Banks

Citigroup Inc

C, C-PN, C-PR · NY · Large bank ($50B and above)
Total assets of FDIC-insured bank subsidiaries: $1836.5B at the end of 2025

Filings on the SEC website · This bank on Bankgraph

In short. In its 2025 annual report, Citigroup Inc mentions AI in 19 passages. It says it is using AI now, for compliance and anti-money laundering and operations. It lists AI as a risk and explains how AI is controlled.

Compare with peers

In the 2025 annual reportThe yearly report a listed company files with the SEC, called a 10-K. It describes the business, its risks and its results.

Mentions AI
Yes
19 passages
Highest detail levelHow specific a passage is about AI at this bank. General: could be in any bank's report. Names an area: says where AI is used or how it is controlled. Concrete example: names a tool or vendor, gives a number, a date or a result.
Names an area
What it says
Using AI now; Sees AI as a risk; Explains how AI is controlled; Standard wording or passing mention
Kinds of AI named
AI agents, Chatbots and assistants, Generative AI, Machine learning
How AI is controlled
Committee, Human review, Model risk management, Policy or framework, Vendor oversight

AI in its annual reports over time

What this shows
How many passages about AI each annual report contains, 2022 to 2025, by what they say.
What it means
0 passages in 2022, 19 passages in 2025.
How to read it
Each bar is a report year, split by what the passages say. Hover or tap a bar for the count.
Where it comes from
Banks' annual reports (10-K) filed with the SEC, up to 6 Oct 2026. How we did this
Passages about AI in Citigroup Inc's annual reports, by report year.
Show as a table
Report yearUsing or planning AIExplains how AI is controlledSees AI as a riskOther mentions
2022
2022
2022
2022
2023
2023
2023
2023
2024
2024
2024
2024
2025
2025
2025
2025

Compared with banks of its size

What this shows
This bank's 2025 annual report next to all 43 banks of its size ($50B and above).
What it means
Its most specific passage is "Names an area"; for banks of its size the typical level is "Names an area".
How to read it
Yes or no for this bank; the share of banks of the same size for comparison.
Where it comes from
Banks' annual reports (10-K) filed with the SEC, up to 6 Oct 2026. How we did this
In the 2025 reportThis bankBanks of its size
Using AI nowYes12 of 43 (28%)
Explains how AI is controlledYes30 of 43 (70%)
Sees AI as a riskYes43 of 43 (100%)
Mentions generative AIYes33 of 43 (77%)
Mentions AI agentsYes10 of 43 (23%)

What changed from 2024

13 passages new in the 2025 report, 4 passages from the 2024 report no longer there.

Every passage about AI

What this shows
All 47 passages about AI in this bank's annual reports, quarterly reports and earnings materials since 2023, newest first.
What it means
10 passages say the bank is using AI now.
How to read it
Highlighted words are the terms that matched. Labels show what each passage says. Follow the link to read it in the filing.
Where it comes from
Banks' annual reports (10-K), quarterly reports (10-Q) and earnings materials (8-K) filed with the SEC. How we did this

Quarterly report, Q2 2026 filed 6 Aug 2026

Generative AI: A type of artificial intelligence that uses generative models to create text and other content.
Standard wording or passing mentionDetail: GeneralGenerative AISame as last period
Quarterly report, page 203Read it in the reportReport an error

Quarterly report, Q1 2026 filed 7 May 2026

The qualitative management adjustment component includes risks that are not fully captured in the quantitative component. These may include but are not limited to portfolio characteristics, idiosyncratic events, factors not within historical loss data or the economic forecast, uncertainty in the credit environment and other factors as required by banking supervisory guidance for the ACL. Risks that are not fully captured in the quantitative component include potential impacts on vulnerable industries and regions due to heightened macroeconomic and geopolitical risks and uncertainties, as well as risks from emerging technologies (including AI) to vulnerable sectors.
Sees AI as a riskDetail: GeneralNew this periodNew since the annual report
Quarterly report, page 82Read it in the reportReport an error
Generative AI: A type of artificial intelligence that uses generative models to create text and other content.
Standard wording or passing mentionDetail: GeneralGenerative AISame as last period
Quarterly report, page 193Read it in the reportReport an error

Annual report, report year 2025 filed 20 Feb 2026

•applied technology solutions leveraging AI to support governance of data reported in key regulatory reports
Using AI nowDetail: Names an areaCompliance and anti-money launderingNew this year
Certain competitors may be subject to different and, in some cases, less stringent legal, regulatory and supervisory requirements, whether due to size, jurisdiction, entity type or other factors, placing Citi at a competitive disadvantage. To the extent that Citi is not able to compete effectively with other financial services companies, including private credit, financial technology and digital asset companies, and non-financial services firms, or adequately assess the competitive landscape, Citi could be placed at a competitive disadvantage, which could result in loss of customers and market share, and its businesses, results of operations and financial condition could suffer. For additional information on Citi’s competitive risks, see the co-branding and private label credit cards and qualified employees risk factors above and the AI risk factor and “Supervision, Regulation and Other—Competition” below.
Sees AI as a riskDetail: GeneralNew this year
Additionally, emerging technologies have the potential to accelerate disruption and intensify competition in the financial services industry. These emerging technologies, such as artificial intelligence (AI) and digital assets (including tokenized deposits, cryptocurrencies, stablecoins and other assets and products that use distributed ledger or blockchain technology) and changes in the payments space (e.g., instant and 24/7 payments) are accelerating, and, as a result, certain of Citi’s products and services could become less competitive (see the AI risk factor below).
Label being checked, not counted yetNew this year
Moreover, as Citi develops new products and services leveraging emerging technologies, new risks may emerge that, if not designed and governed adequately, may result in control gaps and in Citi operating outside of its risk appetite. For example, the use or development of emerging technologies, such as AI or digital assets, without sufficient controls, governance and risk management may result in increased risks across various risk categories (for additional information, see the AI, operational processes and systems and cybersecurity risk factors below). As another example, instant and 24/7 payments products could be accompanied by challenges to forecasting and managing liquidity, as well as increased operational and compliance risks.
Sees AI as a riskDetail: General
The Development and Use of AI by Citi and Others Present Risks to Citi’s Businesses.
Sees AI as a riskDetail: GeneralNew this year
Citi has used AI and machine learning tools for many years and has more recently begun to broadly deploy Generative AI, including within its technology platforms and services. In the future, Citi expects to more broadly integrate Generative AI tools within its systems, businesses and functions, including advanced AI capabilities, such as autonomous agents and sophisticated user interactions, which if improperly managed, could result in increased risks and costs.
Using AI nowDetail: Names an areaMachine learningGenerative AIAI agentsChatbots and assistantsOperationsNew this year
While Citi has policies that govern the use of emerging technologies, including in model risk management, ineffective, inadequate or faulty Generative AI development or deployment practices by Citi or third parties, including insufficient testing and monitoring, poorly structured or manipulated prompts or insufficient or inadequate human oversight, could result in adverse consequences, such as AI algorithms that produce inaccurate or incomplete output or output based on biased, incomplete and/or inaccurate datasets, infringe on intellectual property rights of others, involve data exfiltration risks, including release of confidential or proprietary information, or cause other issues, concerns or deficiencies. The complexity of AI models, particularly Generative AI models, can make it challenging to understand why particular outputs are generated, which can increase the risk of erroneous and/or biased output and complying with regulations requiring documentation, explainability or auditability on the basis of AI-influenced decisions.
Sees AI as a riskDetail: Names an areaGenerative AIMachine learningNew this year
Citi may also rely on AI models developed by third parties and be exposed to risks arising from their development and training methods, including potential inclusion of unauthorized material in the training data or limitations in their risk mitigation strategies, over which Citi may have limited visibility or control (see also the operational processes and systems risk factor below). While Citi may provide restrictions on use of certain data in third-party AI applications or models, a third party could breach those terms, which could expose Citi to legal and reputations risks. Citi is also exposed to risks related to the use of AI technologies by counterparties, clients and vendors, where interconnected AI systems could amplify failures and threats of cyber infiltration, as well as cause widespread disruptions.
Sees AI as a riskDetail: GeneralNew this year
Moreover, the use of increasingly sophisticated AI technologies by malicious actors and others has increased the risk of fraud, including identity theft and bypassing of verification controls, and exposure to cyberattacks (see the cybersecurity risk factor below), as well as disinformation and market manipulation campaigns, and failure to effectively manage such risks could result in misappropriation of funds, unauthorized transactions, exposure of sensitive client or Company information, reputational harm and increased litigation and regulatory risk.
Sees AI as a riskDetail: GeneralSame as last year
Citi also faces competition risks to the extent that competitors may be faster and more successful in developing and deploying AI technologies to improve processes, productivity, efficiency, products and services, and thereby gain competitive advantages over Citi (see the competition risk factor above).
Sees AI as a riskDetail: GeneralNew this year
In addition, compliance with new or changing laws, regulations or industry standards relating to AI may impose additional operational risks and costs. Failure to sufficiently manage these risks could expose Citi to adverse legal, regulatory or reputational consequences.
Sees AI as a riskDetail: General
With the proliferation of emerging technologies, including AI and digital assets, and the use of the internet, mobile devices and cloud services to conduct financial transactions, and customers’ and clients’ increasing use of online banking and trading systems and other platforms, large global financial institutions such as Citi have been, and will continue to be, subject to an ever-increasing risk of operational loss, failure or disruption. For example, Citi’s involvement in digital assets,
Sees AI as a riskDetail: General
The increasing use of cloud and new and emerging technologies (such as AI and digital assets), as well as connectivity solutions to facilitate remote working for Citi’s employees, all increase Citi’s exposure to cybersecurity risks. Citi is also susceptible to cyberattacks given, among other factors, its size and scale, high-profile brand, global footprint and prominent role in the financial system. Additionally, Citi continues to operate in multiple jurisdictions in the midst of geopolitical unrest or uncertainties, including, among others, those affected by the Russia–Ukraine war and the conflicts in the Middle East, which could expose Citi to heightened risk of insider threat, cyber threats from nation-state actors, hacktivism or other cyber incidents.
Sees AI as a riskDetail: GeneralNew this year
Because the techniques used to initiate cyberattacks change frequently or, in some cases, are not recognized until deployed, Citi may be unable to implement effective preventive measures or otherwise proactively address these risks. In addition, cyber threats and cyberattack techniques change, develop and evolve rapidly, including from emerging technologies such as AI and quantum computing. Given the frequency and sophistication of cyberattacks, the determination of the severity and potential impact of a cyber incident may not become apparent for a substantial period of time following detection of the incident. Also, while Citi strives to implement measures to reduce the exposure resulting from outsourcing risks, such as performing security control assessments of third-party vendors and limiting third-party access to the least privileged level necessary to perform service functions, these measures cannot prevent all third-party-related cyberattacks or data breaches.
Sees AI as a riskDetail: GeneralSame as last year
Citi is also a member of various central clearing counterparties and could incur financial losses as a result of defaults by other clearing members due to the requirements of clearing members to share losses. Additionally, systemic risks, including from leveraged finance, non-bank financial institutions, private credit and AI, could increase Citi’s credit costs.
Sees AI as a riskDetail: GeneralNew this year
security), technology resource and talent planning, and technology third-party management policies. Its responsibilities include reviewing and assessing significant technology investments and expenditures, overseeing and reviewing information from management regarding Citi’s approach to Generative AI and reviewing reports on technology and data quality-related matters.
Explains how AI is controlledDetail: Names an areaGenerative AINew this year
Cybersecurity risk is the operational risk associated with the threat posed by a cyberattack, cyber breach or the failure to protect Citi’s most vital business information assets or operations, resulting in a financial or reputational loss (see the operational processes and systems and cybersecurity risk factors in “Risk Factors—Operational Risks” above). With an evolving threat landscape, ever-increasing sophistication of threat actor tactics, techniques and procedures, ongoing and emerging geopolitical conflicts, and the availability of new technologies, including those enabled by artificial intelligence and machine learning capabilities, to conduct financial transactions, Citi and its clients, customers and third parties (and fourth parties, etc.) continue to be at risk from cyberattacks and information security incidents. Citi leverages a threat-focused, industry-standard-aligned, defense-in-depth strategy that ensures that multiple controls work in tandem against various threats to increase the likelihood that malicious activity will be prevented, detected and mitigated.
Sees AI as a riskDetail: GeneralMachine learningSame as last year
In this context, external factors affecting Citi’s operating environment are the economic environment, geopolitical/political landscape, industry/competitive landscape, environmental, customer/client behavior, regulatory/legislative environment and trends related to investors/shareholders. Material strategic risks that Citi is monitoring include the impacts of adverse changes in inflation and interest rates in the U.S., as well as macroeconomic uncertainties driven by weak global growth, tariffs, geopolitical issues and changing regulatory requirements. AI has added competitive pressure while productivity assumptions tied to AI-driven operation model changes may materialize more slowly than expected or require additional unforeseen upfront investment. In addition to external factors affecting Citi’s operating environment, Citi also monitors risks related to the execution of its strategy, with heightened focus on delivering the transformation of its risk and control environment pursuant to the 2020 FRB and OCC Consent Orders.
Sees AI as a riskDetail: GeneralNew this year
Generative AI: A type of artificial intelligence that uses generative models to create text and other content.
Standard wording or passing mentionDetail: GeneralGenerative AINew this year

Quarterly report, Q3 2025 filed 6 Nov 2025

•Expanded the adoption of Generative AI tools with the rollout of new features that enable faster and easier access and increase overall productivity
Using AI nowDetail: Names an areaGenerative AIEmployee productivityNew this periodNew since the annual report
Quarterly report, page 11Read it in the reportReport an error
◦Approximately 1 million automated code reviews completed by Citi’s Generative AI tools year-to-date, saving approximately 100,000 hours per week across Citi’s developer population
Using AI nowDetail: Concrete exampleGenerative AIProcess automationSoftware developmentEmployee productivityNew this periodNew since the annual report
Quarterly report, page 11Read it in the reportReport an error
AI: Artificial intelligence
Standard wording or passing mentionDetail: GeneralNew this periodNew since the annual report
Quarterly report, page 220Read it in the reportReport an error
Generative AI: A type of artificial intelligence that uses generative models to create text and other content.
Standard wording or passing mentionDetail: GeneralGenerative AINew this periodNew since the annual report
Quarterly report, page 222Read it in the reportReport an error

Earnings release, Q3 2025 filed 14 Oct 2025

Citi CEO Jane Fraser said, “The relentless execution of our strategy is delivering stronger business performance quarter after quarter and improving our returns. The cumulative effect of what we have done over the past years – our transformation, our refreshed strategy, our simplification – have put Citi in a materially different place in terms of our ability to compete. Investments in new products, digital assets and AI are driving innovation and improved capabilities across the franchise.
General statement about AIDetail: GeneralNew this periodNew since the annual report

Earnings release, Q2 2025 filed 15 Jul 2025

“We returned $3 billion in capital during the quarter, including $2 billion in share repurchases as part of our $20 billion repurchase plan. I’m particularly pleased that the momentum across our franchise includes the Transformation, as we streamline processes, drive automation and deploy AI.
General statement about AIDetail: GeneralProcess automationNew this periodNew since the annual report

Quarterly report, Q1 2025 filed 8 May 2025

•Significantly expanding adoption of Generative AI tools, increasing efficiency and productivity across Citi
Using AI nowDetail: Names an areaGenerative AIEmployee productivityOperationsNew this periodNew since the annual report
Quarterly report, page 11Read it in the reportReport an error
◦Logged 385,000 utilizations of two enterprise-wide tools (document intelligence and virtual assistant)
Using AI nowDetail: Concrete exampleGenerative AIChatbots and assistantsEmployee productivityOperationsNew this periodNew since the annual report
Quarterly report, page 11Read it in the reportReport an error
◦Completed approximately 220,000 automated code reviews in the Generative AI developer tool, considerably increasing coding capacity
Using AI nowDetail: Concrete exampleGenerative AIProcess automationSoftware developmentNew this periodNew since the annual report
Quarterly report, page 11Read it in the reportReport an error
◦Launched Agent Assist, Citi’s first USPB Generative AI customer service tool
Using AI nowDetail: Concrete exampleGenerative AICustomer serviceNew this periodNew since the annual report
Quarterly report, page 11Read it in the reportReport an error
•Using Generative AI to enhance detection of unauthorized trading activity to improve FX trade surveillance in Markets
Using AI nowDetail: Names an areaGenerative AICompliance and anti-money launderingRisk managementNew this periodNew since the annual report
Quarterly report, page 11Read it in the reportReport an error

Annual report, report year 2024 filed 21 Feb 2025

blockchain technology, including a more favorable regulatory approach to crypto assets. Citi may not be able to provide the same or similar products and services for legal or regulatory reasons, which may be exacerbated by rapidly evolving and conflicting regulatory requirements, as well as increased compliance and other risks. Further, the introduction of mobile platforms and emerging technologies, such as artificial intelligence (AI) and digital assets, and changes in the payments space (e.g., instant and 24/7 payments) are accelerating, and, as a result, certain of Citi’s products and services could become less competitive.
Sees AI as a riskDetail: GeneralNew this year
Simultaneously, as Citi develops new products and services leveraging emerging technologies, new risks may emerge that, if not designed and governed adequately, may result in control gaps and in Citi operating outside of its risk appetite. For example, the use or development of emerging technologies, such as AI or digital assets, without sufficient controls, governance and risk management may result in increased risks across various risk categories (for additional information, see the operational processes and systems risk factor below).
Sees AI as a riskDetail: GeneralNew this year
Citi’s operations must also comply with complex and evolving laws, regulations and heightened regulatory expectations in the jurisdictions in which it operates (see the implementation and interpretation of regulatory changes and legal proceedings risk factors below). With the proliferation of emerging technologies, including AI, and the use of the internet, mobile devices and cloud services to conduct financial transactions, and customers’ and clients’ increasing use of online banking and trading systems and other platforms, large global financial institutions such as Citi have been, and will continue to be, subject to an ever-increasing risk of operational loss, failure or disruption.
Sees AI as a riskDetail: GeneralNew this year
Citi has been working with AI and machine learning for a period of time and has more recently begun using Generative AI, a type of artificial intelligence that uses generative models to create text and other content. Generative AI tools are available to employees within parts of the Company, and in the future Citi may more broadly use, develop and incorporate Generative AI within its technology platform and services, systems and its businesses and functions. While Citi has policies which govern the use of emerging technologies, ineffective, inadequate or faulty Generative AI development or deployment practices by Citi or third parties could result in unintended consequences, such as AI algorithms that produce inaccurate or incomplete output or output based on biased, incomplete and/or inaccurate datasets, or cause other issues, concerns or deficiencies. Moreover, the use of increasingly sophisticated AI technologies by malicious actors and others has increased the risk of fraud, including identity theft and bypassing of verification controls, and failure to effectively manage such risks could result in misappropriation of funds, unauthorized transactions, exposure of sensitive client or Company information, reputational harm and increased litigation and regulatory risk. In addition, compliance with new or changing laws, regulations or industry standards relating to AI may impose additional operational risks and costs.
Using AI nowDetail: Names an areaMachine learningGenerative AIOperationsEmployee productivityNew this year
The increasing use of mobile and other digital banking platforms and services, cloud technologies, new and emerging technologies (such as AI) and connectivity solutions to facilitate remote working for Citi’s employees all increase Citi’s exposure to cybersecurity risks. Citi is also susceptible to cyberattacks given, among other things, its size and scale, high-profile brand, global footprint and prominent role in the financial system, as well as the ongoing wind-down of its
Sees AI as a riskDetail: GeneralNew this year
measures or any other measures can provide sufficient security. Because the techniques used to initiate cyberattacks change frequently or, in some cases, are not recognized until launched or even later, Citi may be unable to implement effective preventive measures or otherwise proactively address these methods. In addition, cyber threats and cyberattack techniques change, develop and evolve rapidly, including from emerging technologies such as AI, cloud computing and quantum computing. Given the frequency and sophistication of cyberattacks, the determination of the severity and potential impact of a cyber incident may not become apparent for a substantial period of time following detection of the incident. Also, while Citi strives to implement measures to reduce the exposure resulting from outsourcing risks, such as performing security control assessments of third-party vendors and limiting third-party access to the least privileged level necessary to perform job functions, these measures cannot prevent all third-party-related cyberattacks or data breaches. In addition, the risk of insider threats may continue to be elevated in the near term due to Citi’s recent overall simplification initiatives, including streamlining its global staff functions.
Sees AI as a riskDetail: GeneralNew this year
impairment. These assumptions, judgments and estimates are inherently limited because they involve techniques, which could include the use of historical data and AI, that cannot anticipate or model every economic and financial outcome in the markets in which Citi operates, nor can they anticipate the specific impact and timing of such outcomes. For example, many models used by Citi include assumptions about correlation or lack thereof among prices of various asset classes or other market indicators that may not hold in times of market stress, limited liquidity or other unforeseen circumstances.
Sees AI as a riskDetail: Names an areaRisk managementNew this year
Cybersecurity risk is the business risk associated with the threat posed by a cyberattack, cyber breach or the failure to protect Citi’s most vital business information assets or operations, resulting in a financial or reputational loss (see the operational processes and systems and cybersecurity risk factors in “Risk Factors—Operational Risks” above). With an evolving threat landscape, ever-increasing sophistication of threat actor tactics, techniques and procedures, ongoing and emerging geopolitical conflicts, and the use of new technologies, including those enabled by artificial intelligence and machine learning capabilities, to conduct financial transactions, Citi and its clients, customers and third parties (and fourth parties, etc.) continue to be at risk from cyberattacks and information security incidents. Citi leverages a threat-focused, defense-in-depth strategy that ensures that multiple controls work in tandem against various threats to increase the likelihood that malicious activity will be prevented, detected and mitigated.
Sees AI as a riskDetail: GeneralMachine learningSame as last year

Annual report, report year 2023 filed 23 Feb 2024

market entrants. Simultaneously, as Citi develops new products and services leveraging emerging technologies, new risks may emerge that, if not designed and governed adequately, may result in control gaps and in Citi operating outside of its risk appetite. For example, failure to strategically embrace the potential of artificial intelligence (AI) may result in a competitive disadvantage to Citi. At the same time, as a new technology, use of AI without sufficient controls, governance and risk management may result in increased risks across all of Citi’s risk categories. As another example, instant and 24x7 payments products could be accompanied by challenges to forecasting and managing liquidity, as well as increased operational and compliance risks.
Sees AI as a riskDetail: GeneralNew this year
While Citi’s monitoring and protection services have historically generally succeeded in detecting, thwarting and/or responding to attacks targeting its systems before they become significant, certain past incidents resulted in limited losses, as well as increases in expenditures to monitor against the threat of similar future cyber incidents. There can be no assurance that such cyber incidents will not occur again, and they could occur more frequently, via novel tactics, including leveraging of tools made possible by emerging technologies, and on a more significant scale. Despite the significant resources Citi allocates to implement, maintain, monitor and regularly upgrade its systems and networks with measures such as intrusion detection and prevention systems and firewalls to safeguard critical business applications, there is no guarantee that these measures or any other measures can provide sufficient security. Because the techniques used to initiate cyberattacks change frequently or, in some cases, are not recognized until launched or even later, Citi may be unable to implement effective preventive measures or otherwise proactively address these methods. In addition, cyber threats and cyberattack techniques change, develop and evolve rapidly, including from emerging technologies such as artificial intelligence, cloud computing and quantum
Sees AI as a riskDetail: GeneralNew this year
Cybersecurity risk is the business risk associated with the threat posed by a cyberattack, cyber breach or the failure to protect Citi’s most vital business information assets or operations, resulting in a financial or reputational loss (see the operational processes and systems and cybersecurity risk factors in “Risk Factors—Operational Risks” above). With an evolving threat landscape, ever-increasing sophistication of threat actor tactics, techniques and procedures, ongoing and emerging geopolitical conflicts, and the use of new technologies, including those enabled by artificial intelligence and machine learning capabilities, to conduct financial transactions, Citi and its clients, customers and third parties (and fourth parties, etc.) continue to be at risk from cyberattacks and information security incidents. Citi leverages a threat-focused, defense-in-depth strategy that ensures that multiple controls work in tandem against various threats to increase the likelihood that malicious activity will be prevented, detected and mitigated.
Sees AI as a riskDetail: GeneralMachine learningNew this year
17 passages in legal noticesThe forward-looking statements notice at the start or end of a filing. It often lists AI among many risks. It is never counted., not counted
•risks to Citi from the development and use of AI, including discovery and exploitation of vulnerabilities and exposure to cyberattacks; ineffective, inadequate or faulty Generative AI development or deployment practices by Citi or third parties; increased risk of fraud, disinformation and market manipulation campaigns; competition risks to the extent that competitors may develop and deploy AI technology faster and more successfully; and risks and costs from
Same as last periodNew since the annual report
Quarterly report, page 89Read it in the reportReport an error
•the increasing risk to Citi’s and third parties’ computer systems, software and networks from evolving and sophisticated cybersecurity incidents, the risks of which are heightened by new and emerging technologies, such as AI and digital assets, as well as conflicts in the Middle East, that could result in, among other things, the theft, loss, non-availability, alteration, misuse or disclosure of personal, confidential or proprietary Citi, client, customer or employee information or assets and a disruption of computer, software or network systems; and the potential impact from such risks, including reputational damage, loss of revenues, deposit outflows, additional costs (including repair, replacement, remediation and other costs), exposure to litigation and regulatory action and other financial losses;
Same as last periodNew since the annual report
Quarterly report, page 90Read it in the reportReport an error
emerging technologies (including AI) and other factors, particularly for vulnerable sectors, industries or countries and jurisdictions; and any systemic risk concerns related to exposures to leveraged finance and non-bank financial institutions, including private credit;
New this periodNew since the annual report
Quarterly report, page 90Read it in the reportReport an error
•risks to Citi from the development and use of AI, including ineffective, inadequate or faulty Generative AI development or deployment practices by Citi or third parties; increased risk of fraud, disinformation and market manipulation campaigns; discovery and exploitation of vulnerabilities and exposure to cyberattacks; competition risks to the extent that competitors may develop and deploy AI technology faster and more successfully; and risks and costs from compliance with new or changing laws, regulations or industry standards;
New this periodNew since the annual report
Quarterly report, page 86Read it in the reportReport an error
•the increasing risk to Citi’s and third parties’ computer systems, software and networks from evolving and sophisticated cybersecurity incidents, the risks of which are heightened by new and emerging technologies, such as AI and digital assets, as well as the conflict in the Middle East, that could result in, among other things, the theft, loss, non-availability, alteration, misuse or disclosure of personal, confidential or proprietary Citi, client, customer or employee information or assets and a disruption of computer, software or network systems; and the potential impact from such risks, including reputational damage, loss of revenues, deposit outflows, additional costs (including repair, replacement, remediation and other costs), exposure to litigation and regulatory action and other financial losses;
New this periodNew since the annual report
Quarterly report, page 87Read it in the reportReport an error
•the potential impact of credit risk and concentrations of risk on Citi’s results of operations, including due to defaults by or a significant downgrade in credit ratings of a consumer or corporate or other counterparty; a decline in the credit quality or value of, or Citi’s inability to liquidate or realize the fair value of, any underlying collateral, which risks can be heightened by macroeconomic, geopolitical, market, emerging technologies (including AI) and other factors, particularly for vulnerable sectors, industries or countries; and any
New this periodNew since the annual report
Quarterly report, page 87Read it in the reportReport an error
•risks to Citi from the development and use of AI, including unintended consequences from ineffective, inadequate or faulty Generative AI development or deployment by Citi or third parties, such as AI algorithms that produce inaccurate or incomplete output or output based on biased, incomplete and/or inaccurate datasets; increased fraud risk, including identity theft and bypassing of verification controls, from the use of increasingly sophisticated AI technologies by malicious actors; competition risks if competitors are more timely and successful in developing and deploying AI
New this periodNew since the annual report
Quarterly report, page 98Read it in the reportReport an error
technologies; and operational risks and costs from compliance with new or changing laws, regulations or industry standards relating to AI;
New this periodNew since the annual report
Quarterly report, page 98Read it in the reportReport an error
•Citi’s ability to compete effectively in the U.S. and globally with both financial and non-financial services firms, including as a result of certain competitors being subject to less stringent legal, regulatory and supervisory requirements; the introduction of mobile platforms and new or emerging technologies, such as artificial intelligence (AI)–driven solutions; mergers and acquisitions involving traditional financial services companies such as regional banks or credit card issuers; changes in the payments space; developments in digital finance, including growth and use of digital assets resulting from regulatory and other changes driven by the
New this periodNew since the annual report
Quarterly report, page 97Read it in the reportReport an error
•the potential impact to Citi from a prior or future failure or disruption of its operational processes or systems, including as a result of, among other things, operational or execution failures or deficiencies by third parties, including third parties that provide products or services to Citi or other market participants or those that otherwise have an ongoing partnership or business relationship with Citi; deficiencies in processes or controls; inadequate management of data governance practices, data controls and monitoring mechanisms that may adversely impact internal or external reporting and decision-making; cyber or information security incidents; human error, such as manual transaction processing errors, which can be exacerbated by staffing challenges and processing backlogs; ineffective, inadequate or faulty Generative AI development or deployment practices by Citi or third parties; fraud or malice on the part of employees or third parties; insufficient (or limited) straight-through processing between legacy or bespoke systems and any failure to design and effectively operate controls that mitigate operational risks associated with those legacy or bespoke systems, leading to potential risk of errors and operating losses; accidental system or technological failure; electrical or telecommunication outages; failure of or cyber incidents involving computer servers or infrastructure, including software updates and cloud services; and other similar losses or damage to Citi’s property or assets;
Same as last periodNew since the annual report
Quarterly report, page 97Read it in the reportReport an error
•Citi’s ability to compete effectively in the U.S. and globally with both financial and non-financial services firms, including as a result of certain competitors being subject to less stringent legal, regulatory and supervisory requirements; the introduction of mobile platforms and new or emerging technologies, such as artificial intelligence (AI)–driven solutions; potential mergers and
New this periodNew since the annual report
Quarterly report, page 92Read it in the reportReport an error
•the potential impact to Citi from a prior or future failure or disruption of its operational processes or systems, including as a result of, among other things, operational or execution failures or deficiencies by third parties, including third parties that provide products or services to Citi or other market participants or those that otherwise have an ongoing partnership or business relationship with Citi; deficiencies in processes or controls; inadequate management of data governance practices, data controls and monitoring mechanisms that may adversely impact internal or external reporting and decision-making; cyber or information security incidents; human error, such as manual transaction processing errors, which can be exacerbated by staffing challenges and processing backlogs; ineffective, inadequate or faulty Generative AI development or deployment practices by Citi or third parties; fraud or malice on the part of employees or third parties; insufficient (or limited) straight-through processing between legacy or bespoke systems and any failure to design and effectively operate controls that mitigate operational risks associated with those legacy or bespoke systems, leading to potential risk of errors and operating losses; accidental system or technological failure; electrical or telecommunication outages; failure of or cyber incidents involving computer servers or infrastructure, including software updates and cloud services; and other similar losses or damage to Citi’s property or assets;
New this periodNew since the annual report
Quarterly report, page 92Read it in the reportReport an error
•Citi’s ability to compete effectively in the U.S. and globally with both financial and non-financial services firms, including as a result of certain competitors being subject to less stringent legal, regulatory and supervisory requirements; the introduction of mobile platforms and new or emerging technologies, such as artificial intelligence-driven solutions; potential mergers and acquisitions involving traditional financial services companies such as regional banks or credit card issuers; changes in the payments space; reliance on third parties
New this periodNew since the annual report
Quarterly report, page 96Read it in the reportReport an error
•Citi’s ability to compete effectively in the U.S. and globally with both financial and non-financial services firms, including as a result of certain competitors being subject to less stringent legal and regulatory requirements; the introduction of mobile platforms and new or emerging technologies, such as artificial intelligence-driven solutions; potential mergers and acquisitions involving traditional financial services companies such as regional banks or credit card issuers; changes in the payments space; reliance on third parties for certain product and service offerings and any impact if a third party is unable to provide adequate support for such product and service offerings; and the increased operational, compliance and other risks resulting from the need to develop new or change or adapt existing products and services to attract and retain customers or clients or to compete more effectively;
Same as last periodNew since the annual report
Quarterly report, page 100Read it in the reportReport an error
•Citi’s ability to compete effectively in the U.S. and globally with both financial and non-financial services firms, including as a result of certain competitors being subject to less stringent legal and regulatory requirements; the introduction of mobile platforms and new or emerging technologies, such as artificial intelligence-driven solutions; potential mergers and acquisitions involving traditional financial services companies such as regional banks or credit card issuers; changes in the payments space; reliance on third parties for certain product and service offerings and any impact if a third party is unable to provide adequate support for such product and service offerings; and the increased operational, compliance and other risks resulting from the need to develop new or change or adapt existing products and services to attract and retain customers or clients or to compete more effectively;
New this periodNew since the annual report
Quarterly report, page 89Read it in the reportReport an error
•Citi’s ability to compete effectively in the U.S. and globally with both financial and non-financial services firms, including as a result of certain competitors being subject to less stringent legal and regulatory requirements; the introduction of new or emerging technologies and mobile platforms; possible disruptions from artificial intelligence-driven solutions; growth in digital asset markets; changes in the payments space; reliance on third parties for certain product and service offerings and impact if any third party is unable to provide adequate support for such product and service offerings; and the increased operational, compliance and other risks resulting from the need to develop new or change or adapt existing products and services to attract and retain customers or clients or to compete more effectively with competitors;
Same as last periodNew since the annual report
Quarterly report, page 88Read it in the reportReport an error
the introduction of new or emerging technologies and mobile platforms; possible disruptions from artificial intelligence-driven solutions; growth in digital asset markets; changes in the payments space; reliance on third parties for certain product and service offerings and impact if any third party is unable to provide adequate support for such product and service offerings; and the increased operational, compliance and other risks resulting from the need to develop new or change or adapt existing products and services to attract and retain customers or clients or to compete more effectively with competitors;
New this periodNew since the annual report
Quarterly report, page 86Read it in the reportReport an error