Last reviewed September 23, 2026. Regulatory references are current as of that date and link to the primary sources.
In short: yes, a bank can use ChatGPT or Claude in its lending work, provided three things are true. The tool runs on a business plan or API agreement under which the bank's data is not used to train the provider's models. Nothing the model produces becomes a credit decision without a person who can explain it. And the vendor goes through the same third-party risk review as any other provider that touches customer information. No federal banking regulator has banned these tools. Since April 2026, generative AI also sits outside the formal model risk guidance, which puts the burden on the bank's own governance rather than removing it.
Every new technology reaches a bank through the side door first. Email did. Smartphones did. Generative AI is doing it now: a loan officer drafts a borrower follow-up in a personal ChatGPT account, a credit analyst asks Claude to summarize a forty-page appraisal, a compliance officer pastes a paragraph of policy and asks what it means. By the time the board asks whether the bank "uses AI," the honest answer is usually that people already do, one tab at a time.
So the useful question is how to use these tools well, and which uses the rules leave open.
The version of the tool matters more than the brand
ChatGPT and Claude each come in two very different forms, and most of the risk lives in the difference.
Consumer plans (the free and individual paid tiers) are built for people, not institutions. Whether a conversation can be used to train future models is governed by a setting the individual user controls, and the bank has no administrative view of what was shared. Using a personal account for borrower information is the AI version of emailing a customer's tax returns from your personal Gmail. It may work for a while, right up until an examiner asks where the returns went.
Business plans and API access are a different contract. OpenAI states that it does not train its models on data from ChatGPT Business, Enterprise or its API platform by default, and that those products have completed a SOC 2 Type 2 audit (OpenAI enterprise privacy). Anthropic states that by default it will not use inputs or outputs from its commercial products, including Claude for Work and the API, to train its models (Anthropic Privacy Center). Anthropic's 2025 consumer-terms changes, which let consumer users choose whether their chats train models, explicitly do not apply to those commercial services (Anthropic).
The first policy decision, then, is simple. Business accounts, provisioned and administered by the bank, for anything that touches customer or loan information. Personal accounts for nothing that does.
What the regulators have said in 2026
Two developments this year shape the answer.
Generative AI is outside the new model risk guidance. On April 17, 2026, the Federal Reserve, the OCC and the FDIC replaced the fifteen-year-old SR 11-7 with revised model risk management guidance (SR 26-2). The attached guidance says that generative and agentic AI models "are not within the scope of this guidance" because they are novel and rapidly evolving, and goes on to say that a banking organization's own risk management and governance practices should determine the controls for anything the guidance does not cover. The guidance itself is aimed mainly at organizations with more than $30 billion in assets. For a community bank, the practical reading is that there is no checklist to satisfy yet, and an examiner will ask what your own framework says instead. The agencies have said a request for information on AI, including generative and agentic models, is coming.
Third-party risk management still applies, and is being rewritten. A business account with OpenAI or Anthropic is a third-party relationship. The 2023 interagency guidance on third-party relationships remains in effect today. On September 11, 2026, the Fed, FDIC, NCUA and OCC proposed replacing it with a more principles-based version that asks banks to scale review to the actual risk of the relationship (Federal Reserve press release). Either way, a tool that receives borrower information is not a low-risk vendor, and it belongs in the vendor inventory with a due diligence file behind it.
The rules that did not change
Two obligations apply no matter which tool a lender uses, and they are the ones that matter most in credit.
Adverse action reasons still have to be specific and accurate. The Equal Credit Opportunity Act and Regulation B require a creditor that denies credit to give the applicant the specific principal reasons (12 CFR 1002.9). In May 2025 the CFPB withdrew its two circulars on applying that rule to complex algorithms (Federal Register). The regulation itself is unchanged. If a general-purpose model is anywhere near the reason a borrower was declined, the lender still has to be able to state that reason in plain terms, and "the model said so" is not a reason.
Customer information still has to be protected, including at the vendor. Under the Gramm-Leach-Bliley Act and the interagency information security guidelines, a bank is responsible for overseeing the service providers that handle its customers' information. Pasting a borrower's financial statements into a chat window is sharing that information with a service provider. The contract, the retention terms and the access controls around that window are the bank's responsibility.
Where general AI tools earn their keep in lending
Used on a business plan with sensible rules, ChatGPT and Claude are useful across a lending team today:
- Drafting. Borrower emails, credit memo narrative from notes the analyst wrote, condition letters, internal summaries. A person edits and owns the final text.
- Reading and summarizing. Long appraisals, leases, loan agreements and regulatory releases, reduced to the points a reviewer should check against the source.
- Policy questions. "What does our policy say about guarantor liquidity?" answered against the policy document the bank provides, with the section quoted back.
- Training and explanation. Walking a newer analyst through a ratio, a covenant structure or a regulation in plain English.
Where they should stop
- Making or recommending the credit decision on their own. The explanation requirement above makes this a compliance problem as well as a judgment problem.
- Arithmetic that goes into the file unchecked. General chat tools can misread a table or carry the wrong line forward. Every number that lands in a credit file needs to be traceable to the page it came from.
- Citations nobody opened. A model can produce a confident reference to a regulation or a document section that does not say what it claims. If it is quoted in a memo, someone opens the source.
- Anything in a personal account. No exceptions for "just this once."
A six-point policy a lending team can adopt this month
- Approved tools only. Name the business plans or API integrations the bank has contracted, and prohibit personal accounts for bank work.
- Data rules by category. Define what may be entered (public information, internal policy text, de-identified examples) and what requires an approved, contracted tool (borrower names, financials, tax returns, account data).
- Vendor file. Put each provider through third-party due diligence: SOC 2 report, data retention and training terms, where data is processed, subprocessors, incident notification.
- Human ownership. Every AI-assisted output that reaches a borrower, a committee or a file has a named person who reviewed it and can explain it.
- Source discipline. Figures and citations in credit work are checked against the source document before they are relied on.
- An inventory and a review date. Keep a list of AI uses by department and revisit it when the agencies publish their AI request for information.
None of this requires a data science team. It requires the same discipline a bank already applies to its core provider, its appraisal management company and its document imaging vendor.
General tools and purpose-built ones
A disclosure, since we build in this space. LenderBox runs on frontier models from both of these companies, accessed by API. No customer data is used to train or fine-tune them, and nothing from one institution's instance is reachable by another. The difference between a general chat window and a lending platform is mostly the layer around the model: documents held in a store scoped to one institution, answers tied back to the pages they came from, checks against the lender's own written policy, and an audit trail an examiner can follow. The model reads your data. It does not learn from it.
Whether you use a general tool, a purpose-built one or both, the questions in the policy above are the ones to ask. If your lending book includes commercial real estate, our overview of what CRE lending AI does covers that side in more depth, and our security page shows how we answer the vendor due diligence questions ourselves.
Frequently asked questions
Is it legal for a bank to use ChatGPT?
Yes. No federal banking regulator prohibits it. The bank remains responsible for protecting customer information, managing the vendor relationship and meeting fair lending and adverse action requirements, so the answer depends on which version of the tool is used and how.
Can a bank use Claude for credit analysis?
For reading, summarizing and drafting, yes, on a commercial plan or API agreement. The credit decision and the reasons behind it stay with the bank's people, and any figure that reaches the credit file should be checked against its source.
Do OpenAI and Anthropic train on bank data?
Both state that data from their business and API products is not used for training by default. Consumer plans are different, which is why personal accounts should be off limits for bank work.
Does SR 11-7 apply to generative AI?
SR 11-7 was replaced on April 17, 2026 by SR 26-2, and the new guidance states that generative and agentic AI models are not within its scope. Banks are expected to govern those tools through their own risk management practices, and the agencies plan a separate request for information on AI.
This article is general information, not legal advice. Talk with your compliance team and counsel before adopting an AI policy.

