Banks

OP Bancorp

OPBK · CA · Mid-size bank ($1B to $50B)
Total assets of FDIC-insured bank subsidiaries: $2.7B at the end of 2025

Filings on the SEC website · This bank on Bankgraph

In short. In its 2025 annual report, OP Bancorp mentions AI in 5 passages. It lists AI as a risk and explains how AI is controlled. Compared with banks of its size, it gives more detail than most.

Compare with peers

In the 2025 annual reportThe yearly report a listed company files with the SEC, called a 10-K. It describes the business, its risks and its results.

Mentions AI
Yes
5 passages
Highest detail levelHow specific a passage is about AI at this bank. General: could be in any bank's report. Names an area: says where AI is used or how it is controlled. Concrete example: names a tool or vendor, gives a number, a date or a result.
Names an area
What it says
Sees AI as a risk
Kinds of AI named
Process automation, Machine learning
How AI is controlled
Model risk management, Vendor oversight

AI in its annual reports over time

What this shows
How many passages about AI each annual report contains, 2022 to 2025, by what they say.
What it means
0 passages in 2022, 5 passages in 2025.
How to read it
Each bar is a report year, split by what the passages say. Hover or tap a bar for the count.
Where it comes from
Banks' annual reports (10-K) filed with the SEC, up to 6 Oct 2026. How we did this
Passages about AI in OP Bancorp's annual reports, by report year.
Show as a table
Report yearUsing or planning AIExplains how AI is controlledSees AI as a riskOther mentions
2022
2022
2022
2022
2023
2023
2023
2023
2024
2024
2024
2024
2025
2025
2025
2025

Compared with banks of its size

What this shows
This bank's 2025 annual report next to all 221 banks of its size ($1B to $50B).
What it means
Its most specific passage is "Names an area"; for banks of its size the typical level is "General".
How to read it
Yes or no for this bank; the share of banks of the same size for comparison.
Where it comes from
Banks' annual reports (10-K) filed with the SEC, up to 6 Oct 2026. How we did this
In the 2025 reportThis bankBanks of its size
Using AI nowNo26 of 221 (12%)
Explains how AI is controlledYes55 of 221 (25%)
Sees AI as a riskYes184 of 221 (83%)
Mentions generative AINo112 of 221 (51%)
Mentions AI agentsNo18 of 221 (8%)

What changed from 2024

4 passages new in the 2025 report, 1 passage from the 2024 report no longer there. The most specific passage is more detailed than last year.

Every passage about AI

What this shows
All 24 passages about AI in this bank's annual reports, quarterly reports and earnings materials since 2023, newest first.
What it means
0 passages say the bank is using AI now.
How to read it
Highlighted words are the terms that matched. Labels show what each passage says. Follow the link to read it in the filing.
Where it comes from
Banks' annual reports (10-K), quarterly reports (10-Q) and earnings materials (8-K) filed with the SEC. How we did this

Quarterly report, Q2 2026 filed 7 Aug 2026

Cybersecurity measures are, by their nature, largely reactive, and threats are constantly evolving. We expect that the development of AI-based technologies will accelerate both the number and the sophistication of these threats. We routinely experience attempts to exploit our networks and systems, and we must continue investing in increasingly advanced (and concomitantly expensive) technology to counteract these threats. Further, if our systems cannot timely detect and mitigate vulnerabilities, or cannot promptly respond to threats, we may experience damage to or interruptions in the availability of our computer networks, or we may experience a loss of data, unauthorized use or disclosure of customer information, or a loss of customer funds as a result of unauthorized access to customer accounts. Likewise, breaches of our payroll, benefits, and other employee-related systems may give rise to liability under employment and privacy laws and may damage our relationships with our employees. Further, we may have a limited ability to enforce warranties, indemnities or other remedies against the providers of these systems in the event we incur a loss.
Sees AI as a riskDetail: GeneralSame as last period
Quarterly report, page 57Read it in the reportReport an error
Our operations could be disrupted by our third‑party service providers, including risks arising from their use of artificial intelligence technologies, experiencing difficulty in providing their services, terminating their services, or failing to comply with banking regulations.
Sees AI as a riskDetail: GeneralSame as last period
Quarterly report, page 58Read it in the reportReport an error
We depend to a significant extent on relationships with third‑party service providers. Specifically, we utilize third‑party core banking services and receive credit card and debit card services, branch capture services, Internet banking services and services complementary to our banking products from various third‑party service providers. Certain of these third‑party service providers may incorporate or rely on artificial intelligence (“AI”), machine learning, automated decision‑making technologies or similar emerging technologies in the development or delivery of their products and services, including technologies that are evolving rapidly and for which regulatory expectations are continuing to develop. These third‑party relationships are subject to increasingly demanding regulatory requirements that require us to maintain and continue to enhance our due diligence, contractual controls, and ongoing monitoring and oversight of our vendors, including with respect to their information security practices, data governance, model risk management, operational resilience and compliance with applicable laws and regulations. The use of AI by our third‑party service providers may increase the complexity of these oversight obligations and may expose us to additional risks, including risks
Sees AI as a riskDetail: Names an areaMachine learningProcess automationSame as last period
Quarterly report, page 58Read it in the reportReport an error
related to data privacy and security, model performance, bias or discrimination, explainability, intellectual property, and regulatory compliance. We may be required to renegotiate or modify our agreements to address these enhanced requirements or evolving supervisory expectations, which could increase our costs or may be impracticable. If our service providers experience operational difficulties, fail to perform in accordance with expectations, experience disruptions related to AI system failures or errors, suffer a cyberattack or other security breach, fail to comply with applicable laws or regulations, or terminate their services, and we are unable to replace them in a timely manner, our operations could be interrupted. It may be difficult for us to replace certain service providers promptly, particularly where the services involve specialized technologies or proprietary platforms, including AI‑enabled systems, and replacement services may be available only at higher cost or on less favorable terms.
Sees AI as a riskDetail: GeneralSame as last period
Quarterly report, page 59Read it in the reportReport an error
In addition, many of our agreements with third‑party service providers limit our ability to recover damages, even for negligent actions that may result in customer harm, regulatory scrutiny, or enforcement actions. Regulatory requirements generally apply directly to financial institutions rather than to their service providers, and we expect that our regulators would hold us responsible for deficiencies in or failures of our third‑party relationships, including deficiencies related to the use of AI technologies by those providers. Such deficiencies could result in supervisory findings, enforcement actions, civil money penalties, litigation, customer remediation obligations, reputational harm, or other administrative or judicial penalties or fines, any of which could have a material adverse effect on our business, financial condition and results of operations.
Sees AI as a riskDetail: GeneralSame as last period
Quarterly report, page 59Read it in the reportReport an error

Quarterly report, Q1 2026 filed 15 May 2026

Cybersecurity measures are, by their nature, largely reactive, and threats are constantly evolving. We expect that the development of AI-based technologies will accelerate both the number and the sophistication of these threats. We routinely experience attempts to exploit our networks and systems, and we must continue investing in increasingly advanced (and concomitantly expensive) technology to counteract these threats. Further, if our systems cannot timely detect and mitigate vulnerabilities, or cannot promptly respond to threats, we may experience damage to or interruptions in the availability of our computer networks, or we may experience a loss of data, unauthorized use or disclosure of customer information, or a loss of customer funds as a result of unauthorized access to customer accounts. Likewise, breaches of our payroll, benefits, and other employee-related systems may give rise to liability under employment and privacy laws and may damage our relationships with our employees. Further, we may have a limited ability to enforce warranties, indemnities or other remedies against the providers of these systems in the event we incur a loss.
Sees AI as a riskDetail: GeneralSame as last period
Quarterly report, page 53Read it in the reportReport an error
Our operations could be disrupted by our third‑party service providers, including risks arising from their use of artificial intelligence technologies, experiencing difficulty in providing their services, terminating their services, or failing to comply with banking regulations.
Sees AI as a riskDetail: GeneralNew this period
Quarterly report, page 54Read it in the reportReport an error
We depend to a significant extent on relationships with third‑party service providers. Specifically, we utilize third‑party core banking services and receive credit card and debit card services, branch capture services, Internet banking services and services complementary to our banking products from various third‑party service providers. Certain of these third‑party service providers may incorporate or rely on artificial intelligence (“AI”), machine learning, automated decision‑making technologies or similar emerging technologies in the development or delivery of their products and services, including technologies that are evolving rapidly and for which regulatory expectations are continuing to develop. These third‑party relationships are subject to increasingly demanding regulatory requirements that require us to maintain and continue to enhance our due diligence, contractual controls, and ongoing monitoring and oversight of our vendors, including with respect to their information security practices, data governance, model risk management, operational resilience and compliance with applicable laws and regulations. The use of AI by our third‑party service providers may increase the complexity of these oversight obligations and may expose us to additional risks, including risks
Sees AI as a riskDetail: Names an areaMachine learningProcess automationNew this period
Quarterly report, page 54Read it in the reportReport an error
related to data privacy and security, model performance, bias or discrimination, explainability, intellectual property, and regulatory compliance. We may be required to renegotiate or modify our agreements to address these enhanced requirements or evolving supervisory expectations, which could increase our costs or may be impracticable. If our service providers experience operational difficulties, fail to perform in accordance with expectations, experience disruptions related to AI system failures or errors, suffer a cyberattack or other security breach, fail to comply with applicable laws or regulations, or terminate their services, and we are unable to replace them in a timely manner, our operations could be interrupted. It may be difficult for us to replace certain service providers promptly, particularly where the services involve specialized technologies or proprietary platforms, including AI‑enabled systems, and replacement services may be available only at higher cost or on less favorable terms.
Sees AI as a riskDetail: GeneralNew this period
Quarterly report, page 55Read it in the reportReport an error
In addition, many of our agreements with third‑party service providers limit our ability to recover damages, even for negligent actions that may result in customer harm, regulatory scrutiny, or enforcement actions. Regulatory requirements generally apply directly to financial institutions rather than to their service providers, and we expect that our regulators would hold us responsible for deficiencies in or failures of our third‑party relationships, including deficiencies related to the use of AI technologies by those providers. Such deficiencies could result in supervisory findings, enforcement actions, civil money penalties, litigation, customer remediation obligations, reputational harm, or other administrative or judicial penalties or fines, any of which could have a material adverse effect on our business, financial condition and results of operations.
Sees AI as a riskDetail: GeneralNew this period
Quarterly report, page 55Read it in the reportReport an error

Annual report, report year 2025 filed 13 Mar 2026

Cybersecurity measures are, by their nature, largely reactive, and threats are constantly evolving. We expect that the development of AI-based technologies will accelerate both the number and the sophistication of these threats. We routinely experience attempts to exploit our networks and systems, and we must continue investing in increasingly advanced (and concomitantly expensive) technology to counteract these threats. Further, if our systems cannot timely detect and mitigate vulnerabilities, or cannot promptly respond to threats, we may experience damage to or interruptions in the availability of our computer networks, or we may experience a loss of data, unauthorized use or disclosure of customer information, or a loss of customer funds as a result of unauthorized access to customer accounts. Likewise, breaches of our payroll, benefits, and other employee-related systems may give rise to liability under employment and privacy laws and may damage our
Sees AI as a riskDetail: General
Our operations could be disrupted by our third‑party service providers, including risks arising from their use of artificial intelligence technologies, experiencing difficulty in providing their services, terminating their services, or failing to comply with banking regulations.
Sees AI as a riskDetail: GeneralNew this year
We depend to a significant extent on relationships with third‑party service providers. Specifically, we utilize third‑party core banking services and receive credit card and debit card services, branch capture services, Internet banking services and services complementary to our banking products from various third‑party service providers. Certain of these third‑party service providers may incorporate or rely on artificial intelligence (“AI”), machine learning, automated decision‑making technologies or similar emerging technologies
Sees AI as a riskDetail: Names an areaMachine learningProcess automationNew this year
in the development or delivery of their products and services, including technologies that are evolving rapidly and for which regulatory expectations are continuing to develop. These third‑party relationships are subject to increasingly demanding regulatory requirements that require us to maintain and continue to enhance our due diligence, contractual controls, and ongoing monitoring and oversight of our vendors, including with respect to their information security practices, data governance, model risk management, operational resilience and compliance with applicable laws and regulations. The use of AI by our third‑party service providers may increase the complexity of these oversight obligations and may expose us to additional risks, including risks related to data privacy and security, model performance, bias or discrimination, explainability, intellectual property, and regulatory compliance. We may be required to renegotiate or modify our agreements to address these enhanced requirements or evolving supervisory expectations, which could increase our costs or may be impracticable. If our service providers experience operational difficulties, fail to perform in accordance with expectations, experience disruptions related to AI system failures or errors, suffer a cyberattack or other security breach, fail to comply with applicable laws or regulations, or terminate their services, and we are unable to replace them in a timely manner, our operations could be interrupted. It may be difficult for us to replace certain service providers promptly, particularly where the services involve specialized technologies or proprietary platforms, including AI‑enabled systems, and replacement services may be available only at higher cost or on less favorable terms.
Sees AI as a riskDetail: GeneralNew this year
In addition, many of our agreements with third‑party service providers limit our ability to recover damages, even for negligent actions that may result in customer harm, regulatory scrutiny, or enforcement actions. Regulatory requirements generally apply directly to financial institutions rather than to their service providers, and we expect that our regulators would hold us responsible for deficiencies in or failures of our third‑party relationships, including deficiencies related to the use of AI technologies by those providers. Such deficiencies could result in supervisory findings, enforcement actions, civil money penalties, litigation, customer remediation obligations, reputational harm, or other administrative or judicial penalties or fines, any of which could have a material adverse effect on our business, financial condition and results of operations.
Sees AI as a riskDetail: GeneralNew this year

Quarterly report, Q3 2025 filed 7 Nov 2025

Notwithstanding these investments, cybersecurity measures are, by their nature, largely reactive, and threats are constantly evolving. We expect that the development of AI-based technologies will accelerate both the number and the sophistication of these threats. We routinely experience attempts to exploit our networks and systems, and we must continue investing in increasingly advanced (and concomitantly expensive) technology to counteract these threats. Further, if our systems cannot timely detect and mitigate vulnerabilities, or cannot promptly respond to threats, we may experience damage to or interruptions in the availability of our computer networks, or we may experience a loss of data, unauthorized use or disclosure of customer information, or a loss of customer funds as a result of unauthorized access to customer accounts. Likewise, breaches of our payroll, benefits, and other employee-related systems may give rise to liability under employment and privacy laws and may damage our relationships with our employees. Further, we may have a limited ability to enforce warranties, indemnities or other remedies against the providers of these systems in the event we incur a loss.
Sees AI as a riskDetail: GeneralNew this period
Quarterly report, page 62Read it in the reportReport an error

Quarterly report, Q2 2025 filed 11 Aug 2025

Notwithstanding these investments, cybersecurity measures are, by their nature, largely reactive, and threats are constantly evolving. We expect that the development of AI-based technologies will accelerate both the number and the sophistication of these threats. We routinely experience attempts to exploit our networks and systems, and we must continue investing in increasingly advanced (and concomitantly expensive) technology to counteract these threats. Further, if our systems cannot timely detect and mitigate vulnerabilities, or cannot promptly respond to threats, we may experience
Sees AI as a riskDetail: GeneralSame as last period
Quarterly report, page 58Read it in the reportReport an error

Quarterly report, Q1 2025 filed 9 May 2025

Notwithstanding these investments, cybersecurity measures are, by their nature, largely reactive, and threats are constantly evolving. We expect that the development of AI-based technologies will accelerate both the number and the sophistication of these threats. We routinely experience attempts to exploit our networks and systems, and we must continue investing in increasingly advanced (and concomitantly expensive) technology to counteract these threats. Further, if our systems cannot timely detect and mitigate vulnerabilities, or cannot promptly respond to threats, we may experience
Sees AI as a riskDetail: General
Quarterly report, page 57Read it in the reportReport an error
Notwithstanding these investments, cybersecurity measures are, by their nature, largely reactive, and threats are constantly evolving. We expect that the development of AI-based technologies will accelerate both the number and the sophistication of these threats. We routinely experience attempts to exploit our networks and systems, and we must continue investing in increasingly advanced (and concomitantly expensive) technology to counteract these threats. Further, if our systems cannot timely detect and mitigate vulnerabilities, or cannot promptly respond to threats, we may experience damage to or interruptions in the availability of our computer networks, or we may experience a loss of data, unauthorized use or disclosure of customer information, or a loss of customer funds as a result of unauthorized access to customer accounts. Likewise, breaches of our payroll, benefits, and other employee-related systems may give rise to liability under employment laws and may damage our relationships with our employees.
Sees AI as a riskDetail: General
Quarterly report, page 60Read it in the reportReport an error

Annual report, report year 2024 filed 28 Mar 2025

The financial services industry is subject to rapid technological changes, of which we cannot predict the effects on our business. We expect that new services and technologies applicable to our industry will continue to emerge, and these new services and technologies may be superior to, or render obsolete, the technologies we currently utilize in our products and services. These rapid changes increase cybersecurity risks to our Company and our third-party vendors and service providers, including the risk of security breaches, “denial of service” attacks, “hacking” and identity theft. Criminals are using increasingly sophisticated methods to engage in illegal activities, including through the use of deposit account products and customer information and may also see their effectiveness enhanced by the use of artificial intelligence. A single significant incident of fraud, or increases in the overall level of fraud, involving our products and services could result in reputational damage to us. Such damage could reduce the use and acceptance of our products and services or lead to greater regulation that would increase our compliance costs. Fraudulent activity could also result in the imposition of regulatory sanctions, including significant monetary fines, which could adversely affect our business, results of operations and financial condition. To address the challenges that we face with respect to fraudulent activity, we maintain certain risk control policies and procedures, both internally and with respect to our third-party vendors and service providers, that make it more difficult for to fraudulently obtain and use our products and services. However, our inability to keep pace with technological changes, including our ability to identify and address cybersecurity risks, may significantly affect our financial position and results of operation.
Sees AI as a riskDetail: General
Notwithstanding these investments, cybersecurity measures are, by their nature, largely reactive, and threats are constantly evolving. We expect that the development of AI-based technologies will accelerate both the number and the sophistication of these threats. We routinely experience attempts to exploit our networks and systems, and we must continue investing in increasingly advanced (and concomitantly expensive) technology to counteract these threats. Further, if our systems cannot timely detect and mitigate vulnerabilities, or cannot promptly respond to threats, we may experience damage to or interruptions in the availability of our computer networks, or we may experience a loss of data, unauthorized use or disclosure of customer information, or a loss of customer funds as a result of unauthorized access to customer accounts. Likewise, breaches of our payroll, benefits, and other employee-related systems may give rise to liability under employment laws and may damage our relationships with our employees.
Sees AI as a riskDetail: GeneralNew this year

Quarterly report, Q3 2024 filed 14 Nov 2024

Notwithstanding these investments, cybersecurity measures are, by their nature, largely reactive, and threats are constantly evolving. We expect that the development of AI-based technologies will accelerate both the number and the sophistication of these threats. We routinely experience attempts to exploit our networks and systems, and we must continue investing in increasingly advanced (and concomitantly expensive) technology to counteract these threats. Further, if our systems cannot timely detect and mitigate vulnerabilities, or cannot promptly respond to threats, we may experience damage to or interruptions in the availability of our computer networks, or we may experience a loss of data, unauthorized use or disclosure of customer information, or a loss of customer funds as a result of unauthorized access to customer
Sees AI as a riskDetail: GeneralSame as last periodNew since the annual report
Quarterly report, page 69Read it in the reportReport an error

Quarterly report, Q2 2024 filed 14 Aug 2024

Notwithstanding these investments, cybersecurity measures are, by their nature, largely reactive, and threats are constantly evolving. We expect that the development of AI-based technologies will accelerate both the number and the sophistication of these threats. We routinely experience attempts to exploit our networks and systems, and we must continue investing in increasingly advanced (and concomitantly expensive) technology to counteract these threats. Further, if our systems cannot timely detect and mitigate vulnerabilities, or cannot promptly respond to threats, we may experience damage to or interruptions in the availability of our computer networks, or we may experience a loss of data, unauthorized use or disclosure of customer information, or a loss of customer funds as a result of unauthorized access to customer accounts. Likewise, breaches of our payroll, benefits, and other employee-related systems may give rise to liability under employment laws and may damage our relationships with our employees.
Sees AI as a riskDetail: GeneralNew this periodNew since the annual report
Quarterly report, page 67Read it in the reportReport an error

Annual report, report year 2023 filed 29 Mar 2024

The financial services industry is subject to rapid technological changes, of which we cannot predict the effects on our business. We expect that new services and technologies applicable to our industry will continue to emerge, and these new services and technologies may be superior to, or render obsolete, the technologies we currently utilize in our products and services. These rapid changes increase cybersecurity risks to our Company and our third-party vendors and service providers, including the risk of security breaches, “denial of service” attacks, “hacking” and identity theft. Criminals are using increasingly sophisticated methods to engage in illegal activities, including through the use of deposit account products and customer information and may also see their effectiveness enhanced by the use of artificial intelligence. A single significant incident of fraud, or increases in the overall level of fraud, involving our products and services could result in reputational damage to us. Such damage could reduce the use and acceptance of our products and services or lead to greater regulation that would increase our compliance costs. Fraudulent activity could also result in the imposition of regulatory sanctions, including significant monetary fines, which could adversely affect our business, results of operations and financial condition. To address the challenges that we face with respect to fraudulent activity, we maintain certain risk control policies and procedures, both internally and with respect to our third-party vendors and service providers, that make it more difficult for to fraudulently obtain and use our products and services. However, our inability to keep pace with
Sees AI as a riskDetail: GeneralNew this year
6 passages in legal noticesThe forward-looking statements notice at the start or end of a filing. It often lists AI among many risks. It is never counted., not counted
•our ability to anticipate and respond to technological changes and challenges, including our ability to identify and timely and effectively respond to cyber-security risks, including those posed by the increasing use of artificial intelligence, such as data security breaches, "denial of service" attacks, "hacking" and identify theft affecting us, our clients or our third party vendors or service providers, which risks continue to grow more serious with the rise of artificial intelligence and increasingly sophisticated attacks on infrastructure, information, and software;
Same as last period
Quarterly report, page 3Read it in the reportReport an error
•our ability to anticipate and respond to technological changes and challenges, including our ability to identify and timely and effectively respond to cyber-security risks, including those posed by the increasing use of artificial intelligence, such as data security breaches, "denial of service" attacks, "hacking" and identify theft affecting us, our clients or our third party vendors or service providers, which risks continue to grow more serious with the rise of artificial intelligence and increasingly sophisticated attacks on infrastructure, information, and software;
New this year
•our ability to anticipate and respond to technological changes and challenges, including our ability to identify and timely and effectively respond to cyber-security risks, including those posed by the increasing use of artificial intelligence, such as data security breaches, "denial of service" attacks, "hacking" and identify theft affecting us, our clients or our third party vendors or service providers, which risks continue to grow more serious with the rise of artificial intelligence and increasingly sophisticated attacks on infrastructure, information, and software;
Same as last periodNew since the annual report
Quarterly report, page 3Read it in the reportReport an error
•our ability to anticipate and respond to technological changes and changes and challenges, including our ability to identify and timely and effectively respond to cyber-security risks, such as data security breaches, "denial of service" attacks, "hacking" and identify theft affecting us or third party vendors or service providers, which risks continue to grow more serious with the rise of artificial intelligence and increasingly sophisticated attacks on infrastructure, information, and software;
Same as last periodNew since the annual report
Quarterly report, page 3Read it in the reportReport an error
•our ability to to anticipate and respond to technological changes and changes and challenges, including our ability to identify, repel and respond to cyber-security risks, such as data security breaches, "denial of service" attacks, "hacking" and identify theft affecting us or third party vendors or service providers, which risk continue to grow more serious with the rise of artificial intelligence and increasingly sophisticated attacks on our infrastructure, information, and software;
New this periodNew since the annual report
Quarterly report, page 3Read it in the reportReport an error
•our ability to keep pace with technological changes, including our ability to identify and address cyber-security risks, including those posed by the increasing use of artificial intelligence, such as data security breaches, “denial of service” attacks, “hacking” and identity theft affecting us or third party vendors or service providers;
New this year