AI Regulation Tracker · Massachusetts AG · Enforcement

What does Massachusetts AG Earnest Operations settlement (July 2025) say about AI in banking?

Published Jul 10, 2025 · Last reviewed Oct 5, 2026

On July 10, 2025 Massachusetts Attorney General Andrea Joy Campbell announced a $2.5 million settlement with Earnest Operations LLC, a Delaware-based student-loan lender, over its AI-driven underwriting. The settlement is an assurance of discontinuance under G.L. c. 93A, §§2 and 5, filed in Suffolk County Superior Court; the office alleged that Earnest failed to test its models for disparate impact, used a Cohort Default Rate variable that penalized Black and Hispanic applicants, automatically denied applicants without a green card, and sent inaccurate adverse-action notices in violation of ECOA and Regulation B. Earnest denies the allegations and admitted nothing. Beyond the payment, it must run a written AI governance program with an algorithmic oversight team, annual fair-lending testing of underwriting models and knockout rules, annual model inventories, four-year decision records, interpretable models with validated decline reasons, and report compliance to the Attorney General.

OFFICIAL TEXT: mass.gov ↗ · IN FORCE · MASSACHUSETTS AG

DocumentMassachusetts AG Earnest Operations settlement (July 2025) — Assurance of Discontinuance: In the matter of Earnest Operations LLC (Massachusetts Attorney General, announced July 10, 2025)
Issued byMassachusetts — Office of the Attorney General (Consumer Protection Division; Consumer Protection Act G.L. c. 93A, Anti-Discrimination Law G.L. c. 151B, data security law G.L. c. 93H)
TypeEnforcement
StatusIn force
PublishedJul 10, 2025
Applies toBinds only Earnest Operations LLC, a Delaware-based private student-loan lender, and its successors and controlled businesses; the release does not bind other private or governmental parties. Its terms are the clearest published statement of what the Massachusetts Attorney General expects of any lender, bank or fintech using AI models in underwriting
Official sourcemass.gov ↗
Use casesCredit scoring & underwriting · Fair lending & discrimination · Model risk management · AI governance (general) · Third-party & vendor AI

What are the key points of Massachusetts AG Earnest Operations settlement (July 2025)?

  • Payment (¶64): Earnest pays $2,500,000 to the Commonwealth within 30 days of the Effective Date, defined (¶9) as the date the AOD is filed in a Massachusetts court; the Attorney General may use the funds for consumers, the General Fund, the Local Consumer Aid Fund or consumer-protection programs (¶65).
  • Allegations (¶5, ¶¶23–63): failing to guard against disparate outcomes in algorithmic and judgmental underwriting; using the Cohort Default Rate (CDR) variable, which the AOD says was a weighted input in the student loan refinance model until September 13, 2017 and produced disparate impact for Black and Hispanic applicants; an immigration-status knockout rule in use until June 30, 2023; and inaccurate adverse-action notices under ECOA and Regulation B.
  • Governance (¶¶67–72): a written corporate governance system of fair lending testing, internal controls and risk assessments for AI models, reviewed at least annually; an internal algorithmic oversight team with a named chairperson; and a way for anyone at Earnest to report algorithmic-bias concerns without repercussions.
  • Policies (¶¶73–75): written policies for responsible design, development and deployment of AI models, including a Model Risk Management policy with specific provisions for compliance with Regulation B; annual fair lending testing of algorithmic underwriting models with defined trigger events; an annual inventory of models covering training algorithms, training and test data, parameters, dates in use and test results; and four-year retention of decision documentation.
  • Knockout rules and judgmental underwriting (¶¶76–77): annual fair lending testing, inventory and a designated steward for knockout rules; training, annual assessment and override controls for human underwriters, with four-year records.
  • Adverse action (¶78): policies to ensure adverse-action models comply with 15 U.S.C. §1691(d), including methods to use interpretable models for credit underwriting, to validate the accuracy of every decline reason, and to ensure notices state the principal reasons specifically and accurately.
  • Prohibitions (¶¶79–82): no AI model or process may use the school rank or Cohort Default Rate variables as inputs; the immigration-status knockout must stay discontinued and not be replicated by any model; Earnest may not ask consumers for access to a social-media account as a step in applying for a loan.
  • Oversight (¶¶83–89): self-review of ECOA, Regulation B and AOD compliance within 180 days of the Effective Date (an independent third party may assist), corrective action within 90 days, a written report to the Attorney General within 60 days, then annual reports for three years, plus raw data on request; the Attorney General must give 10 days' notice and meet and confer before seeking judicial intervention (¶89).

What did Massachusetts AG Earnest Operations settlement (July 2025) change for banks?

The settlement turned the Attorney General's April 2024 AI advisory into a concrete expectation for lenders: fair-lending testing of models and of the human judgment layered on top of them, a model inventory, a named oversight function, and decline reasons that can be traced to the model's real drivers. It also shows the office is willing to treat a lender's failure to test for disparate impact, and training a model on arbitrary human selections, as an unfair or deceptive practice under c. 93A. It does not create new law and the allegations are unproven, but its governance terms are a ready-made checklist for any bank's model risk and fair-lending teams.

What does the Massachusetts AG's Earnest settlement require of an AI lender?

The Earnest Operations LLC assurance of discontinuance, announced July 10, 2025, requires a $2.5 million payment and a fair-lending-centred AI governance program. Earnest must maintain a written governance system with an internal algorithmic oversight team, run annual fair-lending tests of its algorithmic underwriting models, knockout rules and judgmental underwriting, keep an annual inventory of every underwriting model and rule, retain four years of decision documentation, use interpretable models with validated adverse-action reasons, and stop using the Cohort Default Rate and school rank variables and the immigration-status knockout. It must review its own compliance within 180 days of the effective date, fix gaps, and report to the Attorney General annually for three years. The AOD binds only Earnest and Earnest denies the allegations, but it is the most detailed public template of what the office expects from a lender using AI.

RuleAuthorityWhat it requiresApplies
¶64 — Monetary payment ↗Massachusetts AGPay $2,500,000 to the Commonwealth within 30 days of the Effective Date (the date the AOD is filed in court).Announced July 10, 2025
¶¶67–72 — Corporate governance ↗Massachusetts AGMaintain a written governance system of fair lending testing, internal controls and risk assessments for AI models, with an algorithmic oversight team and chairperson, annual review, and a no-retaliation channel for bias concerns.From the Effective Date
¶¶73–74 — Written policies and model risk management ↗Massachusetts AGAdopt written policies for the design, development and deployment of AI models, including a Model Risk Management policy with Regulation B compliance provisions and accountability for documenting model-development decisions.From the Effective Date
¶75 — Underwriting models ↗Massachusetts AGTest and retrain models for fair lending law compliance, run annual fair lending testing with trigger events, inventory models annually (algorithms, data, parameters, dates, test results), retain decision documentation four years and keep account-level data.Annual; from the Effective Date
¶76 — Knockout rules ↗Massachusetts AGAssess and monitor every knockout rule, test annually, inventory features, thresholds and time in use, and designate a steward responsible for testing, documentation and data.Annual; from the Effective Date
¶77 — Judgmental underwriting ↗Massachusetts AGTrain human underwriters on fair lending law, assess decisions annually, control overrides and adjustments to scores or prices, and retain documentation for at least four years.Annual; from the Effective Date
¶78 — Adverse action notices ↗Massachusetts AGUse interpretable models for credit underwriting, validate the accuracy of each decline reason on every notice, and state the principal reasons specifically and accurately under 15 U.S.C. §1691(d).From the Effective Date
¶¶79–82 — Discontinued variables and practices ↗Massachusetts AGDo not use the school rank or Cohort Default Rate variables as inputs, keep the immigration-status knockout rule discontinued and un-replicated, and do not require access to social-media accounts to apply for a loan.From the Effective Date
¶¶83–88 — Compliance review and reporting ↗Massachusetts AGReview ECOA, Regulation B and AOD compliance within 180 days, implement corrective action within 90 days, report within 60 days, then file annual reports for three years and provide data on request.180-day review from the Effective Date; annual reports for three years

The AOD's allegations explain its remedies. The office alleged that Earnest trained a scorecard model on human-selected variables and weights without firm procedures for deciding whether they predicted default, that the Cohort Default Rate subscore penalized Black and Hispanic applicants more than White applicants, that a later model was designed in part to replicate those earlier decisions, and that nobody tested the models or the human underwriting layer for disparate impact. It also alleged that the compliance officer never received the written certification Earnest's own policy required before a new underwriting criterion went live. Each undertaking in Part IV answers one of those findings.

