Use-case guide

AI in Finance & Banking

Financial services has the longest history of model-risk regulation of any industry — and AI is the next chapter, not a new beginning. Credit decisions, fraud scoring, anti-money-laundering surveillance, and algorithmic trading were all already under regulator scrutiny before generative AI arrived. What changed in 2024-2026 is that AI-specific laws are now stacking on top of the existing model-risk rules: the EU AI Act treats credit and insurance pricing as high-risk by default, Colorado classifies consumer finance as a consequential-decision domain, and bank supervisors (Fed/OCC/FCA/ECB) have all issued AI-specific guidance that pulls model-risk principles into the AI era.

For: Banks, insurers, asset managers, fintech founders, compliance and model-risk officers

What's at stake

Credit and insurance are high-risk under the EU AI Act

Annex III §5 of the EU AI Act explicitly lists 'AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score' and 'AI systems intended for risk assessment and pricing in relation to natural persons in the case of life and health insurance' as high-risk. Full Annex III obligation stack applies.

Model-risk management is already mandatory

Banks have been operating under SR 11-7 (Federal Reserve) and similar regimes (OCC 2011-12, UK PRA SS1/23, ECB Guide to TRIM) for over a decade. AI is treated as 'just a particular kind of model' — but the model-risk management framework now extends to feature stores, training pipelines, and post-deployment drift.

Adverse-decision explanations are a legal right, not a nice-to-have

ECOA / Regulation B in the US requires 'specific reasons' for adverse credit decisions. GDPR Article 22 + the right-to-meaningful-information rule applies the same logic in the EU. An AI explanation that says 'the model said no' is not legally sufficient.

Bias liability is concentrated in fair lending

Disparate-impact theory under ECOA and the UK Equality Act has been actively enforced against algorithmic credit decisioning. The CFPB, OCC, and FCA have all signalled that they consider an unexplainable model a per-se compliance failure for adverse-action explanations.

Regulations that apply

Do

  • ✓Bring AI under your existing model-risk framework on Day 1 — don't build a parallel governance regime that competes with model-risk for resources.
  • ✓Document the chain of explanation from raw feature → model output → adverse-action reason, in language a customer can understand.
  • ✓Run fair-lending analysis (disparate impact + disparate treatment) before deployment AND on a quarterly basis afterwards.
  • ✓Maintain a champion-challenger benchmark — a simpler model (logistic regression, GBT) you can fall back to and explain to regulators.
  • ✓Set up a feedback loop from servicing/collections back to model monitoring — drift on input features is the most common cause of post-deployment fair-lending failures.

Don't

  • ✗Don't use a generative AI summary as the underwriting rationale of record — regulators expect a structured, reproducible, machine-readable explanation.
  • ✗Don't deploy AI that uses ZIP code, surname, or other proxy features for protected classes — the CFPB has been explicit that proxies count as direct use.
  • ✗Don't conflate consent with lawful basis under GDPR for credit-scoring — Article 6(1)(b) (contractual necessity) is usually the right basis, not Art. 6(1)(a) consent.
  • ✗Don't let the model risk function and the AI ethics function build separate inventories — they'll diverge within a year and you'll have two incomplete pictures.
  • ✗Don't ignore the second-line independent challenge requirement just because the model 'is just a small adjustment' — Fed SR 11-7 has no de-minimis carve-out.

Also worth knowing

If you're in EU insurance: Solvency II's prudent-person principle interacts with EU AI Act in interesting ways — EIOPA's 2024-2026 guidance is the place to track. If you're in US consumer credit: CFPB Circular 2022-03 already addressed AI adverse-action notices; that bar should be your floor.

Want a tailored answer?

The wizard takes your jurisdiction, AI use case, and data types and gives you the top-3 regulations to focus on — in 60 seconds.

Start the wizard →

Educational guide. Not legal advice. For specific compliance decisions, consult qualified counsel in the relevant jurisdiction.

Note: this guide was drafted with AI assistance — Anthropic Claude.