US Financial Services AI Rules carries 14 tracked obligations for companies in scope. This guide lists who is covered, the duty tiers, and every obligation with its deadline and statutory citation — all from Shieldra's versioned regulation pack, verified 2026-09-09.
What are the duty tiers under US Financial Services AI Rules?
Credit-decision model duties (ECOA / Reg. B (12 CFR 1002.9); FCRA §615; N.J.A.C. 13:16; Ill. P.A. 104-0744)
Citation: ECOA / Reg. B (12 CFR 1002.9); FCRA §615; N.J.A.C. 13:16; Ill. P.A. 104-0744 — https://www.federalregister.gov/documents/2026/04/22/2026-07804/equal-credit-opportunity-act-regulation-b
AI in credit decisions triggers adverse-action explainability and, in New Jersey and Illinois, documented disparate-impact and less-discriminatory-alternative testing. Federal examiners no longer review disparate impact (NCUA Letter 25-CU-04; FTC statement of 7 August 2026), but private plaintiffs and state regulators do.
Insurance AI governance and testing duties (NAIC Model Bulletin on the Use of AI Systems by Insurers (Dec. 2023); NYDFS Circular Letter No. 7 (2024); 3 CCR 702-10 (Colo. Reg. 10-1-1); state payer-AI statutes)
Citation: NAIC Model Bulletin on the Use of AI Systems by Insurers (Dec. 2023); NYDFS Circular Letter No. 7 (2024); 3 CCR 702-10 (Colo. Reg. 10-1-1); state payer-AI statutes — https://content.naic.org/sites/default/files/legal-adoption-map-ai-model-bulletin.pdf
Insurance regulators enforce through market-conduct examination and unfair-trade-practice statutes rather than AI-specific penalties; the NAIC's twelve-state AI Systems Evaluation Tool pilot (March–September 2026) previews the document requests. Health-coverage AI is separately constrained by statute in at least eleven states and by Medicare Advantage rules.
Securities-firm AI supervision and disclosure duties (FINRA Regulatory Notice 24-09 and 2026 Regulatory Oversight Report; SEC FY2026 Examination Priorities; Regulation S-P)
Citation: FINRA Regulatory Notice 24-09 and 2026 Regulatory Oversight Report; SEC FY2026 Examination Priorities; Regulation S-P — https://www.finra.org/rules-guidance/guidance/reports/2026-finra-annual-regulatory-oversight-report/gen-ai
No AI-specific rule has been adopted by the SEC or FINRA; existing supervision, communications, recordkeeping, privacy, and antifraud rules are applied technology-neutrally, and AI representations are an examination priority.
Financial-services baseline (U.S. Treasury, Uses, Opportunities, and Risks of AI in Financial Services (19 Dec. 2024))
Citation: U.S. Treasury, Uses, Opportunities, and Risks of AI in Financial Services (19 Dec. 2024) — https://home.treasury.gov/news/press-releases/jy2760
You are a US financial-services firm but reported no AI in credit, insurance, or securities activity. The general governance expectation below still applies; re-screen when AI enters a decision, a customer interaction, or a vendor relationship.
What should you do about each obligation?
AI governance your regulator expects: inventory, validation, human oversight, vendor oversight (U.S. Treasury, Uses, Opportunities, and Risks of AI in Financial Services (Dec. 2024); NIST AI RMF 1.0)
Keep an inventory of AI uses with tiered governance by risk; run pre-deployment compliance review of higher-risk generative-AI uses (privacy, cybersecurity, bias, lending and consumer-protection rules); assign human oversight and accountability; monitor performance and drift; and oversee AI vendors as you would any critical third party. Treasury's December 2024 report recommends exactly this and alignment to the NIST AI Risk Management Framework; examiners across the banking, insurance, and securities regulators now ask for it, and the OCC's Spring 2026 Semiannual Risk Perspective expects human oversight in AI workflows and governance covering explainability, data poisoning, privacy, and validation.
Specific, accurate principal reasons in AI-driven adverse-action notices (Reg. B and FCRA) (12 CFR 1002.9(b)(2); FCRA §615, 15 U.S.C. 1681m; CFPB Reg. B final rule (22 Apr. 2026, eff. 21 July 2026))
Deliver the specific principal reasons that actually drove each adverse credit decision, which requires mapping model outputs to accurate reasons regardless of model complexity; sample-form checklist reasons that were not the real drivers do not satisfy the rule. Give FCRA adverse-action notices whenever consumer-report data contributed. The CFPB withdrew Circulars 2022-03 and 2023-03 on 12 May 2025 and reports no active AI supervisory guidance, and its Regulation B rule effective 21 July 2026 states ECOA has no disparate-impact liability while confirming that intentional proxies remain disparate treatment; that rule is under APA challenge in the D.D.C. with briefing into January 2027, and the Fair Housing Act's disparate-impact standard still governs mortgage lending. There is no 'CFPB Circular 2026-03' on AI adverse action, despite claims in some vendor material.
New Jersey and Illinois: documented disparate-impact and less-discriminatory-alternative testing for credit models (N.J.A.C. 13:16 (adopted 15 Dec. 2025); Ill. P.A. 104-0744 (SB 3777, signed 31 July 2026, eff. 1 Jan. 2027); Mass. AG–Earnest settlement (July 2025))
Test credit, pricing, scoring, and fraud models for disparate impact on protected classes and document a less-discriminatory-alternative search. New Jersey's rules under the Law Against Discrimination cover lending and use a two-step burden shift: the lender must show a substantial legitimate interest and that no less-discriminatory alternative exists, and the Division on Civil Rights' January 2025 guidance expects pre- and post-deployment evaluation, bias audits, impact assessments, and reasonable steps with vendors. Illinois codifies the same standard for credit decisions from 1 January 2027, reaching pricing models, automated underwriting, and fraud tools. Massachusetts enforced the theory against Earnest in July 2025 ($2.5M; AI underwriting variables, no disparate-impact testing, inaccurate adverse-action notices) and required written AI governance and periodic fair-lending testing. Federal examiners no longer require this testing; these states and private litigation do.
Model risk management under the revised interagency guidance (April 2026) (OCC Bulletin 2026-13; Federal Reserve SR 26-2; FDIC FIL (17 Apr. 2026))
Maintain a model inventory; document development and implementation; validate independently with outcomes analysis and ongoing monitoring at a risk-based frequency (the fixed annual cadence was removed); assign clear roles with board and senior-management oversight; and develop an understanding of, and monitor, third-party models. The revised guidance is principles-based and narrows 'model' to complex quantitative methods, excluding deterministic rule-based processes, and community banks need not perform annual validation (OCC Bulletin 2025-26). It states that generative and agentic AI models 'are not within the scope of this guidance'; the agencies said they would issue a request for information on AI including generative and agentic AI, which had not appeared as of September 2026 — apply general risk-management and third-party principles to those systems in the meantime.
Controls for generative and agentic AI: testing, logging, human-in-the-loop, guardrails (FINRA 2026 Annual Regulatory Oversight Report (Gen AI and agentic AI sections); OCC Semiannual Risk Perspective, Spring 2026; NIST AI 600-1)
Put generative and agentic AI under enterprise-level supervision: formal review and approval before use; pre-deployment and ongoing testing for privacy, integrity, reliability, and accuracy; logging of prompts, outputs, and model versions; human-in-the-loop validation with regular error and bias checks; vendor cybersecurity review; and, for agents, defined guardrails, action tracking, and human-oversight points — an agent's actions are subject to the same controls as an associated person performing the function. Watch for prompt injection (FINRA guidance, March 2026) and for the liability gap in vendor terms, which typically disclaim output quality and cap liability at twelve months' fees while an agent can move far more; set spend and authority limits and immutable authorization records. Regulation S-P and GLBA safeguards apply to any customer data these tools touch.
GLBA Safeguards: AI tools and vendors inside the information security program (16 CFR Part 314 (FTC Safeguards Rule); Interagency Guidelines Establishing Information Security Standards; 12 CFR Part 364 App. B)
Bring every AI tool and vendor that ingests nonpublic personal information into the written information security program: cover them in the risk assessment; apply access controls, encryption, and multi-factor authentication; conduct service-provider due diligence and contractual oversight; and stop 'shadow AI' — employees pasting customer data into public LLMs is a safeguards failure. Notify the FTC within 30 days of a breach affecting 500 or more consumers (non-bank institutions). The FTC has issued no AI-specific safeguards guidance; the existing rule is applied as written.
Regulation S-P: incident response and oversight of AI service providers (Regulation S-P amendments (adopted 16 May 2024), 17 CFR Part 248)
Treat AI vendors and LLM APIs that receive customer information as service providers under Regulation S-P: include them in the written incident-response program, require them to notify you within 72 hours of a breach, oversee them through due diligence and monitoring, and keep the required records. Notify affected customers within 30 days of a breach reasonably likely to cause substantial harm. AI tools that process customer information also fall under the safeguards program.
FINRA: supervise AI under Rules 3110, 2210, and 4511 as technology-neutral rules (FINRA Rules 3110, 2210, 4511; SEA Rule 17a-4; FINRA Regulatory Notice 24-09; 2026 Annual Regulatory Oversight Report)
Apply written supervisory procedures to every generative-AI use: model risk management with documentation, accuracy and hallucination controls, bias and privacy testing, third-party accountability, and recordkeeping of AI-generated communications (chatbots, meeting summaries) under Rule 4511 and SEA 17a-4. Communications with the public produced with AI remain subject to Rule 2210's fair-and-balanced and approval requirements. FINRA's 2026 report adds agentic-AI expectations: autonomy without human validation, scope creep, auditability, data exposure, and misaligned objectives are the named risks, and agent actions are supervised like an associated person's. Regulatory Notice 25-07 is a request for comment on workplace-rule modernization, not a rule. No FINRA disciplinary action premised on AI use had been reported as of September 2026.
SEC: accurate AI representations, pre-deployment evaluation, and human oversight (Advisers Act §206 and Marketing Rule 206(4)-1; Exchange Act §10(b); SEC FY2026 Examination Priorities)
Make only substantiated statements about AI in Form ADV, marketing, and client communications; maintain policies to evaluate AI tools before deployment, monitor outputs, and keep human oversight of material AI-driven decisions across fraud detection, back office, AML, trading, portfolio management, and customer service; and address AI-enabled cyber threats (polymorphic malware, deepfake social engineering). Enforcement: Delphia and Global Predictions (March 2024, Marketing Rule), Presto Automation (January 2025), Nate Inc. (April 2025, parallel criminal case). The 2023 predictive-analytics conflicts proposal was withdrawn on 12 June 2025 and the Chair has said misconduct is judged 'regardless of the medium' with no AI-specific rules planned.
NYDFS Circular Letter 7: proxy analysis, disparate-impact testing, governance, and transparency for AI underwriting and pricing (NYDFS Insurance Circular Letter No. 7 (2024))
Before using external consumer data or an AI system in underwriting or pricing: establish that it is actuarially supported with a clear, empirical, statistically significant relationship to risk; assess correlation with protected-class status; run the three-step unfair-discrimination analysis (disproportionate adverse effect, legitimate explanation, less-discriminatory alternative) before deployment, on a regular cadence, and on material change, using quantitative metrics (adverse impact ratio, standardized mean differences, marginal effects, disparity drivers) with documented methodology available to DFS; put board oversight, senior-management accountability, a cross-functional committee, annual policy review, an inventory with change tracking, complaint records, and internal audit in place; retain responsibility for vendor models with audit and regulatory-cooperation clauses; and in adverse-action notices disclose the use of AI and external data, the right to the underlying data, and specific reasons — with written declination reasons within 15 days for automated rejections. DFS has issued no further AI circular; its 2026 industry letters on frontier-AI cybersecurity risk apply to all Part 500 covered entities.
Written AI Systems Program under the NAIC Model Bulletin (or the state's own instrument) (NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (4 Dec. 2023) and state adoptions; Tex. TDI Bulletin B-0003-26)
Adopt and maintain a written program for the responsible use of AI systems across the insurance lifecycle (product development through claims and fraud): board or senior-management accountability; documented compliance requirements; risk-tiered oversight with data governance and lineage; model validation; testing for bias, unfair discrimination, and drift; internal audit; and third-party due diligence with contract terms giving audit and regulator-cooperation rights — the insurer remains responsible for vendor AI. Be ready to produce on examination the program, inventories, governance charters, testing results, vendor contracts, and complaint handling; the NAIC's AI Systems Evaluation Tool (12-state pilot, March–September 2026) sets out the four exhibits regulators will request, including per-system bias-test results and proxy-discrimination analysis. Texas's June 2026 bulletin expects a person to review and agree with every consequential AI decision before action. No state has yet imposed an AI-specific penalty on an insurer; enforcement runs through market-conduct examination.
Colorado Regulation 10-1-1: governance, quantitative testing, and annual attested reporting for external data and predictive models (3 CCR 702-10, Regulation 10-1-1 (as amended, eff. 15 Oct. 2025), implementing C.R.S. §10-3-1104.9 (SB 21-169))
Maintain the fourteen-component governance framework: documented governing principles; board or board-committee oversight; senior-management accountability; a cross-functional governance group; documented lifecycle policies with validation and training; a consumer-complaint process that gives people what they need to act after an adverse decision; risk assessment and prioritization; an inventory with version control; a change log; documented quantitative testing with methodology, assumptions, results, and remediation; ongoing monitoring including model drift; a documented vendor-selection and oversight process; and an annual comprehensive review. Health plans: a provider acting for the insurer is ultimately responsible for prior-authorization or concurrent-review denials informed by external data or models. File the attested annual compliance report (ten pages, officer attestation, corrective action plan if unable to attest) through SERFF — auto and health insurers' first report was due 1 July 2026. The separate quantitative-testing regulation for life underwriting (BIFSG race estimation, 5-percentage-point and 5% triggers) remains a draft; whether Bulletin B-10.004 supplies the Division's testing requirements should be confirmed with counsel.
Medicare Advantage: individual circumstances, physician review, and prior-authorization timelines (42 CFR 422.101(c), 422.566(d), 422.137; CMS HPMS memo of 6 Feb. 2024 on AI and algorithms; CMS-0057-F)
Base every medical-necessity determination on the individual patient's circumstances, following Traditional Medicare coverage criteria where they exist; have a physician or appropriate professional review each denial; and never let an algorithm or prediction be the basis for a denial or a termination — CMS's February 2024 guidance says AI may assist but cannot decide, and a predicted length of stay cannot itself trigger termination. Since 1 January 2026, decide prior authorizations within 72 hours (expedited) or 7 calendar days (standard), give specific denial reasons to providers, and publish annual prior-authorization metrics; the FHIR prior-authorization APIs are due 1 January 2027. The proposed CY2026 AI guardrail was dropped and the CY2027 rule adds no AI provisions, so the 2024 rule and FAQ remain the federal standard; the nH Predict class actions (UnitedHealth, Humana) are in discovery with a March 2026 order compelling nine years of algorithm records.
State payer-AI laws: a licensed clinician decides every medical-necessity denial; no sole reliance on AI (Cal. Health & Safety Code §1367.01 / Ins. Code §10123.135 (SB 1120); Tex. SB 815; Md. HB 820 and HB 1563; Neb. LB 77; Wash. SB 5395; Ind. HB 1271; Ala. SB 63; Utah SB 319; Ga. SB 544; Ariz. HB 2175; Ill. HB 2472)
Where you cover members in these states: only a licensed physician or clinical peer may deny, delay, or modify care on medical-necessity grounds; AI may support but may not be the sole basis of an adverse determination (Texas bars automated decision systems from making any part of an adverse determination); determinations must rest on the member's individual clinical history rather than group datasets; disclose AI use to the regulator, providers, and enrollees where required (Maryland quarterly reporting of whether AI was used in adverse decisions; Utah and Alabama disclosure and certification; Washington reporting to the Insurance Commissioner); review tools periodically for accuracy and bias; and keep them open to regulator audit. California's CDI guidance SB 1120:1 (5 May 2025) explains the state's expectations. Indiana's law targets AI-only downcoding. Colorado, Minnesota, and Illinois enacted further 2026 laws whose bill numbers were not confirmed at verification; re-check before relying on them.