# Who regulates AI in banking? Every authority, tracked

Source: https://www.bankingnewsai.com/ai-regulation
Last updated: Oct 5, 2026

41 authorities and 237 regulatory documents, each dated, summarised and linked to the official text. Reviewed weekly; documents last updated Oct 5, 2026.

## United States

| Authority | Role | How binding | Latest move | Docs |
| --- | --- | --- | --- | --- |
| [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | Central bank and prudential supervisor | Supervisory guidance | Sep 29, 2026 Vice Chair for Supervision Bowman at the Community Bank Cyber Workshop: AI used by threat actors 'adds complexity to the risk environment' and is becoming 'both a defensive tool and an evolving risk'; Apr 2026 revised model risk guidance | 7 |
| [OCC](https://www.bankingnewsai.com/ai-regulation/occ) | Prudential supervisor | Supervisory guidance | Apr 2026 revised model risk guidance excluding generative/agentic AI; May 2026 risk report on AI-enabled fraud | 8 |
| [FDIC](https://www.bankingnewsai.com/ai-regulation/fdic) | Prudential supervisor and deposit insurer | Supervisory guidance | Apr 2026 adoption of revised interagency model risk guidance (FIL-15-2026); Jun 2026 testimony describing it as 'an avenue for the safe and sound adoption of technology' | 9 |
| [NCUA](https://www.bankingnewsai.com/ai-regulation/ncua) | Prudential supervisor and share insurer for credit unions | Supervisory guidance | Feb 2026 Senate testimony frames 'space to innovate responsibly' with AI as a 2026-2030 strategic-plan goal; Apr 2026 refresh of the AI resource page; no AI mention in the Jan 2026 supervisory priorities | 9 |
| [CFPB](https://www.bankingnewsai.com/ai-regulation/cfpb) | Consumer-protection regulator | Binding law | April 2026 Regulation B final rule (effective July 21, 2026) eliminates disparate-impact liability under ECOA — the fair-lending theory most often applied to AI models — while the statutory duty to give specific, accurate adverse-action reasons remains untouched. | 10 |
| [SEC](https://www.bankingnewsai.com/ai-regulation/sec) | Securities markets regulator and public-company disclosure authority | Supervisory guidance | Chairman Atkins reaffirmed at the Investor Advisory Committee's September 10, 2026 meeting that AI disclosure remains governed by materiality, not new line items, warning that AI 'cannot always discern fact from fiction, much less materiality from immateriality' | 11 |
| [CFTC](https://www.bankingnewsai.com/ai-regulation/cftc) | Derivatives market regulator | Supervisory guidance | Sep 21, 2026: Innovation Task Force announces the Frontier Forum Series, with its inaugural forum on artificial intelligence and agentic finance set for October 28, 2026 | 8 |
| [FinCEN](https://www.bankingnewsai.com/ai-regulation/fincen) | AML/CFT regulator and financial intelligence unit | Binding law | Sep 3, 2026 alert FIN-2026-Alert005 names AI-supported software platforms as part of the ecosystem enabling digital-asset investment scam centers, and AI-tool adoption as fueling their growth; Oct 1, 2026 alert FIN-2026-Alert007 on the Russia-linked A7 Network lists AI-altered invoices among its red flags; the Apr 2026 AML/CFT program NPRM remains unfinalized, with industry trackers reporting a final rule is not expected before 2027 | 9 |
| [U.S. Treasury](https://www.bankingnewsai.com/ai-regulation/treasury) | Policy lead, sector risk-management agency, and FSOC chair | Voluntary framework | June 2026: FSOC and Treasury's AI Transformation Office concluded the four-roundtable AI Innovation Series (Mar–May 2026); participants asked for regulatory clarity and harmonization to scale AI adoption | 9 |
| [White House](https://www.bankingnewsai.com/ai-regulation/white-house) | Sets federal AI policy through executive orders and the AI Action Plan; directs agencies but does not supervise banks | Non-binding standards | On September 29, 2026 the President signed EO 14434, 'Inaugurating the Era of Super Intelligence' (91 FR 63129), directing executive-branch agencies to use the terms 'Super Intelligence' and 'SI' in place of 'Artificial Intelligence' and 'AI' in official correspondence, websites, reports and other non-statutory documents, with 'SI' defined by reference to the existing statutory definition of AI (15 U.S.C. 9401(3)); the Assistant to the President for Science and Technology must submit proposed legislative language for a Federal definition within 60 days | 3 |
| [FINRA](https://www.bankingnewsai.com/ai-regulation/finra) | Self-regulatory organization supervising broker-dealers; technology-neutral AI guidance under existing rules | Supervisory guidance | On July 9, 2026 FINRA published Regulatory Notice 26-14 proposing to modernize Rule 2210 (Communications with the Public), citing advances in generative AI and replacing the prescriptive principal pre-use approval of retail communications with risk-based supervision standards; comments were due September 11, 2026 | 2 |
| [NY DFS](https://www.bankingnewsai.com/ai-regulation/ny-dfs) | State prudential, insurance, and cybersecurity regulator | Supervisory guidance | Sep 21, 2026: Governor Hochul announces RAISE Act implementation next steps — frontier AI developer registration opens November 2026, full compliance from January 2027, and Marc Gilman named Deputy Director of DFS's new DIGIT office | 9 |
| [NYC DCWP](https://www.bankingnewsai.com/ai-regulation/new-york-city) | Municipal consumer and worker protection agency enforcing a bias-audit and notice law for AI hiring tools | Binding law | The New York State Comptroller issued Report 2024-N-6 on December 2, 2025, finding DCWP's system for enforcing Local Law 144 ineffective and recommending enforcement that does not rely only on complaints | 1 |
| [Colorado AI Act](https://www.bankingnewsai.com/ai-regulation/colorado-ai-act) | First US state-level AI law reaching lending and financial-services decisions | Binding law | Colorado AG published proposed ADMT and Conversational AI Service rules on Aug 11, 2026; comments and hearing close Oct 26, 2026 | 6 |
| [California CPPA](https://www.bankingnewsai.com/ai-regulation/california) | State privacy-and-civil-rights regime whose automated decisionmaking rules reach lending, deposit and employment decisions — the most-cited state AI rules after Colorado's | Binding law | Governor Newsom signed AB 1609 (customer-service chatbot disclosure and human hand-off, businesses over $500M revenue) on September 28, 2026 (Chapter 733) and SB 947 (the 'No Robo Bosses Act' — bars sole reliance on automated decision systems for employee discipline or termination) on September 30, 2026 (Chapter 859); AB 1018 did not pass the Legislature. ADMT obligations for significant decisions apply from Jan 1, 2027 | 7 |
| [Texas AG](https://www.bankingnewsai.com/ai-regulation/texas) | State attorney general enforcing an intent-based AI statute with prohibited uses, a cure period and a regulatory sandbox, and an express carve-out from its discrimination rule for federally insured financial institutions | Binding law | September 1, 2026 was the statutory deadline (HB 149, Section 8) for the Attorney General to post the information and online complaint mechanism required by Section 552.102; the Attorney General's consumer-protection site now carries a TRAIGA overview and an online AI complaint form. As of October 5, 2026 this review found no published enforcement action under the Act | 1 |
| [Utah Division of Consumer Protection](https://www.bankingnewsai.com/ai-regulation/utah) | State consumer-protection enforcer for a narrow generative-AI disclosure rule, paired with a state AI policy office that negotiates regulatory relief for AI pilots | Binding law | HB 320 (2026 General Session), signed March 18, 2026 and effective May 6, 2026, amended the Office of Artificial Intelligence Policy's learning-laboratory provisions to add joint interpretation agreements, regular audits of participants and up to two extensions of a demonstration period; the HB 286 frontier-model transparency bill was filed without passing on March 6, 2026 | 2 |
| [Illinois IDHR](https://www.bankingnewsai.com/ai-regulation/illinois) | State civil-rights agency enforcing a statute that makes AI-driven discrimination in employment, and failure to notify employees of AI use, a civil rights violation | Binding law | The Department of Human Rights published proposed amendments to its procedural rules (56 Ill. Adm. Code 2520) implementing HB 3773 in the Illinois Register on May 15, 2026 (Volume 50, Issue 20, page 6794) and noticed a public hearing for June 10, 2026; the codified text reviewed on October 5, 2026 contains no AI rules | 2 |
| [Massachusetts AG](https://www.bankingnewsai.com/ai-regulation/massachusetts) | State attorney general applying existing consumer-protection, anti-discrimination and data-security law to AI, and the author of an AI fair-lending settlement with a student-loan lender | Binding law | July 10, 2025: Attorney General Andrea Joy Campbell announced a $2.5 million settlement with Earnest Operations LLC over AI underwriting models, with mandated AI governance, annual fair-lending testing and reporting to the Attorney General | 2 |
| [New Jersey DCR](https://www.bankingnewsai.com/ai-regulation/new-jersey) | State civil-rights enforcer that treats algorithmic discrimination in credit, employment and housing as a violation of the existing Law Against Discrimination, with codified disparate-impact rules | Binding law | December 15, 2025: the Division's disparate-impact rules (N.J.A.C. 13:16) took effect, following adoption on November 5, 2025; they build on the January 2025 algorithmic-discrimination guidance | 1 |
| [NIST](https://www.bankingnewsai.com/ai-regulation/nist) | Standards body | Voluntary framework | Growing role as the default governance scaffold after the 2026 US model-risk revision excluded generative AI | 9 |

## International

| Authority | Role | How binding | Latest move | Docs |
| --- | --- | --- | --- | --- |
| [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | Binding horizontal AI law | Binding law | Regulation (EU) 2026/1744 (Digital Omnibus on AI) entered into force July 27, 2026, deferring Annex III high-risk obligations — including credit scoring — from Aug 2, 2026 to Dec 2, 2027 | 12 |
| [ECB](https://www.bankingnewsai.com/ai-regulation/ecb) | Prudential supervisor | Supervisory guidance | 7 July 2026 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301): every significant institution must file an action plan with its JST by 31 October 2026 | 13 |
| [EBA](https://www.bankingnewsai.com/ai-regulation/eba) | EU banking standard-setter | Supervisory guidance | Jul 31, 2026: joint ESA statement (JC 2026 25) on ICT risks from frontier AI models — banks told to adjust DORA ICT-risk controls around prevention, detection and management without delay | 10 |
| [ESMA](https://www.bankingnewsai.com/ai-regulation/esma) | EU securities-markets authority that issues non-binding statements and convergence tools on how existing securities rules apply to AI | Supervisory guidance | 23 September 2026: ESMA announced a new Union Strategic Supervisory Priority on digital innovation from 2027, with an initial focus on how supervised entities use AI and tokenisation | 1 |
| [EIOPA](https://www.bankingnewsai.com/ai-regulation/eiopa) | EU insurance and pensions supervisory authority, one of the three European Supervisory Authorities | Supervisory guidance | 6 August 2025 — EIOPA published its Opinion on AI governance and risk management (EIOPA-BoS-25-360) for national insurance supervisors; on 31 July 2026 EIOPA joined the EBA and ESMA in the ESAs' joint statement on ICT risks from frontier AI models (JC 2026 25). | 1 |
| [UK (BoE / PRA / FCA)](https://www.bankingnewsai.com/ai-regulation/uk) | Prudential and conduct regulators | Supervisory guidance | September 30, 2026: Governor Bailey's 'Frontier AI and the Question of Governance' Bank Insights article says 'regulation is not, in my view, the right place to start' and ties frontier AI directly to financial stability through cyber risk and agentic trading and payments; September 2, 2026: FCA multi-firm review on frontier AI and cyber resilience (no new rules); 2026 AI survey (foundation and agentic AI) closed 31 July, results pending | 21 |
| [BaFin](https://www.bankingnewsai.com/ai-regulation/bafin) | Technology-neutral prudential and conduct supervisor that issues non-binding AI guidance and, under the EU AI Act, acts as Germany's market surveillance authority for AI systems used in regulated financial activity | Supervisory guidance | 29 July 2026: BaFin published its page on market surveillance of AI systems, stating that it monitors Article 5 prohibited practices, Article 50 transparency obligations and Article 4 AI literacy now, and high-risk AI systems from 2 December 2027 (including creditworthiness assessment of natural persons) | 3 |
| [ACPR](https://www.bankingnewsai.com/ai-regulation/acpr) | French prudential supervisor and AML authority with an innovation hub that publishes AI governance and fairness papers and is preparing for AI Act market surveillance in finance | Supervisory guidance | 1 July 2026: the ACPR launched a public consultation on algorithmic fairness in the financial sector (open until 30 September 2026) and held a market meeting on AI regulation and supervision | 1 |
| [DNB / AFM](https://www.bankingnewsai.com/ai-regulation/dnb) | Dutch prudential and conduct supervisors that publish joint AI positions and apply existing financial law to AI | Supervisory guidance | 19 January 2026: the AFM announced in its Agenda 2026 that it will intensify supervision of the responsible use of AI and of DORA compliance; April 2026: AFM report on AI in the Dutch asset management sector | 2 |
| [FINMA](https://www.bankingnewsai.com/ai-regulation/finma) | Integrated Swiss financial supervisor that sets AI expectations through supervisory guidance rather than AI-specific law | Supervisory guidance | 24 April 2025: FINMA published a survey of around 400 Swiss financial institutions showing about half use AI or have initial applications in development, following its Guidance 08/2024 of 18 December 2024 | 1 |
| [OSFI](https://www.bankingnewsai.com/ai-regulation/osfi) | Canada's federal prudential supervisor, regulating AI in banks through technology-neutral guidelines on model risk (E-23), third-party risk (B-10), technology and cyber risk (B-13) and operational risk (E-21) | Supervisory guidance | In July 2026 OSFI issued a Technology Risk Bulletin on generative and agentic AI (implications for technology, cyber security and operational resilience), following its April 2026 bulletin on frontier AI and the March 23, 2026 FIFAI II report; Guideline E-23 takes effect 1 May 2027 | 4 |
| [MAS](https://www.bankingnewsai.com/ai-regulation/mas) | Integrated financial regulator whose AI position is principles, information papers and a draft supervisory guideline rather than an AI statute | Supervisory guidance | 28 July 2026: MAS and the Association of Banks in Singapore established the AI-Driven Cyber and Technology Risk Taskforce (ACT) to strengthen resilience against AI-driven cyber threats; on 5 August 2026 a written Parliamentary reply said the AI Risk Management Guidelines would be finalised soon. | 6 |
| [HKMA](https://www.bankingnewsai.com/ai-regulation/hkma) | Principles-based supervisor that regulates AI in banks through circulars, plus the GenA.I. Sandbox for supervised pilots | Supervisory guidance | On 27 August 2026 the HKMA, SFC, Insurance Authority and MPFA announced the first cohort of the GenA.I. Sandbox++: 36 use cases from nearly 100 proposals, 30 financial institutions and 27 technology partners, focused on agentic AI; on 22 June 2026 the HKMA circulated a report on AI in fighting financial crime, and on 2 June 2026 a circular on cyber resilience against AI-empowered threats | 6 |
| [Hong Kong SFC](https://www.bankingnewsai.com/ai-regulation/sfc) | Securities regulator that has issued supervisory circulars on generative AI language models and on AI-enabled cyberattacks for licensed firms | Supervisory guidance | 2 June 2026: SFC Circular 26EC32 on enhanced cybersecurity measures against AI-enabled cyberattacks, addressed to licensed corporations, SFC-licensed VATPs and associated entities. | 2 |
| [Japan FSA](https://www.bankingnewsai.com/ai-regulation/japan-fsa) | Integrated financial supervisor whose AI position is a dialogue-based discussion paper and, in 2026, a joint request with the Bank of Japan on frontier-AI cyber threats | Supervisory guidance | 22 May 2026: the FSA and the Bank of Japan jointly requested financial institutions to implement nine short-term responses to frontier AI cyber threats, expected over roughly one month. | 3 |
| [APRA / ASIC](https://www.bankingnewsai.com/ai-regulation/australia) | Australia's prudential regulator (APRA) and conduct regulator (ASIC), supervising AI in banks through technology-neutral standards and supervisory letters rather than an AI-specific law | Supervisory guidance | On 27 August 2026 APRA and ASIC urged financial entities to move from awareness of frontier AI risks to decisive action after nine roundtables in June and July 2026; on 30 April 2026 APRA's AI letter called for a step-change in AI risk management and the amended CPS 230 took effect on 1 July 2026 | 4 |
| [RBI](https://www.bankingnewsai.com/ai-regulation/rbi) | Banking regulator whose AI position is a non-binding framework (FREE-AI, August 2025) plus a draft, not yet final, model-risk guidance that explicitly covers AI/ML | Voluntary framework | On 24 June 2026 the RBI released the draft Guidance on Regulatory Principles for Model Risk Management, 2026, covering AI/ML and third-party models, with comments invited until 24 July 2026; no final version had been published on the RBI website as of 5 October 2026 | 3 |
| [FSB](https://www.bankingnewsai.com/ai-regulation/fsb) | Global financial-stability standard-setter | Non-binding standards | 31 August 2026: FSB Chair's letter to G20 finance ministers and central bank governors warns that frontier AI models' autonomy and threat capabilities make cyber risk the most immediate financial-stability concern; final AI sound-practices report still expected October 2026 | 9 |
| [Basel Committee](https://www.bankingnewsai.com/ai-regulation/basel-committee) | Global banking standard-setter | Non-binding standards | Oct 1, 2026: following its 28–29 September meeting, the Committee agreed to review the operational risk framework's 'event type' loss categories with a focus on cyber risk and AI developments, its first step toward amending an existing hard standard because of AI; June 2026 ICT risk-management report | 8 |
| [IOSCO](https://www.bankingnewsai.com/ai-regulation/iosco) | Global securities-markets standard-setter; non-binding AI guidance and supervisory tools for securities regulators | Non-binding standards | On May 25, 2026 IOSCO published its final Supervisory Toolkit for AI Use in Capital Markets (FR/02/2026) with a standalone extract (OR/07/2026) for use in examinations and inspections; feedback from stakeholders was invited by June 26, 2026, and the next phase is a review of emerging industry practices | 2 |

## By use case

- [Credit scoring & underwriting](https://www.bankingnewsai.com/ai-regulation/by-use-case#credit-underwriting) — Creditworthiness models are the most heavily regulated bank AI use case: explicitly high-risk under the EU AI Act, and subject to adverse-action, fair-lending and model-risk requirements in the US.
- [Fair lending & discrimination](https://www.bankingnewsai.com/ai-regulation/by-use-case#fair-lending) — Anti-discrimination law applies regardless of how a decision was made. Regulators have said 'the algorithm did it' is not a defence.
- [AML / KYC](https://www.bankingnewsai.com/ai-regulation/by-use-case#aml-kyc) — Regulators actively encourage machine learning in transaction monitoring, but expect the same explainability and validation as any other BSA/AML control.
- [Fraud detection](https://www.bankingnewsai.com/ai-regulation/by-use-case#fraud) — Two sides: banks deploying AI to catch fraud, and regulators warning about deepfakes and generative-AI-enabled scams targeting banks and their customers.
- [Customer-facing chatbots](https://www.bankingnewsai.com/ai-regulation/by-use-case#customer-chatbots) — Consumer-protection law follows the customer interaction: a chatbot that gives wrong information or obstructs a dispute can be a UDAAP or compliance violation.
- [Model risk management](https://www.bankingnewsai.com/ai-regulation/by-use-case#model-risk) — The validation, governance and 'effective challenge' framework that bank examiners test AI models against.
- [Generative & agentic AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#generative-agentic-ai) — The newest and least-settled area: several 2026 frameworks explicitly carve generative and agentic AI out of formal model-risk rules while signalling that dedicated guidance is coming.
- [Third-party & vendor AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#third-party-vendors) — Outsourcing does not outsource accountability: third-party risk management guidance treats AI vendors, foundation-model providers and cloud AI services as critical relationships.
- [Cybersecurity](https://www.bankingnewsai.com/ai-regulation/by-use-case#cybersecurity) — AI as an attack vector (deepfakes, AI-enhanced phishing) and AI as a target (model theft, data poisoning) both fall under existing cyber rules.
- [Data & privacy](https://www.bankingnewsai.com/ai-regulation/by-use-case#data-privacy) — Automated-decision rights, data-governance duties and training-data provenance requirements that sit underneath every AI deployment.
- [Trading & capital markets](https://www.bankingnewsai.com/ai-regulation/by-use-case#trading-markets) — Market regulators focus on conflicts of interest, AI-washing, and the systemic risk of many firms using the same models.
- [AI governance (general)](https://www.bankingnewsai.com/ai-regulation/by-use-case#governance-general) — Cross-cutting principles, sound practices and voluntary frameworks that supervisors reference when they examine a bank's overall AI program.
- [AI-generated code & coding agents](https://www.bankingnewsai.com/ai-regulation/by-use-case#ai-generated-code) — No regulator has a rule for AI-written software, but New York DFS asks for human review of AI-generated code before deployment, NIST profiles the secure development life cycle for AI, and model-risk and third-party guidance decide what an examiner treats as a model or a vendor.

## Other views

- [All documents](https://www.bankingnewsai.com/ai-regulation/documents)
- [Deadlines](https://www.bankingnewsai.com/ai-regulation/deadlines)
- [Compliance checklist](https://www.bankingnewsai.com/ai-regulation/compliance-checklist)
- [Regulator warnings](https://www.bankingnewsai.com/ai-regulation/regulator-warnings)
- [For bank executives](https://www.bankingnewsai.com/ai-regulation/for-bank-executives)
- [For compliance officers](https://www.bankingnewsai.com/ai-regulation/for-compliance-officers)
- [Side-by-side comparisons](https://www.bankingnewsai.com/ai-regulation/compare)

---

Canonical page: https://www.bankingnewsai.com/ai-regulation
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
