No single regulator owns AI in banking. Banks answer to a layered system: binding AI law where it exists (the EU AI Act, whose high-risk regime — including credit scoring — now applies from December 2, 2027 after the 2026 Digital Omnibus deferral, Colorado's ADMT Act from January 1, 2027, and California's ADMT regulations from the same day), prudential supervisors applying existing frameworks to AI (the Federal Reserve, OCC, FDIC, NCUA, ECB, and UK PRA/FCA), consumer-protection, market and financial-crime authorities that regulate outcomes regardless of how a decision was made (CFPB, SEC, CFTC, FinCEN, NY DFS), and global standard-setters shaping what supervisors expect next (FSB, Basel Committee). This page tracks all 19 of them and every document they have published.
Which AI consultations are open for comment?
- CFTC Compute Derivatives RFC — Request for Comment on the Listing of Compute Derivatives Contracts · closes Oct 20, 2026
- Colorado AG proposed ADMT rules — Proposed Automated Decision-Making Technology and Conversational AI Service Rules (Notice of Rulemaking Hearing) · closes Oct 26, 2026
What are the next AI regulation deadlines for banks?
| Date | Authority | Deadline |
|---|---|---|
| Oct 20, 2026 | CFTC | CFTC Compute Derivatives RFC: comment period closes · Comment deadline |
| Oct 26, 2026 | Colorado AI Act | Colorado AG proposed ADMT rules: comment period closes · Comment deadline |
| Oct 31, 2026 | ECB | Deadline for significant institutions to submit AI-cyber action plans to their JSTs · Milestone |
| Nov 20, 2026 | EU AI Act | Consumer Credit Directive (EU) 2023/2225 takes effect · Takes effect |
| Jan 1, 2027 | Colorado AI Act | SB 26-189 takes effect · Takes effect |
| Jan 1, 2027 | Colorado AI Act | HB 26-1263 takes effect · Takes effect |
Which US authorities regulate AI in banking?
| Authority | Jurisdiction | Force | Key document | Latest move |
|---|---|---|---|---|
| Federal Reserve | United States (state member banks, bank holding companies, large financial institutions) | Supervisory guidance | SR 26-2 — Revised interagency Model Risk Management guidance (Apr 2026, supersedes SR 11-7) | Apr 2026 revised model risk guidance; May 2026 Vice Chair speech on AI in the financial system |
| OCC | United States (national banks and federal savings associations) | Supervisory guidance | OCC Bulletin 2026-13 — Revised interagency Model Risk Management guidance (Apr 2026) | Apr 2026 revised model risk guidance excluding generative/agentic AI; May 2026 risk report on AI-enabled fraud |
| FDIC | United States (state-chartered banks that are not Federal Reserve members; deposit insurer for all insured banks) | Supervisory guidance | FIL-15-2026 — Agencies Revise the Interagency Model Risk Management Guidance (Apr 17, 2026) | Apr 2026 adoption of revised interagency model risk guidance (FIL-15-2026); Jun 2026 testimony describing it as 'an avenue for the safe and sound adoption of technology' |
| NCUA | United States (federally insured credit unions) | Supervisory guidance | Credit Union Artificial Intelligence Resource Center (Aug 2025, updated Apr 2026) — the NCUA's only AI-specific publication for credit unions | Feb 2026 Senate testimony frames 'space to innovate responsibly' with AI as a 2026-2030 strategic-plan goal; Apr 2026 refresh of the AI resource page; no AI mention in the Jan 2026 supervisory priorities |
| CFPB | United States (consumer financial products) | Binding law | Regulation B §1002.9 adverse-action requirements (ECOA); April 2026 Reg B final rule | April 2026 Regulation B final rule (effective July 21, 2026) eliminates disparate-impact liability under ECOA — the fair-lending theory most often applied to AI models — while the statutory duty to give specific, accurate adverse-action reasons remains untouched. |
| SEC | United States (broker-dealers, investment advisers, funds, and public companies — including bank holding companies and bank-affiliated securities arms) | Supervisory guidance | Division of Examinations FY2026 Examination Priorities (Nov 17, 2025) — the operative statement of what SEC examiners test on AI | Chairman Atkins told the FSOC AI roundtable on March 4, 2026 that AI disclosure will be governed by materiality, not new line items, and that AI-washing enforcement continues |
| CFTC | United States (futures, options, and swaps markets; bank swap dealers, FCMs, exchanges, and clearinghouses) | Supervisory guidance | CFTC Staff Advisory on the Use of AI in CFTC-Regulated Markets (CFTC Letter No. 24-17, Dec 2024) | Aug 19, 2026 request for comment on listing compute derivatives; Aug 20, 2026 inaugural Innovation Advisory Committee meeting with an 'agentic finance' session |
| FinCEN | United States (Bank Secrecy Act administrator for all US financial institutions) | Binding law | AML/CFT Program proposed rule (Apr 2026) — names effective use of AI as a factor in FinCEN enforcement decisions; supersedes the withdrawn July 2024 proposal | Jul 24, 2026 alert FIN-2026-Alert004 on AI-generated synthetic identities and chatbot-completed coursework in federal student aid fraud; Apr 2026 AML/CFT program NPRM comment period closed Jun 9, 2026 |
| U.S. Treasury | United States (federal; convenes FSOC and the financial-sector critical-infrastructure partnership; parent of the OCC and FinCEN) | Voluntary framework | Financial Services AI Risk Management Framework (FS AI RMF) and AI Lexicon — voluntary, NIST-aligned resources released Feb 19, 2026 | June 2026: FSOC and Treasury's AI Transformation Office concluded the four-roundtable AI Innovation Series (Mar–May 2026); participants asked for regulatory clarity and harmonization to scale AI adoption |
| NY DFS | New York State (state-chartered banks, foreign bank branches and agencies, insurers, money transmitters, virtual-currency licensees, and other DFS-licensed entities) | Supervisory guidance | 23 NYCRR Part 500 (Second Amendment effective Nov 1, 2023; fully phased in Nov 1, 2025) as applied to AI by the Oct 16, 2024 Industry Letter | May 21, 2026: two Industry Letters on frontier AI model cyber risk and measures to take in a heightened threat environment |
| Colorado AI Act | Colorado, United States (any developer or deployer doing business in Colorado) | Binding law | SB 26-189, the Automated Decision-Making Technology Act (signed May 14, 2026; effective Jan 1, 2027) | Colorado AG published proposed ADMT and Conversational AI Service rules on Aug 11, 2026; comments and hearing close Oct 26, 2026 |
| California CPPA | California, United States (any business meeting CCPA thresholds that handles Californians' personal information; employers with five or more California employees) | Binding law | CPPA regulations on cybersecurity audits, risk assessments and automated decisionmaking technology (11 CCR §§ 7001, 7120–7124, 7150–7157, 7200–7222; approved Sep 22, 2025, effective Jan 1, 2026; ADMT obligations from Jan 1, 2027) | Legislature adjourned Aug 31, 2026 with AB 1609 (customer-service chatbots at businesses over $500M revenue) and SB 947 (workplace automated decision systems) on the Governor's desk until Sep 30; AB 1018 did not pass. ADMT obligations for significant decisions apply from Jan 1, 2027 |
| NIST | United States (voluntary, used globally) | Voluntary framework | AI Risk Management Framework 1.0 (Jan 2023) + Generative AI Profile (Jul 2024) | Growing role as the default governance scaffold after the 2026 US model-risk revision excluded generative AI |
Which international bodies set AI rules for banks?
| Authority | Jurisdiction | Force | Key document | Latest move |
|---|---|---|---|---|
| EU AI Act | European Union | Binding law | Regulation (EU) 2024/1689 (in force Aug 1, 2024), as amended by the Digital Omnibus on AI (EU) 2026/1744 | Regulation (EU) 2026/1744 (Digital Omnibus on AI) entered into force July 27, 2026, deferring Annex III high-risk obligations — including credit scoring — from Aug 2, 2026 to Dec 2, 2027 |
| ECB | Euro area (significant institutions) | Supervisory guidance | SSM supervisory priorities 2026–28 (AI under the operational-resilience priority) | 7 July 2026 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301): every significant institution must file an action plan with its JST by 31 October 2026 |
| EBA | European Union | Supervisory guidance | Factsheet on the AI Act's implications for banking and payments (Nov 2025) | Jul 31, 2026: joint ESA statement (JC 2026 25) on ICT risks from frontier AI models — banks told to adjust DORA ICT-risk controls around prevention, detection and management without delay |
| UK (BoE / PRA / FCA) | United Kingdom | Supervisory guidance | BoE/PRA response to the Treasury Select Committee on AI (Apr 2026) | May 2026: BoE/FCA/HM Treasury joint statement on frontier AI and cyber resilience; July 2026: HM Treasury Financial Services AI Adoption Plan; 2026 AI survey (foundation and agentic AI) closed 31 July, results pending |
| FSB | Global (G20) | Non-binding standards | The Financial Stability Implications of Artificial Intelligence (Nov 2024) | 31 August 2026: FSB Chair's letter to G20 finance ministers and central bank governors warns that frontier AI models' autonomy and threat capabilities make cyber risk the most immediate financial-stability concern; final AI sound-practices report still expected October 2026 |
| Basel Committee | Global (28 jurisdictions) | Non-binding standards | Digitalisation of finance report (May 2024) | June 2026 ICT risk-management report; AI monitoring continues in the 2025–26 work programme |
The EU deferred its high-risk AI deadline. The high-risk regime — including credit scoring — was due August 2, 2026; the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force July 27, 2026) moved it to December 2, 2027. The obligations (risk management, data governance, human oversight, logging; fines up to €15M or 3% of global turnover) are unchanged. Details →
The CFPB narrowed fair-lending exposure for AI models. Its April 2026 Regulation B rule (effective July 21, 2026) says ECOA does not authorize disparate-impact liability — while the duty to give specific adverse-action reasons is untouched, and its 2022/2023 AI circulars were withdrawn in May 2025. Details →
The US retired SR 11-7. On April 17, 2026 the OCC, Federal Reserve, and FDIC replaced the 2011 model risk management framework — and explicitly excluded generative and agentic AI from its scope, leaving those to banks' broader governance programs. Details →
The FSB moved toward firm-level expectations. Its June 2026 consultation proposes 12 sound practices for responsible AI adoption — including for agentic AI — with the final report due later in 2026. Details →
| Date | Authority | Development |
|---|---|---|
| Aug 2, 2028 | EU AI Act | Deferred deadline for high-risk AI embedded in regulated products. Article 6(1) / Annex I high-risk systems tied to EU product-safety legislation now apply from this date (moved from August 2, 2027 by the Digital Omnibus on AI). |
| Dec 2, 2027 | EU AI Act | High-risk AI obligations for stand-alone Annex III systems become applicable. Deferred from August 2, 2026 by the Digital Omnibus on AI. Annex III high-risk systems — including credit scoring of natural persons — must comply with risk management, data governance, documentation, logging, human oversight, accuracy, and post-market monitoring requirements. Fines up to €15M / 3% of turnover. |
| Oct 31, 2026 | ECB | Deadline for significant institutions to submit AI-cyber action plans to their JSTs. Under the ECB's 7 July 2026 letter on AI-enabled cybersecurity threats (SSM-2026-0301), each significant institution must deliver a comprehensive action plan — measures, resources, owners, timelines — to its Joint Supervisory Team by 31 October 2026. The ECB will run a horizontal analysis of the plans and share conclusions with banks. |
| Aug 31, 2026 | California CPPA | Legislature adjourns: AB 1018 not passed; chatbot and workplace-ADS bills go to the Governor. The Automated Decisions Safety Act (AB 1018), which would have required pre-deployment bias evaluations of automated decision systems used for consequential decisions including lending, was not among the AI bills sent to the Governor. AB 1609 (customer-service chatbot disclosure and 15-minute human hand-off at businesses over $500 million in revenue) and SB 947 (worker protections for automated decision systems) were; the Governor has until September 30, 2026 to act. |
| Aug 31, 2026 | FSB | FSB Chair's letter to G20 (Aug 2026) — FSB Chair's letter to G20 Finance Ministers and Central Bank Governors: August 2026 — risks arising from frontier artificial intelligence models. On 31 August 2026, ahead of the G20 Finance Ministers and Central Bank Governors meeting, FSB Chair Andrew Bailey wrote that frontier AI models now show 'increasingly sophisticated autonomy and problem-solving abilities, as well as threat capabilities', and that their most immediate financial-stability impact is on cyber risk. |
| Aug 20, 2026 | CFTC | Inaugural Innovation Advisory Committee meeting: 'Preparing for Intelligent Markets'. Session II of the first IAC meeting covered AI in trading, compliance, surveillance and risk management, 'the rise of agentic finance' (autonomous agents executing transactions and managing portfolios), how existing regulatory principles apply to AI-enabled market participants, and whether additional guidance is warranted. Written public comments were accepted through August 27, 2026. |
| Aug 19, 2026 | CFTC | CFTC Compute Derivatives RFC — Request for Comment on the Listing of Compute Derivatives Contracts. On August 19, 2026 the CFTC issued a request for comment on derivatives markets in compute — the GPU and data-center capacity that powers AI — published in the Federal Register on August 21, 2026 (91 FR 54259) with a 60-day comment period. |
| Aug 11, 2026 | Colorado AI Act | Colorado AG proposed ADMT rules — Proposed Automated Decision-Making Technology and Conversational AI Service Rules (Notice of Rulemaking Hearing). On August 11, 2026 the Colorado Department of Law filed proposed rules implementing the ADMT Act (SB 26-189) and the Chatbot Safety Act (HB 26-1263). |
| Aug 6, 2026 | FSB | Responses to FSB AI sound practices consultation (Aug 2026) — Public responses to consultation on Sound Practices for Responsible Adoption of Artificial Intelligence (AI). On 6 August 2026 the FSB published the 159 public responses received by the 22 July 2026 deadline on its AI sound practices consultation. |
| Aug 5, 2026 | UK (BoE / PRA / FCA) | AI Consortium June 2026 minutes published. Minutes of the 3 June 2026 meeting cover frontier models, safe deployment of agentic tools, model harnesses and execution boundaries, AI incident reporting, and stress scenarios including agentic payments. |
| Aug 2, 2026 | EU AI Act | Article 50 transparency obligations apply; Annex III high-risk start deferred. Transparency duties (e.g., telling customers they are interacting with an AI system, marking AI-generated content) apply from this date as originally scheduled. The Annex III high-risk regime — including credit scoring — did NOT start on this date: Regulation (EU) 2026/1744 (Digital Omnibus on AI, in force July 27, 2026) deferred it to December 2, 2027. |
| Jul 31, 2026 | EBA | ESA Statement on ICT risks from frontier AI models (JC 2026 25) — ESA Statement: Toward a consistent and risk-based approach for ICT risks from frontier AI models. On July 31, 2026 the EBA, EIOPA and ESMA published joint statement JC 2026 25 on ICT risks from frontier AI models, warning that highly capable AI models sharply accelerate vulnerability discovery and exploitation and could create systemic cyber risk. |
Who regulates AI in banking?
No single body does. Banks face a layered system: binding law where it exists (the EU AI Act, US consumer statutes like ECOA), prudential supervisors applying existing frameworks to AI (Federal Reserve, OCC, ECB, UK PRA/FCA), and global standard-setters shaping the agenda (FSB, Basel Committee). Voluntary frameworks like the NIST AI RMF fill the gaps supervisors leave open.
Is there a dedicated AI law for banks?
At the federal level, only in the EU: the EU AI Act is the sole binding, cross-sector AI law that reaches banks, and its high-risk regime covering credit scoring applies from December 2, 2027 after the 2026 Digital Omnibus deferral. In the US there is no federal AI statute for banks — but two states bind them: Colorado's Automated Decision-Making Technology Act (effective January 1, 2027) reaches lenders with no bank exemption, and California's CPPA regulations on automated decisionmaking technology (obligations from January 1, 2027) list lending as a significant decision, though GLBA-covered data is exempt. The UK has deliberately chosen to regulate bank AI through existing law and supervision.
What changed for bank AI regulation in 2026?
Four big moves: the US agencies replaced the 15-year-old SR 11-7 model risk framework with revised guidance that excludes generative and agentic AI (Apr 17); the CFPB's Regulation B rule eliminated disparate-impact liability under ECOA (effective Jul 21); the EU's Digital Omnibus deferred the AI Act's high-risk regime, including credit scoring, to December 2, 2027; and the FSB consulted on 12 sound practices for responsible AI adoption, with the final report due later in 2026.
Regulators move daily. So do we.
the daily brief · six sourced stories · in your inbox by 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning