Invest1 distinct publisher3 min readUpdated
Small lenders say their vendor agreements never settled who owns the data. Instead of renegotiating one contract at a time, they are asking for standardized minimum terms.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
Community banks pushing AI into production through third-party vendors have found that their contracts do not clearly say who owns the data, and that the same agreements leave cybersecurity gaps and only fragmented oversight of a lengthening chain of subcontractors [4]. Their proposed remedy is notable: rather than fight it out clause by clause, community bankers are lobbying for regulation that standardizes vendor contracts and consolidates the due-diligence processes now straining their resources [3].
The logic is about negotiating weight. David Schroeder of the Community Bankers Association of Illinois told American Banker that vendors should "incorporate the responsibility and liability into a contract," because community banks are "disadvantaged" in negotiations by their size [13]. If you cannot win the term sheet, you ask for a floor. Anjelica Dortch, the Independent Community Bankers of America's vice president of operational risk and cybersecurity policy, put the absence of that floor plainly: "Without regulatory guidance around contracting, when it comes to banks and what those minimum requirements would be, it's really the wild, wild west" [2]. She said the gap creates unknown risk exposure and complications with cyber insurance [5], and that the industry needs a better framework, particularly on communication, with software vendors, core processors, payment processors and hyperscalers [6].
The dependency is structural, not a choice. ICBA committee chair Greg Ohlendorf said vendor partnerships are crucial for banks with limited in-house innovation capacity compared with the largest firms, while managing Nth-party contracts brings an increased level of risk [7]. "We now are doing business with more vendors than we've ever done business with before," he said, adding that vendor management has risen sharply in importance over the last five or 10 years [8].
Until the terms improve, the fallback is refusal. Steven Gonzalo, CEO of the $2 billion-asset American Commercial Bank & Trust in Ottawa, Illinois, banned employees from using AI, citing the risk that private customer information would end up in the training data of large language models [9][10]. His vendor contracts already required protection of customer data, an expectation that, in his words, "didn't change with the advent of AI" [11]. What will change is access: Gonzalo said guarantees from vendors about data anonymity will determine when the bank widens AI use beyond a small group [12].
The alternative to a standard is duplicated homework. Ferdinand Feola, chief technology officer at the $1.2 billion-asset Dime Bank in Honesdale, Pennsylvania, sent critical and secondary vendors a questionnaire covering their internal AI governance frameworks, change-control notification for AI updates, encryption and multifactor authentication readiness, and data handling [14]. "I'm just asking the basic questions that everybody should be asking," Feola said [15]. That is a competent process, and it is also every bank writing its own version of the same document, which is precisely the burden the ICBA wants consolidated [3][14].
Three things to watch. First, whether any bank regulator picks up minimum contract requirements as a supervisory expectation rather than leaving it to individual negotiation [2][3]. Second, whether vendors accept liability language when asked, given that the ask is currently coming from the smaller side of the table [13]. Third, whether anonymity guarantees actually arrive in writing, because at least one bank has made them the gating condition for rolling AI out to staff [12]. The read-across for anyone selling software to small banks: data ownership and subcontractor disclosure are moving from the appendix to the negotiation [4][7].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
As AI's reach grows, small banks are increasingly reliant on third parties to integrate technologies they cannot build in-house, while gaps in their vendor contracts leave them more exposed to data leaks and cybersecurity threats.
Anjelica Dortch, vice president of operational risk and cybersecurity policy at the Independent Community Bankers of America, said: "Without regulatory guidance around contracting, when it comes to banks and what those minimum requirements would be, it's really the wild, wild west."
Community bankers are pushing for regulation that standardizes vendor contracts and consolidates the due-diligence processes that are currently straining their resources.
As the industry's smallest firms lean harder on outside vendors to deploy AI, they are discovering their contracts lack clarity about data ownership and have left cybersecurity gaps and fragmented oversight of an ever-lengthening chain of subcontractors.
Dortch said the issue creates unknown risk exposure and cyber-insurance complications.
Dortch said: "We need to figure out how to build a better framework - especially from a communication perspective - with software vendors, core processors, payment processors, even our hyperscaler providers."
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named on-record practitioners, single outlet, no documents
Every claim traces to one trade-press article. Its strength is specificity: named executives at identified institutions with disclosed asset sizes, plus two trade-association policy officials, describing concrete practices. Its weakness is that no contract, questionnaire, regulatory filing, supervisory guidance, incident report or survey is produced, and the core assertion that contracts 'lack clarity about data ownership' is asserted rather than documented. No second publisher corroborates.
A few disclosed bank practices; no standardized terms in force
There is real but thin adoption evidence for the behavior described: one bank has banned employee AI use pending vendor anonymity assurances, another has issued an AI due-diligence questionnaire to critical and secondary vendors, and an accelerator lead says nearly all of his fintech cohort companies use AI. Nothing in the source shows vendors accepting the requested terms, any regulator acting, or standardized minimum contract language existing anywhere. Dime Bank's CTO explicitly expects no responses yet.
Modestly overstated: industry-wide framing from a handful of anecdotes
The framing ('a new fight in the age of artificial intelligence', regulators asked to fix contracts) runs somewhat ahead of what is shown: three banks, two trade associations, one vendor executive, no regulator, no quantified exposure and no evidence a standardized-terms regime is under consideration. The gap is small rather than large because the reporting is candid about limits — one CTO says he expects no vendor responses, one CEO says his data-protection expectations predate AI — and does not claim results that have not occurred.
Advocacy-heavy sourcing with disclosed roles
Two of the five voices are trade-association officials (ICBA, Community Bankers Association of Illinois) whose institutional purpose includes lobbying for rules that reduce member burden, and the specific ask — regulators standardizing vendor contracts and consolidating due diligence — directly serves their members. The ICBA committee chair also runs an accelerator that selects fintech vendors and is himself a bank CEO. A digital-banking vendor executive advises banks to push governance onto vendors, a position that favors incumbents able to answer such questions. The source discloses each affiliation, which limits, but does not remove, the slant.
Direction credible, magnitude and outcome unresolved
Confidence is moderate. The qualitative direction — more vendors, older contracts silent on AI data use, rising due-diligence burden at small banks — is consistently described by multiple named practitioners and is internally coherent. Confidence is capped by single-publisher sourcing, absent vendor and regulator voices, no quantitative baseline, and the fact that the headline outcome (regulators setting minimum contract terms) has no evidenced path forward in the material.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 14, 2026