Governed credit decisioning, adverse action, and small-business reporting.

AI governance and compliance for lending and credit: the regulatory perimeter inside which AI-driven credit decisions now operate, and the per-decision evidence regulators ask for.

  • 01AI-driven credit underwriting (denials, approvals, counter-offers, pricing tiers) sits inside SR 11-7's model risk management framework. Independent validation, ongoing monitoring, and audit-grade evidence become per-decision requirements the moment the model adapts in the field rather than being scored once and frozen.
  • 02ECOA and Regulation B prohibit discrimination on protected-class grounds in any credit decision. CFPB UDAAP guidance requires accurate and specific reasons in adverse-action notices when AI denies credit. Generic black-box outputs are sanctionable.
  • 03CFPB §1071 (Small Business Lending Rule) requires demographic and pricing data collection, retention, and reporting on covered small-business credit transactions. Algorithmic non-discrimination evidence is examinable at the moment a covered lender denies credit, not in a quarterly retrospective.
  • 04Colorado AI Act (in force 1 Feb 2026) and Texas TRAIGA (1 Jan 2026) extend documented governance, impact-assessment, and consumer-notice obligations to AI used in consumer-facing credit decisions. EU AI Act Article 9 classifies high-risk AI to include credit scoring and applies the same record-keeping obligations under Article 12.
  • 05The per-decision audit record satisfies all of the above on one chain: the model recommendation, the protected-class denial-ratio against the matched comparison cohort, the adverse-action evidence count, the SR 11-7 validation trail, signed at the moment of the decision. The fair-lending team reads what the model read. The CFPB examiner reads the same record three years later.

The lending and credit-AI regulatory surface, by the calendar.

Every framework below is enforceable today or about to be. Velma evidence is the format both sides expect.

8
1

Open deadlines

8 approaching

Sorted by soonest deadline first.

0days to enforcement
Jan 01, 2026

TRAIGA: Texas Responsible AI Governance Act (HB 149)

AI used in consumer-facing decisions (including lending, insurance, healthcare, employment, and housing) must meet documented governance, impact-assessment, and disclosure obligations enforced by the Texas Attorney General.

Texas joins Colorado as the second comprehensive U.S. state AI law. Penalties are tiered and per-violation.

0days to enforcement
Jul 01, 2026

AI Bill 2338/2023 (Marco Legal da IA)

Comprehensive AI regulation covering high-risk AI in lending, healthcare, employment, and public services, with risk classification, governance documentation, and impact assessments enforced by the ANPD.

Status: pending bill (PL 2338/2023), not yet enacted. No statutory effective date exists; the date shown is a planning estimate pending the Chamber of Deputies vote.

134days to enforcement
Dec 09, 2026

Product Liability Directive (Revised)

AI systems and software are treated as products under EU law. Strict-liability for defects, with reversed burden of proof when claimants face technical complexity barriers.

Lending, healthcare, and agentic-AI vendors now carry product-defect liability. Tamper-evident audit evidence is the primary defense.

157days to enforcement
Jan 01, 2027

Colorado AI Act (SB 24-205 repealed; replaced by SB 26-189, ADMT framework)

SB 24-205 was repealed before taking effect and replaced by SB 26-189, an automated decision technology (ADMT) framework. High-risk AI deployers must document governance, risk assessment, and consumer notice under the replacement law.

Colorado's original 2026 AI law never took effect. SB 26-189 (signed 2026-05-14) takes effect 2027-01-01 as the operative ADMT regime.

492days to enforcement
Dec 02, 2027

EU AI Act: Article 9 (Risk Management)

High-risk AI (credit scoring, healthcare devices, fraud screening, worker management) must ship with documented risk management and regulator-readable evidence.

Original 2 Aug 2026 deadline deferred by the Digital Omnibus on AI provisional agreement (May 2026). Standalone systems now in force 2 Dec 2027; embedded systems 2 Aug 2028. Fines up to 7% of global turnover. Deferral confirms the audit-format gap; it does not eliminate it.

492days to enforcement
Dec 02, 2027

EU AI Act: High-Risk Annex III Conformity

Full conformity for the eight Annex III high-risk categories (including credit scoring, employment, education, law enforcement, and democratic processes) alongside Article 9.

Original 2 Aug 2026 deadline deferred by the Digital Omnibus on AI provisional agreement. Pulls every adaptive AI product touching one of these surfaces into the formal conformity-assessment process on the new date.

522days to enforcement
Jan 01, 2028

§1071: Small Business Lending Rule

Covered lenders must collect, retain, and report demographic and pricing data on small-business applications, including evidence that algorithmic scoring is non-discriminatory.

Compliance has not begun. The tiered structure was repealed; a single date of 2028-01-01 applies to all covered lenders, with the first SBLAR filing 2029-06-01. Non-discriminatory-model evidence remains the defense.

736days to enforcement
Aug 02, 2028

EU AI Act: Phase 3 Final Conformity

Full conformity for high-risk AI in regulated products under Article 6, and the end of the grandfather window for embedded systems.

Original 2 Aug 2027 deadline deferred to 2 Aug 2028 by the Digital Omnibus on AI provisional agreement. The legacy carve-out closes on this date. Every covered system in the field must produce the full evidence package.

Already in force

1 examinable

The examiner can cite any of these on first request.

5,593days examinable
Apr 04, 2011

SR 11-7: Model Risk Management

Model-risk framework for banking models. Independent validation, documentation, ongoing monitoring.

Examiners now apply SR 11-7 to adaptive ML and agentic systems inside banks.

Start with a conversation.

Thirty minutes. Architecture, not sales. On the regulatory surface you already know.