AAI Compliance Atlas
FrameworksState lawsIndustriesToolsNews
GuidesMap my obligations →
AAI Compliance Atlas

Structured, continuously verified reference for US AI compliance — federal frameworks, state laws, and the obligations that connect them.

Atlas

  • Frameworks
  • State laws
  • Industries
  • By role
  • Comparisons

Tools

  • Compliance Checker
  • Penalty Calculator
  • Impact Assessment
  • Vendor Questionnaire

Resources

  • Guides
  • News
  • Blog
  • Methodology

Company

  • About
  • Contact
  • Privacy
  • Terms
© 2026 AI Compliance Atlas. Informational only — not legal advice. Consult qualified counsel before making compliance decisions.Verified Jul 28, 2026
  1. Home/
  2. Industries/
  3. Financial Services

AI Compliance for Financial Services

Banks, lenders, insurers, broker-dealers, and fintech firms using AI for credit decisions, underwriting, fraud detection, and consumer interaction.

US financial services has no single “AI law.” As of 2026, banks, lenders, and fintech firms that use AI in credit, fraud, or pricing decisions must satisfy at least four federal regimes — the CFPB’s adverse-action rules under the Equal Credit Opportunity Act, the CFPB’s April 2026 fair-lending rule narrowing ECOA disparate-impact liability (effective July 21, 2026), interagency model-risk-management guidance (revised April 2026 as SR 26-2), and the Treasury’s AI cybersecurity roadmap — layered on top of cross-sector state AI acts such as the Colorado AI Act, which treats financial and lending decisions as consequential decisions. (Insurance carriers face a separate, sector-specific regime covered on the insurance hub.)

Sector-specific AI regulations

  • ECOA / Regulation B adverse-action requirements for algorithmic credit decisions (CFPB Circulars 2022-03 & 2023-03)Binding

    Equal Credit Opportunity Act (15 U.S.C. 1691) and Regulation B (12 CFR 1002); CFPB Consumer Financial Protection Circulars 2022-03 and 2023-03 • Effective: Circular 2022-03 issued May 26, 2022; reaffirmed by Circular 2023-03 (Sept 2023)

    The Equal Credit Opportunity Act and Regulation B require creditors to give applicants the specific and accurate reasons for an adverse action such as a credit denial. The CFPB has stated that a creditor cannot escape that duty by relying on a complex algorithm or “black-box” machine-learning model that is too opaque to explain — technological complexity is not a defense. AI-driven underwriting must therefore be able to produce accurate, applicant-specific denial reasons.

    Source: CFPB — Consumer Financial Protection Circular 2022-03 — retrieved 2026-07-06

  • Regulation B fair-lending amendments removing the ECOA disparate-impact “effects test” (CFPB final rule)Binding

    Equal Credit Opportunity Act (15 U.S.C. 1691); 12 CFR part 1002; CFPB final rule, Docket No. CFPB-2025-0039, RIN 3170-AB54, 91 FR 21620 (Apr. 22, 2026) • Effective: Published Apr 22, 2026; effective July 21, 2026

    On April 22, 2026 the CFPB issued a final rule amending Regulation B to provide that disparate-impact claims are “not cognizable under ECOA” and that “the Act does not recognize the ‘effects test.’” For AI-driven credit models this materially narrows federal fair-lending exposure under ECOA: a lender is no longer subject to ECOA disparate-impact liability solely because an algorithmic underwriting or credit-scoring model produces disproportionate outcomes for a protected class. Disparate-treatment (intentional discrimination) liability under ECOA is unchanged, and the rule amends only Regulation B — it does not address the Fair Housing Act’s separate disparate-impact standard for mortgage and housing-related credit, nor state fair-lending laws, so disparate-impact model testing remains relevant where those regimes apply.

    Source: Federal Register — Equal Credit Opportunity Act (Regulation B), final rule (91 FR 21620) — retrieved 2026-07-25

  • Interagency Guidance on Model Risk Management (SR 26-2, replacing SR 11-7)Model guidance

    Federal Reserve SR 26-2 / OCC / FDIC (revises Federal Reserve SR 11-7, 2011, and SR 21-8, 2021) • Effective: SR 26-2 issued April 17, 2026 (superseded SR 11-7 of April 4, 2011)

    Model risk management is the supervisory framework banking organizations use to develop, validate, govern, and monitor their quantitative models — including the AI and machine-learning models used in underwriting, pricing, and fraud detection. In April 2026 the Federal Reserve, OCC, and FDIC jointly issued SR 26-2, a risk-based revision that replaces the long-standing SR 11-7 (2011) and applies primarily to banking organizations above $30 billion in assets. Examiners assess whether AI/ML models are independently validated and monitored under this regime, so most institutions treat it as an operative compliance standard even though it is supervisory guidance rather than a statute.

    Source: Federal Reserve — Supervisory Letter SR 26-2 on Revised Guidance on Model Risk Management — retrieved 2026-07-06

  • Treasury report — Managing AI-Specific Cybersecurity Risks in the Financial Services SectorModel guidance

    U.S. Department of the Treasury (directed by Executive Order 14110) • Effective: Released March 2024

    Written at the direction of Executive Order 14110 and informed by interviews with 42 financial and technology firms, the Treasury report catalogues AI-specific operational, cybersecurity, third-party, bias, and data-privacy risks in the financial sector and recommends next steps — including closing the widening capability gap between large and small institutions. It is not binding, but it signals the AI risk areas federal financial regulators are prioritizing and is a common reference point for bank and fintech AI governance programs.

    Source: U.S. Treasury — Report on Managing AI-Specific Cybersecurity Risks in the Financial Services Sector — retrieved 2026-07-06

Last verified: 2026-07-25

Priority law pages

  • Utah AI Policy Act for financial services

    Industry-specific implementation route for Utah consumer-facing financial AI interactions.

Applicable laws

  • Colorado Artificial Intelligence Act for Financial ServicesEffective soon
    Colorado•Effective January 1, 2027•Max penalty: $20Kfull detail
  • Connecticut Public Act 26-15 / SB 5 (Online Safety and AI Provisions) for Financial ServicesEffective soon
    Connecticut•Effective October 1, 2026•Max penalty: Not specifiedfull detail
  • California AI Transparency Act for Financial ServicesEffective soon
    California•Effective August 2, 2026•Max penalty: $5Kfull detail
  • California Generative AI: Training Data Transparency for Financial ServicesIn effect
    California•Effective January 1, 2026•Max penalty: Not specifiedfull detail
  • Transparency in Frontier Artificial Intelligence Act (TFAIA) for Financial ServicesIn effect
    California•Effective January 1, 2026•Max penalty: $1.0Mfull detail
  • Texas Responsible Artificial Intelligence Governance Act (TRAIGA) for Financial ServicesIn effect
    Texas•Effective January 1, 2026•Max penalty: $200Kfull detail
  • Utah Artificial Intelligence Policy Act for Financial ServicesIn effect
    Utah•Effective May 7, 2025•Max penalty: $5Kfull detail
  • Florida AI Legislation (Deepfake and AI Disclosure Laws) for Financial ServicesIn effect
    Florida•Effective July 1, 2024•Max penalty: $15Kfull detail
  • Washington State Artificial Intelligence Task Force / AI Regulation for Financial ServicesIn effect
    Washington•Effective March 18, 2024•Max penalty: Not specifiedfull detail
  • Virginia High-Risk Artificial Intelligence Developer and Deployer Act for Financial ServicesDefeated
    Virginia•Effective Not yet set•Max penalty: $10Kfull detail

Interactive tools

  • Vendor AI due diligence questionnaire

    Generate a source-linked questionnaire covering adverse-action explainability and independent model validation evidence before an AI vendor is onboarded.

Recommended frameworks

  • NIST AI RMF 1.0

    Voluntary US framework. Adopt to demonstrate due care across most state AI laws.

  • ISO/IEC 42001:2023

    Certifiable AI management-system standard. Strong fit for financial services organizations subject to multiple jurisdictions.

Frequently asked questions

How is AI regulated in financial services in the US?

There is no single federal AI statute for financial services. Instead, banks, lenders, and fintech firms sit under a stack of overlapping regimes: (1) the Equal Credit Opportunity Act and Regulation B — which the CFPB has confirmed require specific, accurate adverse-action reasons even for AI or “black-box” credit models; (2) interagency model-risk-management guidance, revised in April 2026 as SR 26-2 (replacing SR 11-7), which governs how banks validate and monitor AI/ML models; (3) the Treasury’s 2024 report on AI-specific cybersecurity risks; and (4) cross-sector state AI acts such as the Colorado AI Act, which classify financial and lending decisions as consequential decisions. Firms should map each AI use case against all four layers.

What legal requirements apply to AI used in lending and credit decisions?

AI-driven lending is governed principally by the Equal Credit Opportunity Act (15 U.S.C. 1691) and Regulation B (12 CFR 1002). Per CFPB Circular 2022-03 (retrieved 2026-07-06), a creditor that denies credit using a complex algorithm must still provide the applicant with the specific and accurate principal reasons for denial; the CFPB has stated that a model being too complicated or opaque to understand is not a valid excuse. Banks additionally validate lending models under interagency model-risk-management guidance (SR 26-2). Note that the fair-lending disparate-impact picture changed on July 21, 2026 — see the fair-lending question below.

Does fair-lending disparate-impact liability still apply to AI credit and lending models?

Federal fair-lending exposure narrowed on July 21, 2026. The CFPB’s final rule amending Regulation B (91 FR 21620, Docket No. CFPB-2025-0039, retrieved 2026-07-25) provides that disparate-impact claims are “not cognizable under ECOA” and that the Act “does not recognize the ‘effects test.’” As a result, an AI or machine-learning underwriting model that produces disproportionate outcomes for a protected class is no longer, on that basis alone, a source of ECOA disparate-impact liability. Two limits still matter for AI lending compliance: (1) disparate-treatment — intentional discrimination, including using prohibited-basis proxies as a matter of policy — remains prohibited under ECOA; and (2) the rule amends only Regulation B, so it does not change the Fair Housing Act’s separate disparate-impact standard for mortgage and housing-related credit, nor state fair-lending or AI-bias statutes. Firms operating where those regimes apply should continue disparate-impact testing of their AI models.

Which AI risk framework should banks and fintech firms adopt?

For firms shopping for AI compliance software or a governance framework, the two most widely referenced voluntary standards are the NIST AI Risk Management Framework (AI RMF 1.0) and ISO/IEC 42001:2023. NIST AI RMF’s govern-map-measure-manage functions align with the documentation and validation expectations of interagency model-risk-management guidance, while ISO/IEC 42001 provides a certifiable AI management system suited to institutions operating across multiple states and regulators. Neither replaces the binding ECOA/Regulation B adverse-action duties or bank supervisory expectations, but adopting one helps evidence due care across them.

Automate AI governance with OneTrust

partner link

Manage AI inventory, risk assessments, and policy enforcement across your organization. Used by hundreds of regulated enterprises.

See OneTrust AI Governance →

Last reviewed 2026-07-25. Reviewed by the AI Compliance Atlas editorial process against primary sources. Source selection, retrieval dates, and update rules are documented in the Atlas methodology.

Legal disclaimer

This content is informational only and does not constitute legal advice. Laws change frequently and vary by jurisdiction. Consult qualified legal counsel before making compliance decisions. Information accuracy not guaranteed as of any specific date.

We may receive referral commissions from recommended compliance tools. Recommendations are based on product fit and not on commission size. Links marked “partner link” include a tracked redirect.