Governed credit decisioning, adverse action, and small-business reporting.

The regulatory perimeter inside which AI-driven credit decisions now have to operate, and the per-decision evidence the regulators ask for.

  • 01AI-driven credit underwriting (denials, approvals, counter-offers, pricing tiers) sits inside SR 11-7's model risk management framework. Independent validation, ongoing monitoring, and audit-grade evidence become per-decision requirements the moment the model adapts in the field rather than being scored once and frozen.
  • 02ECOA and Regulation B prohibit discrimination on protected-class grounds in any credit decision. CFPB UDAAP guidance requires accurate and specific reasons in adverse-action notices when AI denies credit. Generic black-box outputs are sanctionable.
  • 03CFPB §1071 (Small Business Lending Rule) requires demographic and pricing data collection, retention, and reporting on covered small-business credit transactions. Algorithmic non-discrimination evidence is examinable at the moment a covered lender denies credit, not in a quarterly retrospective.
  • 04Colorado AI Act (in force 1 Feb 2026) and Texas TRAIGA (1 Jan 2026) extend documented governance, impact-assessment, and consumer-notice obligations to AI used in consumer-facing credit decisions. EU AI Act Article 9 classifies high-risk AI to include credit scoring and applies the same record-keeping obligations under Article 12.
  • 05The per-decision audit record satisfies all of the above on one chain: the model recommendation, the protected-class denial-ratio against the matched comparison cohort, the adverse-action evidence count, the SR 11-7 validation trail, signed at the moment of the decision. The fair-lending team reads what the model read. The CFPB examiner reads the same record three years later.

The lending and credit-AI regulatory surface, by the calendar.

Every framework below is enforceable today or about to be. Velma evidence is the format both sides expect.

8
2

Open deadlines

8 approaching

Sorted by soonest deadline first.

0days to enforcement
Effective Jan 01, 2026
Last synced ...

TRAIGA: Texas Responsible AI Governance Act (HB 149)

AI used in consumer-facing decisions (including lending, insurance, healthcare, employment, and housing) must meet documented governance, impact-assessment, and disclosure obligations enforced by the Texas Attorney General.

Texas joins Colorado as the second comprehensive U.S. state AI law. Penalties are tiered and per-violation.

0days to enforcement
Effective Feb 01, 2026
Last synced ...

Colorado AI Act (SB 24-205)

Developers and deployers of high-risk AI must use reasonable care to protect consumers from algorithmic discrimination, and document governance, impact assessment, and consumer notice.

First U.S. comprehensive AI law. Applies to lending, employment, healthcare, insurance, and government services.

19days to enforcement
Effective Jul 01, 2026
Last synced ...

AI Bill 2338/2023 (Marco Legal da IA)

Comprehensive AI regulation covering high-risk AI in lending, healthcare, employment, and public services, with risk classification, governance documentation, and impact assessments enforced by the ANPD.

Largest Latin American market joining the EU/U.S. governance arc. Cross-border vendors face a third major framework.

172days to enforcement
Effective Dec 01, 2026
Last synced ...

Frontier AI Regulation Bill

Anticipated obligations for the largest frontier-AI developers. Safety case, capability evaluation, and incident reporting to a new statutory regulator.

UK is on track to be the third major frontier-AI regulator after the EU and California. Multinational vendors will face a fourth distinct framework.

180days to enforcement
Effective Dec 09, 2026
Last synced ...

Product Liability Directive (Revised)

AI systems and software are treated as products under EU law. Strict-liability for defects, with reversed burden of proof when claimants face technical complexity barriers.

Lending, healthcare, and agentic-AI vendors now carry product-defect liability. Tamper-evident audit evidence is the primary defense.

538days to enforcement
Effective Dec 02, 2027
Last synced ...

EU AI Act: Article 9 (Risk Management)

High-risk AI (credit scoring, healthcare devices, fraud screening, worker management) must ship with documented risk management and regulator-readable evidence.

Original 2 Aug 2026 deadline deferred by the Omnibus VII provisional agreement (May 2026). Standalone systems now in force 2 Dec 2027; embedded systems 2 Aug 2028. Fines up to 7% of global turnover. Deferral confirms the audit-format gap; it does not eliminate it.

538days to enforcement
Effective Dec 02, 2027
Last synced ...

EU AI Act: High-Risk Annex III Conformity

Full conformity for the eight Annex III high-risk categories (including credit scoring, employment, education, law enforcement, and democratic processes) alongside Article 9.

Original 2 Aug 2026 deadline deferred by the Omnibus VII provisional agreement. Pulls every adaptive AI product touching one of these surfaces into the formal conformity-assessment process on the new date.

782days to enforcement
Effective Aug 02, 2028
Last synced ...

EU AI Act: Phase 3 Final Conformity

Full conformity for high-risk AI in regulated products under Article 6, and the end of the grandfather window for embedded systems.

Original 2 Aug 2027 deadline deferred to 2 Aug 2028 by the Omnibus VII provisional agreement. The legacy carve-out closes on this date. Every covered system in the field must produce the full evidence package.

Already in force

2 examinable

The examiner can cite any of these on first request.

618days examinable
Effective Oct 01, 2024
Last synced ...

§1071: Small Business Lending Rule

Covered lenders must collect, retain, and report demographic and pricing data on small-business applications, including evidence that algorithmic scoring is non-discriminatory.

First-tier compliance is live; Tier 2 and 3 deadlines in 2025 and 2026.

5,547days examinable
Effective Apr 04, 2011
Last synced ...

SR 11-7: Model Risk Management

Model-risk framework for banking models. Independent validation, documentation, ongoing monitoring.

Examiners now apply SR 11-7 to adaptive ML and agentic systems inside banks.

Start with a conversation.

Thirty minutes. Architecture, not sales. On the regulatory surface you already know.