Bank AI regulations in the United States are a set of existing supervisory instruments covering model risk, third-party risk, consumer protection and information security, which a bank reads its AI use cases against.

This guide sets out which instruments apply, what the April 2026 revision to model risk guidance moved out of scope, how to map a use case to the rules that attach to it, and the evidence supervisors ask for.

Bank compliance officers reviewing bank AI regulations documentation in a meeting room.

What Counts as AI Regulation for a U.S. Bank

Five instruments carry most of the weight in terms of AI regulation:

  1. The interagency guidance on model risk management
  2. The 2023 interagency guidance on third-party relationships
  3. The Equal Credit Opportunity Act and its implementing Regulation B
  4. The Gramm-Leach-Bliley Act information security standards
  5. The statutory prohibitions on unfair, deceptive or abusive acts and practices

The obligation attaches to the decision the model makes, whether that is a credit denial, a suspicious-activity referral or a capital estimate, and the rule that has always governed that decision governs it still.

What the April 2026 Model Risk Guidance Changed

On 17 April 2026 the OCC, the Federal Reserve and the FDIC issued revised guidance on model risk management, superseding SR 11-7 and the OCC bulletins that carried it. Certain changes are applicable to regulating AI in particular:

A model is now defined as a complex quantitative method applying statistical, economic or financial theories. Scope is calibrated to materiality, judged by a model’s purpose and exposure, and the guidance introduces a $30 billion asset threshold.

Generative and agentic AI models were excluded outright on the stated grounds that they are novel and rapidly evolving. The agencies announced a request for information on model risk management and bank use of AI. The guidance also states that it does not set forth enforceable standards.

A large-language-model assistant drafting policy summaries is not covered by the model risk guidance, nor is it unsupervised. It falls instead to the bank’s broader operational risk, third-party and consumer protection frameworks.

Reading an AI Use Case Against Existing Rules

Classify the use case by what it decides and who it touches, then attach the instruments that already govern that decision.

The table below maps the four most common patterns in bank AI deployments to the rule that reaches them and the evidence a bank retains.

AI use caseGoverning instrumentWhat triggers itEvidence retained
Credit scoring or underwritingECOA and Regulation B; model risk guidanceAn automated decision affecting a credit applicantSpecific denial reasons; fair lending testing records
Vendor-supplied compliance assistantInteragency third-party risk guidanceReliance on an external provider for a banking activityDue diligence file; contract terms; performance monitoring
Transaction monitoring or AML triageBSA/AML program rules; model risk guidanceA model influencing suspicious-activity decisionsTuning documentation; validation and override logs
Generative drafting or summarizationOperational risk and information security policyStaff use of a model on non-public customer dataAccess controls; usage policy; output review records

The Evidence Supervisors Expect

Supervision of AI runs through ordinary examination work. In remarks delivered on 27 April 2026, Federal Reserve Vice Chair for Supervision Michelle Bowman said banks are relying on existing risk-management frameworks to guide their use of AI.

Four artifacts carry the burden:

  1. An inventory of AI systems in use
  2. Ongoing performance monitoring with documented thresholds
  3. Third-party due diligence files for vendor-supplied models
  4. A record of who approved the use case and on what basis

Adverse Action and Fair Lending Evidence

Regulation B, at 12 CFR 1002.9, requires a creditor to give the specific principal reasons for an adverse action. Model complexity is not an exemption, and a reason drawn from a generic sample list does not satisfy the requirement when it fails to reflect the actual basis for the denial.

The CFPB withdrew 67 interpretive rules, policy statements and advisory opinions in May 2025, according to its Federal Register notice. The regulation itself is unchanged, which is why interpretation is the operative skill.

Documenting AI Oversight in Practice

Governance, risk and compliance platforms hold this documentation in one place. Predict360 centralizes risk and compliance data from multiple business units and creates risk and regulatory relationships between organizational activities.

Its regulatory change management module tracks new and updated regulations across relevant sources, maps those changes to the policies and procedures they affect, and notifies the stakeholders attached to the affected documents.

Frequently Asked Questions

Is There a U.S. Law That Regulates Bank Use of AI?

No federal statute governs bank AI use specifically. Obligations come from rules already applying to the underlying activity, among them lending, information security, third-party reliance and anti-money-laundering programs, and from supervisory guidance on model risk management. State law adds requirements in some areas, notably insurance and consumer data.

Does the Revised Model Risk Guidance Apply to Generative AI?

No. The April 2026 revised guidance excludes generative and agentic AI models, describing them as novel and rapidly evolving, and the agencies have announced a request for information on the subject. Traditional statistical models and non-generative machine learning remain in scope where they meet the narrowed definition of a model.

Who Regulates AI in Banking?

The OCC, Federal Reserve and FDIC supervise safety-and-soundness aspects through examination. The CFPB enforces consumer financial law, including ECOA, for larger institutions. State banking departments and attorneys general apply state consumer protection law, and functional regulators reach specific activities.

Transform Your Compliance Workflow

Learn how Ask Kaia can assist your organization’s compliance team in gaining clarity on regulatory changes.

Request Demo
  • Policy Drafting
  • Compliance Automation
  • Audit Trails
  • Regulatory Intelligence