The adverse-action terms are the most transferable. The AOD alleges that Earnest's staff picked decline reasons from a drop-down menu that omitted variables the models actually used, such as Cohort Default Rate, school rank and degree type, and chose an available reason instead, and that an auto-generated reasons model sometimes produced nothing specific. The remedy is a requirement to use interpretable models, to validate each reason on every notice, and to state the principal reasons accurately, which is a direct application of ECOA and Regulation B to AI.

The AOD is not a rule and binds only Earnest, which denies the allegations. Its release does not bind other private or governmental entities. For banks it is evidence of the Attorney General's enforcement theory under c. 93A, and a benchmark for how a regulator might measure a lender's AI governance. Federally chartered institutions answer first to their federal regulators and the AOD does not address preemption.

WHAT THIS MEANS IN PRACTICE

  • Map every credit model and knockout rule into a single inventory with training data, parameters, dates in use and latest fair lending test results, refreshed at least annually and after trigger events.
  • Run annual disparate-impact testing on models, on their individual weighted inputs and on human overrides, and keep the reports, documentation and analyses as examinable records.
  • Reconcile the reason codes in adverse-action systems against the variables the models actually use, and test that a model-generated decline always yields a specific, accurate reason.
  • Review any variable that proxies for school, geography or immigration status, and any rule that denies applicants before creditworthiness is assessed, for national-origin and race risk.
  • Name an accountable oversight function (a chair or committee) with a protected route for staff to raise algorithmic-bias concerns, and make sure compliance sign-off on new underwriting criteria really happens and is recorded.

What did the Massachusetts AG's Earnest settlement require?

Earnest Operations LLC agreed to pay $2.5 million, build a written AI governance program with an algorithmic oversight team, test its underwriting models and knockout rules for fair lending every year, inventory its models, keep four years of decision records, use interpretable models with validated adverse-action reasons, stop using the Cohort Default Rate and school rank variables, and report to the Attorney General. It denies the allegations.

Did Earnest admit wrongdoing in the Massachusetts settlement?

No. The assurance of discontinuance states that Earnest denies the allegations and any violation of Massachusetts or federal law, and that agreeing to the AOD is not an admission. The allegations are the Attorney General's, and the AOD says it does not approve Earnest's practices.

Does the Earnest settlement apply to banks?

It binds only Earnest, and the Attorney General's release does not bind any other party. Banks are not parties, but its governance, testing and adverse-action terms show what the office expects of lenders using AI, and a bank's exposure under c. 93A and ECOA depends on its charter and facts.

How does the Earnest settlement compare with SR 11-7 model risk management?

Its model inventory, independent oversight, validation of outputs and ongoing monitoring resemble familiar model risk practice, but the AOD is built around fair lending: annual disparate-impact testing of models, knockout rules and human overrides, and validation that each adverse-action reason is accurate. It is a state enforcement outcome, not supervisory guidance.

DateDocumentStatus
Apr 16, 2024Massachusetts AG AI Advisory (April 2024) — Attorney General Advisory on the Application of the Commonwealth's Consumer Protection, Civil Rights, and Data Privacy Laws to Artificial IntelligenceIn force
Aug 11, 2026Colorado AG proposed ADMT rules — Proposed Automated Decision-Making Technology and Conversational AI Service Rules (Notice of Rulemaking Hearing)Comment period open
Jul 24, 2026Regulation (EU) 2026/1744 (Digital Omnibus on AI) — Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)In force
Jun 24, 2026RBI draft Guidance on Regulatory Principles for Model Risk Management — Guidance on Regulatory Principles for Model Risk Management, 2026 (draft released for public comments)Proposed
May 19, 2026Draft Commission guidelines on high-risk classification — Draft Commission Guidelines on the classification of high-risk AI systems under Article 6 of the AI ActProposed
May 14, 2026SB 26-189 — Automated Decision-Making Technology Act (repeal and reenactment of the Colorado AI Act)Final

Follow every document these regulators publish

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning