Invest1 publisher3 min readPublished
Community banks want regulators, not their own lawyers, to fix AI vendor contracts
Small lenders say their vendor agreements never settled who owns the data. Instead of renegotiating one contract at a time, they are asking for standardized minimum terms.
The Investor · Invest desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- As AI's reach grows, small banks are increasingly reliant on third parties to integrate technologies they cannot build in-house, while gaps in their vendor contracts leave them more exposed to data leaks and cybersecurity threats.
- Anjelica Dortch, vice president of operational risk and cybersecurity policy at the Independent Community Bankers of America, said: "Without regulatory guidance around contracting, when it comes to banks and what those minimum requirements would be, it's really the wild, wild west."
- Community bankers are pushing for regulation that standardizes vendor contracts and consolidates the due-diligence processes that are currently straining their resources.
- As the industry's smallest firms lean harder on outside vendors to deploy AI, they are discovering their contracts lack clarity about data ownership and have left cybersecurity gaps and fragmented oversight of an ever-lengthening chain of subcontractors.
- Dortch said the issue creates unknown risk exposure and cyber-insurance complications.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
Community banks pushing AI into production through third-party vendors have found that their contracts do not clearly say who owns the data, and that the same agreements leave cybersecurity gaps and only fragmented oversight of a lengthening chain of subcontractors [4]. Their proposed remedy is notable: rather than fight it out clause by clause, community bankers are lobbying for regulation that standardizes vendor contracts and consolidates the due-diligence processes now straining their resources [3].
The logic is about negotiating weight. David Schroeder of the Community Bankers Association of Illinois told American Banker that vendors should "incorporate the responsibility and liability into a contract," because community banks are "disadvantaged" in negotiations by their size [13]. If you cannot win the term sheet, you ask for a floor. Anjelica Dortch, the Independent Community Bankers of America's vice president of operational risk and cybersecurity policy, put the absence of that floor plainly: "Without regulatory guidance around contracting, when it comes to banks and what those minimum requirements would be, it's really the wild, wild west" [2]. She said the gap creates unknown risk exposure and complications with cyber insurance [5], and that the industry needs a better framework, particularly on communication, with software vendors, core processors, payment processors and hyperscalers [6].
The dependency is structural, not a choice. ICBA committee chair Greg Ohlendorf said vendor partnerships are crucial for banks with limited in-house innovation capacity compared with the largest firms, while managing Nth-party contracts brings an increased level of risk [7]. "We now are doing business with more vendors than we've ever done business with before," he said, adding that vendor management has risen sharply in importance over the last five or 10 years [8].
Until the terms improve, the fallback is refusal. Steven Gonzalo, CEO of the $2 billion-asset American Commercial Bank & Trust in Ottawa, Illinois, banned employees from using AI, citing the risk that private customer information would end up in the training data of large language models [9][10]. His vendor contracts already required protection of customer data, an expectation that, in his words, "didn't change with the advent of AI" [11]. What will change is access: Gonzalo said guarantees from vendors about data anonymity will determine when the bank widens AI use beyond a small group [12].
The alternative to a standard is duplicated homework. Ferdinand Feola, chief technology officer at the $1.2 billion-asset Dime Bank in Honesdale, Pennsylvania, sent critical and secondary vendors a questionnaire covering their internal AI governance frameworks, change-control notification for AI updates, encryption and multifactor authentication readiness, and data handling [14]. "I'm just asking the basic questions that everybody should be asking," Feola said [15]. That is a competent process, and it is also every bank writing its own version of the same document, which is precisely the burden the ICBA wants consolidated [3][14].
Three things to watch. First, whether any bank regulator picks up minimum contract requirements as a supervisory expectation rather than leaving it to individual negotiation [2][3]. Second, whether vendors accept liability language when asked, given that the ask is currently coming from the smaller side of the table [13]. Third, whether anonymity guarantees actually arrive in writing, because at least one bank has made them the gating condition for rolling AI out to staff [12]. The read-across for anyone selling software to small banks: data ownership and subcontractor disclosure are moving from the appendix to the negotiation [4][7].