The United States has no single AI act for financial services. Instead it governs AI the way it governs most things in finance: through existing law and principles-based regulator guidance, applied institution-by-institution through supervision and examination. For anyone deploying agentic AI in financial services, that means there is no one rulebook to comply with — there is a map of overlapping expectations, and your program has to answer to all of it.
Banking
- Model risk. SR 11-7 set the long-standing expectations for model development, validation, and governance. The revised OCC 2026-13 / SR 26-02 updates that guidance — and explicitly places generative and agentic AI outside its scope, which is why model risk management for agentic AI now leans on other frameworks.
- Fair lending. ECOA and Regulation B require explainable adverse-action reasons; CFPB Circular 2022-03 confirms this holds even for complex algorithms — the basis for explainable AI in lending.
Insurance
Insurance is regulated at the state level, coordinated through the NAIC. The NAIC Model Bulletin on the Use of AI Systems by Insurers, adopted December 2023 and since enacted by roughly half the states, sets principles-based expectations: a written AI Systems program proportionate to risk, governance and accountability, third-party vendor diligence, and a focus on avoiding unfair discrimination. It is explicitly aligned with the NIST framework. See agentic AI in insurance for how this plays out in underwriting and claims.
Cross-cutting frameworks
- NIST AI RMF — the Govern/Map/Measure/Manage core that both banking and insurance guidance point to.
- US Treasury Financial Services AI RMF (February 2026) — a sector-specific adaptation of NIST for financial institutions.
- NYDFS — AI-related cybersecurity and third-party-risk expectations under 23 NYCRR Part 500.
The state patchwork
Above the federal layer sits a fast-moving patchwork of state activity, which is where much of the near-term obligation actually lands. In insurance, the NAIC Model Bulletin has no force until a state adopts it — and roughly half have, each with its own wording and timing, so a multi-state carrier faces a matrix of similar-but-not-identical expectations. In banking, state attorneys general and regulators apply consumer-protection and anti-discrimination law to AI-driven decisions, and state cyber rules such as NYDFS's reach AI through third-party-risk and security expectations. Several states have also begun enacting comprehensive AI statutes of their own, raising the prospect that the strictest state rule effectively sets the floor for a national operator. The practical takeaway: track the states you operate in, not just Washington.
What this means for your program
There is no checkbox. A defensible US AI program maps to all three layers at once — model risk, the relevant sector rules, and the cross-cutting frameworks — and proves it with explainability and a complete audit trail. Build governance in from the start, and treat each examiner conversation as one your system was designed to pass.
A compliance checklist for AI in finance
There is no single checkbox, but there is a repeatable method. For each AI use in scope:
- Inventory it. Know where AI — including agentic systems — touches a customer decision: credit, pricing, claims, onboarding, monitoring.
- Map it to all three layers — existing law (fair lending, UDAAP, privacy), the relevant sector guidance (model risk, NAIC), and a cross-cutting framework (NIST AI RMF, Treasury FS AI RMF).
- Prove explainability — specific, accurate reasons for consequential decisions, as explainable AI in lending requires.
- Keep a complete audit trail and defined human-in-the-loop checkpoints.
- Test for bias and validate the system on an ongoing basis, and document what you did.
- Diligence your vendors — third-party AI inherits your obligations.
Run that loop per use case and the examiner conversation becomes a review of work you have already done.
Regulatory specifics change; confirm the current position with your compliance and legal teams before relying on any detail here.
Talk to BlackGrid about an agentic AI program built to satisfy US financial-services regulation.