The next dated AI-compliance deadline for banks is Oct 20, 2026: CFTC — CFTC Compute Derivatives RFC: comment period closes. 50 documents are in force today, 2 consultations are open for comment, and the binding dated obligations ahead are Colorado's ADMT and chatbot acts (January 1, 2027), the EU AI Act's high-risk regime for credit scoring (December 2, 2027) and its product-embedded extension (August 2, 2028). Everything below is generated from the tracker's primary-source documents and recomputed daily.
What AI obligations land in Q4 2026?
| Date | Authority | Obligation / event | Who must act |
|---|---|---|---|
| Oct 20, 2026 | CFTC | CFTC Compute Derivatives RFC: comment period closes · Comment deadline | Designated contract markets, swap execution facilities, clearinghouses, swap dealers, FCMs, and market participants interested in… |
| Oct 26, 2026 | Colorado AI Act | Colorado AG proposed ADMT rules: comment period closes · Comment deadline | Developers, 'midstream developers', and deployers of covered ADMT under SB 26-189, and operators of conversational AI services… |
| Oct 31, 2026 | ECB | Deadline for significant institutions to submit AI-cyber action plans to their JSTs · Milestone | The ~110 significant euro-area banking groups directly supervised under the SSM |
| Nov 20, 2026 | EU AI Act | Consumer Credit Directive (EU) 2023/2225 takes effect · Takes effect | Creditors and credit intermediaries offering consumer credit in the EU, as transposed by member states |
What AI obligations land in Q1 2027?
| Date | Authority | Obligation / event | Who must act |
|---|---|---|---|
| Jan 1, 2027 | Colorado AI Act | SB 26-189 takes effect · Takes effect | Developers and deployers of covered ADMT that materially influences consequential decisions about Colorado consumers in financial… |
| Jan 1, 2027 | Colorado AI Act | HB 26-1263 takes effect · Takes effect | Operators of conversational AI services accessible to the public in Colorado, including bank customer-service chatbots |
What AI obligations land in Q4 2027?
| Date | Authority | Obligation / event | Who must act |
|---|---|---|---|
| Dec 2, 2027 | EU AI Act | High-risk AI obligations for stand-alone Annex III systems become applicable · Milestone | Any bank, lender, or fintech that develops or uses AI systems in the EU — including non-EU firms whose AI outputs are used in the… |
What AI obligations land in Q3 2028?
| Date | Authority | Obligation / event | Who must act |
|---|---|---|---|
| Aug 2, 2028 | EU AI Act | Deferred deadline for high-risk AI embedded in regulated products · Milestone | Any bank, lender, or fintech that develops or uses AI systems in the EU — including non-EU firms whose AI outputs are used in the… |
Which AI rules is a bank examined against right now?
The newest documents currently in force — the working baseline for an AI compliance program. Full index: all documents →
| Since | Document | The obligation |
|---|---|---|
| Jul 31, 2026 | ESA Statement on ICT risks from frontier AI models (JC 2026 25) | On July 31, 2026 the EBA, EIOPA and ESMA published joint statement JC 2026 25 on ICT risks from frontier AI models, warning that highly capable AI models sharply accelerate vulnerability discovery… |
| Jul 24, 2026 | FIN-2026-Alert004 (Federal Student Aid Fraud) | FinCEN Alert FIN-2026-Alert004, issued July 24, 2026, asks financial institutions to detect and report fraud rings stealing federal student aid through 'ghost students' and 'straw students.' It… |
| Jul 27, 2026 | Regulation (EU) 2026/1744 (Digital Omnibus on AI) | Regulation (EU) 2026/1744, the Digital Omnibus on AI, was proposed by the European Commission on November 19, 2025, agreed by Parliament and Council in May 2026, adopted July 8, 2026, published in… |
| Jul 7, 2026 | ECB 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301) | On 7 July 2026 Claudia Buch, Chair of the ECB Supervisory Board, sent letter SSM-2026-0301, 'Addressing AI-enabled cybersecurity threats', to the CEO of every significant institution. |
| May 21, 2026 | DFS Frontier AI Models Industry Letter (May 2026) | On May 21, 2026, DFS issued an Industry Letter warning that 'frontier AI models' able to identify vulnerabilities and build exploits at unprecedented speed and scale will soon become widely… |
| May 21, 2026 | DFS Heightened Threat Environment Guidance (May 2026) | Issued May 21, 2026 as the companion to DFS's frontier-AI letter, this guidance defines a 'heightened cybersecurity threat environment' as one where risks are significantly elevated with a high… |
| May 15, 2026 | BoE/FCA/HMT joint statement on frontier AI and cyber resilience (May 2026) | On 15 May 2026 the Bank of England, FCA and HM Treasury jointly warned that frontier AI models' cyber capabilities already exceed what a skilled practitioner could achieve, at higher speed, scale and… |
| Jul 21, 2026 | Regulation B final rule on disparate impact (April 2026) | Published April 22, 2026 at 91 FR 21620 and effective July 21, 2026, the CFPB's Regulation B final rule provides that ECOA does not authorize disparate-impact liability (the 'effects test'), narrows… |
| Apr 17, 2026 | SR 26-2 | SR 26-2, issued April 17, 2026 jointly by the Federal Reserve, OCC (Bulletin 2026-13), and FDIC, replaces SR 11-7 (2011) and the 2021 BSA/AML model risk statement (SR 21-8) with a risk-based,… |
| Apr 17, 2026 | OCC Bulletin 2026-13 | On April 17, 2026 the OCC, Federal Reserve, and FDIC issued revised interagency Model Risk Management guidance (OCC Bulletin 2026-13; Fed SR 26-2; FDIC FIL-15-2026), replacing the 2011 framework that… |
| Apr 17, 2026 | FDIC FIL-15-2026 | On April 17, 2026 the FDIC issued FIL-15-2026, adopting revised interagency Model Risk Management guidance jointly with the OCC and Federal Reserve and rescinding FIL-22-2017 and FIL-27-2021. |
| Mar 24, 2026 | CFTC Innovation Task Force | On March 24, 2026 CFTC Chairman Michael S. |
Which AI deadlines have banks already been through this year?
