No single rulebook governs bank AI — 50 documents are in force across 18 authorities, and what applies to you depends on charter, size and footprint. This page is the working orientation: the five documents to read first, the deadlines on your desk this quarter, the warnings your fraud and cyber teams should have seen, and the standing pages that keep each moving part current.
Which five documents should a compliance officer read first?
| # | Document | Why it's first |
|---|---|---|
| 1 | SR 26-2 Federal Reserve | The framework US examiners test AI models against — and the one that deliberately excludes generative and agentic AI. |
| 2 | Regulation B final rule on disparate impact (April 2026) CFPB | What federal fair-lending exposure for AI underwriting looks like after disparate impact — and what still applies (adverse-action notices). |
| 3 | Regulation (EU) 2024/1689 EU AI Act | The only binding cross-sector AI law reaching banks; credit scoring is named high-risk, compliance due December 2, 2027. |
| 4 | FSB AI sound practices consultation (June 2026) FSB | The 12 practices most likely to become the global supervisory baseline — the final report is a 2026 G20 deliverable. |
| 5 | NIST AI RMF 1.0 NIST | The voluntary framework US agencies keep referencing — the closest thing to a common vocabulary for AI risk programs. |
What is due next?
| Date | Authority | Deadline |
|---|---|---|
| Oct 20, 2026 | CFTC | CFTC Compute Derivatives RFC: comment period closes · Comment deadline |
| Oct 26, 2026 | Colorado AI Act | Colorado AG proposed ADMT rules: comment period closes · Comment deadline |
| Oct 31, 2026 | ECB | Deadline for significant institutions to submit AI-cyber action plans to their JSTs · Milestone |
The full checklist, quarter by quarter → · 2 consultations still open for comment
Which warnings should risk teams have read?
| Jul 31, 2026 | ESA Statement on ICT risks from frontier AI models (JC 2026 25) — On July 31, 2026 the EBA, EIOPA and ESMA published joint statement JC 2026 25 on ICT risks from frontier AI models, warning that highly capable AI models sharply accelerate vulnerability discovery… |
| Jul 24, 2026 | FIN-2026-Alert004 (Federal Student Aid Fraud) — FinCEN Alert FIN-2026-Alert004, issued July 24, 2026, asks financial institutions to detect and report fraud rings stealing federal student aid through 'ghost students' and 'straw students.' It… |
| Jul 7, 2026 | ECB 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301) — On 7 July 2026 Claudia Buch, Chair of the ECB Supervisory Board, sent letter SSM-2026-0301, 'Addressing AI-enabled cybersecurity threats', to the CEO of every significant institution. |
Which rules govern each AI system you run?
Credit scoring, AML monitoring, fraud models, chatbots, generative AI — each use case answers to a different set of documents, and the strictest rules follow the use case, not the technology. The use-case matrix maps every system type to its governing documents across all 18 authorities, with each document's current status.
Which AI rules apply to my bank right now?
It depends on your charter and footprint. Every US bank: ECOA/Regulation B adverse-action requirements, FCRA, UDAAP, BSA/AML expectations, and — for institutions over roughly $30B — the April 2026 revised interagency model risk management guidance. New York-regulated institutions add 23 NYCRR Part 500 and the DFS AI letters. EU operations add the AI Act (high-risk obligations from December 2, 2027) and ECB supervisory expectations. Lending into Colorado adds the ADMT Act from January 1, 2027. The by-use-case matrix maps each of your AI systems to its governing documents.
Where should a compliance officer start with AI regulation?
Read five documents before anything else: the revised interagency model risk guidance (SR 26-2 / Bulletin 2026-13), the CFPB's April 2026 Regulation B rule, the EU AI Act if you have EU exposure, the FSB's 12 proposed sound practices, and the NIST AI Risk Management Framework. Together they cover what examiners test today, what fair-lending law still requires, the one binding AI statute, and the two frameworks supervisors keep referencing.
How do I keep up with AI regulatory changes?
Three moving parts are worth a standing watch: dated deadlines (tracked on the checklist and calendar pages, recomputed daily), new documents (18 authorities tracked, each new bulletin or rule added as a standing page), and formal warnings (FinCEN alerts, Dear-CEO letters). The daily brief carries each regulatory move the morning after it happens; the tracker pages hold the durable record.
The brief your examiners can't surprise
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →