No single regulator owns AI in banking. Banks answer to a layered system: binding AI law where it exists (the EU AI Act, whose high-risk regime — including credit scoring — now applies from December 2, 2027 after the 2026 Digital Omnibus deferral, Colorado's ADMT Act from January 1, 2027, and California's ADMT regulations from the same day), prudential supervisors applying existing frameworks to AI (the Federal Reserve, OCC, FDIC, NCUA, ECB, and UK PRA/FCA), consumer-protection, market and financial-crime authorities that regulate outcomes regardless of how a decision was made (CFPB, SEC, CFTC, FinCEN, NY DFS), and global standard-setters shaping what supervisors expect next (FSB, Basel Committee). This page tracks all 41 of them and every document they have published.
Which AI consultations are open for comment?
- CFTC Compute Derivatives RFC — Request for Comment on the Listing of Compute Derivatives Contracts · closes Oct 20, 2026
- Colorado AG proposed ADMT rules — Proposed Automated Decision-Making Technology and Conversational AI Service Rules (Notice of Rulemaking Hearing) · closes Oct 26, 2026
What are the next AI regulation deadlines for banks?
| Date | Authority | Deadline |
|---|---|---|
| Oct 20, 2026 | CFTC | CFTC Compute Derivatives RFC: comment period closes · Comment deadline |
| Oct 26, 2026 | Colorado AI Act | Colorado AG proposed ADMT rules: comment period closes · Comment deadline |
| Oct 31, 2026 | ECB | Deadline for significant institutions to submit AI-cyber action plans to their JSTs · Milestone |
| Nov 2026 | NY DFS | RAISE Act: DFS begins directing large frontier developers to register · Milestone |
| Nov 20, 2026 | EU AI Act | Consumer Credit Directive (EU) 2023/2225 takes effect · Takes effect |
| Dec 1, 2026 | Colorado AI Act | Regulation 10-1-1: annual life insurer reports and non-use attestations due · Milestone |
Which US authorities regulate AI in banking?
| Authority | Jurisdiction | Force | Key document | Latest move |
|---|---|---|---|---|
| Federal Reserve | United States (state member banks, bank holding companies, large financial institutions) | Supervisory guidance | SR 26-2 — Revised interagency Model Risk Management guidance (Apr 2026, supersedes SR 11-7) | Sep 29, 2026 Vice Chair for Supervision Bowman at the Community Bank Cyber Workshop: AI used by threat actors 'adds complexity to the risk environment' and is becoming 'both a defensive tool and an evolving risk'; Apr 2026 revised model risk guidance |
| OCC | United States (national banks and federal savings associations) | Supervisory guidance | OCC Bulletin 2026-13 — Revised interagency Model Risk Management guidance (Apr 2026) | Apr 2026 revised model risk guidance excluding generative/agentic AI; May 2026 risk report on AI-enabled fraud |
| FDIC | United States (state-chartered banks that are not Federal Reserve members; deposit insurer for all insured banks) | Supervisory guidance | FIL-15-2026 — Agencies Revise the Interagency Model Risk Management Guidance (Apr 17, 2026) | Apr 2026 adoption of revised interagency model risk guidance (FIL-15-2026); Jun 2026 testimony describing it as 'an avenue for the safe and sound adoption of technology' |
| NCUA | United States (federally insured credit unions) | Supervisory guidance | Credit Union Artificial Intelligence Resource Center (Aug 2025, updated Apr 2026) — the NCUA's only AI-specific publication for credit unions | Feb 2026 Senate testimony frames 'space to innovate responsibly' with AI as a 2026-2030 strategic-plan goal; Apr 2026 refresh of the AI resource page; no AI mention in the Jan 2026 supervisory priorities |
| CFPB | United States (consumer financial products) | Binding law | Regulation B §1002.9 adverse-action requirements (ECOA); April 2026 Reg B final rule | April 2026 Regulation B final rule (effective July 21, 2026) eliminates disparate-impact liability under ECOA — the fair-lending theory most often applied to AI models — while the statutory duty to give specific, accurate adverse-action reasons remains untouched. |
| SEC | United States (broker-dealers, investment advisers, funds, and public companies — including bank holding companies and bank-affiliated securities arms) | Supervisory guidance | Division of Examinations FY2026 Examination Priorities (Nov 17, 2025) — the operative statement of what SEC examiners test on AI | Chairman Atkins reaffirmed at the Investor Advisory Committee's September 10, 2026 meeting that AI disclosure remains governed by materiality, not new line items, warning that AI 'cannot always discern fact from fiction, much less materiality from immateriality' |
| CFTC | United States (futures, options, and swaps markets; bank swap dealers, FCMs, exchanges, and clearinghouses) | Supervisory guidance | CFTC Staff Advisory on the Use of AI in CFTC-Regulated Markets (CFTC Letter No. 24-17, Dec 2024) | Sep 21, 2026: Innovation Task Force announces the Frontier Forum Series, with its inaugural forum on artificial intelligence and agentic finance set for October 28, 2026 |
| FinCEN | United States (Bank Secrecy Act administrator for all US financial institutions) | Binding law | AML/CFT Program proposed rule (Apr 2026) — names effective use of AI as a factor in FinCEN enforcement decisions; supersedes the withdrawn July 2024 proposal | Sep 3, 2026 alert FIN-2026-Alert005 names AI-supported software platforms as part of the ecosystem enabling digital-asset investment scam centers, and AI-tool adoption as fueling their growth; Oct 1, 2026 alert FIN-2026-Alert007 on the Russia-linked A7 Network lists AI-altered invoices among its red flags; the Apr 2026 AML/CFT program NPRM remains unfinalized, with industry trackers reporting a final rule is not expected before 2027 |
| U.S. Treasury | United States (federal; convenes FSOC and the financial-sector critical-infrastructure partnership; parent of the OCC and FinCEN) | Voluntary framework | Financial Services AI Risk Management Framework (FS AI RMF) and AI Lexicon — voluntary, NIST-aligned resources released Feb 19, 2026 | June 2026: FSOC and Treasury's AI Transformation Office concluded the four-roundtable AI Innovation Series (Mar–May 2026); participants asked for regulatory clarity and harmonization to scale AI adoption |
| White House | United States (federal executive branch; directs executive departments and agencies, not banks) | Non-binding standards | EO 14365, 'Ensuring a National Policy Framework for Artificial Intelligence' (signed December 11, 2025; 90 FR 58499), with EO 14179 (90 FR 8741) and America's AI Action Plan (July 23, 2025) | On September 29, 2026 the President signed EO 14434, 'Inaugurating the Era of Super Intelligence' (91 FR 63129), directing executive-branch agencies to use the terms 'Super Intelligence' and 'SI' in place of 'Artificial Intelligence' and 'AI' in official correspondence, websites, reports and other non-statutory documents, with 'SI' defined by reference to the existing statutory definition of AI (15 U.S.C. 9401(3)); the Assistant to the President for Science and Technology must submit proposed legislative language for a Federal definition within 60 days |
| FINRA | United States (all registered broker-dealer member firms; relevant to banks through bank-affiliated broker-dealers and securities subsidiaries) | Supervisory guidance | Regulatory Notice 24-09, 'FINRA Reminds Members of Regulatory Obligations When Using Generative Artificial Intelligence and Large Language Models' (June 27, 2024), and the GenAI section of the 2026 FINRA Annual Regulatory Oversight Report (December 9, 2025) | On July 9, 2026 FINRA published Regulatory Notice 26-14 proposing to modernize Rule 2210 (Communications with the Public), citing advances in generative AI and replacing the prescriptive principal pre-use approval of retail communications with risk-based supervision standards; comments were due September 11, 2026 |
| NY DFS | New York State (state-chartered banks, foreign bank branches and agencies, insurers, money transmitters, virtual-currency licensees, and other DFS-licensed entities) | Supervisory guidance | 23 NYCRR Part 500 (Second Amendment effective Nov 1, 2023; fully phased in Nov 1, 2025) as applied to AI by the Oct 16, 2024 Industry Letter | Sep 21, 2026: Governor Hochul announces RAISE Act implementation next steps — frontier AI developer registration opens November 2026, full compliance from January 2027, and Marc Gilman named Deputy Director of DFS's new DIGIT office |
| NYC DCWP | New York City, United States (employers and employment agencies using automated employment decision tools to screen candidates for employment or employees for promotion within the city) | Binding law | Local Law 144 of 2021 (NYC Administrative Code §§ 20-870 to 20-874) and DCWP's final rule (6 RCNY §§ 5-300 to 5-304); enforcement began July 5, 2023 | The New York State Comptroller issued Report 2024-N-6 on December 2, 2025, finding DCWP's system for enforcing Local Law 144 ineffective and recommending enforcement that does not rely only on complaints |
| Colorado AI Act | Colorado, United States (any developer or deployer doing business in Colorado) | Binding law | SB 26-189, the Automated Decision-Making Technology Act (signed May 14, 2026; effective Jan 1, 2027) | Colorado AG published proposed ADMT and Conversational AI Service rules on Aug 11, 2026; comments and hearing close Oct 26, 2026 |
| California CPPA | California, United States (any business meeting CCPA thresholds that handles Californians' personal information; employers with five or more California employees) | Binding law | CPPA regulations on cybersecurity audits, risk assessments and automated decisionmaking technology (11 CCR §§ 7001, 7120–7124, 7150–7157, 7200–7222; approved Sep 22, 2025, effective Jan 1, 2026; ADMT obligations from Jan 1, 2027) | Governor Newsom signed AB 1609 (customer-service chatbot disclosure and human hand-off, businesses over $500M revenue) on September 28, 2026 (Chapter 733) and SB 947 (the 'No Robo Bosses Act' — bars sole reliance on automated decision systems for employee discipline or termination) on September 30, 2026 (Chapter 859); AB 1018 did not pass the Legislature. ADMT obligations for significant decisions apply from Jan 1, 2027 |
| Texas AG | Texas, United States (any person who promotes, advertises or conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an AI system in Texas) | Binding law | Texas Responsible Artificial Intelligence Governance Act (HB 149, 89th Legislature; Business & Commerce Code Title 11, Subtitle D, Chapters 551–554; signed June 22, 2025, effective January 1, 2026) | September 1, 2026 was the statutory deadline (HB 149, Section 8) for the Attorney General to post the information and online complaint mechanism required by Section 552.102; the Attorney General's consumer-protection site now carries a TRAIGA overview and an online AI complaint form. As of October 5, 2026 this review found no published enforcement action under the Act |
| Utah Division of Consumer Protection | Utah, United States (suppliers in consumer transactions with Utah consumers, and occupations licensed by the Department of Commerce) | Binding law | Utah Artificial Intelligence Policy Act (SB 149, 2024; Title 13, Chapter 72) and the generative-AI consumer-disclosure chapter (SB 226, 2025; Title 13, Chapter 77, effective May 7, 2025) | HB 320 (2026 General Session), signed March 18, 2026 and effective May 6, 2026, amended the Office of Artificial Intelligence Policy's learning-laboratory provisions to add joint interpretation agreements, regular audits of participants and up to two extensions of a demonstration period; the HB 286 frontier-model transparency bill was filed without passing on March 6, 2026 |
| Illinois IDHR | Illinois, United States (employers with one or more employees in Illinois for 20 or more calendar weeks in a year, or any employer for disability, pregnancy and sexual-harassment claims; employers that ask applicants for Illinois-based positions to record video interviews) | Binding law | Illinois Human Rights Act amendments on artificial intelligence in employment (HB 3773, Public Act 103-0804; 775 ILCS 5/2-101(M), (N) and 2-102(L); approved August 9, 2024, effective January 1, 2026) | The Department of Human Rights published proposed amendments to its procedural rules (56 Ill. Adm. Code 2520) implementing HB 3773 in the Illinois Register on May 15, 2026 (Volume 50, Issue 20, page 6794) and noticed a public hearing for June 10, 2026; the codified text reviewed on October 5, 2026 contains no AI rules |
| Massachusetts AG | Massachusetts, United States (any business that markets, sells or lends to Massachusetts residents, wherever it is based) | Binding law | Attorney General Advisory on the Application of the Commonwealth's Consumer Protection, Civil Rights, and Data Privacy Laws to Artificial Intelligence (April 16, 2024), and the Earnest Operations LLC Assurance of Discontinuance ($2.5 million; announced July 10, 2025) | July 10, 2025: Attorney General Andrea Joy Campbell announced a $2.5 million settlement with Earnest Operations LLC over AI underwriting models, with mandated AI governance, annual fair-lending testing and reporting to the Attorney General |
| New Jersey DCR | New Jersey, United States (employers, housing providers, places of public accommodation, credit providers, contractors and other entities covered by the Law Against Discrimination) | Binding law | Guidance on Algorithmic Discrimination and the New Jersey Law Against Discrimination (January 2025; announced January 9, 2025), and the Division's disparate-impact rules, N.J.A.C. 13:16 (adopted November 5, 2025; effective December 15, 2025) | December 15, 2025: the Division's disparate-impact rules (N.J.A.C. 13:16) took effect, following adoption on November 5, 2025; they build on the January 2025 algorithmic-discrimination guidance |
| NIST | United States (voluntary, used globally) | Voluntary framework | AI Risk Management Framework 1.0 (Jan 2023) + Generative AI Profile (Jul 2024) | Growing role as the default governance scaffold after the 2026 US model-risk revision excluded generative AI |
Which international bodies set AI rules for banks?
| Authority | Jurisdiction | Force | Key document | Latest move |
|---|---|---|---|---|
| EU AI Act | European Union | Binding law | Regulation (EU) 2024/1689 (in force Aug 1, 2024), as amended by the Digital Omnibus on AI (EU) 2026/1744 | Regulation (EU) 2026/1744 (Digital Omnibus on AI) entered into force July 27, 2026, deferring Annex III high-risk obligations — including credit scoring — from Aug 2, 2026 to Dec 2, 2027 |
| ECB | Euro area (significant institutions) | Supervisory guidance | SSM supervisory priorities 2026–28 (AI under the operational-resilience priority) | 7 July 2026 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301): every significant institution must file an action plan with its JST by 31 October 2026 |
| EBA | European Union | Supervisory guidance | Factsheet on the AI Act's implications for banking and payments (Nov 2025) | Jul 31, 2026: joint ESA statement (JC 2026 25) on ICT risks from frontier AI models — banks told to adjust DORA ICT-risk controls around prevention, detection and management without delay |
| ESMA | European Union (investment firms and credit institutions providing investment services under MiFID II; markets and investor-protection supervisory convergence) | Supervisory guidance | ESMA Public Statement on the use of Artificial Intelligence in the provision of retail investment services (30 May 2024, ESMA35-335435667-5924) | 23 September 2026: ESMA announced a new Union Strategic Supervisory Priority on digital innovation from 2027, with an initial focus on how supervised entities use AI and tokenisation |
| EIOPA | European Union | Supervisory guidance | Opinion on AI governance and risk management (EIOPA-BoS-25-360, 6 August 2025) | 6 August 2025 — EIOPA published its Opinion on AI governance and risk management (EIOPA-BoS-25-360) for national insurance supervisors; on 31 July 2026 EIOPA joined the EBA and ESMA in the ESAs' joint statement on ICT risks from frontier AI models (JC 2026 25). |
| UK (BoE / PRA / FCA) | United Kingdom | Supervisory guidance | BoE/PRA response to the Treasury Select Committee on AI (Apr 2026) | September 30, 2026: Governor Bailey's 'Frontier AI and the Question of Governance' Bank Insights article says 'regulation is not, in my view, the right place to start' and ties frontier AI directly to financial stability through cyber risk and agentic trading and payments; September 2, 2026: FCA multi-firm review on frontier AI and cyber resilience (no new rules); 2026 AI survey (foundation and agentic AI) closed 31 July, results pending |
| BaFin | Germany (banks, insurers and other financial entities supervised by BaFin or, for significant banks, the ECB) | Supervisory guidance | Guidance on ICT Risks in the Use of AI at Financial Entities (18 December 2025; English translation published 30 January 2026), alongside the 2021 BDAI principles paper and the 2022 ML risk-models results paper | 29 July 2026: BaFin published its page on market surveillance of AI systems, stating that it monitors Article 5 prohibited practices, Article 50 transparency obligations and Article 4 AI literacy now, and high-risk AI systems from 2 December 2027 (including creditworthiness assessment of natural persons) |
| ACPR | France (banks, insurers and other supervised financial entities; significant banks are supervised jointly with the ECB) | Supervisory guidance | ACPR discussion document 'Governance of Artificial Intelligence in Finance' (June 2020) | 1 July 2026: the ACPR launched a public consultation on algorithmic fairness in the financial sector (open until 30 September 2026) and held a market meeting on AI regulation and supervision |
| DNB / AFM | Netherlands (DNB: prudential supervision of banks, insurers and pension funds; AFM: conduct and market supervision; DNB also acts within the ECB's Single Supervisory Mechanism for significant banks) | Supervisory guidance | AFM and DNB, 'The impact of AI on the financial sector and supervision' (9 April 2024), building on DNB's 'General principles for the use of Artificial Intelligence in the financial sector' (25 July 2019) | 19 January 2026: the AFM announced in its Agenda 2026 that it will intensify supervision of the responsible use of AI and of DORA compliance; April 2026: AFM report on AI in the Dutch asset management sector |
| FINMA | Switzerland (banks, securities firms, insurers, fund managers, managers of collective assets, financial market infrastructures and other supervised institutions) | Supervisory guidance | FINMA Guidance 08/2024: Governance and risk management when using artificial intelligence (18 December 2024) | 24 April 2025: FINMA published a survey of around 400 Swiss financial institutions showing about half use AI or have initial applications in development, following its Guidance 08/2024 of 18 December 2024 |
| OSFI | Canada (federally regulated financial institutions: banks, foreign bank branches, insurers, and trust and loan companies) | Supervisory guidance | Guideline E-23 – Model Risk Management (2027): published 11 September 2025, effective 1 May 2027; names AI/ML in the model definition and sets 3 outcomes and 12 principles | In July 2026 OSFI issued a Technology Risk Bulletin on generative and agentic AI (implications for technology, cyber security and operational resilience), following its April 2026 bulletin on frontier AI and the March 23, 2026 FIFAI II report; Guideline E-23 takes effect 1 May 2027 |
| MAS | Singapore (central bank, integrated financial regulator and supervisor of banks, insurers, capital markets firms and payment providers) | Supervisory guidance | Consultation Paper P017-2025 on proposed Guidelines on Artificial Intelligence Risk Management (13 November 2025; comment period closed 31 January 2026; final not yet issued) | 28 July 2026: MAS and the Association of Banks in Singapore established the AI-Driven Cyber and Technology Risk Taskforce (ACT) to strengthen resilience against AI-driven cyber threats; on 5 August 2026 a written Parliamentary reply said the AI Risk Management Guidelines would be finalised soon. |
| HKMA | Hong Kong SAR (all Authorized Institutions: licensed banks, restricted licence banks and deposit-taking companies) | Supervisory guidance | Circular "High-level Principles on Artificial Intelligence" (1 November 2019), extended to generative AI by the circular "Consumer Protection in respect of Use of Generative Artificial Intelligence" (19 August 2024) | On 27 August 2026 the HKMA, SFC, Insurance Authority and MPFA announced the first cohort of the GenA.I. Sandbox++: 36 use cases from nearly 100 proposals, 30 financial institutions and 27 technology partners, focused on agentic AI; on 22 June 2026 the HKMA circulated a report on AI in fighting financial crime, and on 2 June 2026 a circular on cyber resilience against AI-empowered threats |
| Hong Kong SFC | Hong Kong SAR (regulator of licensed corporations, asset managers and SFC-licensed virtual asset trading platforms; banks are supervised by the HKMA) | Supervisory guidance | SFC Circular 24EC55, 'Use of generative AI language models' (12 November 2024) | 2 June 2026: SFC Circular 26EC32 on enhanced cybersecurity measures against AI-enabled cyberattacks, addressed to licensed corporations, SFC-licensed VATPs and associated entities. |
| Japan FSA | Japan (supervisor of banks, securities firms and insurers) | Supervisory guidance | AI Discussion Paper (Version 1.1), 3 March 2026, updating Version 1.0 of 4 March 2025 | 22 May 2026: the FSA and the Bank of Japan jointly requested financial institutions to implement nine short-term responses to frontier AI cyber threats, expected over roughly one month. |
| APRA / ASIC | Australia (APRA: authorised deposit-taking institutions, insurers and superannuation trustees; ASIC: financial services and credit licensees) | Supervisory guidance | APRA Letter to Industry on Artificial Intelligence (AI), 30 April 2026, with the binding standards CPS 230 (Operational Risk Management) and CPS 234 (Information Security) and ASIC Report 798 (29 October 2024) | On 27 August 2026 APRA and ASIC urged financial entities to move from awareness of frontier AI risks to decisive action after nine roundtables in June and July 2026; on 30 April 2026 APRA's AI letter called for a step-change in AI risk management and the amended CPS 230 took effect on 1 July 2026 |
| RBI | India (commercial banks including foreign banks, small finance banks, payments banks, local area banks, regional rural banks, co-operative banks, all-India financial institutions, NBFCs, asset reconstruction companies and credit information companies) | Voluntary framework | FREE-AI Committee report "Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI) in the Financial Sector" (13 August 2025), and the draft Guidance on Regulatory Principles for Model Risk Management, 2026 (24 June 2026) | On 24 June 2026 the RBI released the draft Guidance on Regulatory Principles for Model Risk Management, 2026, covering AI/ML and third-party models, with comments invited until 24 July 2026; no final version had been published on the RBI website as of 5 October 2026 |
| FSB | Global (G20) | Non-binding standards | The Financial Stability Implications of Artificial Intelligence (Nov 2024) | 31 August 2026: FSB Chair's letter to G20 finance ministers and central bank governors warns that frontier AI models' autonomy and threat capabilities make cyber risk the most immediate financial-stability concern; final AI sound-practices report still expected October 2026 |
| Basel Committee | Global (28 jurisdictions) | Non-binding standards | Digitalisation of finance report (May 2024) | Oct 1, 2026: following its 28–29 September meeting, the Committee agreed to review the operational risk framework's 'event type' loss categories with a focus on cyber risk and AI developments, its first step toward amending an existing hard standard because of AI; June 2026 ICT risk-management report |
| IOSCO | Global (international standard-setter for securities regulators; members include the SEC, ESMA, the FCA and other national securities regulators) | Non-binding standards | FR/02/2026, 'Supervisory Toolkit for AI Use in Capital Markets' (Final Report, May 25, 2026), building on FR06/2021 (September 2021) and CR/01/2025 (March 2025) | On May 25, 2026 IOSCO published its final Supervisory Toolkit for AI Use in Capital Markets (FR/02/2026) with a standalone extract (OR/07/2026) for use in examinations and inspections; feedback from stakeholders was invited by June 26, 2026, and the next phase is a review of emerging industry practices |
The EU deferred its high-risk AI deadline. The high-risk regime — including credit scoring — was due August 2, 2026; the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force July 27, 2026) moved it to December 2, 2027. The obligations (risk management, data governance, human oversight, logging; fines up to €15M or 3% of global turnover) are unchanged. Details →
The CFPB narrowed fair-lending exposure for AI models. Its April 2026 Regulation B rule (effective July 21, 2026) says ECOA does not authorize disparate-impact liability — while the duty to give specific adverse-action reasons is untouched, and its 2022/2023 AI circulars were withdrawn in May 2025. Details →
The US retired SR 11-7. On April 17, 2026 the OCC, Federal Reserve, and FDIC replaced the 2011 model risk management framework — and explicitly excluded generative and agentic AI from its scope, leaving those to banks' broader governance programs. Details →
The FSB moved toward firm-level expectations. Its June 2026 consultation proposes 12 sound practices for responsible AI adoption — including for agentic AI — with the final report due later in 2026. Details →
| Date | Authority | Development |
|---|---|---|
| Aug 2, 2028 | EU AI Act | Deferred deadline for high-risk AI embedded in regulated products. Article 6(1) / Annex I high-risk systems tied to EU product-safety legislation now apply from this date (moved from August 2, 2027 by the Digital Omnibus on AI). |
| Dec 2, 2027 | EU AI Act | High-risk AI obligations for stand-alone Annex III systems become applicable. Deferred from August 2, 2026 by the Digital Omnibus on AI. Annex III high-risk systems — including credit scoring of natural persons — must comply with risk management, data governance, documentation, logging, human oversight, accuracy, and post-market monitoring requirements. Fines up to €15M / 3% of turnover. |
| Dec 2, 2027 | BaFin | BaFin begins monitoring high-risk AI system requirements. BaFin states that from 2 December 2027 it will also monitor compliance with the requirements for high-risk AI systems, which under Annex III(5)(b) and (c) of the AI Act include systems evaluating the creditworthiness or credit score of natural persons (except fraud detection) and risk assessment and pricing for life and health insurance. |
| Aug 2, 2027 | EU AI Act | Deadline for general-purpose AI models placed on the market before August 2025. Providers of general-purpose AI models placed on the market before 2 August 2025 must comply with the AI Act's GPAI obligations by this date. |
| Jul 10, 2027 | EBA | EU Anti-Money Laundering Regulation applies. Regulation (EU) 2024/1624 (AMLR) applies from 10 July 2027, setting the customer due diligence rules that remote and AI-assisted onboarding under EBA/GL/2022/15 must meet. |
| Jul 1, 2027 | Utah Division of Consumer Protection | Scheduled repeal of the Artificial Intelligence Policy Act (Title 13, Chapter 72). Section 63I-2-213 provides that Title 13, Chapter 72, Artificial Intelligence Policy Act, is repealed July 1, 2027, the date SB 332 (2025) substituted for May 1, 2025. The listed repeal does not name Chapter 77, the generative-AI disclosure chapter. |
| Jan 1, 2027 | NY DFS | RAISE Act takes effect. The New York RAISE Act, as amended by the 2026 chapter amendment, takes effect; large frontier developers' disclosure obligations apply from this date. |
| Dec 2, 2026 | EU AI Act | Article 50(2) marking transition ends. The Digital Omnibus transition period for Article 50(2) machine-readable marking of AI-generated content ends; the rest of Article 50 has applied since 2 August 2026. |
| Dec 1, 2026 | Colorado AI Act | Regulation 10-1-1: annual life insurer reports and non-use attestations due. Life insurers file their annual SB 21-169 governance report, and insurers that do not use external consumer data or algorithms file attestations, under the Division of Insurance's amended regulation. |
| Nov 2026 | NY DFS | RAISE Act: DFS begins directing large frontier developers to register. DFS said on 21 September 2026 that its Office of Digital Innovation, Governance, Integrity and Trust (DIGIT) will begin directing large frontier AI developers to register starting November 2026. |
| Oct 31, 2026 | ECB | Deadline for significant institutions to submit AI-cyber action plans to their JSTs. Under the ECB's 7 July 2026 letter on AI-enabled cybersecurity threats (SSM-2026-0301), each significant institution must deliver a comprehensive action plan — measures, resources, owners, timelines — to its Joint Supervisory Team by 31 October 2026. The ECB will run a horizontal analysis of the plans and share conclusions with banks. |
| Oct 1, 2026 | Basel Committee | Committee agrees to review operational-risk loss categories for AI and cyber risk. Meeting in Indonesia on 28–29 September 2026, the Committee said AI developments 'have continued to evolve at a remarkable speed' since its May meeting and that frontier AI's integration into critical financial functions 'will require careful governance, robust risk management and ongoing supervisory attention.' It agreed to review the sufficiency and adequacy of the operational risk framework's existing 'event type' loss categories, with a focus on cyber risk and AI developments — the Committee's first concrete step toward amending an existing hard standard because of AI, short of a new standard itself. |
Who regulates AI in banking?
No single body does. Banks face a layered system: binding law where it exists (the EU AI Act, US consumer statutes like ECOA), prudential supervisors applying existing frameworks to AI (Federal Reserve, OCC, ECB, UK PRA/FCA), and global standard-setters shaping the agenda (FSB, Basel Committee). Voluntary frameworks like the NIST AI RMF fill the gaps supervisors leave open.
Is there a dedicated AI law for banks?
At the federal level, only in the EU: the EU AI Act is the sole binding, cross-sector AI law that reaches banks, and its high-risk regime covering credit scoring applies from December 2, 2027 after the 2026 Digital Omnibus deferral. In the US there is no federal AI statute for banks — but two states bind them: Colorado's Automated Decision-Making Technology Act (effective January 1, 2027) reaches lenders with no bank exemption, and California's CPPA regulations on automated decisionmaking technology (obligations from January 1, 2027) list lending as a significant decision, though GLBA-covered data is exempt. The UK has deliberately chosen to regulate bank AI through existing law and supervision.
What changed for bank AI regulation in 2026?
Four big moves: the US agencies replaced the 15-year-old SR 11-7 model risk framework with revised guidance that excludes generative and agentic AI (Apr 17); the CFPB's Regulation B rule eliminated disparate-impact liability under ECOA (effective Jul 21); the EU's Digital Omnibus deferred the AI Act's high-risk regime, including credit scoring, to December 2, 2027; and the FSB consulted on 12 sound practices for responsible AI adoption, with the final report due later in 2026.
Regulators move daily. So do we.
when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning