AI Artificial Intelligence
Standard wording or passing mentionDetail: GeneralSame as last year
MTB, MTB-PH, MTB-PJ, MTB-PK, MTB-PL · NY · Large bank ($50B and above)
Total assets of FDIC-insured bank subsidiaries: $213.7B at the end of 2025
Filings on the SEC website · This bank on Bankgraph
| Report year | Using or planning AI | Explains how AI is controlled | Sees AI as a risk | Other mentions |
|---|---|---|---|---|
| 2022 | ||||
| 2022 | ||||
| 2022 | ||||
| 2022 | ||||
| 2023 | ||||
| 2023 | ||||
| 2023 | ||||
| 2023 | ||||
| 2024 | ||||
| 2024 | ||||
| 2024 | ||||
| 2024 | ||||
| 2025 | ||||
| 2025 | ||||
| 2025 | ||||
| 2025 |
| In the 2025 report | This bank | Banks of its size |
|---|---|---|
| Using AI now | No | 12 of 43 (28%) |
| Explains how AI is controlled | No | 30 of 43 (70%) |
| Sees AI as a risk | Yes | 43 of 43 (100%) |
| Mentions generative AI | Yes | 33 of 43 (77%) |
| Mentions AI agents | No | 10 of 43 (23%) |
1 passage new in the 2025 report, 1 passage from the 2024 report no longer there.
AI Artificial Intelligence
•The development and use of AI, including by third parties, presents risks and challenges that may adversely impact M&T.
Technological change is influencing how individuals and firms conduct their financial affairs and is changing the delivery channels for financial services. Financial technology providers, who invest substantial resources in developing and designing new technology (in particular digital and mobile technology) are beginning to offer more traditional banking products (either directly or through bank partnerships), or products that may be viewed as substitutes for traditional banking products, and may in the future be able to provide additional services by obtaining a bank-like charter, such as the OCC’s financial technology company charter. In addition, the emergence, adoption and evolution of new technologies that do not require intermediation, including distributed ledgers such as digital assets and blockchain, as well as advances in robotic process automation and AI, could significantly affect the competition for financial services. As a result, the Company has had and will likely continue to have to contend with a broader range of competitors including many that are not located within the geographic footprint of its banking office network. Further, along with other participants in the financial services industry, the Company frequently attempts to introduce new technology-driven products and services that are aimed at allowing the Company to better serve customers and to reduce costs. The Company may not be able to effectively implement new technology-driven products and services that allow it to remain competitive or be successful in marketing these products and services to its customers.
Information security risks for large financial institutions such as M&T have increased significantly in recent years in part because of the proliferation of new technologies, such as AI and digital and mobile banking to conduct financial transactions, the increased connectivity of third parties (including contractors) and electronic devices to the Company's systems, and the increased sophistication and activities of organized crime, hackers, terrorists, nation-states, activists and other external parties. There have been increasing efforts on the part of third parties, including through cyber attacks, to breach data security at financial institutions or with respect to financial transactions.
Like other financial services firms, the systems, networks and devices of the Company, its customers, employees, service providers or other third parties with whom the Company interacts continue to be the subject of attempted unauthorized access, denial-of-service attacks, computer viruses, hacking, malware, ransomware, phishing or other forms of social engineering, and cyber attacks designed to obtain confidential information, destroy data, disrupt or degrade service, eliminate access or cause other damage. These threats may arise from human error, fraud on the part of employees, insiders or third parties or may result from accidental technology failure or vulnerabilities of suppliers through supply-chain attacks. Further, cybersecurity and information security risks for financial institutions have generally increased because of, among other things, the growth of new technologies (including AI), the use of the Internet and telecommunications technologies (including computers, smartphones, and other mobile devices outside the Company’s systems) by customers to conduct financial transactions, and the increased sophistication and activities of organized crime, fraudsters, hackers, terrorists, activists, instrumentalities of foreign governments and other external parties.
The development and use of AI, including by third parties, presents risks and challenges that may adversely impact M&T.
The Company or its third-party vendors, clients or counterparties may develop or incorporate AI technology in certain business processes, services or products. The development and use of AI presents a number of risks and challenges to M&T’s business. The legal and regulatory environment relating to AI is uncertain and rapidly evolving, and includes regulation targeted specifically at AI as well as provisions in intellectual property, privacy, consumer protection, employment and other laws
Similar wording appears in 9 other banks' reports.
applicable to the use of AI. These evolving laws and regulations could require changes in the Company’s or third parties’ implementation of AI technology and increase the Company’s compliance costs and risk of non-compliance.
AI models, including generative AI models may produce output or influence the Company or its third-party service providers to take actions that are incorrect, that result in the release of private, confidential or proprietary information, that reflect biases included in the data on which they are trained, that infringe on the intellectual property rights of others, or that are otherwise harmful. In addition, the complexity of certain AI models makes it challenging to understand why they are generating particular outputs. This limited transparency increases the challenges associated with assessing the proper operation of AI models, understanding and monitoring the capabilities of the AI models, reducing erroneous output, eliminating bias and complying with regulations that require documentation or explanation of the basis on which decisions are made. Further, the Company may rely on AI models developed by third parties, and, to that extent, would be dependent in part on the manner in which those third parties develop and train their models, including risks arising from the inclusion of any unauthorized material in the training data for their models, and the effectiveness of the steps these third parties have taken to limit the risks associated with the output of their models, matters over which the Company may have limited visibility. Any of these risks could expose M&T to liability or adverse legal or regulatory consequences and harm its reputation and the public perception of its business or the effectiveness of its security measures.
In addition to the Company’s use of AI technologies, the Company is exposed to risks arising from the use of AI technologies by bad actors to commit fraud and misappropriate funds and to facilitate cyber attacks. Use of AI technologies by bad actors can contribute to the evolution of new and more effective techniques, which can hinder the Company’s efforts to prevent, detect and remediate such harmful activities. AI, if used to perpetrate fraud or launch cyber attacks, could result in losses, liquidity outflows or other adverse effects at a particular exchange or financial institution, including the Company.
AI Artificial Intelligence
•The development and use of AI, including by third parties, presents risks and challenges that may adversely impact M&T.
Information security risks for large financial institutions such as M&T have increased significantly in recent years in part because of the proliferation of new technologies, such as AI and digital and mobile banking to conduct financial transactions, the increased connectivity of third parties (including contractors) and electronic devices to our systems, and the increased sophistication and activities of organized crime, hackers, terrorists, nation-states, activists and other external parties.
Like other financial services firms, the systems, networks and devices of the Company, its customers, employees, service providers or other third parties with whom the Company interacts continue to be the subject of attempted unauthorized access, denial-of-service attacks, computer viruses, hacking, malware, ransomware, phishing or other forms of social engineering, and cyber attacks designed to obtain confidential information, destroy data, disrupt or degrade service, eliminate access or cause other damage. These threats may arise from human error, fraud on the part of employees, insiders or third parties or may result from accidental technology failure or vulnerabilities of suppliers through supply-chain attacks. Further, cybersecurity and information security risks for financial institutions have generally increased because of, among other things, the growth of new technologies (including AI), the use of the Internet and telecommunications technologies (including computers, smartphones, and other mobile devices outside the Company’s systems) by customers to conduct financial transactions, and the increased sophistication and activities of organized crime, fraudsters, hackers, terrorists, activists, instrumentalities of foreign governments and other external parties.
The development and use of AI, including by third parties, presents risks and challenges that may adversely impact M&T.
The Company or its third-party vendors, clients or counterparties may develop or incorporate AI technology in certain business processes, services or products. The development and use of AI presents a number of risks and challenges to M&T’s business. The legal and regulatory environment relating to AI is uncertain and rapidly evolving, and includes regulation targeted specifically at AI as well as provisions in intellectual property, privacy, consumer protection, employment and other laws applicable to the use of AI. These evolving laws and regulations could require changes in the
Similar wording appears in 9 other banks' reports.
Company’s or third parties’ implementation of AI technology and increase the Company’s compliance costs and risk of non-compliance.
AI models, including generative AI models may produce output or influence the Company or its third-party service providers to take actions that are incorrect, that result in the release of private, confidential or proprietary information, that reflect biases included in the data on which they are trained, that infringe on the intellectual property rights of others, or that are otherwise harmful. In addition, the complexity of certain AI models makes it challenging to understand why they are generating particular outputs. This limited transparency increases the challenges associated with assessing the proper operation of AI models, understanding and monitoring the capabilities of the AI models, reducing erroneous output, eliminating bias and complying with regulations that require documentation or explanation of the basis on which decisions are made. Further, the Company may rely on AI models developed by third parties, and, to that extent, would be dependent in part on the manner in which those third parties develop and train their models, including risks arising from the inclusion of any unauthorized material in the training data for their models, and the effectiveness of the steps these third parties have taken to limit the risks associated with the output of their models, matters over which the Company may have limited visibility. Any of these risks could expose M&T to liability or adverse legal or regulatory consequences and harm its reputation and the public perception of its business or the effectiveness of its security measures.
In addition to the Company’s use of AI technologies, the Company is exposed to risks arising from the use of AI technologies by bad actors to commit fraud and misappropriate funds and to facilitate cyber attacks. Use of AI technologies by bad actors can contribute to the evolution of new and more effective techniques, which can hinder the Company’s efforts to prevent, detect and remediate such harmful activities. AI, if used to perpetrate fraud or launch cyber attacks, could result in losses, liquidity outflows or other adverse effects at a particular exchange or financial institution, including the Company.