| Date | Authority | What happened |
|---|---|---|
| Aug 20, 2026 | CFTC | Inaugural Innovation Advisory Committee meeting: 'Preparing for Intelligent Markets' · Milestone |
| Aug 5, 2026 | UK (BoE / PRA / FCA) | AI Consortium June 2026 minutes published · Milestone |
| Aug 2, 2026 | EU AI Act | Article 50 transparency obligations apply; Annex III high-risk start deferred · Milestone |
| Jul 31, 2026 | UK (BoE / PRA / FCA) | 2026 BoE/FCA AI survey closes to responses · Milestone |
| Jul 31, 2026 | UK (BoE / PRA / FCA) | 2026 BoE/FCA AI survey: comment period closes · Comment deadline |
| Jul 27, 2026 | EU AI Act | Regulation (EU) 2026/1744 (Digital Omnibus on AI) takes effect · Takes effect |
| Jul 23, 2026 | EU AI Act | Draft Commission guidelines on high-risk classification: comment period closes · Comment deadline |
| Jul 22, 2026 | FSB | Comment deadline passes on FSB AI sound-practices consultation · Milestone |
| Jul 22, 2026 | FSB | FSB AI sound practices consultation (June 2026): comment period closes · Comment deadline |
| Jul 21, 2026 | CFPB | Amended Regulation B takes effect: no disparate-impact liability under ECOA · Milestone |
| Jul 21, 2026 | CFPB | Regulation B final rule on disparate impact (April 2026) takes effect · Takes effect |
| Jun 30, 2026 | Colorado AI Act | Original SB 24-205 effective date passes without the law taking effect · Milestone |
| Jun 9, 2026 | FinCEN | Comment period closes on the April 2026 AML/CFT program proposal · Milestone |
| Jun 9, 2026 | FinCEN | 2026 AML/CFT Program Proposed Rule: comment period closes · Comment deadline |
| May 20, 2026 | Basel Committee | Committee flags frontier AI models as a cyber-risk accelerant · Milestone |
| Apr 27, 2026 | Colorado AI Act | AG commits not to enforce until rulemaking concludes; federal court stays xAI challenge · Milestone |
| Apr 17, 2026 | NIST | US model-risk revision amplifies the RMF's role · Milestone |
| Apr 17, 2026 | FinCEN | 2021 BSA/AML model risk statement rescinded · Milestone |
| Apr 17, 2026 | NCUA | NCUA sits out the revised interagency model risk management guidance · Milestone |
| Mar 24, 2026 | CFTC | Innovation Task Force formed with an AI and autonomous systems workstream · Milestone |
| Mar 9, 2026 | NIST | CAISI RFI on AI agent security (2026): comment period closes · Comment deadline |
| Feb 18, 2026 | U.S. Treasury | Treasury announces completion of the AIEOG public-private AI initiative · Milestone |
| Jan 30, 2026 | NIST | NIST IR 8596 (Cyber AI Profile): comment period closes · Comment deadline |
| Jan 12, 2026 | CFTC | Technology Advisory Committee renamed Innovation Advisory Committee · Milestone |
| Jan 1, 2026 | EBA | EBA Work Programme 2026 takes effect · Takes effect |
| Jan 1, 2026 | ECB | SSM supervisory priorities 2026–28 takes effect · Takes effect |
What are the next AI regulation deadlines for banks?
The next dated deadlines are: Oct 20, 2026 — CFTC: CFTC Compute Derivatives RFC: comment period closes; Oct 26, 2026 — Colorado AI Act: Colorado AG proposed ADMT rules: comment period closes; Oct 31, 2026 — ECB: Deadline for significant institutions to submit AI-cyber action plans to their JSTs. The full calendar through 2028 is maintained on this page and at /ai-regulation/deadlines.
Do US banks face binding AI compliance deadlines?
At the federal level, no — US bank AI is governed through supervisory guidance (the April 2026 revised model risk management guidance) and existing statutes like ECOA and the FCRA, which carry no AI-specific dates. The binding dated obligations come from states and the EU: Colorado's Automated Decision-Making Technology Act and Chatbot Safety Act take effect January 1, 2027, New York DFS applies its Part 500 cybersecurity regulation to AI threats now, and the EU AI Act's high-risk regime reaches EU credit-scoring operations on December 2, 2027.
When does the EU AI Act apply to bank credit scoring?
December 2, 2027. The original date was August 2, 2026, but the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force July 27, 2026) deferred stand-alone Annex III high-risk systems — which include credit scoring of natural persons — to December 2, 2027, and AI embedded in regulated products to August 2, 2028. Article 50 transparency duties have applied since August 2, 2026.
What should a bank compliance team do before the end of 2026?
Four concrete items: file the AI-cybersecurity action plan the ECB requires from significant euro-area institutions by October 31, 2026 (SSM-2026-0301, if in scope); map models against the revised interagency model risk management guidance in force since April 17, 2026; review adverse-action notice processes against the Regulation B rule effective July 21, 2026; and prepare for Colorado's ADMT Act taking effect January 1, 2027 — the state rulemaking finishes in late 2026.
New obligations land in the brief first
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →