Resources · Tracker
Financial services AI regulation tracker.
The rules and supervisory guidance that govern AI at banks, broker-dealers, investment advisers, insurers and fintechs. Each row gives the status, the date that matters, the primary source, and the date the row was last checked against it.
Updated 11 October 2026 · 22 instruments · United States, European Union, United Kingdom
Showing 22 of 22 instruments. Grouped by sector; select a column heading to sort.
United States · Federal Reserve, OCC, FDIC
SR 26-2, Revised Guidance on Model Risk Management
Model risk management for banking organizations. Generative and agentic AI are outside its scope; the organization's own risk management and governance practices should guide their controls.
GuidanceSupersedes SR 11-7
17 April 2026
Issued
- Federal Reserve SR 26-2
- Reference: SR 26-2 →
- Reference: SR 11-7 → SR 26-2 →
- Reference: SR 26-2 generative and agentic AI carve-out →
Last reviewed 11 Oct 2026
United States · OCC
OCC Bulletin 2026-13, Model Risk Management: Revised Guidance
The OCC's issuance of the revised guidance. It rescinds Bulletin 2011-12 and announces a request for information on AI.
Guidance17 April 2026
Issued
Last reviewed 9 Oct 2026
United States · Federal Reserve, OCC, FDIC
Request for information on model risk management and AI
A planned request on model risk management that considers banks' use of AI, including generative AI, agentic AI and AI-based models.
AnnouncedNot yet published
17 April 2026
Announced in OCC Bulletin 2026-13
Last reviewed 11 Oct 2026
United States · Federal Reserve, FDIC, OCC
Interagency Guidance on Third-Party Relationships: Risk Management
Risk management across the life cycle of any business arrangement with another entity, which takes in AI vendors and model providers.
Guidance6 June 2023
Issued
Last reviewed 11 Oct 2026
United States · Federal Reserve, FDIC, OCC, NCUA
Proposed Third-Party Risk Management Guidance
Proposed guidance that would replace the 2023 interagency guidance. AI vendors and model providers fall within its definition of a third-party relationship.
Proposed16 November 2026
UpcomingComment period closes
Last reviewed 11 Oct 2026
United Kingdom · Prudential Regulation Authority
Supervisory Statement SS1/23, Model risk management principles for banks
Model risk expectations for UK banks, building societies and PRA-designated investment firms with internal model approval. It never mentions AI; its model definition reaches vendor models, and an LLM is one.
GuidanceSupervisory statement, updated April 2026
17 May 2024
Took effect
Last reviewed 11 Oct 2026
United States · FINRA
Regulatory Notice 24-09
Reminds member firms that existing rules, including supervision and communications, apply to generative AI and large language models.
Guidance27 June 2024
Issued
Last reviewed 11 Oct 2026
United States · FINRA
2026 Annual Regulatory Oversight Report, GenAI section
The generative AI practices FINRA observed, including AI agents, and the rules they implicate.
Guidance9 December 2025
Published
Last reviewed 30 Sep 2026
United States · FINRA
Regulatory Notice 26-14
Requests comment on proposed changes to modernize Rule 2210, communications with the public, including communications that generative AI tools produce.
Request for comment11 September 2026
Comment period closed
Last reviewed 11 Oct 2026
United States · SEC
Exchange Act Rule 17a-4 and Advisers Act Rule 204-2
Books and records rules that decide which AI prompts, outputs, transcripts and agent actions are records, and how long and in what form they are kept.
In force3 May 2023
Amended Rule 17a-4 compliance date
Last reviewed 9 Oct 2026
United States · SEC Division of Examinations
Fiscal Year 2026 Examination Priorities
Makes AI an examination focus: the accuracy of registrants' claims about their AI capabilities, and the policies and procedures that supervise their use of AI.
GuidanceExamination priorities
17 November 2025
Published
Last reviewed 11 Oct 2026
United States (states) · NAIC
Model Bulletin: Use of Artificial Intelligence Systems by Insurers
Expects insurers to maintain a written program for AI systems that make or support regulated decisions, covering governance, risk management and internal controls, and third-party AI.
Adopted by statesAdopted in 27 states, DC and Puerto Rico (adoption map, 8 October 2026)
4 December 2023
Adopted by the NAIC
Last reviewed 11 Oct 2026
United States (states) · NAIC Big Data and Artificial Intelligence (H) Working Group
AI Risk Evaluation Supplement (formerly the AI Systems Evaluation Tool)
A guide for regulators collecting information on an insurer's AI use, governance, risk controls, high-risk models and data inputs during exams and financial analysis.
ProposedDraft; piloted by 12 states from March 2026; comments on version 5.0 closed 29 September 2026
14 November 2026
UpcomingFall National Meeting, where adoption is planned
- NAIC Big Data and AI (H) Working Group
- Reference: NAIC AI Evaluation Tool →
- Reference: NAIC AI Bulletin →
Last reviewed 11 Oct 2026
Colorado · Colorado Division of Insurance
Regulation 10-1-1 (3 CCR 702-10)
Governance and risk management for life, private passenger auto and health benefit plan insurers that use external consumer data, algorithms and predictive models.
In force1 July 2026
Auto and health insurers' first annual report due
Last reviewed 11 Oct 2026
New York · NYDFS
Insurance Circular Letter No. 7 (2024)
Expectations for insurers that use AI systems and external consumer data in underwriting and pricing, including testing for unfair or unlawful discrimination before use.
Guidance11 July 2024
Issued
Last reviewed 11 Oct 2026
New York · NYDFS
23 NYCRR Part 500, Cybersecurity Requirements for Financial Services Companies
Cybersecurity rules for DFS-regulated entities that reach AI through risk assessment, access controls, asset inventory and third-party oversight.
In force1 November 2025
Last Second Amendment phase: MFA and asset inventory
Last reviewed 11 Oct 2026
New York · NYDFS
Industry letter: Cybersecurity Risks Arising from Artificial Intelligence and Strategies to Combat Related Risks
How Part 500 applies to the cybersecurity risks AI creates. It imposes no new requirements.
Guidance16 October 2024
Issued
Last reviewed 11 Oct 2026
New York · NYDFS
Industry letter: Heightened Cybersecurity Risks Associated with Frontier AI Models
Asks regulated entities to prepare for frontier AI models: updated risk assessments, faster vulnerability fixes and oversight of AI-generated code. It imposes no new requirements.
Guidance21 May 2026
Issued
Last reviewed 11 Oct 2026
United States · CFPB
Equal Credit Opportunity Act (Regulation B) final rule
Provides that ECOA does not authorize disparate-impact liability, the theory commenters cited for AI-driven credit models. ECOA's other protections continue to apply.
In force21 July 2026
Effective
Last reviewed 11 Oct 2026
United States · CFPB
Consumer Financial Protection Circular 2022-03
Adverse action notice requirements for credit decisions based on complex algorithms. Withdrawn with other CFPB guidance documents.
Withdrawn12 May 2025
Withdrawn
Last reviewed 11 Oct 2026
European Union · European Parliament and Council
Regulation (EU) 2024/1689, the AI Act, as amended by Regulation (EU) 2026/1744
Risk-based AI rules. Credit scoring and life and health insurance pricing are high-risk uses, and the Digital Omnibus moved their obligations to 2 December 2027.
In forceApplies in phases
2 December 2027
UpcomingAnnex III high-risk obligations apply
- Regulation (EU) 2026/1744 (EUR-Lex)
- Reference: EU AI Act timeline →
- Reference: EU AI Act Article 12 logging →
Last reviewed 11 Oct 2026
European Union · European Parliament and Council
Regulation (EU) 2022/2554, the Digital Operational Resilience Act
ICT risk management, incident reporting and third-party risk for EU financial entities, which reach AI workloads and their providers.
In force17 January 2025
Applies
Last reviewed 11 Oct 2026
Status, dates and review.
- In force
- Binding law or regulation that applies now. A phased regime counts once its first obligations apply.
- Adopted by states
- A model text that takes effect state by state. The count is the issuer's own adoption map.
- Guidance
- Supervisory guidance, letters, reports, frameworks and examination priorities. They set expectations and apply existing rules.
- Proposed
- Published for comment and not yet final.
- Request for comment
- A regulator asking for views before it proposes anything.
- Announced
- Announced by the regulator and not yet published.
- Withdrawn
- Withdrawn by the issuer. Listed while policies and procedures may still cite it.
- Key date
- The date that matters most for the instrument now: the issue date for guidance, the effective or compliance date for a rule, the comment deadline for a proposal, and the deferred deadline for a phased regime. Dates after the update date are marked Upcoming.
- Last reviewed
- The date the row was last checked against its primary source. A row that links a Regulatory Reference entry shares that entry's review date, so a refreshed entry refreshes the row.
- Scope
- Instruments written for AI, and the general rules that decide how AI is supervised in financial services: model risk, third-party risk, cybersecurity and recordkeeping.
Using it each quarter.
- 01Filter to the sectors your organization is supervised in, then read the Status column. Rows marked Proposed, Request for comment or Announced are where the next change will come from.
- 02Carry every key date marked Upcoming into the compliance calendar, with an owner.
- 03Compare each Last reviewed date with the date of your previous review. A newer date means the row was rechecked or changed since, and the linked reference entry says what moved.
- 04Open the primary source before relying on a row. The reference entry sets out what the instrument requires and the evidence an examiner asks for.
In practice
Updated 11 October 2026. This tracker summarises publicly available rules and regulatory guidance and is provided for general information. It is not legal advice. Obligations depend on an institution's charter, licences, registration status, size and activities. Verify against the primary source linked on each row and consult counsel before relying on any summary here.