Design Partner ProgramWe're accepting applications for the next cohort of design partners in finance, insurance, healthcare, and HR. Apply now →

meilynx

Resources · Tracker

Financial services AI regulation tracker.

The rules and supervisory guidance that govern AI at banks, broker-dealers, investment advisers, insurers and fintechs. Each row gives the status, the date that matters, the primary source, and the date the row was last checked against it.

Updated 11 October 2026 · 22 instruments · United States, European Union, United Kingdom

Sector
Status

Showing 22 of 22 instruments.

  • United States · Federal Reserve, OCC, FDIC

    SR 26-2, Revised Guidance on Model Risk Management

    Model risk management for banking organizations. Generative and agentic AI are outside its scope; the organization's own risk management and governance practices should guide their controls.

    Guidance

    Supersedes SR 11-7

    17 April 2026

    Issued

    Last reviewed 11 Oct 2026

  • United States · OCC

    OCC Bulletin 2026-13, Model Risk Management: Revised Guidance

    The OCC's issuance of the revised guidance. It rescinds Bulletin 2011-12 and announces a request for information on AI.

    Guidance

    17 April 2026

    Issued

    Last reviewed 9 Oct 2026

  • United States · Federal Reserve, OCC, FDIC

    Request for information on model risk management and AI

    A planned request on model risk management that considers banks' use of AI, including generative AI, agentic AI and AI-based models.

    Announced

    Not yet published

    17 April 2026

    Announced in OCC Bulletin 2026-13

    Last reviewed 11 Oct 2026

  • United States · Federal Reserve, FDIC, OCC

    Interagency Guidance on Third-Party Relationships: Risk Management

    Risk management across the life cycle of any business arrangement with another entity, which takes in AI vendors and model providers.

    Guidance

    6 June 2023

    Issued

    Last reviewed 11 Oct 2026

  • United States · Federal Reserve, FDIC, OCC, NCUA

    Proposed Third-Party Risk Management Guidance

    Proposed guidance that would replace the 2023 interagency guidance. AI vendors and model providers fall within its definition of a third-party relationship.

    Proposed

    16 November 2026

    UpcomingComment period closes

    Last reviewed 11 Oct 2026

  • United Kingdom · Prudential Regulation Authority

    Supervisory Statement SS1/23, Model risk management principles for banks

    Model risk expectations for UK banks, building societies and PRA-designated investment firms with internal model approval. It never mentions AI; its model definition reaches vendor models, and an LLM is one.

    Guidance

    Supervisory statement, updated April 2026

    17 May 2024

    Took effect

    Last reviewed 11 Oct 2026

  • United States · FINRA

    Regulatory Notice 24-09

    Reminds member firms that existing rules, including supervision and communications, apply to generative AI and large language models.

    Guidance

    27 June 2024

    Issued

    Last reviewed 11 Oct 2026

  • United States · FINRA

    2026 Annual Regulatory Oversight Report, GenAI section

    The generative AI practices FINRA observed, including AI agents, and the rules they implicate.

    Guidance

    9 December 2025

    Published

    Last reviewed 30 Sep 2026

  • United States · FINRA

    Regulatory Notice 26-14

    Requests comment on proposed changes to modernize Rule 2210, communications with the public, including communications that generative AI tools produce.

    Request for comment

    11 September 2026

    Comment period closed

    Last reviewed 11 Oct 2026

  • United States · SEC

    Exchange Act Rule 17a-4 and Advisers Act Rule 204-2

    Books and records rules that decide which AI prompts, outputs, transcripts and agent actions are records, and how long and in what form they are kept.

    In force

    3 May 2023

    Amended Rule 17a-4 compliance date

    Last reviewed 9 Oct 2026

  • United States · SEC Division of Examinations

    Fiscal Year 2026 Examination Priorities

    Makes AI an examination focus: the accuracy of registrants' claims about their AI capabilities, and the policies and procedures that supervise their use of AI.

    Guidance

    Examination priorities

    17 November 2025

    Published

    Last reviewed 11 Oct 2026

  • United States (states) · NAIC

    Model Bulletin: Use of Artificial Intelligence Systems by Insurers

    Expects insurers to maintain a written program for AI systems that make or support regulated decisions, covering governance, risk management and internal controls, and third-party AI.

    Adopted by states

    Adopted in 27 states, DC and Puerto Rico (adoption map, 8 October 2026)

    4 December 2023

    Adopted by the NAIC

    Last reviewed 11 Oct 2026

  • United States (states) · NAIC Big Data and Artificial Intelligence (H) Working Group

    AI Risk Evaluation Supplement (formerly the AI Systems Evaluation Tool)

    A guide for regulators collecting information on an insurer's AI use, governance, risk controls, high-risk models and data inputs during exams and financial analysis.

    Proposed

    Draft; piloted by 12 states from March 2026; comments on version 5.0 closed 29 September 2026

    14 November 2026

    UpcomingFall National Meeting, where adoption is planned

    Last reviewed 11 Oct 2026

  • Colorado · Colorado Division of Insurance

    Regulation 10-1-1 (3 CCR 702-10)

    Governance and risk management for life, private passenger auto and health benefit plan insurers that use external consumer data, algorithms and predictive models.

    In force

    1 July 2026

    Auto and health insurers' first annual report due

    Last reviewed 11 Oct 2026

  • New York · NYDFS

    Insurance Circular Letter No. 7 (2024)

    Expectations for insurers that use AI systems and external consumer data in underwriting and pricing, including testing for unfair or unlawful discrimination before use.

    Guidance

    11 July 2024

    Issued

    Last reviewed 11 Oct 2026

  • New York · NYDFS

    23 NYCRR Part 500, Cybersecurity Requirements for Financial Services Companies

    Cybersecurity rules for DFS-regulated entities that reach AI through risk assessment, access controls, asset inventory and third-party oversight.

    In force

    1 November 2025

    Last Second Amendment phase: MFA and asset inventory

    Last reviewed 11 Oct 2026

  • New York · NYDFS

    Industry letter: Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks

    How Part 500 applies to the cybersecurity risks AI creates. It imposes no new requirements.

    Guidance

    16 October 2024

    Issued

    Last reviewed 11 Oct 2026

  • New York · NYDFS

    Industry letter: Heightened Cybersecurity Risks Associated with Frontier AI Models

    Asks regulated entities to prepare for frontier AI models: updated risk assessments, faster vulnerability fixes and oversight of AI-generated code. It imposes no new requirements.

    Guidance

    21 May 2026

    Issued

    Last reviewed 11 Oct 2026

  • United States · CFPB

    Equal Credit Opportunity Act (Regulation B) final rule

    Provides that ECOA does not authorize disparate-impact liability, the theory commenters cited for AI-driven credit models. ECOA's other protections continue to apply.

    In force

    21 July 2026

    Effective

    Last reviewed 11 Oct 2026

  • United States · CFPB

    Consumer Financial Protection Circular 2022-03

    Adverse action notice requirements for credit decisions based on complex algorithms. Withdrawn with other CFPB guidance documents.

    Withdrawn

    12 May 2025

    Withdrawn

    Last reviewed 11 Oct 2026

  • European Union · European Parliament and Council

    Regulation (EU) 2024/1689, the AI Act, as amended by Regulation (EU) 2026/1744

    Risk-based AI rules. Credit scoring and life and health insurance pricing are high-risk uses, and the Digital Omnibus moved their obligations to 2 December 2027.

    In force

    Applies in phases

    2 December 2027

    UpcomingAnnex III high-risk obligations apply

    Last reviewed 11 Oct 2026

  • European Union · European Parliament and Council

    Regulation (EU) 2022/2554, the Digital Operational Resilience Act

    ICT risk management, incident reporting and third-party risk for EU financial entities, which reach AI workloads and their providers.

    In force

    17 January 2025

    Applies

    Last reviewed 11 Oct 2026

Reading the tracker

Status, dates and review.

In force
Binding law or regulation that applies now. A phased regime counts once its first obligations apply.
Adopted by states
A model text that takes effect state by state. The count is the issuer's own adoption map.
Guidance
Supervisory guidance, letters, reports, frameworks and examination priorities. They set expectations and apply existing rules.
Proposed
Published for comment and not yet final.
Request for comment
A regulator asking for views before it proposes anything.
Announced
Announced by the regulator and not yet published.
Withdrawn
Withdrawn by the issuer. Listed while policies and procedures may still cite it.
Key date
The date that matters most for the instrument now: the issue date for guidance, the effective or compliance date for a rule, the comment deadline for a proposal, and the deferred deadline for a phased regime. Dates after the update date are marked Upcoming.
Last reviewed
The date the row was last checked against its primary source. A row that links a Regulatory Reference entry shares that entry's review date, so a refreshed entry refreshes the row.
Scope
Instruments written for AI, and the general rules that decide how AI is supervised in financial services: model risk, third-party risk, cybersecurity and recordkeeping.
Quarterly review

Using it each quarter.

  1. 01Filter to the sectors your organization is supervised in, then read the Status column. Rows marked Proposed, Request for comment or Announced are where the next change will come from.
  2. 02Carry every key date marked Upcoming into the compliance calendar, with an owner.
  3. 03Compare each Last reviewed date with the date of your previous review. A newer date means the row was rechecked or changed since, and the linked reference entry says what moved.
  4. 04Open the primary source before relying on a row. The reference entry sets out what the instrument requires and the evidence an examiner asks for.

Updated 11 October 2026. This tracker summarises publicly available rules and regulatory guidance and is provided for general information. It is not legal advice. Obligations depend on an institution's charter, licences, registration status, size and activities. Verify against the primary source linked on each row and consult counsel before relying on any summary here.

Regulatory updates

When a regulator changes what an AI examination asks for, hear about it first.

Short notes on SR 26-2, NYDFS 500, FINRA, the NAIC bulletin, the EU AI Act, and the employment-AI statutes, plus what we ship. A few emails a month.