In short. In its 2025 annual report, Cullen/frost Bankers, Inc. mentions AI in 4 passages. It lists AI as a risk, but the report does not say how AI is controlled. Compared with banks of its size, it gives less detail than most.
In the 2025 annual reportThe yearly report a listed company files with the SEC, called a 10-K. It describes the business, its risks and its results.
Mentions AI
Yes
4 passages
Highest detail levelHow specific a passage is about AI at this bank. General: could be in any bank's report. Names an area: says where AI is used or how it is controlled. Concrete example: names a tool or vendor, gives a number, a date or a result.
General
What it says
Sees AI as a risk
Kinds of AI named
Process automation
How AI is controlled
Not described
AI in its annual reports over time
What this shows
How many passages about AI each annual report contains, 2022 to 2025, by what they say.
What it means
1 passage in 2022, 4 passages in 2025.
How to read it
Each bar is a report year, split by what the passages say. Hover or tap a bar for the count.
Where it comes from
Banks' annual reports (10-K) filed with the SEC, up to 6 Oct 2026. How we did this
Passages about AI in Cullen/frost Bankers, Inc.'s annual reports, by report year.Show as a table
Report year
Using or planning AI
Explains how AI is controlled
Sees AI as a risk
Other mentions
2022
2022
2022
2022
2023
2023
2023
2023
2024
2024
2024
2024
2025
2025
2025
2025
Compared with banks of its size
What this shows
This bank's 2025 annual report next to all 43 banks of its size ($50B and above).
What it means
Its most specific passage is "General"; for banks of its size the typical level is "Names an area".
How to read it
Yes or no for this bank; the share of banks of the same size for comparison.
Where it comes from
Banks' annual reports (10-K) filed with the SEC, up to 6 Oct 2026. How we did this
In the 2025 report
This bank
Banks of its size
Using AI now
No
12 of 43 (28%)
Explains how AI is controlled
No
30 of 43 (70%)
Sees AI as a risk
Yes
43 of 43 (100%)
Mentions generative AI
No
33 of 43 (77%)
Mentions AI agents
No
10 of 43 (23%)
What changed from 2024
2 passages new in the 2025 report, 0 passages from the 2024 report no longer there.
Every passage about AI
What this shows
All 8 passages about AI in this bank's annual reports, quarterly reports and earnings materials since 2023, newest first.
What it means
0 passages say the bank is using AI now.
How to read it
Highlighted words are the terms that matched. Labels show what each passage says. Follow the link to read it in the filing.
Where it comes from
Banks' annual reports (10-K), quarterly reports (10-Q) and earnings materials (8-K) filed with the SEC. How we did this
Annual report, report year 2025 filed 5 Feb 2026
The financial services industry is continually undergoing rapid technological change with frequent introductions of new technology-driven products and services, including the increased usage of intelligent automation within the industry. Our future success depends, in part, upon our ability to address the needs of our customers by using technology to provide products and services that will satisfy customer demands, as well as to create additional efficiencies in our operations. Many of our competitors have substantially greater resources to invest in technological improvements. We may not be able to effectively implement new technology driven products and services or be successful in marketing these products and services to our customers. In addition, our implementation of certain new technologies, such as those related to artificial intelligence, automation and algorithms, in our business processes may have unintended consequences due to their limitations or our failure to use them effectively. In addition, cloud technologies are critical to the operation of our systems, and our reliance on cloud technologies is growing. Failure to successfully keep pace with technological change affecting the financial services industry could have a material adverse effect on our business, financial condition and results of operations.
Sees AI as a riskDetail: GeneralProcess automation
Similar wording appears in 16 other banks' reports.
In the ordinary course of business, we rely on electronic communications and information systems to conduct our operations and to store sensitive data. Any failure, interruption or breach in security of these systems could result in significant disruption to our operations. Information security breaches and cybersecurity-related incidents include, but are not limited to, attempts to access information, including customer and company information, malicious code, computer viruses and denial of service attacks that could result in unauthorized access, theft, misuse, loss, release or destruction of data (including confidential customer information), account takeovers, unavailability of service or other events. These types of threats may derive from human error, fraud or malice on the part of external or internal parties or may result from accidental technological failure. Our technologies, systems, networks and software have been and continue to be subject to cybersecurity threats and attacks, which range from uncoordinated individual attempts to sophisticated and targeted measures directed at us. Any failures related to upgrades and maintenance of our technology and information systems could further increase our information and system security risk. Our increased use of cloud and other technologies, such as remote work technologies, adoption of artificial intelligence, and the increased connectivity of third parties and electronic devices to our systems also increases our risk of being subject to a cyber-attack. The risk of a security breach or disruption, particularly through cyber-attack or cyber-intrusion, has increased as the number, intensity and sophistication of attempted attacks and intrusions from around the world have increased.
