Over nineteen months, we sat down with 90 lending institutions and asked them how they underwrite, what they think of AI, and what they would need to believe before they bought any of it. Forty-nine were banks, credit unions and CDFIs. Twenty-four were private credit and non-bank lenders. Thirteen were intermediaries. Four were other lenders whose function did not cleanly fit those categories. We recorded most of the conversations, and every number and every quote in this piece traces back to one of them.
Correction, September 2026: an earlier version of this piece omitted the fourth category above (four institutions whose lending function we could not cleanly classify) from this sentence. The total of 90 institutions, and every other figure in this piece, was always correct.
This is not a representative sample. It is Texas-weighted, CRE-weighted, and built almost entirely from warm introductions. Every figure that follows is "among the institutions we spoke with," never an industry average.
What surprised me: the industry's questions about AI got noticeably sharper this year, and almost nobody can answer the questions that would let them judge an answer.
Where the work actually happens
Start with the stack. Twenty-five of the institutions we spoke with described underwriting that lives in Excel and Word, and 14 said they have no loan origination system or spreading platform at all. The range runs from a $140 million bank to an $80 billion one.
When we asked one Texas bank under $200 million what underwriting software it uses, the answer was four words: "No, we're using humans." (July 2026.) At the other end of the scale, a US regional bank told us in January 2026: "you'll be shocked at how archaic [we are] as an $80 billion bank."
Inside those spreadsheets, the time goes to assembly rather than judgment. Three institutions put a number on it: 60% to 90% of analyst time goes to data entry, with whatever is left for analysis. A credit union described it this way in August 2026: "they'll spend 80, 90% of the time putting all the information in, but when it comes to actually analyzing the information, they're so brain dead."
Where does the work stall? Two answers tied. Thirteen institutions named memo writing as the bottleneck and 13 named pre-screen triage. Eighteen named post-close monitoring as a blind spot, which is a different problem.
Then there is the arithmetic that makes all of it worse. Seven institutions gave us enough of their funnel to compute a close rate from deals seen to deals closed, and the median was about 5%. If most of the analytical capacity in the building is spent on deals that die, the real bottleneck is learning which deals deserve a memo. Package-to-memo turnaround, from the six institutions that told us, ran from 48 hours to three weeks, clustering at four to five days.
One more finding from this section. Roughly 40 of the institutions we spoke with described their own loan mix. Sixteen of them are diversified or C&I-heavy. Four are CRE-only. Every AI underwriting vendor, ours included, is selling a CRE-shaped product. Most of the book at most of these institutions is not CRE. Whatever gets built for them has to work in a credit shop that does many things.
The questions got better
When we tallied what lenders asked us, the ranking was clear. Twenty-one institutions asked about data security. Twenty asked why they should not just use a general-purpose model. Eighteen asked about hallucination and accuracy. Seventeen asked for a SOC 2 report, an NDA, or references. Thirteen asked whether their data would train a shared model. Eleven asked about explainability, and 10 raised what their regulator would think.

Those are good questions, and they are being asked well. A private credit fund, hearing an accuracy claim in February 2026, responded: "How are you measuring that? Is it verified by a third party?" A Texas community bank in May 2026 put the whole problem in one sentence: "the data accuracy is really the important piece, because you can draw great conclusions, but if it's based on junk, you've... drawn a wrong conclusion." A Texas business bank in March 2026 went straight to the failure mode that keeps chief credit officers up at night: "you've got to have... a pretty good level of human oversight... a banker comes in and says, Look, this is great, [the system] told me to do it. Then we get in further and figure out that... The information that was put in was not accurate."
The surprise was policy. Eleven institutions asked whether AI can read a credit policy at all. Six named policy exception detection as the thing that most impressed them, ahead of underwriting itself. We did not ask about it. They brought it up. A large international bank, March 2026: "we look at policy not as black and white, but we have to interpret policy and... work around the policy. Does your AI... do that?" A US regional bank, January 2026: "what got my attention, even beyond the underwriting, is policy... create a vehicle where... the exceptions go way down." And a beat later: "I think credit would foam at the mouth over something like this." And a chief credit officer, the same month: "I receive multiple teams messages a day... policy doesn't speak to... aircraft lending... I don't freaking know."
The security question changed between 2025 and 2026. In October 2025, a Texas community bank asked: "Most things, when they're extracted, they're sold, right? Or shared? ... Who is it sold and shared to." By August 2026, a credit union asked: "tax returns, personal financial statements... where is that data going? Who's using it?... Do we get our own instance... doesn't trickle out into these other LLMs?" The 2025 question is whether an outside party can touch the data at all. The 2026 question assumes one will, and asks for the Type II and the NDA.
