US

United States - Market Insights (Finance)

Law Over Borders Comparative Guide: Artificial Intelligence Law Guide

29 Sep 2026
Artificial Intelligence Law Guide Artificial Intelligence Law Guide
Q&A Market Insights

How the financial industry uses artificial intelligence and the risks and benefits that your business should know

Introduction

The financial sector’s use of artificial intelligence (AI) is not a new phenomenon. Indeed, financial institutions have long since adopted AI — or, as the Department of Treasury calls it, “traditional AI” — for credit underwriting, trading, investment advice, customer service, compliance, and process automation. But with the advancement of generative AI — and its ability to create new content based on training data — financial institutions have started using emerging technologies to reshape customer interactions, make quick credit/lending decisions, and detect illegal financial activity.

This Market Insight outlines key AI use cases in the financial sector, highlights risks and compliance standards derived from financial regulator guidance, and offers practical recommendations to help mitigate these risks.

AI use cases in the financial sector

Recently, several federal agencies have requested information from the financial sector to better understand how it uses AI; for example, the US Government Accountability Office (GAO) report Artificial Intelligence, Use and Oversight in Services, May 2025 (see www.gao.gov/assets/gao-25-107197.pdf) and the Department of the Treasury, Report on the Uses, Opportunities, and Risks of Artificial Intelligence (see home.treasury.gov/system/files/136/Artificial-Intelligence-in-Financial-Services.pdf). Seven major AI use cases emerged:

  • Automated trading tools. These help assess how an order for securities or derivatives should be placed to optimize execution and can execute large trade orders in a dynamic way to minimize price impacts.
  • Threat and fraud detecting tools. These help assess transaction data to detect money laundering, terrorist financing, bribery, tax evasion, or insider trading.
  • Cybersecurity tools. These detect and mitigate cyber threats in a wide variety of ways ranging from detecting servers in need of patches to analyzing unexpected traffic on networks.
  • Credit decision-making tools. These analyze data from multiple sources (e.g., utility payments, financial statements, transaction history) to assess credit worthiness.
  • Customer service tools. These customer-facing tools (such as chatbots or virtual assistants) can respond to basic customer questions.
  • Investment decision-making tools. These analyze large data sets to predict price movement of stocks or other securities or help provide investment advice.
  • Compliance and risk management tools. These predict borrower risk by analyzing historical customer data.

Each new use of AI, however, creates a new attack surface and can generate new risks or change old risks. For example, many financial regulators have raised concerns over biased credit and lending AI decisions for individuals in federally protected classes. Further, AI may introduce new biases or reframe old ones. Industry stakeholders also raised privacy risks related to AI models identifying individuals using de-identified data, and risks of AI models providing consumers with false or misleading data. Given these risks, regulators have released guidance, reports, and advisory alerts on how the financial sector can mitigate them.

The elephant in the room: The Trump pivot

The transition from the Biden Administration to the Trump Administration has certainly marked a sea change in the language used by regulators. Attacking “ideological bias or engineered social agendas,” President Trump’s Executive Order 14179 repealed the prior Biden Administration Executive Order 14110 — which, while pursuing United States AI leadership, had emphasized safety and security; promoted innovation, competition, and responsible development; and advanced equity and civil rights, consumer protection, privacy and civil liberties, and risk management.

The Trump approach eschewed secondary concerns to focus on its drive to solidify the United States’ role as the “global leader in AI.” Although this shift may lessen the risk of interference from Washington in the near term, it presents a possible quandary for financial institutions operating outside of the United States: compliance with international AI safety and nondiscrimination rules and guidance — echoed in international consensus — may incur US federal regulatory ire.

The complexity is only becoming more challenging in light of the Colorado AI Act and EU AI Act. Passed in May 2024, the Colorado Artificial Intelligence Act (CAIA) was set to become the first comprehensive state law to regulate AI use in employment, housing, credit, education, and healthcare decisions. More specifically, the CAIA requires developers of “high-risk” artificial intelligence systems to use “reasonable care” to protect consumers from any “known or reasonably foreseeable risks of algorithmic discrimination.” The CAIA also requires covered businesses to conduct impact assessments, provide disclosures, and maintain risk management policies when using high risk AI for consequential decisions. The law’s effective date, however, has been pushed to June 30, 2026, even as dozens of other states debate potential AI legislation.

Across the pond, the European Union (EU) is steadily adopting the EU AI Act, which applies to the development, deployment, and use of AI in the EU regardless of company location. The requirements for AI depend on the risk level of their intended purpose or use — these categories are unacceptable risk, high risk, limited risk, and minimal risk. Whether the EU’s potentially forthcoming Omnibus package (intended to reduce administrative burdens) weakens this approach remains to be seen.

What United States financial regulators have said about the risks of using AI

Despite the shift in administrations, most federal regulators have yet to substantially revise their guidance, leaving financial institutions with the task of understanding prior guidance and discerning whether it will survive relatively intact and whether previous priorities will return in a few years. Indeed, some regulators have seen such material cuts to their funding and personnel that their guidance may only be valuable for its persuasive force.

Department of the Treasury

In a December 2024 report, the Treasury Department summarized several categorical challenges related to the implementation of AI. These challenges — derived from industry responses to the department’s request for information — include:

  • data privacy, security, and quality standards related to the quality and protection of customer data;
  • bias, explainability, and hallucinations in customer-facing AI model responses;
  • impacts on consumers, fair lending, and financial inclusions;
  • third-party risks related to heavy reliance on vendors; and
  • illicit finance risks, such as adversaries using AI to commit illicit cyber activity and fraud.

To combat these risks, the report recommended several next steps that the Treasury Department, other government agencies, and financial sector should consider:

  • Collaboration between governments, regulators, and the financial services sector to promote consistent and robust standards for uses of AI, identification of enhancements to existing risk management frameworks, and enhancement of understanding on the use of emerging AI in financial services.
  • Further analysis and stakeholder engagement to explore solutions for any identified gaps in the existing regulatory frameworks, and to address the potential risk of AI causing consumer harms.
  • Prioritizing review of AI use cases for compliance with existing laws and regulations before deployment and periodically reevaluating compliance.

Securities and Exchange Commission (SEC)

In a 2025 report, the SEC stated that it remains focused on registered businesses that use automated investment tools, AI, and trading algorithms or platforms, and the risks associated with these technologies. As a result, the SEC will closely examine businesses that use AI for “certain digital engagement practices, such as digital investment advisory services, recommendations, and related tools and methods.” The SEC also identified the following factors that it will consider during its assessment, such as whether a registered business:

  • discloses fair and accurate AI representations;
  • has in place operations and controls that are consistent with disclosures made to investors;
  • provides algorithms that produce advice or recommendations consistent with investors’ investment profiles or stated strategies;
  • has controls in place confirming that advice or recommendations resulting from digital engagement practices are consistent with regulatory obligations to investors;
  • has implemented adequate policies and procedures to monitor and/or supervise the use of AI; and
  • protects against loss or misuse of client records and information that may occur from the use of third-party AI models and tools.

These factors are in line with prior SEC guidance related to company disclosure of AI use in their annual reports. For example, the SEC’s Division of Corporate Finance has previously commented that “existing rules or regulations may require disclosure about how a company uses artificial intelligence” and that SEC staff will assess whether a company’s annual report:

  • clearly defines what it means by artificial intelligence and how the technology could improve the company’s results of operations, financial condition, and future prospects;
  • provides tailored disclosures about the material risks and impact AI is reasonably likely to have on its business and financial results;
  • focuses on the company’s current or proposed use of artificial intelligence technology rather than generic buzz not relating to its business; and
  • has a reasonable basis for its claims when discussing artificial intelligence prospects.

Department Office of the Comptroller of the Currency (OCC)

The OCC similarly explained that adverse outcomes resulting from AI use in the financial sector can generally be caused by:

  • poorly designed mathematical models;
  • faulty data;
  • changes in model assumptions;
  • inadequate model validation or testing;
  • limited human oversight; and
  • the absence of adequate planning and due diligence when engaging third-party AI vendors.

To mitigate the risk of these outcomes, the OCC expects financial institutions using AI to implement:

  • Risk management programs. For example, internal validation and audits to achieve appropriate levels of explainability.
  • Adequate data management programs. These include data governance policies that require institutions to understand the origins and use of the AI data pool to avoid illegal outcomes.
  • Adequate privacy and cyber controls. Such as privacy and security policies that perpetuate cyber hygiene and effective cybersecurity practices to prevent/limit the impact of corrupted or contaminated data.
  • Third-party risk management programs. For example, robust due diligence, effective contract management processes, and oversight of third parties that:
  • obtains documentation on models used;
  • establishes roles and responsibilities and defining data ownership and permitted uses; and
  • implements security, privacy and limitations of any data shared with or exchanged with the vendor.

Further to these expectations, the OCC (along with other agencies) has taken direct action by implementing a final interagency rule requiring mortgage originators and secondary market mortgage issuers to implement “quality control standards” for their automated valuation models (AVM). The rule defines AVMs as “any computerized model used by mortgage originators and secondary market issuers to determine the value of a consumer’s principal dwelling collateralizing a mortgage.”

Regarding the “quality control standards,” covered entities must:

  • ensure a high level of confidence in the estimates produced;
  • protect against the manipulation of data;
  • seek to avoid conflicts of interest;
  • require random sample testing and reviews; and
  • comply with applicable nondiscrimination laws.

Consumer Financial Protection Bureau (CFPB)

According to the CFPB, the financial sector must look to existing laws when implementing AI. After seeking information from the industry on uses, opportunities, and risks of AI in the financial sector, the CFPB made its view clear — emerging technologies must still comply with existing laws such as the Equal Credit Opportunity Act (ECOA), Consumer Financial Protection Act (CFPA), and Fair Credit Reporting Act (FCRA). In particular, the CFPB highlighted several AI use cases and its expectations for companies adopting them:

  • Automated customer service technologies. These tools may provide incorrect information, fail to provide meaningful dispute resolution, and raise privacy and security risks. The CFPB will be monitoring compliance with ECOA and other civil rights laws.
  • Fraud screening technologies. Third-party vendors often provide these tools, which assign individualized “risk scores” to customers. The CFPB noted that companies must recognize consumer finance laws (like ECOA, CFPA, and FCRA) in their implementation.
  • Credit and lending decision technologies. These tools may be used for faster credit/lending decisions. The CFPB noted that financial institutions must regularly test their tools for disparate treatment and disparate impact and implement less discriminatory alternatives using manual or automated techniques.

Commodity Futures Trading Commission (CFTC)

In a recent advisory, the CFTC similarly reminded regulated entities that existing regulations and Commodity Exchange Act obligations still apply to AI. The advisory included a non-exhaustive list of AI use cases that, according to the CFTC, could trigger statutory and regulatory requirements:

  • Order processing and trade matching tools. These can anticipate trades before they happen and help allocate system resources in advance. Regulated entities must continue to provide competitive, open, and efficient markets and mechanisms for executing transactions that protect the price discovery process of trading in their centralized market.
  • Market surveillance tools. These can help detect abusive trading practices, investigate rule violations, and conduct real-time market surveillance. Regulated entities must maintain compliance staff and resources to oversee these processes.
  • System safeguard tools. These can further implement existing information security controls. Regulated entities must continue developing and maintaining appropriate controls for: enterprise risk management and governance, information security, business continuity and disaster recovery planning, capacity and performance planning, systems operations, and systems development and quality assurance.

Key takeaways for your business

Given this ever-changing executive branch landscape, financial institutions should approach the above agency reports, advisories, and guidance as reflecting financial regulator expectations regarding how the financial sector implements AI, as tempered by a more innovation-focused desire to win the global AI competition. When adopting AI internally and externally, businesses in the financial sector should consider:

  • creating an AI governance structure, expressed through policies, that allows for consideration of the issues in all the jurisdictions, and whether the financial institution operates and finesses any tensions in a set of clear policies;
  • developing an AI environment that allows for aggressive adoption of AI without compromising the protection of confidentiality, privacy, and cybersecurity;
  • engaging with employees to avoid pockets of “shadow AI” use of unauthorized systems;
  • avoiding representations that overpromise or overexaggerate what AI can actually deliver to consumers;
  • implementing internal policies and procedures that require oversight of AI outputs and explainability, especially for AI use cases that could return biased decisions or discriminate against protected classes of people;
  • using AI to promote effective cybersecurity practices and hygiene;
  • ensuring that their vendor contracts disclose the provenance of training data, and include audit and training data rights, information security representations, model change notifications, incident response requirements, and acceptable model testing norms;
  • adopting data management programs that de-identify sensitive data and record where AI tools obtain data from — and how they use it — to prevent unnecessary contamination/manipulation of data; and
  • regularly testing and validating consumer-facing AI tools for decision bias, hallucinations, and discrimination.