From the journal

AI Lending: Fair Lending and UDAAP Convergence

AI underwriting receives no federal exemption. The governing statutory elements remain technology-neutral, while complex models can increase the proof and controls needed for fair-lending, notice, accuracy, and deception compliance. Current CFPB ECOA policy emphasizes intentional discrimination and specific adverse-action reasons, not disparate impact. FTC exposure remains strongest for nonbank ECOA violations, unfair injury, and unsupported AI claims. Mortgage models retain separate FHA disparate-impact risk.

Illia ProkopievCo-Founder and CEO18 min read

The question presented is whether, as of August 2, 2026, the Consumer Financial Protection Bureau and Federal Trade Commission subject AI-driven credit or underwriting models to the same or greater fair-lending and UDAAP scrutiny as conventional models. This analysis assumes United States federal law, a consumer-credit product, and no lender-specific facts. State law, prudential safety-and-soundness standards, and licensing requirements fall outside the stated scope.

Summary

AI receives no exemption from federal consumer-finance law. ECOA, Regulation B, the Fair Credit Reporting Act, the Fair Housing Act, the Consumer Financial Protection Act, and Section 5 of the FTC Act apply according to the conduct, product, and institutional role involved.

Complex models can require more validation, documentation, testing, reason-generation, data controls, and vendor access. Those practical burdens arise from existing duties rather than a separate AI liability category.

The quoted proposition needs a current-status qualification. The CFPB withdrew its 2022 and 2023 AI adverse-action circulars on May 12, 2025. It later adopted a Regulation B rule, effective July 21, 2026, stating that ECOA does not authorize disparate-impact liability. Interpretive Rules, Policy Statements, and Advisory Opinions; Withdrawal, 90 Fed. Reg. 20,084, 20,086 (May 12, 2025); Equal Credit Opportunity Act (Regulation B), 91 Fed. Reg. 21,620, 21,668–70 (Apr. 22, 2026).

Intentional discrimination remains prohibited. A creditor may not use a prohibited basis directly or design a facially neutral variable as an intentional proxy. 15 U.S.C. § 1691(a); 12 C.F.R. §§ 1002.4(a), 1002.6(a); 12 C.F.R. pt. 1002, Supp. I, cmt. 6(a)-2.

ECOA’s notice duty survives the circular withdrawals. A creditor must give the actual principal reasons for adverse action. A generic score, policy reference, or plausible post-hoc explanation is insufficient when it does not identify the factors that drove the decision. 15 U.S.C. § 1691(d)(2)–(3); 12 C.F.R. § 1002.9(a)(2), (b)(2).

CFPB UDAAP authority and FTC UDAP authority are distinct. A discriminatory result does not automatically establish unfairness under either statute. The agency must prove the statutory elements of unfairness, deception, abuse, substantial assistance, or another applicable claim.

FTC v. FloatMe Corp. shows direct enforcement overlap among lending, AI representations, and discrimination. It does not establish that a functioning AI model produced discriminatory results. The complaint alleged that the advertised automated increase process did not exist, while a separate policy excluded certain public-assistance income. No. 5:24-cv-00001-XR, Compl. ¶¶ 3–4, 61–66, 77–79, 94–100; Stipulated Order §§ I.A.5, VI–VIII, Dkt. 7 (W.D. Tex. filed Jan. 22, 2024).

Alternative-data and model vendors may trigger FCRA duties when they meet the statutory definitions of a consumer reporting agency and consumer report. Permissible-purpose, accuracy, dispute, and adverse-action duties can then apply independently of ECOA. 15 U.S.C. §§ 1681a, 1681b, 1681e, 1681m.

Residential mortgage models retain separate Fair Housing Act disparate-impact exposure. HUD proposed removing its discriminatory-effects regulation in January 2026, but no final removal appeared in the official sources reviewed through August 2, 2026. The Supreme Court’s statutory holding also remains controlling. 42 U.S.C. § 3605; 24 C.F.R. § 100.500; Texas Department of Housing & Community Affairs v. Inclusive Communities Project, Inc., 576 U.S. 519, 533–46 (2015).

The more accurate current formulation is that AI underwriting remains subject to technology-neutral federal duties. Model complexity may increase the proof and controls needed for fair-lending, notice, accuracy, and deception compliance. Current CFPB ECOA policy centers on intentional discrimination and specific adverse-action reasons, while mortgage lending retains a distinct FHA disparate-impact analysis.

Joint Statement

In April 2023, the CFPB, FTC, Department of Justice Civil Rights Division, and Equal Employment Opportunity Commission issued a joint statement about automated systems. They stated that existing laws apply to automated decision-making. The statement expressly created no new rights or obligations. Joint Statement on Enforcement Efforts Against Discrimination and Bias in Automated Systems 1, 4 (Apr. 25, 2023).

The CFPB also issued two circulars addressing adverse-action explanations from complex algorithms. Those circulars took the position that model complexity did not excuse vague or inaccurate reasons. The CFPB withdrew both circulars on May 12, 2025. Interpretive Rules, Policy Statements, and Advisory Opinions; Withdrawal, 90 Fed. Reg. 20,084, 20,086 (May 12, 2025).

The withdrawal did not repeal ECOA or Regulation B. It removed the circulars as current CFPB interpretive materials. The underlying notice provisions remain in force.

The CFPB then changed its disparate-impact position. Its current public materials state that the Bureau no longer uses disparate-impact liability in fair-lending supervision or enforcement. The Bureau states that it focuses on intentional discrimination involving identifiable victims.

A Regulation B amendment took effect on July 21, 2026. The regulation now states that ECOA does not provide an effects test. 12 C.F.R. § 1002.6(a). The adopting release explains the CFPB’s view that ECOA does not authorize disparate-impact liability. Equal Credit Opportunity Act (Regulation B), 91 Fed. Reg. 21,620, 21,668–70 (Apr. 22, 2026).

The FTC has not adopted a lending-specific rule imposing heightened legal scrutiny on AI models. Its July 2026 proposed AI policy statement addresses representations about AI accuracy, reliability, and objectivity under Section 5. It remains proposed and does not create a separate underwriting standard.

Existing federal laws continue to apply when an entity uses AI. A complex model may require more evidence and controls to prove compliance. Model complexity does not change the elements of the governing claim.

ECOA applies according to the credit function, not the model label

ECOA prohibits a creditor from discriminating against an applicant on a prohibited basis regarding any aspect of a credit transaction. 15 U.S.C. § 1691(a). Regulation B applies the prohibition to credit availability, standards of creditworthiness, credit terms, servicing, collection, and related treatment. 12 C.F.R. § 1002.4(a).

The rule reaches automated and manual decisions alike. A model violates ECOA when it directly uses race, color, religion, national origin, sex, marital status, age, public-assistance status, or protected-rights activity to disadvantage an applicant.

A facially neutral variable can also violate the current intent-based rule. The Regulation B commentary identifies intentional proxy discrimination as prohibited treatment. 12 C.F.R. pt. 1002, Supp. I, cmt. 6(a)-2. A lender cannot evade ECOA by replacing a protected classification with a variable deliberately selected to reproduce that classification.

Intent may be proved through direct or circumstantial evidence. Relevant evidence can include feature selection, development documents, stated objectives, manual overrides, inconsistent exceptions, unexplained departures from policy, or false explanations. Statistical disparities can support that inquiry. Under the current CFPB rule, disparity alone does not establish ECOA disparate-impact liability.

Age receives a limited statutory treatment. A creditor may use age in an empirically derived, demonstrably and statistically sound credit-scoring system. It may not assign an elderly applicant a negative factor or value. 15 U.S.C. § 1691(b)(3); 12 C.F.R. § 1002.6(b)(2)(ii).

Regulation B defines the scoring systems that qualify for this treatment. The system must use accepted statistical principles and methodology. It must undergo periodic revalidation and adjustment when predictive ability deteriorates. 12 C.F.R. § 1002.2(p)(1)(iii)–(iv).

That definition has a limited function. It principally governs the regulatory status needed for lawful use of age. It does not create a universal validation statute covering every AI model.

Public-assistance income also receives specific protection. ECOA prohibits discrimination because all or part of an applicant’s income derives from public assistance. 15 U.S.C. § 1691(a)(2). A creditor may evaluate the amount and probable continuance of income in a lawful manner. It may not reject income merely because its source is public assistance. 15 U.S.C. § 1691(b)(2); 12 C.F.R. § 1002.6(b)(2).

Adverse-action reasons must describe the actual decision

ECOA’s notice requirement remains controlling despite the circular withdrawals. A creditor must give an adverse-action applicant specific reasons or disclose the right to obtain them. 15 U.S.C. § 1691(d)(2)–(3).

Regulation B requires the creditor to identify the principal reasons for the action. A statement that the applicant failed the creditor’s internal standards is insufficient. A credit score alone is also insufficient when it does not state the reasons that produced the result. 12 C.F.R. § 1002.9(a)(2), (b)(2).

The official commentary requires reasons that relate to factors actually considered or scored. The creditor may not omit a principal factor. It must state the actual reason even when that factor’s predictive relationship appears nonintuitive to the applicant. 12 C.F.R. pt. 1002, Supp. I, cmt. 9(b)(2)-2 to -4.

Regulation B does not mandate one technical explanation method. A post-hoc explanation method can satisfy the rule only when it reliably identifies the actual principal factors. A plausible narrative fails when it describes what the model might have considered rather than what drove the applicant’s decision.

This distinction matters for large language models, neural networks, ensemble systems, and vendor models. Local explanation tools can produce unstable or approximate reason rankings. A lender must validate that the disclosed reasons correspond to the operative model, feature transformations, decision threshold, and applicant record.

A vendor’s inability to reveal model factors does not eliminate the creditor’s duty. The creditor must either obtain adequate reason-generation capability, constrain the model’s use, add a verified decision layer, or avoid deploying the model for decisions that require ECOA notices.

FCRA score-factor disclosures do not replace ECOA reasons. When both statutes apply, the creditor must satisfy both disclosure regimes. 12 C.F.R. pt. 1002, Supp. I, cmt. 9(b)(2)-9.

Current ECOA disparate-impact risk depends on agency posture and forum

The current CFPB rule rejects standalone ECOA disparate-impact liability. The CFPB also states that it no longer uses disparate impact in supervision or enforcement. This change removes the Bureau’s former administrative position. It does not constitute a Supreme Court interpretation of ECOA.

Older appellate decisions do not present a uniform answer. The Ninth Circuit recognized an ECOA disparate-impact theory. Miller v. American Express Co., 688 F.2d 1235, 1239–40 (9th Cir. 1982).

The D.C. Circuit and Sixth Circuit assumed the possible availability of that theory without deciding the issue. Garcia v. Johanns, 444 F.3d 625, 633 n.9 (D.C. Cir. 2006); Midkiff v. Adams County Regional Water District, 409 F.3d 758, 771–72 (6th Cir. 2005).

A Fifth Circuit decision recognized disparate-impact liability with limited statutory analysis. The Supreme Court later vacated and remanded that judgment on other grounds. Bhandari v. First National Bank of Commerce, 808 F.2d 1082, 1101 (5th Cir. 1987), vacated and remanded, 492 U.S. 901 (1989).

Courts retain authority to interpret ECOA. A private plaintiff may invoke older circuit precedent or challenge the validity of the 2026 regulation. The practical litigation answer can therefore depend on forum, claim posture, and later judicial treatment.

The current federal position can be stated with precision. CFPB ECOA supervision and enforcement no longer rely on disparate impact. Regulation B now rejects an effects test. Private litigation remains unsettled where older circuit authority bears on the claim.

