Article
Finance & Banking
Applied AI
In mid-market banks, AI readiness is a data-ownership question
The banks that will use AI well are the ones that can get a clean, owned copy of their own data out of a third-party core.
By
The Lunon Team
6 minute read
IN SHORT
In the 2025 annual reports of 28 mid-market banks, 27 name artificial intelligence and only 1 names a data-governance program.
Roughly 1,000 banks sit in the mid-market between $1 billion and $50 billion in assets, and most run their system of record on 1 of 3 outside core vendors.
A single core provider alone holds the account data of more than 1 in 5 banks at or below $55 billion, which is where readiness is decided.

Every mid-market bank now tells its shareholders that it is preparing for artificial intelligence. The more useful question, and the one that separates the banks that will use AI well from the ones that will only talk about it, is quieter: who actually controls the data an AI system would have to run on. This piece is for the operators who run these banks and the investors who buy and sell them.
To answer it we read the 2025 annual reports of 28 mid-market banks and counted the language of using AI against the language of owning data. The result is lopsided, and it points to a plain thesis: in a mid-market bank, AI readiness is a data-ownership question before it is a technology question. What a readiness assessment should measure is that gap, not the choice of model.
Banks name the technology and skip the data that feeds it
In the 2025 annual reports of 28 mid-market banks, 27 name artificial intelligence, and all 28 describe an information-security program. 18 discuss data privacy. 1 names a data-governance program, 1 names a chief data officer, and none describes a data-governance framework. The disclosed attention runs to the technology and its security wrapper, not to the data underneath.
We compared how often 8 exact phrases appear across those filings, drawn from a sample of 28 U.S. mid-market bank holding companies holding $6.4 billion to $32.1 billion in assets. The pattern is a wide distance between the language of using AI and the language of owning the data it needs. We call it the data-ownership gap, and it is the real readiness question: in a mid-market bank, AI readiness is a data-ownership question before it is a technology question.
The AI language is broad but shallow
The technology vocabulary is wide and thin at once. Beyond artificial intelligence, 8 of the 28 banks name machine learning, 13 use the phrase data management, and 18 discuss data privacy. Protecting data is nearly universal, while governing and owning it is nearly absent. Banks describe the shield around the data far more than custody of the data itself.
Where AI appears, it is almost always a risk rather than a deployment. In these filings artificial intelligence shows up in risk factors about competition, cybersecurity, and new regulation, phrased as something the bank must guard against or invest to keep pace with. That is a tell. A bank writing about AI as a threat to manage has not yet made it a capability it owns, and it cannot until it controls the data.
None of this measures deployed capability. It measures the language of annual reports, counted the same way in the same filings across a single reporting period. That is why the comparison is fair: every phrase is measured identically, so the distance between the AI line and the data-governance line reflects where management attention sits, not an artifact of how it was counted.
EXHIBIT
In the 2025 annual reports of 28 mid-market banks, 27 name artificial intelligence and 1 names a data-governance program.

Source: Lunon analysis of FY2025 Form 10-K filings, SEC EDGAR full-text search.
The mid-market is 1,000 banks between a long tail and a few giants
The United States still has more than 4,200 insured banks. Roughly 1,000 of them sit in the mid-market, between $1 billion and $50 billion in assets, above a tail of more than 3,000 community banks under $1 billion and below the 50 banks larger than $50 billion. This middle is large enough to want AI and small enough that few have built the dedicated data function the biggest banks staffed years ago.
That position is the trap. A community bank under $1 billion can defer the question, and a bank above $50 billion has usually spent years and real money building a data organization to answer it. The mid-market has neither the room to wait nor the scale to have finished, which is why AI readiness is settled here on data terms rather than technology terms.
The core system holds the data, and the bank rents access to it
Data ownership is not an abstraction in banking. A mid-market bank's system of record, where its account and transaction data physically lives, is typically operated by 1 of 3 outside vendors, and the bank reaches its own data through the vendor's platform. A single core provider runs that system for more than 900 banks, inside a market of roughly 4,300 banks at or below $55 billion in assets.
That is more than 1 in 5 banks in the band whose core data sits with a single vendor, and the same provider serves over 7,200 financial institutions in all. The other 2 vendors hold much of the remainder, so the great majority of mid-market and community banks do not run their own system of record. The data-ownership gap begins here, in the plumbing, long before anyone evaluates a model.
Outsourcing the core is sensible economics, because most mid-market banks cannot each build a system of record. But it changes what readiness means. The data an AI system needs to be useful about customers, risk, and pricing lives on someone else's platform, and getting a clean, current, permissioned copy of it is a contract and engineering problem before it is a technology choice.
The gap is structural across the industry, not a mid-market failing
This is not a mid-market shortcoming that the largest banks have already solved. We applied the same method to 13 large-bank holding companies at or above $50 billion in assets. All 13 name artificial intelligence. 2 name a data-governance program, 1 names a chief data officer, and none describes a framework.
Even among the 4 largest banks, only 1 uses the phrase data governance in its annual report, and none names a chief data officer or a framework. Part of this is filing vocabulary, since the language of data governance rarely appears in risk factors at any size. The finding survives the caveat, because the measure is disclosure and attention held constant across every filing, and the distance between the AI line and the data-ownership line holds at every size.
Regulators already treat data as the binding constraint on AI
Supervisors reached this conclusion first. A 2021 interagency request for information on financial institutions' use of AI, issued jointly by 5 agencies, states plainly that data quality is important for AI and that biased or incomplete training data becomes biased output. A 2023 interagency guidance on third-party relationships tells a bank that outsources a function it still owns the risk of the vendor that runs it. Read together, they place data ownership ahead of technology as the supervisory position, not only an editorial one.
The sequence matters for a buyer of advice as much as for a bank. A readiness assessment that opens with model selection or a proof of concept measures the wrong thing. The question that predicts success is whether the bank can obtain and govern a clean copy of its own data, and that question can be answered before a single tool is trialed.
Readiness turns on 4 questions about the data, not the model
The useful version of the readiness question is concrete, and none of its 4 parts is about which model a bank buys.
Custody decides who physically holds the data. For most mid-market banks the answer is a core vendor, and that answer sets everything downstream.
Extraction decides whether a clean copy comes out. A model is only as good as the data a bank can pull from its core on its own terms and schedule.
Permission decides what the bank may do with it. Vendor contracts and privacy law settle which uses are open well before any tool is chosen.
Governance decides who owns the data inside the bank. A named data owner is rare in the filings, and that absence is the data-ownership gap stated in a single line.
The readiness question is not which model a bank buys
The banks that get this right will not be the ones with the best model. They will be the ones that can get a clean, owned, permissioned copy of their own data out of a third-party core, on a schedule they control. Close the data-ownership gap and the technology question becomes easy, while leaving it open means no model will fix it. In the mid-market, readiness is decided before any tool is chosen.
Next up
Start with the decision in front of you.
Tell us what your team needs to understand, evaluate, or deliver.