It is also a signal: by the time an institution has a checklist, someone is usually already in the building. The lenders asking us the sharpest questions were the ones most likely to already have another vendor. A checklist is what you have after you have been through it once.
The floor moved
This is the section that requires having asked the same people the same thing a year apart.
In June 2025, a real estate debt principal told us: "we've tried to use AI... and failed over and over and over again." And then: "it produces junk... I can't present this." That was the typical 2025 report.
In April 2026, a private credit fund told us it was "pumping out something that is... 90% correct," and then: "we're blown away. It's insane." In the same conversation: "is... the business version... going to be enough for what we need... that's literally what I'm looking at."
Within a year, the general-purpose model went from unusable to good enough that the live procurement question became whether a subscription is all a lending team needs. Eighteen of the institutions we spoke with use a general-purpose model informally today. Sixteen have an internal AI build underway. In August 2026, a private credit fund that had told us no vendor could build what they needed said, twenty days later: "we've actually taken a step back and are evaluating a single-agent build right now."
Lenders are not naive about vendors, either. Twenty-two institutions described vendor fatigue or a failed implementation. A Texas community bank, May 2026: "I've dealt with enough vendors now that it's easy to sell you something... you don't know how it works until you've signed something, and then you're in it and go, Oh, this doesn't work like I had hoped." An Oklahoma community bank, July 2026: "it's always a bunch of software developers... but they always miss the banking standpoint."
The alternative to a purpose-built system is now a capable general model and a motivated analyst, ours included. Any vendor who pretends otherwise is not paying attention. Lenders should be asking the same question that fund asked in April.
The measurement gap
Eight institutions told us they have a board or executive mandate on AI. Every one of them is dated 2026. None from 2025. None of the eight had converted the mandate into a purchase when we spoke.
The mandates are real. A mid-size Texas bank, February 2026: "our board has... charged us [with] thinking about how to leverage AI, and then... our underwriting process, not just with real estate, but across the board." A Texas community bank, July 2026: "there's an edict that we have a proposal to the board of directors in 2026 with a plan of implementation and cost." And: "it's not if we're doing it, it's just when and how." A large regional bank, back from a state banking association CFO conference in June 2026, counted: "30 to 40% of the presentations had something to do with AI."
Now the numbers a board would need to judge any proposal. Of the 77 lenders we spoke with, 27% could state their own deals per month. Fourteen percent could state their own package-to-memo time. Twenty-two percent could state their own underwriting headcount. Six percent could state what they currently spend on origination, spreading and market data. And of the 49 depositories, not one volunteered what any of this would be worth to them. Zero of 49.

Several of these institutions manage credit risk with a discipline I admire. Nobody has ever needed these numbers before. Cycle time, close rate, the cost of an analyst hour: none of those has ever had to be produced, because nothing was ever priced against them. You cannot buy on ROI against numbers you have never generated. A mandate to do something with AI and a plan with implementation and cost both stall at the same place, which is the absence of a baseline. The industry's questions about vendors got sharper. Its questions about itself did not keep pace.
Better questions
So here is what we ask, phrased for a lender to ask of themselves first and then of any vendor, including us. It will make every conversation you have about AI shorter.
How many deals do you see and close in a month? How long does it take from package to memo, and from intake to close? How many people underwrite, and what does each analyst cost, fully loaded? What is your asset size or AUM, and what share of the book is CRE? And what do you spend today on your loan origination system, your spreading tool and your market data?
If you can answer those five, you can evaluate any answer a vendor gives you. If you cannot, no demo will help and no pilot will end in a decision. The last one is the most useful question on the list, and it is the one with the lowest fill rate.
Three more we would add for vendors. What does your third-party risk questionnaire actually require? What has your examiner said about AI vendor use? Can your credit policy be shared under NDA?
We intend to ask all eight in every conversation from here, and we will publish what we learn, in the same form as this piece.
We put all eight questions on one printable page, with the fill rates under each: download the one-pager.
The paradox
It came from a Texas community bank in July 2026, one that had already asked how its own data would be kept separate: "it's really beneficial for other banks to see or hear what... everybody else is [doing]." And then: "I don't know how much of that can be shared." That bank is not unusual. Thirteen institutions asked whether their data would train a shared model, and roughly the same population, often in the same conversation, asked what their peers were doing, how their numbers compared, and what everybody else had decided. The refusals were about their own data leaving the building. The requests were about other people's data arriving. Nobody in our sample has resolved that, and I do not think a vendor can resolve it alone, because what is being asked for is trust between institutions. If you think we have read this wrong, say so in public.
We are running this study again. Tell us where to send the next one: vijay@lenderbox.ai.
LenderBox builds AI underwriting and policy intelligence software for commercial real estate lenders: lenderbox.ai.

