AI Regulation Tracker · Compare

AI regulation, side by side.

Last reviewed Sep 24, 2026 · 5 comparisons

The "X vs Y" questions bank risk, compliance and model teams ask about AI and model risk rules, answered side by side from the official texts. Every table cell cites its source, and each side links to its page in the regulation tracker.

ComparisonThe short answer
SR 11-7 vs SR 26-2SR 26-2, issued April 17, 2026 by the Federal Reserve, OCC (Bulletin 2026-13) and FDIC (FIL-15-2026), supersedes SR 11-7. The biggest change is scope: a model is now a "complex" quantitative method, spreadsheet arithmetic and deterministic rule-based processes with no underpinning theory are excluded, generative and agentic AI are "not within the scope of this guidance", and it is "expected to be most relevant" to banks with over $30 billion in assets. Validation, effective challenge, governance, inventory and vendor-model expectations carry over, and non-compliance "will not result in supervisory criticism".
OCC vs CFPB on AI lendingThe OCC treats AI in lending as a model risk and safety-and-soundness question; the CFPB treats it as a consumer-protection question under ECOA and Regulation B. The sharpest difference is force: Regulation B requires every adverse-action notice to give "specific" principal reasons whatever model is used, while the OCC's revised model risk guidance "does not set forth enforceable standards". Both stepped back in 2025–26: the CFPB withdrew its AI adverse-action circulars and removed disparate impact from Regulation B; the OCC stopped examining for disparate impact.
EU AI Act vs Colorado AI ActThe EU AI Act regulates the AI system: credit scoring of natural persons is "high-risk", so providers carry a full compliance regime and bank deployers must run human oversight, keep logs and complete a fundamental rights impact assessment, from December 2, 2027. Colorado's SB 26-189, effective January 1, 2027, regulates the decision instead: no impact assessment, but notice before use, a plain-language explanation within 30 days of an adverse outcome, data correction and human review; a lender's ECOA notice can satisfy the notice duties.
PRA SS1/23 vs SR 26-2SS1/23 is narrower in who it covers but broader in what it covers: it applies to UK banks with internal-model approval for regulatory capital, yet reaches "all types of models" used to inform business decisions, "regardless of technology", and names a Senior Management Function holder accountable for model risk. SR 26-2 addresses all US banking organizations but is "most relevant" above $30 billion in assets, narrows the model definition and places generative and agentic AI outside its scope.
NIST AI RMF vs ISO 42001The NIST AI RMF is a free framework "intended for voluntary use", organised around four functions (Govern, Map, Measure, Manage); ISO/IEC 42001 is a paid international standard that "specifies requirements" for an AI management system, and organisations can be audited and certified against it under ISO/IEC 42006. A bank can use the RMF to structure AI risk work and 42001 to prove a management system to third parties. Neither is named in SR 26-2 or the EU AI Act.

Follow every document these regulators publish

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning