results. We may be liable if we were to violate applicable laws and regulations, third-party intellectual property, privacy or other rights, or contracts we have. Further, the use of models and AI solutions within products or services that we use or that are used by our third-party service providers may pose similar risks, and we have limited ability to control the manner in which third-party products are developed or maintained or the manner in which third-party services are provided.
Sees AI as a riskDetail: GeneralMachine learningNew this year
The development and implementation of some of these models require us to make difficult, subjective and complex judgments. Our risk reporting and risk management, including our business decisions that are based on information gathered through models and AI, depend on the effectiveness of our models and AI. They also depend on our policies, programs, processes and practices governing how data, models and AI are acquired, validated, stored, protected, processed and analyzed, including our data aggregation and validation procedures, and any issues with the quality or effectiveness of the foregoing could have negative consequences.
Sees AI as a riskDetail: Names an areaMachine learningRisk managementNew this year
While we continuously update our policies, programs, processes and risk management practices, many of our data management, modeling, AI, aggregation and implementation processes are manual. They may be subject to human error, data limitations, process delays or system failure. If any of our employees, contractors, third-party service providers or other third parties with which we do business use any third-party AI solutions in connection with our business, it may lead to the inadvertent or unauthorized disclosure or incorporation of our sensitive and confidential information, including personal information, into third-party systems or publicly available or third-party training sets, which may impact our ability to realize the benefit of our intellectual property or other proprietary rights in such information. Failure to manage data effectively and to aggregate data in an accurate and timely manner may limit our ability to manage current and emerging risks; to produce accurate financial, regulatory and operational reporting; and to manage changing business needs. If our Framework is ineffective, we could suffer unexpected losses, which could materially adversely affect our results of operation or financial condition.
Sees AI as a riskDetail: Names an areaNew this year
Any information we provide to the public or to our regulators based on incorrectly designed/implemented models or AI could be inaccurate or misleading. Some of the decisions that our regulators make could be adversely affected if their perception is that the quality of the data, models and AI used to generate the information is insufficient.
Sees AI as a riskDetail: GeneralNew this year
The regulation of AI is rapidly evolving worldwide as legislators and regulators are increasingly focused on these powerful, emerging technologies. The technologies underlying AI and its uses are subject to a variety of laws and regulations, including intellectual property, privacy, data protection and data security, consumer protection, competition and equal opportunity laws and regulations. They are expected to be subject to increased regulation and new laws or new applications of existing laws and regulations.
Sees AI as a riskDetail: GeneralNew this year
Various U.S. governmental and regulatory agencies continue to review AI. Several U.S. states and foreign jurisdictions are applying (or are considering applying) their platform moderation, privacy, data protection, and data security laws and regulations to AI. They are also considering general legal frameworks for AI. In particular, several states, including Colorado and California, have passed or are continuing to propose laws and regulations that govern various facets and uses of AI.
Sees AI as a riskDetail: GeneralNew this year
We may not be able to anticipate how to respond to these rapidly evolving frameworks, and we may need to expend resources to adjust our offerings in certain jurisdictions if the legal frameworks are inconsistent across jurisdictions. Furthermore, because AI technology itself is highly complex and rapidly developing, it is not possible to predict all of the legal, operational, competitive or technological risks that may arise from using AI.
Sees AI as a riskDetail: GeneralSame as last year
Emerging generative AI capabilities, such as synthetic video, images and identity documents may introduce new risks, in the form of identity fraud and scams. Additionally, the growth of agentic commerce, in which autonomous AI agents initiate and execute transactions on behalf of users, may increase fraud losses as well as change circumstances when the merchant or issuer is liable for fraud losses.
Sees AI as a riskDetail: GeneralGenerative AIAI agentsNew this year
Legal frameworks governing such autonomous agents remain nascent, with limited direct guidance, and the interplay between laws and regulations relating to, among other things, fraud, payments, privacy, data protection, data security and AI may create uncertainty around compliance obligations and potential liability exposure as more participants (including sellers, fintechs, AI developers and enablers) enter the agentic commerce ecosystem.
Sees AI as a riskDetail: GeneralAI agentsNew this year
The legislative, regulatory and supervisory environment is beyond our control, may change rapidly and unpredictably, and may negatively influence our revenue, costs, operations, transaction volumes, earnings, growth, liquidity and capital levels. There have been efforts to impose price controls and other impositions. Such changes, among others, could impact credit availability, affect our ability or willingness to provide certain products or services, necessitate changes to our business practices or materially reduce our revenues. Some laws and regulations may be subject to litigation or other challenges that delay implementation or result in modifications, rescissions or withdrawals, which impacts us. Furthermore, political and policy goals of elected and appointed officials may change over time, which could impact the rulemaking, supervision, examination and enforcement priorities of the Federal Banking Agencies. It is possible that expected changes in law, regulation and policy do not occur or are reversed subsequently, or the regulatory measures that are ultimately enacted deliver significant competitive advantages to financial services that are structured differently or serve different markets than us. For example, there may be future legislation or rulemaking in emerging regulatory areas, such as a more accommodative stance on novel financial services or new technologies, including those related to stablecoins. Adoption of new technologies, such as distributed ledger technologies, tokenization, cloud computing, AI and machine learning technologies, can present challenges in applying and relying on existing compliance systems.
Sees AI as a riskDetail: GeneralMachine learningNew this year
Further, we make public statements about our use, collection, disclosure and other processing of personal information through our privacy policies, information provided on our website and press statements. Although we endeavor to comply with our public statements and documentation, we may at times fail to do so or be alleged to have failed to do so. The publication of our privacy policies and other statements that provide promises and assurances about privacy, data protection and data security can subject us to potential government or legal action if they are found to be deceptive, unfair or misrepresentative of our actual practices. We have been subject to these types of claims in the past, and there can be no assurance that we will not be subject to these types of claims in the future. Additional risks could arise in connection with any failure or perceived failure by us, our service providers or other third parties with which we do business to provide adequate disclosure or transparency to individuals, including our customers, about the personal information collected from them and its use, to receive, document or honor the privacy preferences expressed by individuals, to protect personal information from unauthorized disclosure, misuse or mishandling or to maintain proper training on privacy practices for all employees or third parties who have access to personal information in our possession or control. Furthermore, the increased risk of inadvertent disclosure of confidential information or personal data in connection with the utilization of AI technologies may result in stronger regulatory scrutiny, leading to legal and regulatory investigations and enforcement actions that may negatively affect our business, even if unfounded.
Sees AI as a riskDetail: Names an areaNew this year
Some of our competitors, including new and emerging competitors in the digital and mobile payments space and other financial technology providers and payment networks, are not subject to the same regulatory requirements or scrutiny to which we are subject, which also could place us at a competitive disadvantage, in particular in the development of new technology platforms or the ability to rapidly innovate. We compete with many forms of payments offered by both bank and non-bank providers, including a variety of new and evolving alternative payment mechanisms, systems and products, such as aggregators and web-based and wireless payment platforms or technologies, digital currencies or cryptocurrencies (including stablecoins and tokenized deposits), prepaid systems and payment services targeting users of social networks, communications platforms and online gaming. If we are unable to continue to keep pace with innovation and fail to reflect such technology in our payments offerings, do not effectively market our products and services, are unable to deliver them effectively and securely to our customers or are prohibited from or unwilling to enter emerging areas of competition, our business and results of operations could be adversely affected. Also, our competitors or other third parties may incorporate emerging technologies, such as AI, into their products or services more quickly or more successfully than we do, which could impair our ability to compete effectively. For example, our competitors may be more timely or successful in developing or integrating AI technologies to increase their productivity and reduce their costs or to provide better transaction execution or improved products or services to clients. In addition, government actions or initiatives by the federal and state governmental authorities, including the Federal Banking Agencies, may also provide competitors with increased opportunities to derive competitive advantages and may create new competitors. These actions or initiatives may include more accommodative positions on the processing and approval of traditional bank charters and deposit insurance, expanded access to the banking and payments systems through the approval of competitors, including competitors with novel business models, to hold specialized charters, or more accommodative positions on novel activities performed by banks or non-banks. For example, the Guiding and Establishing National Innovation for U.S. Stablecoins Act of 2025 (GENIUS Act) provides a legal framework for stablecoins to be issued in the United States, which may allow new and existing competitors to compete for funds that may have otherwise been deposited with banks, such as the Bank.
Sees AI as a riskDetail: GeneralNew this year
In addition, if we are unable to maintain sufficient network functionality to be competitive with other networks, or if our competitors develop better data security solutions or more innovative products and services than we do, our ability to retain and attract Network Partners and maintain or increase the revenues generated by the Global Payment Network or our proprietary card-issuing businesses could be materially and adversely affected. Our competitive position could also be affected if we are unable to deploy, in a cost-effective and competitive manner, technology such as generative AI. Additionally, competitors may develop ancillary products, which as a consequence of the competitors’ size and scale, we may be forced to use. Such developments could adversely affect our business, as those competitors may be better positioned to absorb the costs of such data security solutions over higher volumes or a larger customer base.
Sees AI as a riskDetail: GeneralGenerative AINew this year
Our industry is subject to rapid and significant technological changes, including due to the increasing development and use of AI, and our ability to meet our customers’ needs and expectations is key to our ability to grow revenue and earnings. We expect digital technologies to continue to have a significant impact on banking over time. Consumers expect robust digital experiences from their financial services providers. The ability for customers to access their accounts and conduct financial transactions using digital technology, including mobile applications, is an important aspect of the financial services industry, and financial institutions are rapidly introducing new digital and other technology-driven products and services that aim to offer a better customer experience and to reduce costs. We continue to invest in digital technology designed to attract new customers, facilitate the ability of existing customers to conduct financial transactions and enhance the customer experience related to our products and services.
General statement about AIDetail: GeneralSame as last year
rapidly changing and competitive technological and business environments in which we operate, if our competitors or other third parties are successful in obtaining such patents or prevail in intellectual property-related litigation or demands against us, we could lose significant revenues, incur significant license, royalty, technology development or other expenses, or pay significant damages. Furthermore, given intellectual property ownership and license rights surrounding AI, such as generative AI, are currently not fully addressed by courts or regulators, any output created by us using AI may not be subject to copyright or other intellectual property protection, which may adversely affect our intellectual property or other proprietary rights in, or ability to commercialize or use, any such output, and our use or adoption of AI may result in exposure to claims by third parties.
Sees AI as a riskDetail: GeneralGenerative AINew this year
While we employ a broad and diversified set of risk monitoring and risk mitigation techniques, those techniques and the judgments that accompany their application cannot anticipate every economic and financial outcome or the timing of such outcomes. For example, our ability to implement our risk management strategies may be hindered by adverse changes in the volatility or liquidity conditions in certain markets and, as a result, may limit our ability to distribute such risks (for instance, when we seek to syndicate exposure in bridge financing transactions we have underwritten). We may, therefore, incur losses in the course of our risk management or investing activities. As our business expands and evolves, including in connection with the Transaction and the adoption of new technologies, such as AI, our risk management methods may not always effectively adapt with those changes.
Sees AI as a riskDetail: GeneralNew this year
In addition, advances in technology, such as automation and AI, may lead to workforce evolution. This could require us to invest in additional employee training, manage impacts on morale and retention, and compete for employment candidates who possess more advanced technological skills, all of which could have a negative impact on our business and operations.
Sees AI as a riskDetail: GeneralProcess automationNew this year

Earnings release, Q1 2026 filed 22 Jan 2026

Brex is a modern, AI-native software platform offering intelligent finance solutions that make it easy for businesses to issue corporate cards, automate expense management and make secure, real-time payments. The company also leverages AI agents to help customers automate complex workflows to reduce manual review and control spend.
Using AI nowDetail: Concrete exampleAI agentsProcess automationOperationsCustomer serviceBrexNew this periodNew since the annual report
“We started Brex in 2017 as a category creator – bringing together financial services and software into one AI-native platform,” said Pedro Franceschi, Founder and CEO of Brex. “Now we get to supercharge our next chapter in partnership with the team at Capital One. Together, we’ll maximize founder mode by combining Brex’s payments expertise and spend management software with Capital One’s massive scale, sophisticated underwriting, and compelling brand to accelerate growth and increase the speed at which we can offer better finance solutions to the millions of businesses in the U.S. mainstream economy.”
General statement about AIDetail: Names an areaBrexNew this periodNew since the annual report
Earnings release, page 1Pedro Franceschi, Founder and CEORead it in the releaseReport an error
Brex is the intelligent finance platform that empowers growing companies to spend smarter and move faster – in more than 50 countries. By combining the world’s smartest corporate card with intuitive spend management software and banking, Brex enables founders and finance teams to accelerate operations, gain real-time visibility, and control spend effortlessly. Brex’s AI-powered automation and world-class service eliminate manual expense and accounting tasks for customers. Over 25,000 of the world’s best companies, from startups to enterprises, run their finances on Brex – including DoorDash, TikTok, Anthropic, Robinhood, Crowdstrike, Zoom, Plaid, Intel, SeatGeek and the Boston Celtics.
Standard wording or passing mentionDetail: GeneralProcess automationBrexNew this periodNew since the annual report

Quarterly report, Q3 2025 filed 3 Nov 2025

AI: Artificial Intelligence
Standard wording or passing mentionDetail: GeneralSame as last periodNew since the annual report
Quarterly report, page 76Read it in the reportReport an error

Quarterly report, Q2 2025 filed 31 Jul 2025

AI: Artificial Intelligence
Standard wording or passing mentionDetail: GeneralNew this periodNew since the annual report
Quarterly report, page 77Read it in the reportReport an error
•We face risks resulting from the extensive use of models and data, as well as from our evolving use of AI.
Sees AI as a riskDetail: GeneralNew this period
Quarterly report, page 161Read it in the reportReport an error
•Technology-driven disruption of certain industries, such as those due to advances in AI, robotics and cryptocurrency;
Sees AI as a riskDetail: GeneralNew this period
Quarterly report, page 164Read it in the reportReport an error
Decreases in overall business activity and changes in customer behavior may lead to increases in our charge-off rate caused by bankruptcies and may reduce our ability to recover debt that we have previously charged off. Such changes may also decrease the reliability of our internal processes and models, including those we use to estimate our allowance for credit losses, particularly if unexpected variations in key inputs and assumptions cause actual losses to diverge from the projections of our models and our estimates become increasingly subject to management’s judgment. See “We face risks resulting from the extensive use of models and data, as well as from our evolving use of AI.”
Sees AI as a riskDetail: GeneralNew this periodNew since the annual report
Quarterly report, page 164Read it in the reportReport an error
•Incorrect Estimates of Expected Credit Losses: The credit quality of our loan portfolios can have a significant impact on our earnings. We allow for and reserve against credit risks based on our assessment of expected credit losses in our loan portfolios. This process, which is critical to our financial condition and results of operations, requires complex judgments, including forecasts of economic conditions. We may underestimate our expected credit losses and fail to hold an allowance for credit losses sufficient to account for these credit losses. Incorrect assumptions could lead to material underestimations of expected credit losses and an inadequate allowance for credit losses. See “We face risks resulting from the extensive use of models and data, as well as from our evolving use of AI.”
Sees AI as a riskDetail: GeneralNew this period
Quarterly report, page 166Read it in the reportReport an error
For example, on July 29, 2019, we announced that on March 22 and 23, 2019 an outside individual gained unauthorized access to our systems (the “2019 Cybersecurity Incident”). This individual obtained certain types of personal information relating to people who had applied for our credit card products and to our credit card customers. While the 2019 Cybersecurity Incident has been remediated, it resulted in fines, litigation, consent orders, settlements, government investigations and other regulatory enforcement inquiries. Cyber and information security risks for large financial institutions like us continue to increase due to the proliferation of new technologies, the industry-wide shift to reliance upon the internet to conduct financial transactions, the increased sophistication and activities of malicious actors, organized crime, perpetrators of fraud, hackers, terrorists, activists, extremist parties, formal and informal instrumentalities of foreign governments, state-sponsored or nation-state actors and other external parties and the growing use of AI by threat actors.
Sees AI as a riskDetail: GeneralNew this period
Quarterly report, page 171Read it in the reportReport an error
In addition, our customers access our products and services using personal devices that are necessarily external to our security control systems. There has also been a significant proliferation of consumer information available on the internet resulting from breaches of third-party entities, including personal information, log-in credentials and authentication data. These third-party breach events could create a threat for our customers if their Capital One log-in credentials are the same as or similar to the credentials that have been compromised on other internet sites. This threat could include the risk of unauthorized account access, data loss and fraud. The use of AI, “bots” or other automation software can increase the velocity and efficacy of these types of attacks. As our employees are operating under our hybrid work model, our remote interaction with employees, service providers, partners and other third parties on systems, networks and environments over which we have less control (such as through employees’ personal devices) increases our cybersecurity risk exposure. We will likely face an increasing number of attempted cyber-attacks as we expand our mobile and other internet-based products and services, expand our usage of mobile, cloud and other internet-based technologies, increase international merchant acceptance of credit cards issued on the Discover Network, acquire new business operations or outsource certain business operations and otherwise attempt to keep pace with rapid technological changes in the financial services industry.
Sees AI as a riskDetail: GeneralProcess automationNew this period
Quarterly report, page 171Read it in the reportReport an error
The methods and techniques employed by malicious actors continue to develop and evolve rapidly, including from emerging technologies, such as advanced forms of AI and quantum computing, are increasingly sophisticated and often are not fully recognized or understood until after they have occurred, and some techniques could occur and enable persistent access for an extended period of time before being detected and remediated, if at all. We and our service providers and other third parties with which we interact may be unable to anticipate or identify certain attack methods or techniques in order to implement effective preventative or detective measures or mitigate or remediate the damages caused in a timely manner. Similarly, any cyber-attack or other security incident, information or security breach or technology failure that significantly exposes, degrades, destroys or compromises our information systems or networks could adversely impact third parties and the critical infrastructure of the financial services industry, thereby creating additional risk for us.
Sees AI as a riskDetail: GeneralNew this period
Quarterly report, page 171Read it in the reportReport an error
We face risks resulting from the extensive use of models and data, as well as from our evolving use of AI.
Sees AI as a riskDetail: GeneralNew this period
Quarterly report, page 172Read it in the reportReport an error
We rely on quantitative models and in some cases the use of AI, as well as our ability to manage and aggregate data in an accurate and timely manner, to assess and manage our various risk exposures, create estimates and forecasts, and manage compliance with regulatory capital requirements. We continue to invest in building new capabilities that employ new AI technologies such as generative AI, and we expect our use of these technologies to increase over time. However, there are significant risks involved in utilizing models and AI, and no assurance can be provided that our use will enhance our business or produce only intended or beneficial results. For example, generative AI has been known to produce false or “hallucinatory” inferences or output, and certain generative AI uses machine learning and predictive analytics, which can create inaccurate, incomplete or misleading output, unexpected results, errors or inadequacies, any of which may not be easily detectable. AI may subject us to new or heightened legal, regulatory, ethical, or other challenges; and negative public opinion of AI could impair the acceptance of AI solutions. Accordingly, if the models or AI solutions that we create or use, or if the content, analyses or recommendations that models or AI solutions assist in producing in our products and services, are, or are perceived to be deficient, inaccurate, biased, unethical or controversial, we could incur operational inefficiencies, competitive harm, legal liability, brand or reputational harm, or other adverse impacts on our business and financial results. We also may incur liability through the violation of applicable laws and regulations, third-party intellectual property, privacy or other rights, or contracts to which we are a party.
Sees AI as a riskDetail: Names an areaMachine learningGenerative AIRisk managementCompliance and anti-money launderingNew this period
Quarterly report, page 172Read it in the reportReport an error
We may use models and AI in processes such as determining the pricing of various products, identifying potentially fraudulent transactions, grading loans and extending credit, measuring interest rate and other market risks, predicting deposit levels or loan losses, assessing capital adequacy, calculating managerial and regulatory capital levels, estimating the value of financial instruments and balance sheet items, and other operational functions. Development and implementation of some of these models, such as the models for credit loss accounting under CECL, require us to make difficult, subjective and complex judgments. Our risk reporting and management, including business decisions based on information incorporating models and the use of AI, depend on the effectiveness of our models and AI and our policies, programs, processes and practices governing how data, models and AI, as applicable, are acquired, validated, stored, protected, processed and analyzed. Any issues with the quality or effectiveness of our data aggregation and validation procedures, as well as the quality and integrity of data inputs,
Using AI nowDetail: Names an areaMachine learningFraud detectionCredit and lendingRisk managementOperationsCompliance and anti-money launderingNew this period
Quarterly report, page 172Read it in the reportReport an error
formulas or algorithms, could result in inaccurate forecasts, ineffective risk management practices or inaccurate risk reporting. In addition, models and AI based on historical data sets might not be accurate predictors of future outcomes, and their ability to appropriately predict future outcomes may degrade over time due to limited historical patterns, extreme or unanticipated market movements or customer behavior and liquidity, especially during severe market downturns or stress events (e.g., geopolitical or pandemic events).
Sees AI as a riskDetail: GeneralMachine learningRisk managementNew this periodNew since the annual report
Quarterly report, page 173Read it in the reportReport an error
While we continuously update our policies, programs, processes and practices, many of our data management, modeling, AI, aggregation and implementation processes are manual and may be subject to human error, data limitations, process delays or system failure. Failure to manage data effectively and to aggregate data in an accurate and timely manner may limit our ability to manage current and emerging risk, to produce accurate financial, regulatory and operational reporting as well as to manage changing business needs. If our Framework is ineffective, we could suffer unexpected losses which could materially adversely affect our results of operation or financial condition. Also, any information we provide to the public or to our regulators based on incorrectly designed or implemented models or AI could be inaccurate or misleading. Some of the decisions that our regulators make could be affected adversely due to the perception that the quality of the data, models and AI used to generate the relevant information is insufficient. In addition, regulation of AI is rapidly evolving worldwide as legislators and regulators are increasingly focused on these powerful emerging technologies. The technologies underlying AI and its uses are subject to a variety of laws and regulations, including intellectual property, privacy, data protection and data security, consumer protection, competition, and equal opportunity laws, and are expected to be subject to increased regulation and new laws or new applications of existing laws and regulations. AI is the subject of ongoing review by various U.S. governmental and regulatory agencies, and various U.S. states and other foreign jurisdictions are applying, or are considering applying, their platform moderation, privacy, data protection and data security laws and regulations to AI or are considering general legal frameworks for AI. We may not be able to anticipate how to respond to these rapidly evolving frameworks, and we may need to expend resources to adjust our offerings in certain jurisdictions if the legal frameworks are inconsistent across jurisdictions. Furthermore, because AI technology itself is highly complex and rapidly developing, it is not possible to predict all of the legal, operational, competitive or technological risks that may arise relating to the use of AI.
Sees AI as a riskDetail: GeneralMachine learningNew this period
Quarterly report, page 173Read it in the reportReport an error
We are subject to the risk of fraudulent activity associated with merchants, customers and other third parties handling customer information. The risk of fraud continues to be a persistent inherent risk for the financial services industry, and our risk of fraud increased as a result of our recent acquisition of a payments network that process payment transactions for other card issuers. Credit and debit card fraud, identity theft and electronic-transaction related crimes are prevalent, and perpetrators are growing ever more sophisticated. Emerging generative AI capabilities, such as synthetic video, images and identity documents may introduce new risks, in the form of identity fraud and scams. While we have policies and procedures designed to address such risk, there can be no assurance that losses will not occur. Our resources, customer authentication methods and fraud prevention tools may be insufficient to accurately predict, prevent or detect fraud. Consumer activists and regulators have sought to expand financial institutions’ responsibility to hold customers harmless for fraudulent transactions that they authorized on their accounts.
Sees AI as a riskDetail: GeneralGenerative AINew this period
Quarterly report, page 173Read it in the reportReport an error
The legislative, regulatory and supervisory environment is beyond our control, may change rapidly and unpredictably, and may negatively influence our revenue, costs, earnings, growth, liquidity and capital levels. Such changes could affect our ability or willingness to provide certain products or services, necessitate changes to our business practices, or reduce our revenues. There may also be future rulemaking in emerging regulatory areas, such as climate-related risks and new technologies. Adoption of new technologies, such as distributed ledger technologies, tokenization, cloud computing, AI and machine learning technologies, can present unforeseen challenges in applying and relying on existing compliance systems. In addition, some laws and regulations may be subject to litigation or other challenges that delay or modify their implementation and impact on us. Furthermore, political and policy goals of elected officials may change over time, which could impact the rulemaking, supervision, examination and enforcement priorities of the Federal Banking Agencies.
Sees AI as a riskDetail: GeneralMachine learningNew this period
Quarterly report, page 174Read it in the reportReport an error
Over the last several years, federal and state regulators have focused on risk management, compliance with anti-money laundering (“AML”) and sanctions laws, privacy, data protection and data security, use of service providers, fair lending, unfair or deceptive practices, and other consumer protection issues and innovative activities, such as those that utilize AI and other new technology. Regulators have indicated the potential for escalating consequences for banks that do not timely resolve open issues or have repeat issues. Regulatory scrutiny is expected to continue in these areas, including as a result of implementation of the AML Act of 2020.
Sees AI as a riskDetail: GeneralNew this period
Quarterly report, page 176Read it in the reportReport an error
Some of our competitors, including new and emerging competitors in the digital and mobile payments space and other financial technology providers, are not subject to the same regulatory requirements or scrutiny to which we are subject, which also could place us at a competitive disadvantage, in particular in the development of new technology platforms or the ability to rapidly innovate. We compete with many forms of payments offered by both bank and non-bank providers, including a variety of new and evolving alternative payment mechanisms, systems and products, such as aggregators and web-based and wireless payment platforms or technologies, digital or cryptocurrencies, prepaid systems and payment services targeting users of social networks, communications platforms and online gaming. If we are unable to continue to keep pace with innovation, do not effectively market our products and services or are prohibited from or unwilling to enter emerging areas of competition, our business and results of operations could be adversely affected. Also, our competitors or other third parties may incorporate AI into their products or services more quickly or more successfully than we do, which could impair our ability to compete effectively. In addition, government actions or initiatives may also provide competitors with increased opportunities to derive competitive advantages and may create new competitors.
Sees AI as a riskDetail: GeneralNew this period
Quarterly report, page 177Read it in the reportReport an error
In addition, if we are unable to maintain sufficient network functionality to be competitive with other networks, or if our competitors develop better data security solutions or more innovative products and services than we do, our ability to retain and attract Network Partners and maintain or increase the revenues generated by the Global Payment Network or our proprietary card-issuing businesses could be materially and adversely affected. Our competitive position could also be affected if we are unable to deploy, in a cost effective and competitive manner, technology such as generative AI. Additionally, competitors may develop ancillary products, which as a consequence of the competitors’ size and scale, we may be forced to use. Such developments could adversely affect our business, as those competitors may be better positioned to absorb the costs of such data security solutions over higher volumes or a larger customer base.
Sees AI as a riskDetail: GeneralGenerative AINew this periodNew since the annual report
Quarterly report, page 178Read it in the reportReport an error
Our industry is subject to rapid and significant technological changes, including due to the increasing development and use of AI, and our ability to meet our customers’ needs and expectations is key to our ability to grow revenue and earnings. We expect digital technologies to continue to have a significant impact on banking over time. Consumers expect robust digital experiences from their financial services providers. The ability for customers to access their accounts and conduct financial transactions using digital technology, including mobile applications, is an important aspect of the financial services industry and financial institutions are rapidly introducing new digital and other technology-driven products and services that aim to offer a better customer experience and to reduce costs. We continue to invest in digital technology designed to attract new customers, facilitate the ability of existing customers to conduct financial transactions and enhance the customer experience related to our products and services.
General statement about AIDetail: GeneralNew this period
Quarterly report, page 181Read it in the reportReport an error
While we employ a broad and diversified set of risk monitoring and risk mitigation techniques, those techniques and the judgments that accompany their application cannot anticipate every economic and financial outcome or the timing of such outcomes. For example, our ability to implement our risk management strategies may be hindered by adverse changes in the volatility or liquidity conditions in certain markets and, as a result, may limit our ability to distribute such risks (for instance, when we seek to syndicate exposure in bridge financing transactions we have underwritten). We may, therefore, incur losses in the course of our risk management or investing activities. As our business expands and evolves, including in connection with the Transaction and the adoption of new technologies, such as AI, our risk management methods may not always effectively adapt with those changes.
Sees AI as a riskDetail: GeneralNew this periodNew since the annual report
Quarterly report, page 184Read it in the reportReport an error

Annual report, report year 2024 filed 20 Feb 2025

•We face risks resulting from the extensive use of models and data, as well as from our evolving use of AI.
Sees AI as a riskDetail: GeneralMachine learningNew this year
•Technology-driven disruption of certain industries, such as those due to advances in AI, robotics and cryptocurrency;
Sees AI as a riskDetail: GeneralNew this year
particularly if unexpected variations in key inputs and assumptions cause actual losses to diverge from the projections of our models and our estimates become increasingly subject to management’s judgment. See “We face risks resulting from the extensive use of models and data, as well as our evolving use of AI.”
Sees AI as a riskDetail: GeneralNew this year
•Incorrect Estimates of Expected Credit Losses: The credit quality of our loan portfolios can have a significant impact on our earnings. We allow for and reserve against credit risks based on our assessment of expected credit losses in our loan portfolios. This process, which is critical to our financial condition and results of operations, requires complex judgments, including forecasts of economic conditions. We may underestimate our expected credit losses and fail to hold an allowance for credit losses sufficient to account for these credit losses. Incorrect assumptions could lead to material underestimations of expected credit losses and an inadequate allowance for credit losses. See “We face risks resulting from the extensive use of models and data, as well as our evolving use of AI.”
Sees AI as a riskDetail: General
For example, on July 29, 2019, we announced that on March 22 and 23, 2019 an outside individual gained unauthorized access to our systems (the “2019 Cybersecurity Incident”). This individual obtained certain types of personal information relating to people who had applied for our credit card products and to our credit card customers. While the 2019 Cybersecurity Incident has been remediated, it resulted in fines, litigation, consent orders, settlements, government investigations and other regulatory enforcement inquiries. Cyber and information security risks for large financial institutions like us continue to increase due to the proliferation of new technologies, the industry-wide shift to reliance upon the internet to conduct financial transactions, the increased sophistication and activities of malicious actors, organized crime, perpetrators of fraud, hackers, terrorists, activists, extremist parties, formal and informal instrumentalities of foreign governments, state-sponsored or nation-state actors and other external parties and the growing use of AI by threat actors.
Sees AI as a riskDetail: GeneralSame as last year
In addition, our customers access our products and services using personal devices that are necessarily external to our security control systems. There has also been a significant proliferation of consumer information available on the internet resulting from breaches of third-party entities, including personal information, log-in credentials and authentication data. These third-party breach events could create a threat for our customers if their Capital One log-in credentials are the same as or similar to the credentials that have been compromised on other internet sites. This threat could include the risk of unauthorized account access, data loss and fraud. The use of AI, “bots” or other automation software can increase the velocity and efficacy of these types of attacks. As our employees are operating under our hybrid work model, our remote interaction with employees, service providers, partners and other third parties on systems, networks and environments over which we have less control (such as through employees’ personal devices) increases our cybersecurity risk exposure. We will likely face an increasing number of attempted cyber-attacks as we expand our mobile and other internet-based products and services, expand our usage of mobile, cloud and other internet-based technologies and provide more of such products and these services to a greater number of retail banking customers.
Sees AI as a riskDetail: GeneralProcess automation
The methods and techniques employed by malicious actors continue to develop and evolve rapidly, including from emerging technologies, such as advanced forms of AI and quantum computing, are increasingly sophisticated and often are not fully recognized or understood until after they have occurred, and some techniques could occur and enable persistent access for an extended period of time before being detected and remediated, if at all. We and our service providers and other third parties with which we interact may be unable to anticipate or identify certain attack methods or techniques in order to implement effective preventative or detective measures or mitigate or remediate the damages caused in a timely manner. Similarly, any cyber-attack or other security incident, information or security breach or technology failure that significantly exposes, degrades, destroys or compromises our information systems or networks could adversely impact third parties and the critical infrastructure of the financial services industry, thereby creating additional risk for us.
Sees AI as a riskDetail: General
We face risks resulting from the extensive use of models and data, as well as from our evolving use of AI.
Sees AI as a riskDetail: GeneralNew this year
We rely on quantitative models and in some cases the use of AI, as well as our ability to manage and aggregate data in an accurate and timely manner, to assess and manage our various risk exposures, create estimates and forecasts, and manage compliance with regulatory capital requirements. We continue to invest in building new capabilities that employ new AI technologies such as generative AI, and we expect our use of these technologies to increase over time. However, there are significant risks involved in utilizing models and AI and no assurance can be provided that our use will enhance our business or produce only intended or beneficial results. For example, generative AI has been known to produce false or “hallucinatory” inferences or output, and certain generative AI uses machine learning and predictive analytics, which can create inaccurate, incomplete or misleading output, unexpected results, errors or inadequacies, any of which may not be easily detectable. AI may subject us to new or heightened legal, regulatory, ethical, or other challenges; and negative public opinion of AI could impair the acceptance of AI solutions. Accordingly, if the models or AI solutions that we create or use, or if the content, analyses or recommendations that models or AI solutions assist in producing in our products and services, are, or are perceived to be deficient, inaccurate, biased, unethical or controversial, we could incur operational inefficiencies, competitive harm, legal liability, brand or reputational harm, or other adverse impacts on our business and financial results. We also may incur liability through the violation of applicable laws and regulations, third-party intellectual property, privacy or other rights, or contracts to which we are a party.
Sees AI as a riskDetail: Names an areaMachine learningGenerative AIRisk managementCompliance and anti-money laundering
We may use models and AI in processes such as determining the pricing of various products, identifying potentially fraudulent transactions, grading loans and extending credit, measuring interest rate and other market risks, predicting deposit levels or loan losses, assessing capital adequacy, calculating managerial and regulatory capital levels, estimating the value of financial instruments and balance sheet items, and other operational functions. Development and implementation of some of these models, such as the models for credit loss accounting under CECL, require us to make difficult, subjective and complex judgments. Our risk reporting and management, including business decisions based on information incorporating models and the use of AI, depend on the effectiveness of our models and AI and our policies, programs, processes and practices governing how data, models and AI, as applicable, are acquired, validated, stored, protected, processed and analyzed. Any issues with the quality or effectiveness of our data aggregation and validation procedures, as well as the quality and integrity of data inputs, formulas or algorithms, could result in inaccurate forecasts, ineffective risk management practices or inaccurate risk reporting. In addition, models and AI based on historical data sets might not be accurate predictors of future outcomes and their ability to appropriately predict future outcomes may degrade over time due to limited historical patterns, extreme or unanticipated market
Using AI nowDetail: Names an areaMachine learningFraud detectionCredit and lendingRisk managementOperations
While we continuously update our policies, programs, processes and practices, many of our data management, modeling, AI, aggregation and implementation processes are manual and may be subject to human error, data limitations, process delays or system failure. Failure to manage data effectively and to aggregate data in an accurate and timely manner may limit our ability to manage current and emerging risk, to produce accurate financial, regulatory and operational reporting as well as to manage changing business needs. If our Framework is ineffective, we could suffer unexpected losses which could materially adversely affect our results of operation or financial condition. Also, any information we provide to the public or to our regulators based on incorrectly designed or implemented models or AI could be inaccurate or misleading. Some of the decisions that our regulators make could be affected adversely due to the perception that the quality of the data, models and AI used to generate the relevant information is insufficient. In addition, regulation of AI is rapidly evolving worldwide as legislators and regulators are increasingly focused on these powerful emerging technologies. The technologies underlying AI and its uses are subject to a variety of laws and regulations, including intellectual property, privacy, data protection and data security, consumer protection, competition, and equal opportunity laws, and are expected to be subject to increased regulation and new laws or new applications of existing laws and regulations. AI is the subject of ongoing review by various U.S. governmental and regulatory agencies, and various U.S. states and other foreign jurisdictions are applying, or are considering applying, their platform moderation, privacy, data protection and data security laws and regulations to AI or are considering general legal frameworks for AI. We may not be able to anticipate how to respond to these rapidly evolving frameworks, and we may need to expend resources to adjust our offerings in certain jurisdictions if the legal frameworks are inconsistent across jurisdictions. Furthermore, because AI technology itself is highly complex and rapidly developing, it is not possible to predict all of the legal, operational, competitive or technological risks that may arise relating to the use of AI.
Sees AI as a riskDetail: GeneralMachine learningSame as last year
We are subject to the risk of fraudulent activity associated with merchants, customers and other third parties handling customer information. The risk of fraud continues to be a persistent inherent risk for the financial services industry. Credit and debit card fraud, identity theft and electronic-transaction related crimes are prevalent and perpetrators are growing ever more sophisticated. Emerging generative AI capabilities, such as synthetic voice and conversation generation, introduced an increase in fraud risks, especially in the form of identity fraud. While we have policies and procedures designed to address such risk, there can be no assurance that losses will not occur. Our resources, customer authentication methods and fraud prevention tools may be insufficient to accurately predict, prevent or detect fraud. Consumer activists and regulators have sought to expand financial institutions’ responsibility to hold customers harmless for fraudulent transactions that they authorized on their accounts.
Sees AI as a riskDetail: GeneralGenerative AINew this year
The legislative, regulatory and supervisory environment is beyond our control, may change rapidly and unpredictably, and may negatively influence our revenue, costs, earnings, growth, liquidity and capital levels. For example, the CFPB has announced several initiatives related to the amounts and types of fees financial institutions may charge, including a final rule amending Regulation Z that, if it goes into effect as currently issued, would significantly lower the safe harbor amount for past due fees that a large credit card issuer, such as the Bank, can charge on consumer credit card accounts. Such changes could affect our ability or willingness to provide certain products or services, necessitate changes to our business practices, or reduce our revenues. There may also be future rulemaking in emerging regulatory areas, such as climate-related risks and new technologies. Adoption of new technologies, such as distributed ledger technologies, tokenization, cloud computing, AI and machine learning technologies, can present unforeseen challenges in applying and relying on existing compliance systems. In addition, some laws and regulations may be subject to litigation or other challenges that delay or modify their implementation and impact on us. Furthermore, political and policy goals of elected officials may change over time, which could impact the rulemaking, supervision, examination and enforcement priorities of the Federal Banking Agencies.
Sees AI as a riskDetail: GeneralMachine learning
Over the last several years, federal and state regulators have focused on risk management, compliance with anti-money laundering (“AML”) and sanctions laws, privacy, data protection and data security, use of service providers, fair lending, unfair or deceptive practices, and other consumer protection issues and innovative activities, such as those that utilize AI and other new technology. Regulators have indicated the potential for escalating consequences for banks that do not timely resolve open issues or have repeat issues. Regulatory scrutiny is expected to continue in these areas, including as a result of implementation of the AML Act of 2020.
Sees AI as a riskDetail: GeneralNew this year
Some of our competitors, including new and emerging competitors in the digital and mobile payments space and other financial technology providers, are not subject to the same regulatory requirements or scrutiny to which we are subject, which also could place us at a competitive disadvantage, in particular in the development of new technology platforms or the ability to rapidly innovate. We compete with many forms of payments offered by both bank and non-bank providers, including a variety of new and evolving alternative payment mechanisms, systems and products, such as aggregators and web-based and wireless payment platforms or technologies, digital or cryptocurrencies, prepaid systems and payment services targeting users of social networks, communications platforms and online gaming. If we are unable to continue to keep pace with innovation, do not effectively market our products and services or are prohibited from or unwilling to enter emerging areas of competition, our business and results of operations could be adversely affected. Also, our competitors or other third parties may incorporate AI into their products or services more quickly or more successfully than we do, which could impair our ability to compete effectively. In addition, government actions or initiatives may also provide competitors with increased opportunities to derive competitive advantages and may create new competitors. For example, the CFPB has released a final rule that will require certain financial institutions, including the Company, to share certain financial information with third parties upon a customer’s request, which could enable those third parties to offer competing financial services to consumers.
Sees AI as a riskDetail: GeneralNew this year
Our industry is subject to rapid and significant technological changes, including due to the increasing development and use of AI, and our ability to meet our customers’ needs and expectations is key to our ability to grow revenue and earnings. We expect digital technologies to continue to have a significant impact on banking over time. Consumers expect robust digital experiences from their financial services providers. The ability for customers to access their accounts and conduct financial transactions using digital technology, including mobile applications, is an important aspect of the financial services industry and financial institutions are rapidly introducing new digital and other technology-driven products and services that aim to offer a better customer experience and to reduce costs. We continue to invest in digital technology designed to attract new customers, facilitate the ability of existing customers to conduct financial transactions and enhance the customer experience related to our products and services.
General statement about AIDetail: GeneralNew this year

Earnings release, Q1 2025 filed 24 Jan 2025

• AI : Artificial Intelligence • FASB : Financial Accounting Standards Board
Standard wording or passing mentionDetail: GeneralNew this periodNew since the annual report
Earnings release, page 73Read it in the releaseReport an error

Annual report, report year 2023 filed 23 Feb 2024

•We face risks resulting from the extensive use of models, AI, and data.
Sees AI as a riskDetail: GeneralMachine learningNew this year
Decreases in overall business activity and changes in customer behavior may lead to increases in our charge-off rate caused by bankruptcies and may reduce our ability to recover debt that we have previously charged-off. Such changes may also decrease the reliability of our internal processes and models, including those we use to estimate our allowance for credit losses, particularly if unexpected variations in key inputs and assumptions cause actual losses to diverge from the projections of our models and our estimates become increasingly subject to management’s judgment. See “We face risks resulting from the extensive use of models, AI, and data.”
Sees AI as a riskDetail: GeneralCredit and lendingNew this year
•Incorrect Estimates of Expected Credit Losses: The credit quality of our loan portfolios can have a significant impact on our earnings. We allow for and reserve against credit risks based on our assessment of expected credit losses in our loan portfolios. This process, which is critical to our financial condition and results of operations, requires complex judgments, including forecasts of economic conditions. We may underestimate our expected credit losses and fail to hold an allowance for credit losses sufficient to account for these credit losses. Incorrect assumptions could lead to material underestimations of expected credit losses and an inadequate allowance for credit losses. See “We face risks resulting from the extensive use of models, AI, and data.”
Sees AI as a riskDetail: GeneralNew this year
For example, on July 29, 2019, we announced that on March 22 and 23, 2019 an outside individual gained unauthorized access to our systems (the “2019 Cybersecurity Incident”). This individual obtained certain types of personal information relating to people who had applied for our credit card products and to our credit card customers. While the 2019 Cybersecurity Incident has been remediated, it resulted in fines, litigation, consent orders, settlements, government investigations and other regulatory enforcement inquiries. Cyber and information security risks for large financial institutions like us continue to increase due to the proliferation of new technologies, the industry-wide shift to reliance upon the internet to conduct financial transactions, the increased sophistication and activities of malicious actors, organized crime, perpetrators of fraud, hackers, terrorists, activists, extremist parties, formal and informal instrumentalities of foreign governments, state-sponsored or nation-state actors and other external parties and the growing use of AI by threat actors. In addition, our customers access our products and services using personal devices that are necessarily external to our security control systems. There has also been a significant proliferation of
Sees AI as a riskDetail: General
consumer information available on the internet resulting from breaches of third-party entities, including personal information, log-in credentials and authentication data. These third-party breach events could create a threat for our customers if their Capital One log-in credentials are the same as or similar to the credentials that have been compromised on other internet sites. This threat could include the risk of unauthorized account access, data loss and fraud. The use of AI, “bots” or other automation software can increase the velocity and efficacy of these types of attacks. As our employees are operating under our hybrid work model, our remote interaction with employees, service providers, partners and other third parties on systems, networks and environments over which we have less control (such as through employees’ personal devices) increases our cybersecurity risk exposure. We will likely face an increasing number of attempted cyber-attacks as we expand our mobile and other internet-based products and services, as well as our usage of mobile and cloud technologies and as we provide more of these services to a greater number of retail banking customers.
Sees AI as a riskDetail: GeneralProcess automationNew this year
The methods and techniques employed by malicious actors develop and evolve rapidly, including from emerging technologies, such as advanced forms of AI and quantum computing, are increasingly sophisticated and often are not fully recognized or understood until after they have occurred, and some techniques could occur and persist for an extended period of time before being detected and remediated. For example, although we immediately fixed the configuration vulnerability that was exploited in the 2019 Cybersecurity Incident once we discovered the unauthorized access, a period of time elapsed between the occurrence of the unauthorized access and the time when we discovered it. In other circumstances, we and our service providers and other third parties with which we interact may be unable to anticipate or identify certain attack methods or techniques in order to implement effective preventative or detective measures or mitigate or remediate the damages caused in a timely manner. We may also be unable to hire, develop and retain talent that keeps pace with the rapidly changing cyber threat landscape, and which are capable of preventing, detecting, mitigating or remediating these risks. Although we seek to maintain a robust suite of authentication and layered information security controls, any one or combination of these controls could fail to prevent, detect, mitigate, remediate or recover from these risks in a timely manner.
Sees AI as a riskDetail: GeneralNew this year
We rely on quantitative models and the use of AI, as well as our ability to manage and aggregate data in an accurate and timely manner, to assess and manage our various risk exposures, create estimates and forecasts, and manage compliance with regulatory capital requirements. We continue to invest in building new capabilities that employ new AI technologies such as generative AI, and we expect our use of these technologies to increase over time. However, there are significant risks involved in utilizing models and AI and no assurance can be provided that our use will produce only intended or beneficial results. AI may subject us to new or heightened legal, regulatory, ethical, or other challenges; and negative public opinion of AI could impair the acceptance of AI solutions. If the models or AI solutions that we create or use are deficient, inaccurate or controversial, we could incur operational inefficiencies, competitive harm, legal liability, brand or reputational harm, or other adverse impacts on our business and financial results. We also may incur liability through the violation of applicable laws and regulations, third-party intellectual property, privacy or other rights, or contracts to which we are a party.
Sees AI as a riskDetail: Names an areaMachine learningGenerative AIRisk managementCompliance and anti-money launderingNew this year
We may use models and AI in processes such as determining the pricing of various products, identifying potentially fraudulent transactions, grading loans and extending credit, measuring interest rate and other market risks, predicting deposit levels or loan losses, assessing capital adequacy, calculating managerial and regulatory capital levels, estimating the value of financial instruments and balance sheet items, and other operational functions. Development and implementation of some of these models , such as the models for credit loss accounting under CECL, require us to make difficult, subjective and complex judgments. Our risk reporting and management, including business decisions based on information incorporating models and the use of AI, depend on the effectiveness of our models and AI and our policies, programs, processes and practices governing how data, models and AI, as applicable, are acquired, validated, stored, protected, processed and analyzed. Any issues with the quality or effectiveness of our data aggregation and validation procedures, as well as the quality and integrity of data inputs, formulas or algorithms, could result in inaccurate forecasts, ineffective risk management practices or inaccurate risk reporting. In addition, models and AI based on historical data sets might not be accurate predictors of future outcomes and their ability to appropriately predict future outcomes may degrade over time due to limited historical patterns, extreme or unanticipated market movements or customer behavior and liquidity, especially during severe market downturns or stress events (e.g., geopolitical or pandemic events).
Using AI nowDetail: Names an areaMachine learningFraud detectionCredit and lendingRisk managementOperationsNew this year
While we continuously update our policies, programs, processes and practices, many of our data management, modeling, AI, aggregation and implementation processes are manual and may be subject to human error, data limitations, process delays or system failure. Failure to manage data effectively and to aggregate data in an accurate and timely manner may limit our ability to manage current and emerging risk, to produce accurate financial, regulatory and operational reporting as well as to manage changing business needs. If our Framework is ineffective, we could suffer unexpected losses which could materially adversely affect our results of operation or financial condition. Also, any information we provide to the public or to our regulators based on incorrectly designed or implemented models or AI could be inaccurate or misleading. Some of the decisions that our regulators make, including those related to capital distribution to our stockholders, could be affected adversely due to the perception that the quality of the data, models and AI used to generate the relevant information is insufficient. In addition, regulation of AI is rapidly evolving worldwide as legislators and regulators are increasingly focused on these powerful emerging technologies. The technologies underlying AI and its uses are subject to a variety of laws and regulations, including intellectual property, privacy, data protection and information security, consumer protection, competition, and equal opportunity laws, and are expected to be subject to increased regulation and new laws or new applications of existing laws and regulations. AI is the subject of ongoing review by various U.S. governmental and regulatory agencies, and various U.S. states and other foreign jurisdictions are applying, or are considering applying, their platform moderation, privacy, data protection and data security laws and regulations to AI or are considering general legal frameworks for AI. We may not be able to anticipate how to respond to these rapidly evolving frameworks, and we may need to expend resources to adjust our offerings in certain jurisdictions if the legal frameworks are inconsistent across jurisdictions. Furthermore, because AI technology itself is highly complex and rapidly developing, it is not possible to predict all of the legal, operational or technological risks that may arise relating to the use of AI.
Sees AI as a riskDetail: Names an areaMachine learningNew this year
The legislative and regulatory environment is beyond our control, may change rapidly and unpredictably, and may negatively influence our revenue, costs, earnings, growth, liquidity and capital levels. For example, the CFPB has announced several initiatives related to the amounts and types of fees financial institutions may charge, including by issuing a proposed rule that would, among other things, significantly lower the safe harbor amount for past due fees that a credit card issuer can charge on consumer credit card accounts. Such changes could affect our ability or willingness to provide certain products or services, necessitate changes to the our business practices, or reduce our revenues. There may also be future rulemaking in emerging regulatory areas such as climate-related risks and new technologies. Adoption of new technologies, such as distributed ledger technologies, tokenization, cloud computing, AI and machine learning technologies, can present unforeseen challenges in applying and relying on existing compliance systems. In addition, some laws and regulations may be subject to litigation or other challenges that delay or modify their implementation and impact on us.
Sees AI as a riskDetail: GeneralMachine learningNew this year

Annual report, report year 2022 filed 24 Feb 2023

For example, on July 29, 2019, we announced that on March 22 and 23, 2019 an outside individual gained unauthorized access to our systems (the “Cybersecurity Incident”). This individual obtained certain types of personal information relating to people who had applied for our credit card products and to our credit card customers. While the Cybersecurity Incident has been remediated, it has resulted in fines, litigation, settlements, government investigations and other regulatory enforcement inquiries, as well as consent orders with the Federal Reserve and the OCC. On August 31, 2022, the OCC terminated its consent order. Cyber and information security risks for large financial institutions like us continue to increase due to the proliferation of new technologies, the industry-wide shift to reliance upon the internet to conduct financial transactions, and the increased sophistication and activities of malicious actors, organized crime, perpetrators of fraud, hackers, terrorists, activists, extremist parties, formal and informal instrumentalities of foreign governments, state-sponsored actors and other external parties. In addition, our customers access our products and services using personal devices that are necessarily external to our security control systems. There has also been a significant proliferation of consumer information available on the internet resulting from breaches of third-party entities, including personal information, log-in credentials and authentication data. While we were not directly involved in these third-party breach events, the stolen information can create a threat for our customers if their Capital One log-in credentials are the same as or similar to the credentials that have been compromised on other internet sites. This threat could include the risk of unauthorized account access, data loss and fraud. The use of artificial intelligence, “bots” or other automation software can increase the velocity and efficacy of these types of attacks. As our employees are currently operating under our hybrid work model, our remote interaction with service providers, partners and other third parties on systems, networks and environments over which we have less control increases our cybersecurity risk exposure. We will likely face an increasing number of attempted cyber-attacks as we expand our mobile and other internet-based products and services, as well as our usage of mobile and cloud technologies and as we provide more of these services to a greater number of retail banking customers.
Sees AI as a riskDetail: GeneralProcess automation
The legislative and regulatory environment is beyond our control, may change rapidly and unpredictably, and may negatively influence our revenue, costs, earnings, growth, liquidity and capital levels. For example, there may be future rulemaking in emerging regulatory areas such as climate-related risks and new technologies. In addition, some rules and regulations may be subject to litigation or other challenges that delay or modify their implementation and impact on us. Adoption of new technologies, such as distributed ledger technologies, tokenization, cloud computing, artificial intelligence and machine learning technologies, can present unforeseen challenges in applying and relying on existing compliance systems.
Sees AI as a riskDetail: GeneralMachine learning
11 passages in legal noticesThe forward-looking statements notice at the start or end of a filing. It often lists AI among many risks. It is never counted., not counted
•the use, reliability, and accuracy of the models, artificial intelligence (“AI”), and data on which we rely;
Same as last period
Quarterly report, page 68Read it in the reportReport an error
•the use, reliability, and accuracy of the models, artificial intelligence (“AI”), and data on which we rely;
Same as last period
Quarterly report, page 69Read it in the reportReport an error
•the use, reliability, and accuracy of the models, artificial intelligence, and data on which we rely;
Same as last period
Quarterly report, page 63Read it in the reportReport an error
•the extensive use, reliability, and accuracy of the models, artificial intelligence, and data on which we rely;
Same as last period
Quarterly report, page 66Read it in the reportReport an error
•the extensive use, reliability, and accuracy of the models, artificial intelligence, and data on which we rely;
Same as last period
Quarterly report, page 66Read it in the reportReport an error
•the extensive use, reliability, and accuracy of the models, artificial intelligence, and data on which we rely;
New this period
Quarterly report, page 63Read it in the reportReport an error
•the extensive use, reliability, and accuracy of the models, artificial intelligence (“AI”), and data on which we rely;
New this year