Although we make significant efforts to maintain the security and integrity of our information systems and have implemented various measures to manage the risks of a security breach or disruption, there can be no assurance that our security efforts and measures will be effective or that attempted security breaches or disruptions would not be successful or damaging. It is possible that employees, merchants or our third-party vendors may not follow our cybersecurity policies and procedures, which may expose us to a cyber-attack. Furthermore, even well protected information, networks, systems and facilities remain potentially vulnerable to attempted security breaches or disruptions because the techniques used in such attempts are constantly evolving, including as a result of artificial intelligence, and generally are not recognized until launched against a target, and in some cases are designed not to be detected and, in fact, may not be detected. Accordingly, we may be unable to anticipate these techniques or to implement adequate security barriers or other preventative measures, and thus it is virtually impossible for us to entirely mitigate this risk. In the event of a cyber-attack, we may be delayed in identifying or responding to the attack, which could increase the negative impact of the cyber-attack on our business, financial condition and results of operations. While we maintain specific “cyber” insurance coverage, which would apply in the event of various breach scenarios, the amount of coverage may not be adequate in any particular case. Furthermore, because cyber threat scenarios are inherently difficult to predict and can take many forms, some breaches may not be covered under our cyber insurance coverage. A security breach or other significant disruption of our information systems or those related to our customers, merchants or our third-party vendors, including as a result of cyber-attacks, could (i) disrupt the proper functioning of our networks and systems and therefore our operations and/or those of our customers; (ii) result in the unauthorized access to, and destruction, loss, theft, misappropriation or release of confidential, sensitive or otherwise valuable information of ours or our customers; (iii) result in a violation of applicable privacy, data breach and other laws, subjecting us to additional regulatory scrutiny and exposing us to civil litigation, enforcement actions, governmental fines and possible financial liability; (iv) require significant management attention and resources to remedy the damages that result; or (v) harm our reputation or cause a decrease in the number of customers that choose to do business with us. The occurrence of any of the foregoing could have a material adverse effect on our business, financial condition and results of operations and could result in serious and harmful consequences to our customers.
Although we employ robust security measures, including authentication protocols, transaction monitoring, and fraud detection systems, these controls may not be sufficient to prevent all fraudulent activity. Criminals continuously adapt their methods to circumvent existing safeguards, and emerging technologies such as artificial intelligence may further enhance their ability to perpetrate fraud.
The financial services industry is continually undergoing rapid technological change with frequent introductions of new technology-driven products and services. Our future success depends, in part, upon our ability to address the needs of our customers by using technology to provide products and services that will satisfy customer demands, as well as to create additional efficiencies in our operations. Many of our competitors have substantially greater resources to invest in technological improvements. We may not be able to effectively implement new technology driven products and services or be successful in marketing these products and services to our customers. In addition, our implementation of certain new technologies, such as those related to artificial intelligence, automation and algorithms, in our business processes may have unintended consequences due to their limitations or our failure to use them effectively. In addition, cloud technologies are also critical to the operation of our systems, and our reliance on cloud technologies is growing. Failure to successfully keep pace with technological change affecting the financial services industry could have a material adverse effect on our business, financial condition and results of operations.
Sees AI as a riskDetail: GeneralProcess automationSame as last year
Similar wording appears in 10 other banks' reports.
Although we make significant efforts to maintain the security and integrity of our information systems and have implemented various measures to manage the risks of a security breach or disruption, there can be no assurance that our security efforts and measures will be effective or that attempted security breaches or disruptions would not be successful or damaging. It is possible that employees, merchants or our third-party vendors may not follow our cybersecurity policies and procedures, which may expose us to a cyber-attack. Furthermore, even well protected information, networks, systems and facilities remain potentially vulnerable to attempted security breaches or disruptions because the techniques used in such attempts are constantly evolving, including as a result of artificial intelligence, and generally are not recognized until launched against a target, and in some cases are designed not to be detected and, in fact, may not be detected. Accordingly, we may be unable to anticipate these techniques or to implement adequate security barriers or other preventative measures, and thus it is virtually impossible for us to entirely mitigate this risk. In the event of a cyber-attack, we may be delayed in identifying or responding to the attack, which could increase the negative impact of the cyber-attack on our business, financial condition and results of operations. While we maintain specific “cyber” insurance coverage, which would apply in the event of various breach scenarios, the amount of coverage may not be adequate in any particular case. Furthermore, because cyber threat scenarios are inherently difficult to predict and can take many forms, some breaches may not be covered under our cyber insurance coverage. A security breach or other significant disruption of our information systems or those related to our customers, merchants or our third-party vendors, including as a result of cyber-attacks, could (i) disrupt the proper functioning of our networks and systems and therefore our operations and/or those of our customers; (ii) result in the unauthorized access to, and destruction, loss, theft, misappropriation or release of confidential, sensitive or otherwise valuable information of ours or our customers; (iii) result in a violation of applicable privacy, data breach and other laws, subjecting us to additional regulatory scrutiny and exposing us to civil litigation, enforcement actions, governmental fines and possible financial liability; (iv) require significant management attention and resources to remedy the damages that result; or (v) harm our reputation or cause a decrease in the number of customers that choose to do business with us. The occurrence of any of the foregoing could have a material adverse effect on our business, financial condition and results of operations.
The financial services industry is continually undergoing rapid technological change with frequent introductions of new technology-driven products and services. Our future success depends, in part, upon our ability to address the needs of our customers by using technology to provide products and services that will satisfy customer demands, as well as to create additional efficiencies in our operations. Many of our competitors have substantially greater resources to invest in technological improvements. We may not be able to effectively implement new technology driven products and services or be successful in marketing these products and services to our customers. In addition, our implementation of certain new technologies, such as those related to artificial intelligence, automation and algorithms, in our business processes may have unintended consequences due to their limitations or our failure to use them effectively. In addition, cloud technologies are also critical to the operation of our systems, and our reliance on cloud technologies is growing. Failure to successfully keep pace with technological change affecting the financial services industry could have a material adverse effect on our business, financial condition and results of operations.
Sees AI as a riskDetail: GeneralProcess automationSame as last year
Similar wording appears in 7 other banks' reports.
The financial services industry is continually undergoing rapid technological change with frequent introductions of new technology-driven products and services. Our future success depends, in part, upon our ability to address the needs of our customers by using technology to provide products and services that will satisfy customer demands, as well as to create additional efficiencies in our operations. Many of our competitors have substantially greater resources to invest in technological improvements. We may not be able to effectively implement new technology driven products and services or be successful in marketing these products and services to our customers. In addition, our implementation of certain new technologies, such as those related to artificial intelligence, automation and algorithms, in our business processes may have unintended consequences due to their limitations or our failure to use them effectively. In addition, cloud technologies are also critical to the operation of our systems, and our reliance on cloud technologies is growing. Failure to successfully keep pace with technological change affecting the financial services industry could have a material adverse effect on our business, financial condition and results of operations.
Sees AI as a riskDetail: GeneralMachine learningProcess automation
5 passages in legal noticesThe forward-looking statements notice at the start or end of a filing. It often lists AI among many risks. It is never counted., not counted
We do not undertake any obligation to update any forward-looking statement to reflect events or circumstances after the date on which such statement is made, or to reflect the occurrence of unanticipated events. • Changes in the reliability of our vendors, internal control systems or information systems. • Our ability to increase market share and control expenses. • Our ability to attract and retain qualified employees. • Changes in our organization, compensation, and benefit plans. • The soundness of other financial institutions. • Volatility and disruption in national and international financial and commodity markets. • Changes in the competitive environment in our markets and among banking organizations and other financial service providers. • Government intervention in the U.S. financial system. • Political or economic instability. • Acts of God or of war or terrorism. • The potential impact of climate change. • The impact of pandemics, epidemics, or any other health-related crisis. • The costs and effects of legal and regulatory developments, the resolution of legal proceedings or regulatory or other governmental inquiries, the results of regulatory examinations or reviews and the ability to obtain required regulatory approvals. • The effect of changes in laws and regulations (including laws and regulations concerning taxes, banking, securities, and insurance) and their application with which we and our subsidiaries must comply. • The effect of changes in accounting policies and practices, as may be adopted by the regulatory agencies, as well as the Public Company Accounting Oversight Board, the Financial Accounting Standards Board and other accounting standard setters. • Our success at managing the risks involved in the foregoing items. • The effects of and changes in trade and monetary and fiscal policies and laws, including the interest rate policies of the Federal Reserve Board and the implementation of tariffs and other protectionist trade policies. • Inflation, interest rate, securities market, and monetary fluctuations. • Local, regional, national, and international economic conditions and the impact they may have on us and our customers and our assessment of that impact. • Changes in the financial performance and/or condition of our borrowers. • Changes in the mix of loan geographies, sectors and types or the level of non-performing assets and charge-offs. • Changes in estimates of future credit loss reserve requirements based upon the periodic review thereof under relevant regulatory and accounting requirements. • Changes in our liquidity position. • Impairment of our goodwill or other intangible assets. • The timely development and acceptance of new products and services and perceived overall value of these products and services by users. • Changes in consumer spending, borrowing, and saving habits. • Greater than expected costs or difficulties related to the integration of new products and lines of business. • Technological changes, including advances in artificial intelligence and quantum computing. • The cost and effects of cyber incidents or other failures, interruptions, or security breaches of our systems or those of our customers or third-party providers. • Acquisitions and integration of acquired businesses.
10 Technology Highlights Modernization of Core Banking 2028 +: 100% of Tier 1 Capabilities current and on regular schedule of updates (53% in the cloud) 2027: 91% of Tier 1 Capabilities modernized (43% in the cloud) Today: 66% of Tier 1 Capabilities modernized (40% in the cloud, 8 new capabilities) 2021: 47% of Tier 1 Capabilities modernized (16% in the cloud) Overall Digital Transformation Timeline Completed • Data center & network modernization • RTP/FedNew receive • Public cloud expansion • Upgrades to mainframe platform • Contact center conversion • Fraud & sanction screening modernization 2026 & Beyond • Debit card conversion • Consumer wires • RTP/FedNow send • Wires conversion • Disputes & Adjustments conversion • Commercial loan system conversion • Customer single sign-on Call Center Stats1 Facilitated By: Call Center Modernization Contact Center Copilot Enhanced Customer Chat Zelle Send and Receive Volume $2.0 $2.2 Q2-2025 Q2-2026 Apple App Store Rating 4.9 4.9 Q2-2025 Q2-2026 % of Checking Households that engaged digitally over the past month 80% 81% Q2-2025 Q2-2026 Consumer Digital Banking Stats +10% +1% 1 Call center stats as of December, 2025
10 Technology Highlights Modernization of Core Banking 2028 +: 100% of Tier 1 Capabilities current and on regular schedule of updates (53% in the cloud) 2027: 91% of Tier 1 Capabilities modernized (43% in the cloud) Today: 66% of Tier 1 Capabilities modernized (40% in the cloud, 8 new capabilities) 2021: 47% of Tier 1 Capabilities modernized (16% in the cloud) Overall Digital Transformation Timeline Completed • Data center & network modernization • RTP/FedNew receive • Public cloud expansion • Upgrades to mainframe platform • Contact center conversion • Fraud & sanction screening modernization 2026 & Beyond • Debit card conversion • Consumer wires • RTP/FedNow send • Wires conversion • Disputes & Adjustments conversion • Commercial loan system conversion • Customer single sign-on Call Center Stats Facilitated By: Call Center Modernization Contact Center Copilot Enhanced Customer Chat Zelle Send and Receive Volume $1.7 $1.9 Q4-2024 Q4-2025 Apple App Store Rating 4.9 4.9 Q4-2024 Q4-2025 % of Checking Households that engaged digitally over the past month 79% 82% Q4-2024 Q4-2025 Consumer Digital Banking Stats +17.1% +2.8%