The CFPB regulates AI in lending through existing law — the Equal Credit Opportunity Act, Regulation B, the Fair Credit Reporting Act and UDAAP — not through AI-specific rules. Its 2022 and 2023 circulars stating that 'black-box' models do not excuse vague denial reasons were withdrawn on May 12, 2025, but the statutory requirement in 15 U.S.C. 1691(d) and 12 CFR 1002.9 to give applicants the specific principal reasons for adverse action still applies to every model. In April 2026 the Bureau finalized a Regulation B rule (effective July 21, 2026) declaring that ECOA does not authorize disparate-impact liability, sharply narrowing the fair-lending theory most often used against algorithmic underwriting.
| Full name | Consumer Financial Protection Bureau |
| Role | Consumer-protection regulator |
| Force on banks | Binding law |
| Applies to | Banks, credit unions, mortgage lenders, and fintechs offering consumer financial products in the US |
| Key document | Regulation B §1002.9 adverse-action requirements (ECOA); April 2026 Reg B final rule |
| Latest move | April 2026 Regulation B final rule (effective July 21, 2026) eliminates disparate-impact liability under ECOA — the fair-lending theory most often applied to AI models — while the statutory duty to give specific, accurate adverse-action reasons remains untouched. |
| Documents tracked | 10 · all documents → |
For years the Bureau's operative position was set by Circular 2022-03 (May 2022) and Circular 2023-03 (September 2023): a creditor that uses complex algorithms or machine-learning underwriting must still provide the specific, accurate principal reasons for adverse action required by ECOA and Regulation B §1002.9, and cannot hide behind a sample checklist or the model's opacity. Both circulars were withdrawn on May 12, 2025 as part of a rescission of 67 guidance documents — but they were interpretations, not rules. The statutory duty they described (15 U.S.C. 1691(d), 12 CFR 1002.9) is unchanged and remains enforceable by the CFPB, the prudential regulators, state attorneys general and private plaintiffs.
The bigger 2026 change is the Regulation B final rule published April 22, 2026 and effective July 21, 2026: it declares that ECOA does not authorize disparate-impact liability, narrows the 'discouragement' concept, and restricts special-purpose credit programs. Disparate impact was the fair-lending theory most often applied to algorithmic underwriting, so the rule materially lowers federal fair-lending exposure for AI models — while leaving adverse-action notices, FCRA key-factor disclosures and UDAAP fully intact, and while state laws (New York DFS, Colorado) move in the opposite direction.
What are the US regulatory requirements for automated credit decisions?
No US law regulates automated credit decisions as such — but four separate bodies of requirement apply to every model that decides who gets credit. Consumer law binds first and hardest: ECOA and Regulation B require a notice stating the specific principal reasons for any adverse action within 30 days of a completed application, and the FCRA adds credit-score key factors when a consumer report is used — neither has an exception for model complexity. Prudential guidance adds development, validation and governance duties for banks under the April 2026 interagency model risk framework. State law is now the fastest-moving layer: Colorado's ADMT Act reaches consequential lending decisions from January 1, 2027 with no bank exemption. The April 2026 Regulation B rule removed disparate-impact liability under ECOA — narrowing federal fair-lending exposure without changing a single notice obligation.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| ECOA / Regulation B §1002.9 | CFPB | Written notice of the specific principal reasons for adverse action within 30 days of a completed application. Reasons must relate to and accurately describe the factors the model actually scored — “failure to achieve a qualifying score” and the nearest box on the Appendix C sample form are both insufficient. | Since 1974 |
| Adverse action, defined (12 CFR 1002.2(c)) | CFPB | The duty is not limited to denials: terminations, unfavorable changes in terms and refusals to increase a credit limit all trigger it, which puts automated line-management and re-pricing systems in scope. | In force |
| FCRA §§615(a), 609(f) | CFPB | When a consumer report or score drives the decision: identify the reporting agency, state that it did not make the decision, and disclose the score, its range and the up-to-four key factors that adversely affected it. This is a separate notice from the Regulation B one. | Since 1970 |
| Regulation B final rule (April 2026) | CFPB | ECOA no longer supports disparate-impact claims; the effects test is removed from Regulation B and its commentary. Adverse-action duties under §1002.9 are expressly unchanged. | Since Jul 21, 2026 |
| UDAAP (Dodd-Frank §1031) ↗ | CFPB | A model that produces unfair, deceptive or abusive outcomes — or a disclosure that misdescribes how a decision was reached — is actionable regardless of the technique used. | In force |
| Joint Statement on Automated Systems | CFPB | The CFPB, DOJ, EEOC and FTC's shared position that existing law applies to automated systems and that opacity is not a defence. The 2025 guidance withdrawal did not touch this statement. | Since Apr 2023 |
| Model risk management (SR 26-2 / OCC 2026-13 / FIL-15-2026) | Federal Reserve | Sound development and testing, independent validation with outcomes analysis, effective challenge, and board-level governance for credit models — risk-based, and most relevant above $30 billion in assets. Generative and agentic AI are explicitly out of scope. | Since Apr 17, 2026 |
| Third-party risk management (SR 23-4 / OCC 2023-17 / FIL-29-2023) | Federal Reserve | A purchased or vendor-hosted credit model carries the same expectations as one built in-house: the bank must understand it, validate it, and remain accountable for its outputs. | In force |
| Colorado ADMT Act (SB 26-189) | Colorado AI Act | Notice at the point of consumer interaction; within 30 days of an adverse outcome, an explanation of the decision, the system's role and the data used; rights to correct the data and to request human review by someone able to override. There is no bank, credit-union or GLBA exemption in the enrolled act — only §6-1-1704(6)(a), under which an ECOA/Reg B notice (and FCRA where applicable) substitutes for Colorado's notice only if that federal notice also satisfies Colorado's own disclosure requirements. | From Jan 1, 2027 |
| California CPPA ADMT regulations (11 CCR 7200–7222) | California CPPA | Pre-use notice, an opt-out (or a human-appeal alternative), and a plain-language explanation on request when automated technology makes a “significant decision” — a category that expressly includes lending. For GLBA-covered lenders the reach is much narrower than it looks; see below. | From Jan 1, 2027 |
| EU AI Act, Annex III 5(b) | EU AI Act | For US banks with EU lending operations: creditworthiness scoring of natural persons is high-risk, requiring risk management, data governance, technical documentation, logging, human oversight and post-market monitoring. | From Dec 2, 2027 |
The two documents most often cited as “the CFPB's AI rules” — Circulars 2022-03 and 2023-03 — were withdrawn on May 12, 2025, alongside 65 other guidance documents. Their withdrawal changed nothing about the underlying obligation. The specific-reasons requirement is statutory (15 U.S.C. 1691(d)) and sits in the regulation itself (12 CFR 1002.9); it is enforceable by the Bureau, by the prudential regulators through their own examination authority, by state attorneys general under Dodd-Frank §1042, and by private plaintiffs. What was withdrawn was the Bureau's published interpretation of how that duty applies to complex models — not the duty, and not the case law.
The April 2026 Regulation B rule is the most consequential federal change for algorithmic underwriting in a decade. Disparate impact was the theory under which a model producing discriminatory outcomes from facially neutral inputs could be challenged; removing it narrows federal exposure substantially. It reaches ECOA only. Disparate-treatment claims survive — including the argument that a proxy variable amounts to intentional discrimination — as do state fair-lending and UDAP statutes, mortgage-specific fair-housing law, and the contractual and reputational consequences of a model nobody can explain.
California's ADMT regulations are the most-cited state rules in this area and the most misread for banks. The California Privacy Protection Agency's package was approved on September 22, 2025, took effect January 1, 2026 and requires ADMT compliance by January 1, 2027. Lending is the first-listed “significant decision” — 11 CCR 7001(ddd) defines financial or lending services as the extension of credit or a loan, transmitting or exchanging funds, deposit or checking accounts, check cashing, and installment payment plans. Two things narrow it sharply for banks. First, scope: ADMT means technology that replaces or substantially replaces human decision-making (7001(e)), so a genuine human decision-maker — one who actually knows how to interpret the output, reviews it, and has authority to change the outcome — takes a credit model out of the article entirely. Second, and more decisive, the CCPA's exemption at Cal. Civ. Code §1798.145(e) is written at the level of the information, not the institution: personal information collected or processed subject to the Gramm-Leach-Bliley Act, the California Financial Information Privacy Act or the Farm Credit Act sits outside the statute. The Agency confirmed this reading in its Final Statement of Reasons, rejecting an entity-level exemption because the CCPA “instead includes a data-level exemption for information subject to the GLBA.” At a GLBA-covered lender the application, income, credit-bureau, account and adverse-action data behind a credit decision is exactly that, so the ADMT obligations largely do not reach the credit decision itself. Where they do reach a bank is everything GLBA does not cover — above all employment, since HR, applicant and contractor data has been inside the CCPA since January 1, 2023 and hiring and compensation are themselves significant decisions — plus prospect and advertising data, non-GLBA product lines, and model training data. Mixed-input models, where GLBA and non-GLBA data are combined, are the genuinely unresolved edge: the Agency was asked to draw a line and declined. Risk assessments covering 2026–27 processing must be submitted with an executive attestation, under penalty of perjury, by April 1, 2028.
Beyond California and Colorado, no other US state has an in-force or dated law that specifically governs automated decision-making in consumer credit — a point worth checking against the many summaries that say otherwise. Connecticut is the common error: the 2025 bill whose consequential-decision definition covered financial and lending services died, and the AI act Connecticut actually enacted in 2026 does not reach credit. Texas's Responsible AI Governance Act, in force since January 1, 2026, bans discrimination only where intent is shown — a disparate impact is expressly insufficient — and carries a safe harbor for federally insured institutions. Illinois amended only the employment article of its Human Rights Act, leaving the financial-credit article untouched; Virginia's high-risk AI bill was vetoed; New York's automated-decision statute binds state agencies, and its DFS circular covers insurers. Maryland and Oregon are the instructive near-misses: both list financial or lending services as decisions with legal or similarly significant effects and give consumers a profiling opt-out, but both then exempt financial institutions at the entity level — the mirror image of California, where the exemption follows the data instead. For a multi-state lender that asymmetry is the whole planning problem: the same credit model can be out of scope in Oregon because of what you are, out of scope in California because of what the data is, and squarely in scope in Colorado because it is neither.
For a bank the practical test is rarely “is there an AI rule?” It is two questions asked in different rooms. Can you produce the reason? — a consumer-law duty that applies to the very first automated decision, at any institution size, with no materiality threshold. And can you defend the model? — a supervisory expectation that scales with the model's materiality and the institution's size. A lender can satisfy the second and still fail the first.
WHAT THIS MEANS IN PRACTICE
- Every declined application needs a reason that maps to a factor the model actually used. Explainability tooling is a compliance requirement for anyone running a non-linear model, not an engineering preference.
- Regulation B and the FCRA are two notices, not one. Satisfying the specific-reasons requirement does not satisfy the key-factor disclosure when a score was used.
- Automated line management, term changes and re-pricing are adverse actions when unfavorable — compliance scoping that stops at originations misses the account-management models entirely.
- The documentation that satisfies the April 2026 model risk framework — development evidence, independent validation, outcomes analysis — is the same evidence base used to defend a fair-lending challenge. Build it once.
- A vendor that will not explain its scoring is a compliance problem, not a commercial one: under third-party guidance the bank still owns the outcome and still owes the applicant a reason.
- Read California's ADMT rules through the §1798.145(e) data exemption before budgeting for them: at a GLBA-covered lender they bite hardest on employment decisions, not on credit ones.
- A real human decision-maker can put a credit model outside California's ADMT article altogether — but the test is substantive, not a rubber stamp: the reviewer must understand the output, actually review it, and be able to change the result.
- Colorado's January 1, 2027 date is the binding US deadline for explanation duties on consequential decisions. Scope remediation to it rather than to the deferred EU timeline.
What has the CFPB actually published on AI?
| Date | Document | Status |
|---|---|---|
| Apr 22, 2026 | Regulation B final rule on disparate impact (April 2026) — Equal Credit Opportunity Act (Regulation B) — final rule amending disparate impact, discouragement and special purpose credit program provisions | In force |
| May 12, 2025 | CFPB withdrawal of 67 guidance documents (May 2025) — Interpretive Rules, Policy Statements, and Advisory Opinions; Withdrawal | In force |
| Aug 12, 2024 | CFPB comment to Treasury on AI in financial services (2024) — CFPB Comment on Request for Information on Uses, Opportunities, and Risks of Artificial Intelligence in the Financial Services Sector | Final |
| Sep 19, 2023 | CFPB Circular 2023-03 — Adverse action notification requirements and the proper use of the CFPB's sample forms provided in Regulation B | Withdrawn |
| Jun 6, 2023 | CFPB Chatbots in Consumer Finance (issue spotlight, 2023) — Chatbots in consumer finance | Final |
| Apr 25, 2023 | Joint Statement on Automated Systems (CFPB, DOJ, EEOC, FTC) — Joint Statement on Enforcement Efforts Against Discrimination and Bias in Automated Systems | Final |
| May 26, 2022 | CFPB Circular 2022-03 — Adverse action notification requirements in connection with credit decisions based on complex algorithms | Withdrawn |
| Jul 7, 2020 | CFPB Innovation Spotlight on AI/ML adverse action notices (2020) — Innovation spotlight: Providing adverse action notices when using AI/ML models | Final |
| Oct 28, 1974 | ECOA / Regulation B adverse action (15 U.S.C. 1691(d); 12 CFR 1002.9) — Equal Credit Opportunity Act section 701(d) and Regulation B section 1002.9 — notification of adverse action and statement of specific reasons | In force |
| Oct 26, 1970 | FCRA adverse action and credit-score disclosures (15 U.S.C. 1681m, 1681g(f)) — Fair Credit Reporting Act — adverse-action notices based on consumer reports and disclosure of key factors affecting credit scores | In force |
| Date | Type | Document / event |
|---|---|---|
| Jul 21, 2026 | Milestone | Amended Regulation B takes effect: no disparate-impact liability under ECOA. The April 22, 2026 final rule (91 FR 21620) became effective, removing the 'effects test' from Regulation B, narrowing 'discouragement' to statements of intent to discriminate, and restricting special purpose credit programs. Adverse-action notice rules in 12 CFR 1002.9 were not changed. |
| Apr 22, 2026 | Regulation | Regulation B final rule on disparate impact (April 2026) — Equal Credit Opportunity Act (Regulation B) — final rule amending disparate impact, discouragement and special purpose credit program provisions. Published April 22, 2026 at 91 FR 21620 and effective July 21, 2026, the CFPB's Regulation B final rule provides that ECOA does not authorize disparate-impact liability (the 'effects test'), narrows the prohibition on 'discouragement' to statements of intent to discriminate, and restricts special purpose credit programs, including barring race, color, national origin or sex as the common characteristic. source ↗ |
| May 12, 2025 | Regulation | CFPB withdrawal of 67 guidance documents (May 2025) — Interpretive Rules, Policy Statements, and Advisory Opinions; Withdrawal. On May 12, 2025 the CFPB published a Federal Register notice withdrawing 67 guidance documents issued since 2011: 8 policy statements, 7 interpretive rules, 13 advisory opinions and 39 other documents. source ↗ |
| May 12, 2025 | Milestone | CFPB withdraws 67 guidance documents, including AI adverse-action Circulars 2022-03 and 2023-03. A single Federal Register notice (90 FR 20084, doc. 2025-08286) withdrew 8 policy statements, 7 interpretive rules, 13 advisory opinions and 39 other guidance documents effective May 12, 2025. Both algorithmic adverse-action circulars are listed on the Bureau's Withdrawn Guidance page; the underlying ECOA/Regulation B duty to give specific reasons is statutory and unchanged. |
| Aug 12, 2024 | Letter | CFPB comment to Treasury on AI in financial services (2024) — CFPB Comment on Request for Information on Uses, Opportunities, and Risks of Artificial Intelligence in the Financial Services Sector. On August 12, 2024 the CFPB responded to Treasury's June 2024 RFI on AI in financial services, stating that there is 'no fancy new technology carveout' to federal consumer financial law. source ↗ |
| Sep 19, 2023 | Circular | CFPB Circular 2023-03 — Adverse action notification requirements and the proper use of the CFPB's sample forms provided in Regulation B. Circular 2023-03, issued September 19, 2023 (published at 89 FR 27361 in April 2024), addressed lenders using AI and other complex models that consider data not on the Regulation B sample forms. source ↗ |
| Jun 6, 2023 | Report | CFPB Chatbots in Consumer Finance (issue spotlight, 2023) — Chatbots in consumer finance. The CFPB's June 6, 2023 issue spotlight found that all of the top 10 US commercial banks had deployed chatbots and that roughly 37% of the US population — over 98 million people — interacted with a bank chatbot in 2022. source ↗ |
| Apr 25, 2023 | Guidance | Joint Statement on Automated Systems (CFPB, DOJ, EEOC, FTC) — Joint Statement on Enforcement Efforts Against Discrimination and Bias in Automated Systems. On April 25, 2023 the CFPB, the Justice Department's Civil Rights Division, the EEOC and the FTC issued a joint statement pledging to enforce existing civil-rights and consumer-protection laws against discriminatory outcomes from automated systems and AI. source ↗ |
| May 26, 2022 | Circular | CFPB Circular 2022-03 — Adverse action notification requirements in connection with credit decisions based on complex algorithms. Circular 2022-03, issued May 26, 2022 and published at 87 FR 35864, answered 'yes' to whether creditors using complex algorithms must still give ECOA's statement of specific reasons for adverse action. source ↗ |
| Jul 7, 2020 | Guidance | CFPB Innovation Spotlight on AI/ML adverse action notices (2020) — Innovation spotlight: Providing adverse action notices when using AI/ML models. In July 2020 the CFPB published an Innovation Spotlight explaining how ECOA and Regulation B accommodate AI and machine-learning underwriting. source ↗ |
| Oct 28, 1974 | Statute | ECOA / Regulation B adverse action (15 U.S.C. 1691(d); 12 CFR 1002.9) — Equal Credit Opportunity Act section 701(d) and Regulation B section 1002.9 — notification of adverse action and statement of specific reasons. ECOA (15 U.S.C. source ↗ |
| Oct 26, 1970 | Statute | FCRA adverse action and credit-score disclosures (15 U.S.C. 1681m, 1681g(f)) — Fair Credit Reporting Act — adverse-action notices based on consumer reports and disclosure of key factors affecting credit scores. The Fair Credit Reporting Act governs the data feeding many AI credit, fraud and account-opening models. source ↗ |
Which of the 100 largest US banks answer to the CFPB on AI?
82 of the 100 bank pages on this site name the CFPB among the authorities their AI programme answers to. Each page lists the documents that apply and why.
- Litigation challenging the April 2026 Regulation B rule's elimination of disparate-impact liability, and whether states (New York DFS, Colorado, California) fill the gap for AI underwriting
- Whether the Bureau issues any replacement guidance on adverse-action notices for machine-learning models after withdrawing Circulars 2022-03 and 2023-03
- Private ECOA and FCRA litigation testing whether model-derived denial reasons are 'specific' and 'accurate' enough
- Colorado's Automated Decision-Making Technology Act rules (effective January 1, 2027) as the de facto US standard for consequential AI decisions in financial services
Can a bank use a black-box AI model for credit decisions?
Only if it can still comply with ECOA and Regulation B: the lender must give applicants specific, accurate reasons for adverse action. CFPB Circulars 2022-03 and 2023-03 said model complexity does not excuse vague or generic denial reasons; although both circulars were withdrawn in May 2025, that requirement comes from the statute and Regulation B itself, so it still effectively requires explainability tooling around any underwriting model.
Does the CFPB have AI-specific regulations?
No — and it has said it doesn't need them. The Bureau applies existing consumer law (ECOA, Regulation B, UDAAP) to AI systems. Its circulars clarify how those laws apply to algorithmic credit decisions, chatbots, and digital marketing.
Are CFPB Circulars 2022-03 and 2023-03 still in effect?
No. Both were withdrawn on May 12, 2025 as part of a Federal Register notice rescinding 67 CFPB guidance documents. The circulars were interpretations, not rules: the obligation they described — providing specific and accurate principal reasons for adverse action under ECOA section 701(d) and Regulation B section 1002.9 — is statutory and remains fully enforceable by the CFPB, prudential regulators, state attorneys general and private plaintiffs.
Did the 2026 Regulation B rule change adverse-action notice requirements for AI models?
No. The final rule published April 22, 2026 (effective July 21, 2026) amended the disparate-impact, discouragement and special-purpose-credit-program provisions of Regulation B. It did not amend 12 CFR 1002.9, so lenders using machine-learning underwriting must still deliver notices with specific principal reasons within 30 days of a completed application.
Follow every move these regulators make
the daily brief · six sourced stories · in your inbox by 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning