US financial services has no single “AI law.” As of 2026, banks, lenders, and fintech firms that use AI in credit, fraud, or pricing decisions must satisfy at least four federal regimes — the CFPB’s adverse-action rules under the Equal Credit Opportunity Act, the CFPB’s April 2026 fair-lending rule narrowing ECOA disparate-impact liability (effective July 21, 2026), interagency model-risk-management guidance (revised April 2026 as SR 26-2), and the Treasury’s AI cybersecurity roadmap — layered on top of cross-sector state AI acts such as the Colorado AI Act, which treats financial and lending decisions as consequential decisions. (Insurance carriers face a separate, sector-specific regime covered on the insurance hub.)
ECOA / Regulation B adverse-action requirements for algorithmic credit decisions (CFPB Circulars 2022-03 & 2023-03)Binding
Equal Credit Opportunity Act (15 U.S.C. 1691) and Regulation B (12 CFR 1002); CFPB Consumer Financial Protection Circulars 2022-03 and 2023-03 • Effective: Circular 2022-03 issued May 26, 2022; reaffirmed by Circular 2023-03 (Sept 2023)
The Equal Credit Opportunity Act and Regulation B require creditors to give applicants the specific and accurate reasons for an adverse action such as a credit denial. The CFPB has stated that a creditor cannot escape that duty by relying on a complex algorithm or “black-box” machine-learning model that is too opaque to explain — technological complexity is not a defense. AI-driven underwriting must therefore be able to produce accurate, applicant-specific denial reasons.
Source: CFPB — Consumer Financial Protection Circular 2022-03 — retrieved 2026-07-06
Regulation B fair-lending amendments removing the ECOA disparate-impact “effects test” (CFPB final rule)Binding
Equal Credit Opportunity Act (15 U.S.C. 1691); 12 CFR part 1002; CFPB final rule, Docket No. CFPB-2025-0039, RIN 3170-AB54, 91 FR 21620 (Apr. 22, 2026) • Effective: Published Apr 22, 2026; effective July 21, 2026
On April 22, 2026 the CFPB issued a final rule amending Regulation B to provide that disparate-impact claims are “not cognizable under ECOA” and that “the Act does not recognize the ‘effects test.’” For AI-driven credit models this materially narrows federal fair-lending exposure under ECOA: a lender is no longer subject to ECOA disparate-impact liability solely because an algorithmic underwriting or credit-scoring model produces disproportionate outcomes for a protected class. Disparate-treatment (intentional discrimination) liability under ECOA is unchanged, and the rule amends only Regulation B — it does not address the Fair Housing Act’s separate disparate-impact standard for mortgage and housing-related credit, nor state fair-lending laws, so disparate-impact model testing remains relevant where those regimes apply.
Source: Federal Register — Equal Credit Opportunity Act (Regulation B), final rule (91 FR 21620) — retrieved 2026-07-25
Interagency Guidance on Model Risk Management (SR 26-2, replacing SR 11-7)Model guidance
Federal Reserve SR 26-2 / OCC / FDIC (revises Federal Reserve SR 11-7, 2011, and SR 21-8, 2021) • Effective: SR 26-2 issued April 17, 2026 (superseded SR 11-7 of April 4, 2011)
Model risk management is the supervisory framework banking organizations use to develop, validate, govern, and monitor their quantitative models — including the AI and machine-learning models used in underwriting, pricing, and fraud detection. In April 2026 the Federal Reserve, OCC, and FDIC jointly issued SR 26-2, a risk-based revision that replaces the long-standing SR 11-7 (2011) and applies primarily to banking organizations above $30 billion in assets. Examiners assess whether AI/ML models are independently validated and monitored under this regime, so most institutions treat it as an operative compliance standard even though it is supervisory guidance rather than a statute.
Source: Federal Reserve — Supervisory Letter SR 26-2 on Revised Guidance on Model Risk Management — retrieved 2026-07-06
Treasury report — Managing AI-Specific Cybersecurity Risks in the Financial Services SectorModel guidance
U.S. Department of the Treasury (directed by Executive Order 14110) • Effective: Released March 2024
Written at the direction of Executive Order 14110 and informed by interviews with 42 financial and technology firms, the Treasury report catalogues AI-specific operational, cybersecurity, third-party, bias, and data-privacy risks in the financial sector and recommends next steps — including closing the widening capability gap between large and small institutions. It is not binding, but it signals the AI risk areas federal financial regulators are prioritizing and is a common reference point for bank and fintech AI governance programs.
Source: U.S. Treasury — Report on Managing AI-Specific Cybersecurity Risks in the Financial Services Sector — retrieved 2026-07-06