Regulation · 4 min read

US AI Regulation for Financial Services: 2026 Map

US AI regulation for financial services, mapped: SR 11-7, OCC 2026-13, the NAIC AI Model Bulletin, and NIST AI RMF — what banks and insurers must meet.

By Evgeny Aleksandrov, Founder, BlackGrid ·


The United States has no single AI act for financial services. Instead it governs AI the way it governs most things in finance: through existing law and principles-based regulator guidance, applied institution-by-institution through supervision and examination. For anyone deploying agentic AI in financial services, that means there is no one rulebook to comply with — there is a map of overlapping expectations, and your program has to answer to all of it.

Diagram of US AI regulation for financial services as three layers: sector guidance (SR 11-7 / OCC 2026-13 and ECOA/CFPB for banking; the NAIC AI Model Bulletin for insurance), the state patchwork (attorneys general, state insurance departments, new state AI statutes), and cross-cutting frameworks (NIST AI RMF, Treasury FS AI RMF, NYDFS) — with one AI program answering to all three at once.

Banking

Insurance

Insurance is regulated at the state level, coordinated through the NAIC. The NAIC Model Bulletin on the Use of AI Systems by Insurers, adopted December 2023 and since enacted by roughly half the states, sets principles-based expectations: a written AI Systems program proportionate to risk, governance and accountability, third-party vendor diligence, and a focus on avoiding unfair discrimination. It is explicitly aligned with the NIST framework. See agentic AI in insurance for how this plays out in underwriting and claims.

Cross-cutting frameworks

  • NIST AI RMF — the Govern/Map/Measure/Manage core that both banking and insurance guidance point to.
  • US Treasury Financial Services AI RMF (February 2026) — a sector-specific adaptation of NIST for financial institutions.
  • NYDFS — AI-related cybersecurity and third-party-risk expectations under 23 NYCRR Part 500.

The state patchwork

Above the federal layer sits a fast-moving patchwork of state activity, which is where much of the near-term obligation actually lands. In insurance, the NAIC Model Bulletin has no force until a state adopts it — and roughly half have, each with its own wording and timing, so a multi-state carrier faces a matrix of similar-but-not-identical expectations. In banking, state attorneys general and regulators apply consumer-protection and anti-discrimination law to AI-driven decisions, and state cyber rules such as NYDFS's reach AI through third-party-risk and security expectations. Several states have also begun enacting comprehensive AI statutes of their own, raising the prospect that the strictest state rule effectively sets the floor for a national operator. The practical takeaway: track the states you operate in, not just Washington.

What this means for your program

There is no checkbox. A defensible US AI program maps to all three layers at once — model risk, the relevant sector rules, and the cross-cutting frameworks — and proves it with explainability and a complete audit trail. Build governance in from the start, and treat each examiner conversation as one your system was designed to pass.

A compliance checklist for AI in finance

There is no single checkbox, but there is a repeatable method. For each AI use in scope:

  1. Inventory it. Know where AI — including agentic systems — touches a customer decision: credit, pricing, claims, onboarding, monitoring.
  2. Map it to all three layers — existing law (fair lending, UDAAP, privacy), the relevant sector guidance (model risk, NAIC), and a cross-cutting framework (NIST AI RMF, Treasury FS AI RMF).
  3. Prove explainability — specific, accurate reasons for consequential decisions, as explainable AI in lending requires.
  4. Keep a complete audit trail and defined human-in-the-loop checkpoints.
  5. Test for bias and validate the system on an ongoing basis, and document what you did.
  6. Diligence your vendors — third-party AI inherits your obligations.

Run that loop per use case and the examiner conversation becomes a review of work you have already done.

Regulatory specifics change; confirm the current position with your compliance and legal teams before relying on any detail here.

Talk to BlackGrid about an agentic AI program built to satisfy US financial-services regulation.

Frequently asked questions

Is there a US AI law for financial services?

There is no single federal AI act. The US governs AI in finance through existing law (fair lending, consumer protection, model risk) plus principles-based regulator guidance — applied institution-by-institution through supervision and examination. That makes the landscape a map of overlapping rules rather than one statute.

What rules apply to AI in banking?

Model risk management guidance (SR 11-7, revised by OCC 2026-13), fair-lending law (ECOA / Regulation B) with CFPB's adverse-action expectations, and OCC / Federal Reserve / FDIC supervisory expectations. The revised model-risk guidance places generative and agentic AI outside its scope, shifting weight to voluntary frameworks.

What governs AI in insurance?

The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (adopted December 2023), which individual state insurance departments adopt. It is principles-based, expects a written AI Systems program, aligns with the NIST AI RMF, and emphasizes avoiding unfair discrimination.

How does the US approach differ from the EU AI Act?

The EU AI Act is a comprehensive, risk-tiered statute with explicit high-risk categories and obligations. The US relies on principles-based guidance plus existing law applied through supervision. A firm operating in both has to satisfy the EU's prescriptive regime and the US's examiner-driven one.


Sources

  1. Federal Reserve SR 11-7, Guidance on Model Risk Management (Apr 2011)
  2. OCC Bulletin 2026-13 / SR 26-02, Model Risk Management: Revised Guidance (Apr 2026)
  3. NAIC, Model Bulletin on the Use of AI Systems by Insurers (adopted Dec 4, 2023)
  4. NIST AI Risk Management Framework (AI RMF 1.0)
  5. US Treasury, Financial Services AI Risk Management Framework (Feb 2026)
  6. CFPB Circular 2022-03, Adverse-action requirements and complex algorithms (May 2022)
  7. NYDFS Industry Letter on cybersecurity risks from AI (Oct 16, 2024)

Related reading