No single regulator owns AI in banking. Banks answer to a layered system: one binding AI law (the EU AI Act, whose high-risk regime — including credit scoring — became applicable August 2, 2026), prudential supervisors applying existing frameworks to AI (the Federal Reserve, OCC, ECB, and UK PRA/FCA), consumer-protection law that ignores how a decision was made (CFPB under ECOA), and global standard-setters shaping what supervisors expect next (FSB, Basel Committee). This page tracks all of them.
| Authority | Jurisdiction | Force | Key document | Latest move |
|---|---|---|---|---|
| Federal Reserve | United States (state member banks, bank holding companies, large financial institutions) | Supervisory guidance | SR 26-2 — Revised interagency Model Risk Management guidance (Apr 2026, supersedes SR 11-7) | Apr 2026 revised model risk guidance; May 2026 Vice Chair speech on AI in the financial system |
| OCC | United States (national banks and federal savings associations) | Supervisory guidance | OCC Bulletin 2026-13 — Revised interagency Model Risk Management guidance (Apr 2026) | Apr 2026 revised model risk guidance excluding generative/agentic AI; May 2026 risk report on AI-enabled fraud |
| CFPB | United States (consumer financial products) | Binding law | Circular 2026-03 — adverse action notices for ML underwriting (May 2026) | May 2026 circular: lenders using ML underwriting remain fully responsible for specific, accurate adverse-action reasons |
| NIST | United States (voluntary, used globally) | Voluntary framework | AI Risk Management Framework 1.0 (Jan 2023) + Generative AI Profile (Jul 2024) | Growing role as the default governance scaffold after the 2026 US model-risk revision excluded generative AI |
| EU AI Act | European Union | Binding law | Regulation (EU) 2024/1689 (in force Aug 1, 2024) | High-risk obligations, including for credit scoring, became applicable Aug 2, 2026 |
| ECB | Euro area (significant institutions) | Supervisory guidance | SSM supervisory priorities 2026–28 (AI under the operational-resilience priority) | Feb 2026 supervisory speech on AI governance; 2026–28 priorities single out generative AI |
| EBA | European Union | Supervisory guidance | Factsheet on the AI Act's implications for banking and payments (Nov 2025) | 2026–27 workplan: supervisory convergence on AI Act implementation in banking |
| UK (BoE / PRA / FCA) | United Kingdom | Supervisory guidance | BoE/PRA response to the Treasury Select Committee on AI (Apr 2026) | Apr 2026: tech-agnostic approach reaffirmed; AI named a 2026 PRA supervisory priority; new AI survey covering foundation and agentic AI |
| FSB | Global (G20) | Non-binding standards | The Financial Stability Implications of Artificial Intelligence (Nov 2024) | June 2026 consultation on 12 sound practices for responsible AI adoption; final report due Oct 2026 |
| Basel Committee | Global (28 jurisdictions) | Non-binding standards | Digitalisation of finance report (May 2024) | June 2026 ICT risk-management report; AI monitoring continues in the 2025–26 work programme |
The EU AI Act's high-risk regime went live. From August 2, 2026, AI credit-scoring systems in the EU must meet binding requirements — risk management, data governance, human oversight, logging — with fines up to €15M or 3% of global turnover. Details →
The US retired SR 11-7. On April 17, 2026 the OCC, Federal Reserve, and FDIC replaced the 2011 model risk management framework — and explicitly excluded generative and agentic AI from its scope, leaving those to banks' broader governance programs. Details →
The FSB moved toward firm-level expectations. Its June 2026 consultation proposes 12 sound practices for responsible AI adoption — including for agentic AI — with the final report due October 2026. Details →
| Date | Authority | Development |
|---|---|---|
| Aug 2, 2027 | EU AI Act | Extended deadline for high-risk AI embedded in regulated products. Article 6(1) high-risk systems tied to EU product-safety legislation get an additional year. |
| Aug 2, 2026 | EU AI Act | High-risk AI obligations become applicable. Annex III high-risk systems — including credit scoring — must comply with risk management, data governance, documentation, logging, human oversight, accuracy, and post-market monitoring requirements. Fines up to €15M / 3% of turnover. |
| Jun 2, 2026 | Basel Committee | Range of practices report on ICT risk management. Analysis of global ICT risk-management practices under the 2025–26 work programme, which also monitors AI developments and their implications for bank cybersecurity. |
| Jun 1, 2026 | FSB | Sound Practices for Responsible Adoption of AI (consultation). Proposes 12 sound practices for financial institutions' AI governance and risk management, with specific attention to agentic AI acting without human oversight. Final report expected October 2026. |
| Jun 1, 2026 | UK (BoE / PRA / FCA) | New AI survey covering foundation models and agentic AI. Fourth-generation voluntary survey of AI/ML use in UK financial services, extended to foundation models, generative AI, and agentic AI. |
| May 7, 2026 | OCC | Semiannual Risk Perspective highlights AI risks. Warns that AI is amplifying fraud and the speed, scale, and sophistication of cyberattacks; signals forthcoming AI governance guidance. |
| May 5, 2026 | CFPB | Circular 2026-03: adverse action notices and ML underwriting. Reaffirms that lenders using machine-learning underwriting models must provide specific, accurate reasons for adverse action — updated for the current generation of models. |
| May 1, 2026 | Federal Reserve | Vice Chair for Supervision speech on AI in the financial system. Sets out the Fed's supervisory philosophy on AI adoption in banking. |
| Apr 17, 2026 | NIST | US model-risk revision amplifies the RMF's role. With generative and agentic AI excluded from formal interagency model-risk guidance (SR 26-2), NIST's framework becomes the leading reference for how banks govern those systems. |
| Apr 17, 2026 | OCC | Revised interagency Model Risk Management guidance (Bulletin 2026-13). OCC, Fed, and FDIC supersede the 2011 guidance; OCC rescinds 2011-12, 1997-24 (credit scoring), and 2021-19 (BSA/AML model risk). Generative and agentic AI are explicitly excluded from scope as 'novel and rapidly evolving.' |
Who regulates AI in banking?
No single body does. Banks face a layered system: binding law where it exists (the EU AI Act, US consumer statutes like ECOA), prudential supervisors applying existing frameworks to AI (Federal Reserve, OCC, ECB, UK PRA/FCA), and global standard-setters shaping the agenda (FSB, Basel Committee). Voluntary frameworks like the NIST AI RMF fill the gaps supervisors leave open.
Is there a dedicated AI law for banks?
Only in the EU. The EU AI Act is the sole binding, AI-specific law that reaches banks — its high-risk regime, covering credit scoring, became applicable August 2, 2026. The US and UK have deliberately chosen to regulate bank AI through existing law and supervision instead.
What changed for bank AI regulation in 2026?
Three big moves: the EU AI Act's high-risk obligations became applicable (Aug 2); the US agencies replaced the 15-year-old SR 11-7 model risk framework with revised guidance that excludes generative and agentic AI (Apr 17); and the FSB opened consultation on 12 sound practices for responsible AI adoption, with the final report due October 2026.
Regulators move daily. So do we.
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →