Discover Financial Services is advancing generative AI applications with a prudent strategy. From experiments and pilots across business functions to use case deployment, the financial institution sets specific safeguards based on risk levels, evaluates the best uses of AI with a clear perspective, and prioritizes project value—whether for customer-facing scenarios or back-office tasks.

This approach also provides Discover with stronger protection against the significant risks posed by generative AI.

"All of this aligns with our standards, expectations, and policies, but still requires 'human-in-the-loop' involvement," Discover CIO Jason Strle told CIO Dive. "This is a key part of our risk mitigation, and this state will continue for some time."

Discover CIO Jason Strle.
Discover CIO Jason Strle.
Permission granted by Discover

Discover's risk mitigation strategy closely follows guidelines issued by the National Institute of Standards and Technology (NIST). NIST released the draft of its Generative AI Risk Management Framework in July.

"NIST's AI Risk Management Framework is highly consistent with financial risk management, non-financial risk management, or the operational risk management that banks need to conduct," Strle said. "The model is very familiar."

As companies remain cautious about generative AI, NIST's risk mitigation guidance has become a reference for organizations seeking a starting point amid rapid technological evolution. Although leaders are eager for the potential returns of large-scale AI integration, they prioritize avoiding mistakes and developing comprehensive adoption plans.

The popularity of the NIST framework is no accident. The government agency has spent years strengthening cybersecurity standards and has gained widespread recognition, and is now gradually becoming the standard-setting body for generative AI.

A wealth of options

For Discover, Strle distills NIST's voluntary framework into three steps:

  • Identify where capabilities may introduce risk.
  • Demonstrate that the organization understands how to quantify and mitigate risk.
  • Monitor on a daily basis.

The final version of the NIST framework stems from U.S. President Joe Biden's executive order last October and provides organizations deploying and developing generative AI with more than 200 risk mitigation actions. This is a reduction from the 400 steps in the initial version released in April.

NIST's AI guidance focuses on a broad range of risks, including information integrity, security, data privacy, harmful bias, hallucinations, and environmental impact. The framework provides organizations with methods to contextualize and mitigate risks.

For example, to prevent erroneous generative outputs, NIST offers about 19 actions companies can take, such as setting minimum performance thresholds and incorporating them into the review process of deployment approval policies.

NIST is not the only institution providing guidance on generative AI adoption. As vendors race to embed generative AI into solutions, industry groups and advocacy organizations are also working to clarify confusion around model evaluation, risk management, and responsible processes.

These efforts have produced a wealth of guidance, policy recommendations, and safeguard options, but have not yet formed a single authoritative source.

The International Organization for Standardization (ISO) released AI-related management system standards in December. The Massachusetts Institute of Technology (MIT) launched an AI risk database in August, pointing out more than 700 threats, and several professional services firms have also created governance frameworks.

Whether the growing number of options confuses CIOs or actually helps them depends on who you ask.

"I don't think there's a simple answer," Strle said. Having more ways to mitigate threats is not always inherently effective, so business leaders need to determine which protections the business requires.

Standing on the sidelines only lasts so long. Executives are facing increasingly stringent AI regulation worldwide, from the EU's AI Act to California's controversial Senate Bill 1047—which was vetoed by Governor Gavin Newsom on Sunday. Most leaders expect stricter requirements in the future, and companies are reviewing and updating existing practices to prepare.

Shohreh Abedi, EVP and chief operations and technology officer and membership experience at ACG
Shohreh Abedi, EVP, chief operations and technology officer, membership experience at ACG.
Permission granted by AAA - The Auto Club Group

"I have to stay prepared, because eventually it will reach other states too," said Shohreh Abedi, EVP, chief operations and technology officer, and membership experience lead at AAA - The Auto Club Group. The organization has focused on embedding generative AI over the past year, with operations spanning 14 states, a Canadian province, Puerto Rico, and the U.S. Virgin Islands.

"We can't bury our heads in the sand," Abedi said.

The bottom line for CIOs

CIOs are increasingly weary of the seemingly hollow promises of generative AI and want to turn discussions into action. However, the technology's risk list requires more meticulous security reviews, necessitating new frameworks, best practices, and training.

Although there are hundreds of ways to mitigate generative AI risks, analysts told CIO Dive that technology leaders do not necessarily need to rush to deploy all of them.

CIOs should identify the most critical risks, whether from a reputational damage or intellectual property perspective, said Thomas Humphreys, compliance expert and content manager at Prevalent. "Such thinking will help determine which mitigation techniques are most useful to the business."

Protecting intellectual property when using generative AI tools has become an ongoing point of contention, as the ease of third-party tools and employee enthusiasm have led to a surge in shadow AI. Gartner analysts predict that over the next two years, increased spending by enterprises to curb intellectual property losses will hurt ROI and slow adoption.

NIST recommends that organizations regularly monitor and address sensitive data exposure. At AAA's second-largest North American club, Abedi said the organization prohibits employees from casually entering sensitive information into models or using proprietary data to train models.

"The first thing we said is, you cannot use any of our assets to do your own generative AI," Abedi told CIO Dive. "We will monitor, and if we find you've used my assets to do something, we will come to you and shut it down."

Abedi said employees are encouraged to propose use case ideas that address pain points, but the organization is reluctant to give unauthorized third-party providers full access to its vast proprietary information.

This balance was reached after dialogue with stakeholders and risk assessments, a strategy NIST emphasizes in its guidance.

An overview perspective of two people sitting at a white table looking at a laptop. A person's shirt reads, "DISCOVER."
Discover Technology Academy participants work together on the computer. DTA is an internal tech program offering employees learning modules, risk training, networking opportunities and other avenues for upskilling and continued learning.
Permission granted by Discover

Understanding risk tolerance

NIST recommends that organizations develop risk mitigation measures based on their risk tolerance as a core governance principle.

"A friendly and acceptable approach is to first assess the business need for implementing AI, rather than treating all AI risk mitigation guidance as a panacea," said Rahul Vishwakarma, senior member of the Institute of Electrical and Electronics Engineers (IEEE).

When Discover considers incorporating generative AI into workflows, it keeps current risk boundaries in mind.

"If it's fully autonomous and answering where the nearest ATM is, that's one risk profile," Strle said. "When fully autonomous decisions affect a customer's financial livelihood or financial outcomes, that's a very high risk profile, and we're not there yet."

Discover has set controls and safeguards, but relies on trained employees with usage policies and procedure guidelines to discern the value of generative AI outputs. This is also a strategy NIST recommends in its guidance.

"A lot of what we do in the contact center is 'human-in-the-loop,' where you can leverage these generative AI capabilities while contact center agents are performing their work," Strle said. "The final decision is made by someone who follows all the training and processes."

When generative AI has a degree of autonomy in specific use cases, CIOs need to develop contingency plans for when the model errs. For some technology leaders, having a kill switch is critical.

The city of Glendale, Arizona turned to generative AI to address pressing support issues when it approved a major renovation of its city hall, according to former CIO and CISO Feroz Merchhiya, who now serves as CIO of Santa Monica, California.

City of Santa Monica CIO Feroz Merchhiya
City of Santa Monica CIO Feroz Merchhiya
Permission granted by Feroz Merchhiya

"I have full control over the data and the system, and if it doesn't work or gives bad advice, I can shut it down," Merchhiya said of the enterprise IT-support copilot tool. "And I have mechanisms to resolve issues by deploying human resources."

Technology leaders told CIO Dive that risk mitigation and implementation plans are best developed together. Strle said Discover's upfront work on how to best use generative AI in the contact center is combined with assessments of risks for identified use cases.

"All the controls we create—financial services must be sustainable indefinitely—must account for the dynamics of the industry we're in, and the industry is constantly changing," Strle said. "In my view, the NIST framework is an extension of the same basic model."

Next steps for CIOs

Although some enterprises are making progress in risk management, research shows a persistent gap between the number of organizations deploying generative AI and the prevalence of responsible, safe practices. Analysts attribute this to the rapid pace of technological innovation and adoption.

"I see CIOs facing greater challenges because they have to make very difficult technology decisions, even more difficult than ever, because these tools, technologies, and models are evolving so fast," said Rowan Curran, senior analyst at Forrester.

Despite generative AI capturing enterprise interest, it is still evolving and best practices have not yet solidified. Moreover, risk management is not always simple. According to a recent KPMG survey, more than three-fifths of executives expect the level of risk they are responsible for to increase significantly over the next three to five years. About two-fifths of executives expect more than half of their risk management budgets to go toward technology.

Freshworks CIO Ashwin Ballal
Freshworks CIO Ashwin Ballal
Permission granted by Freshworks

"There are no prescriptive standards yet, but these will evolve over time," Freshworks CIO Ashwin Ballal told CIO Dive. "Right now, it's like we all have an AI hammer and think everything is a nail."

But a shift is underway. Companies are quickly tiring of experimentation and pilot phases. As leaders link use cases to success metrics, the hype veil of early adopters is being lifted.

According to research released by Deloitte in August, interest in generative AI among senior executives and boards has declined since the beginning of the year. Fortune 500 companies are also more likely to list AI as a potential risk factor in securities filings rather than highlight its benefits or use cases, according to research by Arize AI, which analyzed each company's latest annual report.

The decline in interest comes as most organizations grapple with adoption barriers related to technical debt and insufficient infrastructure, as well as risk management. Nevertheless, companies still hold hope for their AI initiatives, using recommended actions from frameworks like NIST to reduce adoption risk.

"You have to come to leadership with recommendations and solutions," Curran said. "Be the educator who explains how this technology can make a difference, how it ties to business objectives, and the path to achieve it."