Guide · Regulation
Which rules apply to AI at credit unions and banks?
No single federal rule governs AI at credit unions or banks. AI falls under rules you already follow: model risk, third-party risk, information security, fair lending, consumer protection, and BSA. Two of those frameworks changed in 2026. This guide maps each one to AI and notes where credit unions differ from banks.
Is there a federal AI rule for financial institutions?
No. As of October 2026, neither the federal banking agencies nor NCUA has issued an AI-specific regulation. Regulators apply existing law to AI. The examiner’s question is not “is this AI?” It is “does this activity meet the rules that already apply to it?”
| Area | Banks | Credit unions |
|---|---|---|
| Model risk | SR 26-2 / OCC Bulletin 2026-13 (April 2026) | Limited NCUA guidance; SR 26-2 as a reference |
| Third-party risk | 2023 interagency guidance; 2026 proposal | Letter 07-CU-13; NCUA joined the 2026 proposal |
| Information security | GLBA; Interagency Guidelines Establishing Information Security Standards | GLBA; NCUA Part 748 and Appendices A and B |
| Incident reporting | 36-hour notification rule | 72-hour reporting under Part 748 |
| Fair lending | ECOA / Regulation B; Fair Housing Act | Same |
| BSA/AML | Each agency’s BSA program rule | NCUA Part 748.2 |
| Voluntary frameworks | NIST AI RMF; NIST AI 600-1 | Same |
What changed in the past year?
- December 2025: NCUA updated its AI resource page, which collects federal references on AI risk, vendor diligence, and cybersecurity.
- January 2026: NCUA issued its 2026 Supervisory Priorities (Letter to Credit Unions 26-CU-01). It does not list AI as a separate priority. It names third-party risk management, payment fraud, and BSA, where AI often appears.
- April 17, 2026: The Federal Reserve, OCC, and FDIC replaced SR 11-7 with revised model risk guidance, issued as SR 26-2 and OCC Bulletin 2026-13. It excludes generative and agentic AI. The agencies said they plan to seek public input on AI use.
- September 11, 2026: The Federal Reserve, FDIC, OCC, and NCUA proposed new third-party risk management guidance. Once final, it would replace the 2023 interagency guidance.
How does model risk guidance apply to AI?
SR 26-2 replaced SR 11-7 on April 17, 2026. It also withdrew the 2021 interagency statement on model risk for BSA/AML systems (SR 21-8). The key points:
- It is risk-based. The agencies say it is most relevant to banking organizations with more than $30 billion in assets.
- It drops fixed validation cycles. Validation still covers conceptual soundness, outcomes analysis, and ongoing monitoring.
- It covers third-party models. When a bank cannot fully validate a vendor model, the principles still apply.
- It excludes generative and agentic AI. The agencies describe those models as novel and rapidly evolving. Banks govern them through broader risk management practices.
For credit unions: NCUA did not issue SR 26-2. In May 2025, GAO found NCUA’s model risk guidance limited in scope and detail and recommended an update. Credit unions can use SR 26-2 as a reference for predictive models such as credit scoring and fraud detection.
The gap: Generative and agentic AI now sit outside model risk guidance for banks as well. Your AI governance program has to cover them directly.
How do information security rules apply to AI?
- GLBA requires financial institutions to protect customer and member information. It applies to any AI tool that receives that data, including text staff paste into a chat assistant.
- Credit unions: NCUA Part 748 and Appendix A require a board-approved information security program and oversight of service providers. Appendix B covers response to unauthorized access to member information.
- Banks: The Interagency Guidelines Establishing Information Security Standards set the same expectations.
- Incident reporting: Credit unions must report a reportable cyber incident to NCUA within 72 hours. Banks must notify their primary federal regulator within 36 hours of determining that a notification incident occurred. An AI-related breach or outage can trigger either rule.
The bank clock starts when the bank determines that a notification incident occurred. The credit union clock starts when it reasonably believes a reportable incident occurred.
The FFIEC IT Examination Handbook remains the examiner reference. Its Information Security, Outsourcing Technology Services, and Development, Acquisition, and Maintenance booklets apply most directly to AI.
How does third-party risk guidance apply to AI vendors?
Most AI reaches credit unions and banks through vendors, so third-party guidance is where examiners look first.
- Banks: The June 2023 interagency guidance on third-party relationships stays in effect until the September 2026 proposal is final.
- Credit unions: NCUA Letter 07-CU-13 sets due diligence and monitoring expectations. NCUA joined the 2026 proposal.
- Limits: NCUA cannot examine technology service providers. A credit union’s own diligence file carries more weight as a result.
The AI vendor due diligence guide lists the questions, documents, and contract terms.
How do fair lending and consumer protection laws apply?
- ECOA and Regulation B prohibit credit discrimination and require specific principal reasons when an application is denied. A complex model does not excuse vague reasons. If a system cannot produce accurate, specific reasons, it is not ready for credit decisions.
- The Fair Housing Act applies to AI used in mortgage lending and marketing.
- Unfair or deceptive practices: A chatbot that gives members wrong information about fees or terms creates consumer protection risk, no matter who built it.
Test credit models for disparate outcomes before deployment and on a schedule after. Keep records of the testing and of the alternatives you considered.
How does BSA/AML apply to AI?
AI in transaction monitoring and fraud detection must still support a BSA/AML program that meets the rules. For credit unions, that is NCUA Part 748.2. For banks, it is each agency’s BSA program rule. SR 26-2 withdrew the 2021 model risk statement for BSA systems, but the program requirements did not change. Document how alerts are generated, tuned, and reviewed, so you can show the system finds what it should.
Which voluntary frameworks help?
- NIST AI Risk Management Framework (AI RMF 1.0), released in January 2023. It organizes AI risk work into four functions: Govern, Map, Measure, and Manage.
- NIST Generative AI Profile (NIST AI 600-1), released in July 2024. It applies the AI RMF to generative AI.
Neither is required. Both give you a structure examiners recognize. NCUA’s AI resource page points to NIST resources.
Some states have also passed AI laws that cover automated decisions or consumer interactions, and several have delayed or amended them. Check the laws in each state where you lend or serve members, and ask counsel whether exemptions for financial institutions apply.
Frequently asked questions
Is SR 11-7 still in effect?
No. On April 17, 2026, the Federal Reserve, OCC, and FDIC replaced SR 11-7 with revised model risk guidance, issued as SR 26-2 and OCC Bulletin 2026-13.
Does SR 26-2 cover generative AI?
No. SR 26-2 excludes generative and agentic AI because the agencies view them as novel and rapidly evolving. Banks govern them through broader risk management and governance practices.
Does SR 26-2 apply to credit unions?
No. NCUA did not join it. Credit unions can use its principles as a reference for predictive models such as credit scoring and fraud detection.
Is the 2023 interagency third-party risk guidance still in effect?
Yes. The agencies and NCUA proposed replacement guidance in September 2026. The 2023 guidance applies until final guidance is issued.
Is the NIST AI Risk Management Framework required for banks or credit unions?
No. It is voluntary. It gives institutions a structure that examiners recognize, and NCUA’s AI resource page points to NIST resources.
Must an AI-related cyber incident be reported to NCUA?
Yes, if it meets the definition of a reportable cyber incident. A credit union must report within 72 hours of reasonably believing that a reportable incident occurred.
This guide is general information, not legal advice. Regulatory references reflect public guidance as of October 10, 2026. Confirm current requirements with your counsel and examiner.