🔍 "Data Lineage": Knowing Where Every Number Actually Came From
M&T's data programme developed alongside the broader technology overhaul. Foster, who joined the bank in 2023, began building a data-lineage programme to track where information originates, how it is used, and how it moves between systems. He told American Banker that this work was not created in response to generative AI, he described it as a core capability for understanding M&T's data estate.
|
M&T's AI Rollout By the Numbers
|
15,000+
employees now using AI copilots, out of roughly 22,000 total
|
|
80%
reduction in technology outages since the 2018 overhaul began
|
|
$1.2B+
technology spending in 2025, nearly triple 2017 levels
|
|
That "not created in response to generative AI" detail is genuinely worth flagging. Foster is essentially saying the data governance discipline that AI now depends on would have been built anyway, for entirely separate operational reasons, and AI simply became one more, particularly high-profile beneficiary of work that was already underway.
|
Data-lineage tracking lets M&T trace exactly where an AI-generated answer's underlying information actually came from.
|
📚 An Internal Encyclopedia Called Edison
The bank also established a Data Academy focused on data governance and data skills, with around 2,000 employees participating. M&T has created an internal repository called Edison containing authoritative documents and information on bank policies, and the bank uses data-lineage software from Solidatus and Monte Carlo to trace information as it passes through databases, applications, and business-intelligence systems.
The lineage work gives M&T visibility into the source, meaning, quality, and governance of individual data elements, and M&T also uses retrieval-augmented generation with internal, governed data.
That combination, retrieval-augmented generation plus a governed, well-documented internal knowledge base like Edison, is a genuinely sound architecture for a regulated industry. Rather than relying on a language model's general training data, which can be outdated or simply wrong about internal policy specifics, the AI is grounded in the bank's own current, authoritative documents before it generates an answer.
That's the technical answer to a question that should worry anyone using AI at a bank, "how do I know the AI's answer about a policy is actually correct and current?" Grounding the model in a governed, traceable internal source is a genuinely stronger answer than simply trusting the model's own general knowledge.
|
👀 The Rule That Never Gets Waived
Software developers at the bank use GitLab tools to generate code, while employees remain responsible for reviewing AI-generated work, a rule that isn't just a soft internal expectation, it's written directly into policy. M&T's human-review requirement is reflected in its 2026 Code of Business Conduct and Ethics, which requires employees to use approved AI tools and prohibits confidential, proprietary, customer, employee, or regulated information from being entered into unapproved systems.
|
M&T's Three Routes Into Generative AI
| ⚠️ General employee use, drafting, summarising, coding, via Microsoft Copilot |
| ⚠️ AI capabilities already embedded in the bank's 1,800+ third-party applications |
| ⚠️ Proprietary AI systems built around the bank's own data, for fraud prevention, cyber defence, and repetitive operational work |
|
That three-route framework, described by Wisler to Forbes, is a genuinely clear-headed way for a large, complex organisation to think about AI adoption, rather than one single top-down mandate, M&T is layering general-purpose tools, vendor-embedded AI it doesn't have to build itself, and custom systems built for its own specific, highest-value problems.
|
Developers use AI to generate code, but remain formally responsible for reviewing it under the bank's written policy.
|
🧠 AI Spotlight Analysis
M&T's approach is genuinely worth comparing against what other large US banks are doing, because the pattern that emerges is remarkably consistent, and instructive. JPMorgan Chase launched its internal LLM Suite platform to more than 200,000 employees in 2024, and by 2025, more than 65,000 employees in its Corporate and Investment Bank were actively using the platform, with more than 90% of its engineers using AI coding assistants. The bank also said AI-based transaction screening allowed it to review more than twice the previous transaction volume while reducing manual operator checks by half.
Bank of America is using a generative AI-enabled system called EricaAssist with more than 18,000 customer service employees, summarising why a customer is calling, retrieving relevant information, and recommending possible next steps, while keeping the employee responsible for the interaction. The bank said in July 2026 that EricaAssist can deliver contextual guidance in under three seconds and has reduced average call times by nearly one minute.
💬 Quote of the Week
"Data lineage was not created in response to generative AI. It's a core capability for understanding the bank's data estate."
— Andrew Foster, chief data officer, M&T Bank
The common thread across all three banks, M&T, JPMorgan, and Bank of America, is that human oversight is preserved as a formal, structural feature at every one of them, not an informal courtesy. Employees stay responsible for reviewing AI-generated code, for the accuracy of a customer interaction, for the final call on a flagged transaction. That consistency across three separate, competing institutions suggests it's less a matter of individual company caution and more an emerging industry norm for how regulated finance is choosing to deploy AI at scale.
|
💡 Final Thoughts
The real lesson in M&T's story isn't about Microsoft Copilot at all, it's about sequencing. A bank that blocked AI outright in its early days didn't do so out of resistance to the technology, it did so because its own data and technology foundations weren't ready to support it safely. Eight years of unglamorous infrastructure work, replacing legacy platforms, cutting outages, building data lineage, had to happen first.
That's a genuinely useful cautionary tale for any organisation eager to deploy AI quickly without doing that foundational work first. The exciting part, 15,000 employees using AI copilots daily, six minutes saved per call, is the visible result. The actual hard part, the part that determined whether any of it would work reliably and safely, was the years of infrastructure and governance work nobody outside the bank ever saw.
Does your own organisation have the data foundation in place to deploy AI safely, or is that still the unfinished work? Hit reply, we read every response.
|
🔗 Sources and Further Reading
|
❤️ Enjoying AI Spotlight?
If today's edition helped you see the unglamorous work behind a smooth AI rollout, consider sharing it with a colleague, founder, or friend interested in technology.
Share AI Spotlight →
|
|
|
Thanks for reading AI Spotlight.
Our mission is simple: deliver clear, trustworthy, and actionable AI insights that help professionals stay ahead without the hype.
|
|