AI Regulation Tracker · Reference

Who regulates AI in banking?
Every major authority, tracked.

Last updated Sep 10, 2026 · 19 authorities · 164 documents · Updated as rules change

No single regulator owns AI in banking. Banks answer to a layered system: binding AI law where it exists (the EU AI Act, whose high-risk regime — including credit scoring — now applies from December 2, 2027 after the 2026 Digital Omnibus deferral, Colorado's ADMT Act from January 1, 2027, and California's ADMT regulations from the same day), prudential supervisors applying existing frameworks to AI (the Federal Reserve, OCC, FDIC, NCUA, ECB, and UK PRA/FCA), consumer-protection, market and financial-crime authorities that regulate outcomes regardless of how a decision was made (CFPB, SEC, CFTC, FinCEN, NY DFS), and global standard-setters shaping what supervisors expect next (FSB, Basel Committee). This page tracks all 19 of them and every document they have published.

Which AI consultations are open for comment?

What are the next AI regulation deadlines for banks?

DateAuthorityDeadline
Oct 20, 2026CFTCCFTC Compute Derivatives RFC: comment period closes · Comment deadline
Oct 26, 2026Colorado AI ActColorado AG proposed ADMT rules: comment period closes · Comment deadline
Oct 31, 2026ECBDeadline for significant institutions to submit AI-cyber action plans to their JSTs · Milestone
Nov 20, 2026EU AI ActConsumer Credit Directive (EU) 2023/2225 takes effect · Takes effect
Jan 1, 2027Colorado AI ActSB 26-189 takes effect · Takes effect
Jan 1, 2027Colorado AI ActHB 26-1263 takes effect · Takes effect

Full deadlines calendar →

Which US authorities regulate AI in banking?

AuthorityJurisdictionForceKey documentLatest move
Federal ReserveUnited States (state member banks, bank holding companies, large financial institutions)Supervisory guidanceSR 26-2 — Revised interagency Model Risk Management guidance (Apr 2026, supersedes SR 11-7)Apr 2026 revised model risk guidance; May 2026 Vice Chair speech on AI in the financial system
OCCUnited States (national banks and federal savings associations)Supervisory guidanceOCC Bulletin 2026-13 — Revised interagency Model Risk Management guidance (Apr 2026)Apr 2026 revised model risk guidance excluding generative/agentic AI; May 2026 risk report on AI-enabled fraud
FDICUnited States (state-chartered banks that are not Federal Reserve members; deposit insurer for all insured banks)Supervisory guidanceFIL-15-2026 — Agencies Revise the Interagency Model Risk Management Guidance (Apr 17, 2026)Apr 2026 adoption of revised interagency model risk guidance (FIL-15-2026); Jun 2026 testimony describing it as 'an avenue for the safe and sound adoption of technology'
NCUAUnited States (federally insured credit unions)Supervisory guidanceCredit Union Artificial Intelligence Resource Center (Aug 2025, updated Apr 2026) — the NCUA's only AI-specific publication for credit unionsFeb 2026 Senate testimony frames 'space to innovate responsibly' with AI as a 2026-2030 strategic-plan goal; Apr 2026 refresh of the AI resource page; no AI mention in the Jan 2026 supervisory priorities
CFPBUnited States (consumer financial products)Binding lawRegulation B §1002.9 adverse-action requirements (ECOA); April 2026 Reg B final ruleApril 2026 Regulation B final rule (effective July 21, 2026) eliminates disparate-impact liability under ECOA — the fair-lending theory most often applied to AI models — while the statutory duty to give specific, accurate adverse-action reasons remains untouched.
SECUnited States (broker-dealers, investment advisers, funds, and public companies — including bank holding companies and bank-affiliated securities arms)Supervisory guidanceDivision of Examinations FY2026 Examination Priorities (Nov 17, 2025) — the operative statement of what SEC examiners test on AIChairman Atkins told the FSOC AI roundtable on March 4, 2026 that AI disclosure will be governed by materiality, not new line items, and that AI-washing enforcement continues
CFTCUnited States (futures, options, and swaps markets; bank swap dealers, FCMs, exchanges, and clearinghouses)Supervisory guidanceCFTC Staff Advisory on the Use of AI in CFTC-Regulated Markets (CFTC Letter No. 24-17, Dec 2024)Aug 19, 2026 request for comment on listing compute derivatives; Aug 20, 2026 inaugural Innovation Advisory Committee meeting with an 'agentic finance' session
FinCENUnited States (Bank Secrecy Act administrator for all US financial institutions)Binding lawAML/CFT Program proposed rule (Apr 2026) — names effective use of AI as a factor in FinCEN enforcement decisions; supersedes the withdrawn July 2024 proposalJul 24, 2026 alert FIN-2026-Alert004 on AI-generated synthetic identities and chatbot-completed coursework in federal student aid fraud; Apr 2026 AML/CFT program NPRM comment period closed Jun 9, 2026
U.S. TreasuryUnited States (federal; convenes FSOC and the financial-sector critical-infrastructure partnership; parent of the OCC and FinCEN)Voluntary frameworkFinancial Services AI Risk Management Framework (FS AI RMF) and AI Lexicon — voluntary, NIST-aligned resources released Feb 19, 2026June 2026: FSOC and Treasury's AI Transformation Office concluded the four-roundtable AI Innovation Series (Mar–May 2026); participants asked for regulatory clarity and harmonization to scale AI adoption
NY DFSNew York State (state-chartered banks, foreign bank branches and agencies, insurers, money transmitters, virtual-currency licensees, and other DFS-licensed entities)Supervisory guidance23 NYCRR Part 500 (Second Amendment effective Nov 1, 2023; fully phased in Nov 1, 2025) as applied to AI by the Oct 16, 2024 Industry LetterMay 21, 2026: two Industry Letters on frontier AI model cyber risk and measures to take in a heightened threat environment
Colorado AI ActColorado, United States (any developer or deployer doing business in Colorado)Binding lawSB 26-189, the Automated Decision-Making Technology Act (signed May 14, 2026; effective Jan 1, 2027)Colorado AG published proposed ADMT and Conversational AI Service rules on Aug 11, 2026; comments and hearing close Oct 26, 2026
California CPPACalifornia, United States (any business meeting CCPA thresholds that handles Californians' personal information; employers with five or more California employees)Binding lawCPPA regulations on cybersecurity audits, risk assessments and automated decisionmaking technology (11 CCR §§ 7001, 7120–7124, 7150–7157, 7200–7222; approved Sep 22, 2025, effective Jan 1, 2026; ADMT obligations from Jan 1, 2027)Legislature adjourned Aug 31, 2026 with AB 1609 (customer-service chatbots at businesses over $500M revenue) and SB 947 (workplace automated decision systems) on the Governor's desk until Sep 30; AB 1018 did not pass. ADMT obligations for significant decisions apply from Jan 1, 2027
NISTUnited States (voluntary, used globally)Voluntary frameworkAI Risk Management Framework 1.0 (Jan 2023) + Generative AI Profile (Jul 2024)Growing role as the default governance scaffold after the 2026 US model-risk revision excluded generative AI

Which international bodies set AI rules for banks?

AuthorityJurisdictionForceKey documentLatest move
EU AI ActEuropean UnionBinding lawRegulation (EU) 2024/1689 (in force Aug 1, 2024), as amended by the Digital Omnibus on AI (EU) 2026/1744Regulation (EU) 2026/1744 (Digital Omnibus on AI) entered into force July 27, 2026, deferring Annex III high-risk obligations — including credit scoring — from Aug 2, 2026 to Dec 2, 2027
ECBEuro area (significant institutions)Supervisory guidanceSSM supervisory priorities 2026–28 (AI under the operational-resilience priority)7 July 2026 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301): every significant institution must file an action plan with its JST by 31 October 2026
EBAEuropean UnionSupervisory guidanceFactsheet on the AI Act's implications for banking and payments (Nov 2025)Jul 31, 2026: joint ESA statement (JC 2026 25) on ICT risks from frontier AI models — banks told to adjust DORA ICT-risk controls around prevention, detection and management without delay
UK (BoE / PRA / FCA)United KingdomSupervisory guidanceBoE/PRA response to the Treasury Select Committee on AI (Apr 2026)May 2026: BoE/FCA/HM Treasury joint statement on frontier AI and cyber resilience; July 2026: HM Treasury Financial Services AI Adoption Plan; 2026 AI survey (foundation and agentic AI) closed 31 July, results pending
FSBGlobal (G20)Non-binding standardsThe Financial Stability Implications of Artificial Intelligence (Nov 2024)31 August 2026: FSB Chair's letter to G20 finance ministers and central bank governors warns that frontier AI models' autonomy and threat capabilities make cyber risk the most immediate financial-stability concern; final AI sound-practices report still expected October 2026
Basel CommitteeGlobal (28 jurisdictions)Non-binding standardsDigitalisation of finance report (May 2024)June 2026 ICT risk-management report; AI monitoring continues in the 2025–26 work programme

The EU deferred its high-risk AI deadline. The high-risk regime — including credit scoring — was due August 2, 2026; the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force July 27, 2026) moved it to December 2, 2027. The obligations (risk management, data governance, human oversight, logging; fines up to €15M or 3% of global turnover) are unchanged. Details →

The CFPB narrowed fair-lending exposure for AI models. Its April 2026 Regulation B rule (effective July 21, 2026) says ECOA does not authorize disparate-impact liability — while the duty to give specific adverse-action reasons is untouched, and its 2022/2023 AI circulars were withdrawn in May 2025. Details →

The US retired SR 11-7. On April 17, 2026 the OCC, Federal Reserve, and FDIC replaced the 2011 model risk management framework — and explicitly excluded generative and agentic AI from its scope, leaving those to banks' broader governance programs. Details →

The FSB moved toward firm-level expectations. Its June 2026 consultation proposes 12 sound practices for responsible AI adoption — including for agentic AI — with the final report due later in 2026. Details →

DateAuthorityDevelopment
Aug 2, 2028EU AI ActDeferred deadline for high-risk AI embedded in regulated products. Article 6(1) / Annex I high-risk systems tied to EU product-safety legislation now apply from this date (moved from August 2, 2027 by the Digital Omnibus on AI).
Dec 2, 2027EU AI ActHigh-risk AI obligations for stand-alone Annex III systems become applicable. Deferred from August 2, 2026 by the Digital Omnibus on AI. Annex III high-risk systems — including credit scoring of natural persons — must comply with risk management, data governance, documentation, logging, human oversight, accuracy, and post-market monitoring requirements. Fines up to €15M / 3% of turnover.
Oct 31, 2026ECBDeadline for significant institutions to submit AI-cyber action plans to their JSTs. Under the ECB's 7 July 2026 letter on AI-enabled cybersecurity threats (SSM-2026-0301), each significant institution must deliver a comprehensive action plan — measures, resources, owners, timelines — to its Joint Supervisory Team by 31 October 2026. The ECB will run a horizontal analysis of the plans and share conclusions with banks.
Aug 31, 2026California CPPALegislature adjourns: AB 1018 not passed; chatbot and workplace-ADS bills go to the Governor. The Automated Decisions Safety Act (AB 1018), which would have required pre-deployment bias evaluations of automated decision systems used for consequential decisions including lending, was not among the AI bills sent to the Governor. AB 1609 (customer-service chatbot disclosure and 15-minute human hand-off at businesses over $500 million in revenue) and SB 947 (worker protections for automated decision systems) were; the Governor has until September 30, 2026 to act.
Aug 31, 2026FSBFSB Chair's letter to G20 (Aug 2026) — FSB Chair's letter to G20 Finance Ministers and Central Bank Governors: August 2026 — risks arising from frontier artificial intelligence models. On 31 August 2026, ahead of the G20 Finance Ministers and Central Bank Governors meeting, FSB Chair Andrew Bailey wrote that frontier AI models now show 'increasingly sophisticated autonomy and problem-solving abilities, as well as threat capabilities', and that their most immediate financial-stability impact is on cyber risk.
Aug 20, 2026CFTCInaugural Innovation Advisory Committee meeting: 'Preparing for Intelligent Markets'. Session II of the first IAC meeting covered AI in trading, compliance, surveillance and risk management, 'the rise of agentic finance' (autonomous agents executing transactions and managing portfolios), how existing regulatory principles apply to AI-enabled market participants, and whether additional guidance is warranted. Written public comments were accepted through August 27, 2026.
Aug 19, 2026CFTCCFTC Compute Derivatives RFC — Request for Comment on the Listing of Compute Derivatives Contracts. On August 19, 2026 the CFTC issued a request for comment on derivatives markets in compute — the GPU and data-center capacity that powers AI — published in the Federal Register on August 21, 2026 (91 FR 54259) with a 60-day comment period.
Aug 11, 2026Colorado AI ActColorado AG proposed ADMT rules — Proposed Automated Decision-Making Technology and Conversational AI Service Rules (Notice of Rulemaking Hearing). On August 11, 2026 the Colorado Department of Law filed proposed rules implementing the ADMT Act (SB 26-189) and the Chatbot Safety Act (HB 26-1263).
Aug 6, 2026FSBResponses to FSB AI sound practices consultation (Aug 2026) — Public responses to consultation on Sound Practices for Responsible Adoption of Artificial Intelligence (AI). On 6 August 2026 the FSB published the 159 public responses received by the 22 July 2026 deadline on its AI sound practices consultation.
Aug 5, 2026UK (BoE / PRA / FCA)AI Consortium June 2026 minutes published. Minutes of the 3 June 2026 meeting cover frontier models, safe deployment of agentic tools, model harnesses and execution boundaries, AI incident reporting, and stress scenarios including agentic payments.
Aug 2, 2026EU AI ActArticle 50 transparency obligations apply; Annex III high-risk start deferred. Transparency duties (e.g., telling customers they are interacting with an AI system, marking AI-generated content) apply from this date as originally scheduled. The Annex III high-risk regime — including credit scoring — did NOT start on this date: Regulation (EU) 2026/1744 (Digital Omnibus on AI, in force July 27, 2026) deferred it to December 2, 2027.
Jul 31, 2026EBAESA Statement on ICT risks from frontier AI models (JC 2026 25) — ESA Statement: Toward a consistent and risk-based approach for ICT risks from frontier AI models. On July 31, 2026 the EBA, EIOPA and ESMA published joint statement JC 2026 25 on ICT risks from frontier AI models, warning that highly capable AI models sharply accelerate vulnerability discovery and exploitation and could create systemic cyber risk.

Who regulates AI in banking?

No single body does. Banks face a layered system: binding law where it exists (the EU AI Act, US consumer statutes like ECOA), prudential supervisors applying existing frameworks to AI (Federal Reserve, OCC, ECB, UK PRA/FCA), and global standard-setters shaping the agenda (FSB, Basel Committee). Voluntary frameworks like the NIST AI RMF fill the gaps supervisors leave open.

Is there a dedicated AI law for banks?

At the federal level, only in the EU: the EU AI Act is the sole binding, cross-sector AI law that reaches banks, and its high-risk regime covering credit scoring applies from December 2, 2027 after the 2026 Digital Omnibus deferral. In the US there is no federal AI statute for banks — but two states bind them: Colorado's Automated Decision-Making Technology Act (effective January 1, 2027) reaches lenders with no bank exemption, and California's CPPA regulations on automated decisionmaking technology (obligations from January 1, 2027) list lending as a significant decision, though GLBA-covered data is exempt. The UK has deliberately chosen to regulate bank AI through existing law and supervision.

What changed for bank AI regulation in 2026?

Four big moves: the US agencies replaced the 15-year-old SR 11-7 model risk framework with revised guidance that excludes generative and agentic AI (Apr 17); the CFPB's Regulation B rule eliminated disparate-impact liability under ECOA (effective Jul 21); the EU's Digital Omnibus deferred the AI Act's high-risk regime, including credit scoring, to December 2, 2027; and the FSB consulted on 12 sound practices for responsible AI adoption, with the final report due later in 2026.

Regulators move daily. So do we.

the daily brief · six sourced stories · in your inbox by 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning