Artificial intelligence is transforming the U.S. financial services industry at a pace that regulators are racing to match. From algorithmic trading and automated credit decisions to AI-powered fraud detection and customer service chatbots, banks, broker-dealers, insurance companies, and fintech firms are deploying machine learning models across every business function. But the regulatory landscape governing these deployments is neither simple nor unified. For CTOs and CISOs at American financial institutions, understanding the patchwork of federal and state requirements is no longer optional -- it is a fiduciary obligation.
This guide maps the major U.S. regulatory frameworks that affect AI adoption in financial services, explains their practical implications, and provides a compliance checklist your team can act on immediately. Whether you are a community bank deploying your first AI model or a regional institution scaling an existing program, these are the rules you must navigate.
The Federal Regulatory Framework
Unlike the EU, which has enacted a single comprehensive AI Act, the United States regulates AI through a layered system of sector-specific statutes, agency guidance, and supervisory expectations. For financial institutions, several federal frameworks converge.
- The GLBA Safeguards Rule requires financial institutions to protect nonpublic personal information (NPI). When AI systems ingest, process, or generate outputs from customer NPI, they fall squarely within the Safeguards Rule's scope. FEDERAL
- AI models trained on customer data must be inventoried as information systems under your GLBA risk assessment. Document what NPI each model accesses, how training data is stored, and whether inference outputs could re-identify individuals.
- The FTC's 2024-2025 enforcement actions have clarified that algorithmic outputs derived from NPI are themselves protected information. If your AI system generates risk scores, customer profiles, or behavioral predictions, those outputs inherit GLBA protections.
- Third-party AI vendors who receive NPI must be assessed under your GLBA service provider oversight program. The Safeguards Rule requires contractual protections and ongoing monitoring -- vendor assurances alone are insufficient.
- When AI systems contribute to financial reporting -- revenue forecasting, reserve calculations, impairment estimates, or journal entry analysis -- they become relevant to SOX Section 404 internal controls over financial reporting (ICFR). FEDERAL
- Auditors are increasingly asking for model documentation, validation records, and change management logs for AI systems that feed financial statements. The PCAOB's 2025 staff guidance flagged AI-assisted estimates as an area of heightened audit risk.
- Establish clear change control procedures for AI models that affect financial reporting. Any model retraining, feature engineering change, or threshold adjustment must go through your IT General Controls (ITGC) change management process.
- Maintain human-in-the-loop review for AI-generated financial figures. SOX requires that management can attest to the accuracy of financial statements -- full automation of material estimates without human validation creates attestation risk.
- The Federal Financial Institutions Examination Council's 2025 joint statement on AI/ML established supervisory expectations across all five member agencies (OCC, FDIC, Federal Reserve, NCUA, and CFPB). Examiners now evaluate AI governance as part of safety and soundness examinations. FEDERAL
- FFIEC expects institutions to apply risk management practices proportional to the complexity and materiality of each AI use case. A chatbot answering FAQs does not require the same governance rigor as a credit underwriting model -- but both need documentation.
- Board and senior management oversight of AI is now a supervisory expectation. Examiners will ask whether your board has been briefed on AI deployments, associated risks, and the institution's AI risk appetite.
- FFIEC guidance emphasizes the need for explainability in consumer-facing AI decisions. If your model cannot produce an explanation that satisfies adverse action notice requirements under Regulation B or ECOA, it should not be deployed for credit decisions.
- The SEC's proposed rule on predictive data analytics (PDA) -- initially introduced in 2023 and refined through 2025 -- targets broker-dealers and investment advisers that use AI to optimize for their own revenue at the expense of investor interests. Even before final rulemaking, the Commission has signaled that existing fiduciary duties apply to AI-driven recommendations. FEDERAL
- The SEC's Division of Examinations has added AI governance to its annual examination priorities for 2026. Registered firms should expect questions about AI model inventories, conflicts-of-interest assessments for algorithmic recommendations, and AI-related disclosures to clients.
- AI-washing -- making misleading claims about AI capabilities in marketing materials or investor communications -- has drawn SEC enforcement attention. In 2025, the Commission settled charges against two advisory firms for overstating their AI capabilities. Ensure marketing claims match actual model functionality.
- For public company disclosure, the SEC staff has indicated that material AI risks (model failure, regulatory action, data breaches involving AI systems) may need to be disclosed in risk factor sections and MD&A. Assess whether your AI program creates material risks warranting disclosure.
- OCC Supervisory Letter SR 11-7 (Supervision and Regulation Letter on Model Risk Management) remains the foundational guidance for AI model governance at national banks. The OCC confirmed in 2024 that SR 11-7 applies fully to AI and machine learning models, including deep learning and generative AI systems. FEDERAL
- SR 11-7 requires independent model validation. For AI models, this means a qualified team that did not build the model must validate its conceptual soundness, data integrity, performance metrics, and limitations before deployment -- and periodically thereafter.
- Model risk management must address the full lifecycle: development, implementation, use, and retirement. AI models that evolve through continuous learning or frequent retraining require validation triggers tied to material performance changes, not just calendar-based schedules. SR 11-7
- Maintain model risk reporting to the board or a designated board committee. SR 11-7 expects aggregate model risk reporting that includes the number of models in use, validation status, exceptions, and material findings -- AI models must be included in this reporting.
- The Federal Reserve Board's SR 11-7 companion guidance (SR 15-18 and subsequent supervisory letters) applies to state member banks and bank holding companies. The Fed has emphasized that AI governance must be integrated into existing enterprise risk management frameworks rather than treated as a standalone program. FEDERAL
- The Fed's 2025 supervisory guidance on third-party relationships explicitly addresses AI vendors and foundation model providers. Institutions must assess whether third-party AI creates concentration risk, model dependency, or data sovereignty concerns.
- Fair lending implications of AI are a Federal Reserve enforcement priority. The Fed expects institutions using AI for credit decisions to conduct disparate impact testing and document any less discriminatory alternatives that were considered. FAIR LENDING
- The Federal Reserve has joined other agencies in endorsing the NIST AI Risk Management Framework as a useful reference for financial institutions. While not mandatory, alignment with NIST AI RMF demonstrates good-faith governance to examiners.
State-Level AI Regulation
Beyond federal oversight, financial institutions must contend with a growing body of state AI legislation. These laws vary significantly in scope, but several directly affect financial services operations.
- The New York Department of Financial Services cybersecurity regulation (23 NYCRR 500), as amended in 2023 and fully effective in 2025, imposes specific requirements on covered entities that extend to AI systems. Any AI system that accesses nonpublic information or connects to your information systems is an in-scope asset. STATE
- 23 NYCRR 500 requires a written cybersecurity policy approved by a senior officer or the board. That policy must now address AI-specific risks: model tampering, adversarial attacks, training data poisoning, and AI-enabled threat vectors targeting your institution.
- The regulation's access control, encryption, and audit trail requirements apply to AI infrastructure. Model training environments, inference APIs, and vector databases that store customer data must meet the same security controls as traditional information systems.
- Annual penetration testing and vulnerability assessments under 23 NYCRR 500 should now scope AI systems. NYDFS examiners are asking whether institutions have tested their AI models for adversarial vulnerabilities alongside traditional infrastructure testing.
- Colorado's AI Act (SB 24-205), effective February 2026, requires deployers of high-risk AI systems -- including those making insurance and lending decisions -- to conduct impact assessments, disclose AI use to consumers, and provide opt-out mechanisms where feasible. STATE
- Illinois' AI Video Interview Act and the proposed Illinois AI Accountability Act impose transparency requirements on automated decision-making in employment and financial services. Institutions with Illinois operations or customers must evaluate compliance obligations.
- Connecticut, Texas, Virginia, and California have enacted or proposed AI governance legislation that could affect financial services. California's proposed AI transparency and accountability framework, if enacted, would create disclosure and audit requirements for high-impact AI systems deployed in the state. STATE
- Multi-state compliance is unavoidable. Financial institutions operating across state lines should adopt a highest-common-denominator approach: build AI governance to satisfy the most stringent state requirements and you will meet most others by default.
Practical Compliance Checklist
The following checklist synthesizes the regulatory requirements above into actionable steps. Each item is tagged to the frameworks it addresses, allowing your team to prioritize based on your institution's specific regulatory exposure.
- Build and maintain a centralized AI model inventory with model owner, data inputs, use case classification, risk tier, validation status, and deployment date. Update it quarterly at minimum. SR 11-7 FFIEC
- Conduct AI-specific risk assessments for each model, evaluating fair lending risk, data privacy exposure (GLBA), financial reporting impact (SOX), and cybersecurity posture (23 NYCRR 500). FEDERAL STATE
- Implement independent model validation per SR 11-7 for all material AI models. Ensure validation covers conceptual soundness, data quality, ongoing performance monitoring, and outcomes analysis. SR 11-7
- Document AI governance policies and obtain board-level or senior management approval. Include AI risk appetite, acceptable use policies, and escalation procedures for model failures. FFIEC
- Run disparate impact testing on all AI models used in credit, insurance, or employment decisions. Document the results and any less discriminatory alternatives considered. FAIR LENDING
- Review AI vendor contracts for GLBA compliance, data residency, model training restrictions, and sub-processor controls. Assess concentration risk across foundation model providers. FEDERAL
- Integrate AI systems into your SOX ICFR framework where models affect financial reporting. Establish change management procedures, human review checkpoints, and audit trails. SOX
- Conduct annual AI-focused penetration testing and adversarial robustness assessments, particularly for institutions subject to 23 NYCRR 500. NYDFS
- Prepare AI impact assessments for deployments in states with enacted AI legislation (Colorado, Illinois, Connecticut). Implement consumer disclosure and opt-out mechanisms where required. STATE
- Establish an AI incident response playbook covering model failure, biased outputs, data breaches involving AI systems, and regulatory inquiries. Test it through tabletop exercises at least annually. FFIEC NYDFS
Looking Ahead: 2026-2027 Regulatory Outlook
The regulatory environment for AI in financial services will continue to tighten. The SEC's predictive data analytics rulemaking is expected to reach final form in late 2026 or early 2027. The CFPB has signaled increased scrutiny of AI-driven consumer lending, particularly around adverse action notice requirements for opaque models. Meanwhile, more states are introducing AI governance bills, and the federal government continues to explore comprehensive AI legislation, though bipartisan consensus remains elusive.
For CTOs and CISOs, the strategic imperative is clear: build AI governance infrastructure now, while you can do it proactively rather than reactively. Institutions that treat AI compliance as an afterthought will face not only regulatory penalties but also reputational damage and operational disruption when examiners arrive. Those that embed compliance into their AI development lifecycle will gain a durable competitive advantage -- the ability to deploy AI faster and with confidence that they can withstand scrutiny.
The U.S. regulatory framework for AI in financial services is complex, but it is not unknowable. The agencies have been remarkably transparent about their expectations. The institutions that will thrive are those that listen, act, and document -- in that order.
Need Help Navigating AI Compliance?
Our team advises U.S. financial institutions on AI governance, model risk management, and regulatory compliance. We help you build frameworks aligned with FFIEC, OCC SR 11-7, NYDFS, and emerging state requirements -- before examiners ask the questions.
Book a Consultation