AI Artificial Intelligence
Standard wording or passing mentionDetail: GeneralSame as last periodNew since the annual report
RBCAA · KY · Mid-size bank ($1B to $50B)
Total assets of FDIC-insured bank subsidiaries: $7B at the end of 2025
Filings on the SEC website · This bank on Bankgraph
| Report year | Using or planning AI | Explains how AI is controlled | Sees AI as a risk | Other mentions |
|---|---|---|---|---|
| 2022 | ||||
| 2022 | ||||
| 2022 | ||||
| 2022 | ||||
| 2023 | ||||
| 2023 | ||||
| 2023 | ||||
| 2023 | ||||
| 2024 | ||||
| 2024 | ||||
| 2024 | ||||
| 2024 | ||||
| 2025 | ||||
| 2025 | ||||
| 2025 | ||||
| 2025 |
| In the 2025 report | This bank | Banks of its size |
|---|---|---|
| Using AI now | No | 26 of 221 (12%) |
| Explains how AI is controlled | Yes | 55 of 221 (25%) |
| Sees AI as a risk | Yes | 184 of 221 (83%) |
| Mentions generative AI | Yes | 112 of 221 (51%) |
| Mentions AI agents | No | 18 of 221 (8%) |
5 passages new in the 2025 report, 1 passage from the 2024 report no longer there. The most specific passage is more detailed than last year.
AI Artificial Intelligence
o AI, particularly generative AI, adoption risks including performance failures, bias, or reliance on third-party AI vendors, and more effective adoption by industry competitors;
AI Artificial Intelligence
o AI, particularly generative AI, adoption risks including performance failures, bias, or reliance on third-party AI vendors, and more effective adoption by industry competitors;
AI Artificial Intelligence ESPP Employee Stock Purchase Plan OREO Other Real Estate Owned
o AI, particularly generative AI, adoption risks including performance failures, bias, or reliance on third-party AI vendors, and more effective adoption by industry competitors;
The Company’s operations, including third-party and client interactions, are increasingly done via electronic means, and this has increased the risks related to cybersecurity threats. The Company is exposed to the risk of cyber-attacks in the normal course of business and incurs substantial cybersecurity protection costs. In general, cyber incidents can result from deliberate attacks or unintentional events. Management has observed an increased level of attention in the industry focused on cyber-attacks that include, but are not limited to, gaining unauthorized access to digital systems for purposes of misappropriating assets or sensitive information, corrupting data, or causing operational disruption. Cyber-attacks may also be carried out in a manner that does not require gaining unauthorized access, such as by causing denial-of-service attacks on websites. Further, the rapid evolution and increased adoption of AI technologies may further intensify cybersecurity risks by making cyber-attacks more difficult to detect, contain or mitigate. Cyber-attacks may be carried out directly against the Company, or against the Company’s clients or service providers/vendors by third parties or insiders using techniques that range from highly sophisticated efforts to electronically circumvent network security or overwhelm
The evolving federal “AI Action Plan” and related regulatory initiatives could increase compliance costs, constrain the Company’s use of AI, and expose the Company to new legal, operational, and reputational risks. The U.S. federal government has announced an “AI Action Plan” pursuant to a January 2025 Executive Order directing federal agencies to develop a coordinated framework for the governance, development, and use of AI. The Company is in the initial stages of incorporating AI into its business activities to increase employee productivity. The Company has not deployed AI-driven systems in critical decision making or client-facing processes. While the scope, timing, and final form of the AI Action Plan and any resulting laws, regulations, supervisory guidance, or enforcement priorities remain uncertain, these initiatives may significantly affect how financial institutions develop, deploy, and oversee AI-enabled systems.
The AI Action Plan may result in new or enhanced requirements related to model governance, data usage, explainability, human oversight, testing, recordkeeping, vendor management, and accountability for AI-driven outcomes. Compliance with these requirements could require substantial investments in technology, personnel, controls, documentation, and third-party risk management, and may reduce the efficiency or effectiveness of certain AI-enabled processes. In addition, heightened regulatory scrutiny of AI systems—particularly in areas such as fair lending, consumer protection, privacy, and model risk management—could increase the risk of supervisory findings, enforcement actions, civil litigation, or reputational harm, even where AI systems are designed and implemented in good faith. The use of third-party AI models or data sources may further increase these risks if such vendors fail to meet evolving regulatory expectations or contractual standards.
If the AI Action Plan or related regulatory actions limit the Company’s ability to use AI technologies, require material changes to existing systems, or impose inconsistent or overlapping obligations across federal and state regulators, operating costs could increase and the Company’s ability to compete with other financial institutions or non-bank competitors could be adversely affected. Any of these outcomes could have a material adverse effect on our business, financial condition, results of operations, or reputation.
The Company’s operations, including third-party and client interactions, are increasingly done via electronic means, and this has increased the risks related to cybersecurity threats. The Company is exposed to the risk of cyber-attacks in the normal course of business and incurs substantial cybersecurity protection costs. In general, cyber incidents can result from deliberate attacks or unintentional events. Management has observed an increased level of attention in the industry focused on cyber-attacks that include, but are not limited to, gaining unauthorized access to digital systems for purposes of misappropriating assets or sensitive information, corrupting data, or causing operational disruption. Cyber-attacks may also be carried out in a manner that does not require gaining unauthorized access, such as by causing denial-of-service attacks on websites. Further, the rapid evolution and increased adoption of artificial intelligence technologies may further intensify our cybersecurity risks by making cyberattacks more difficult to detect, contain or mitigate. Cyber-attacks may be carried out directly against the Company, or against the Company’s clients or service providers/vendors by third parties or insiders using techniques that range from highly sophisticated efforts to electronically circumvent network security or overwhelm websites to more traditional intelligence gathering and social engineering aimed at obtaining information necessary to gain access. While the Company, to its knowledge, has not incurred any material losses related to cyber-attacks, the Bank may incur substantial costs and suffer other negative consequences if the Bank, the Bank’s clients, or one of the Bank’s third-party service providers fall victim to successful cyber-attacks. Such negative consequences could include: remediation costs for stolen assets or information; system repairs; consumer protection costs; increased cybersecurity protection costs that may include organizational changes; deploying additional personnel and protection technologies, training employees, and engaging third-party experts and consultants; lost revenues resulting from unauthorized use of proprietary information or the failure to retain or attract clients following an attack; litigation and payment of damages; and reputational damage adversely affecting client or investor confidence.