Outcome disparities still have evidentiary value. They can identify direct protected-class use, intentional proxies, selective overrides, pretext, inconsistent treatment, or a flawed explanation. They can also trigger separate FHA, FCRA, FTC Act, or state-law inquiries.

CFPB UDAAP authority does not create a general discrimination prohibition

The Consumer Financial Protection Act prohibits covered persons and service providers from engaging in unfair, deceptive, or abusive acts or practices. 12 U.S.C. §§ 5531, 5536.

An unfairness claim requires substantial consumer injury. Consumers must be unable reasonably to avoid the injury, and countervailing benefits must not outweigh it. 12 U.S.C. § 5531(c).

A deception claim generally requires a material representation, omission, act, or practice that is likely to mislead consumers acting reasonably under the circumstances. An abusive claim must satisfy one of the statutory tests in 12 U.S.C. § 5531(d).

The CFPB’s 2022 examination-manual changes treated discrimination itself as an unfair practice. A federal district court vacated those changes and enjoined their application to the plaintiff members. Chamber of Commerce of the United States v. CFPB, 691 F. Supp. 3d 730, 743–46 (E.D. Tex. 2023). The CFPB dismissed its appeal in May 2025.

That decision restricts the categorical theory. It does not exempt discriminatory model conduct from all Consumer Financial Protection Act claims.

A lender may face deception liability when it misstates eligibility rules, conceals material exclusions, gives false adverse-action explanations, or claims that an automated process exists when decisions are made differently.

Unfairness may apply when the conduct independently satisfies Section 1031(c). Abusive conduct may apply when the entity materially interferes with consumer understanding or takes unreasonable advantage of a statutory circumstance. A model developer or vendor may face substantial-assistance liability when the elements of 12 U.S.C. § 5536(a)(3) are met.

Each claim requires proof of its own statutory elements. A demographic disparity does not by itself establish UDAAP liability.

Terminology also matters. The CFPB administers a federal prohibition on unfair, deceptive, or abusive acts or practices. The FTC Act prohibits unfair or deceptive acts or practices. It contains no abusive category.

FTC authority reaches nonbank lending, AI representations, and fact-specific unfairness

The FTC can reach nonbank credit conduct through Section 5 and ECOA’s enforcement allocation.

Section 5 prohibits unfair or deceptive acts or practices in or affecting commerce. 15 U.S.C. § 45(a). Unfairness requires substantial injury that consumers cannot reasonably avoid and that countervailing benefits do not outweigh. 15 U.S.C. § 45(n).

Ordinary Section 5 jurisdiction excludes banks, savings and loan institutions, and federal credit unions. 15 U.S.C. § 45(a)(2). Entity classification therefore determines whether the FTC can use its general Section 5 authority.

ECOA separately grants the FTC enforcement authority, subject to the assignments made to other federal agencies and the Consumer Financial Protection Act. An ECOA violation within that allocation is treated as an FTC Act violation for enforcement purposes. 15 U.S.C. § 1691c(c).

FTC v. FloatMe Corp. provides the clearest direct example of overlap. FloatMe marketed a cash-advance product and represented that an automated process could increase a consumer’s advance limit. The FTC complaint alleged that no such automated increase process existed. It separately alleged that FloatMe excluded applicants whose income came solely from certain public-assistance programs.

The complaint pleaded false-representation claims, an FTC Act unfair-discrimination claim, and an ECOA discrimination claim. The stipulated order prohibited false AI and algorithm claims, barred discrimination, required a fair-lending program, and entered a $3 million monetary judgment. FTC v. FloatMe Corp., No. 5:24-cv-00001-XR, Compl. ¶¶ 3–4, 61–66, 77–79, 94–100; Stipulated Order §§ I.A.5, VI–VIII, Dkt. 7 (W.D. Tex. filed Jan. 22, 2024).

FloatMe has two important limits. Complaint allegations are not adjudicated findings. The stipulated order resolved the action without a merits determination governing other defendants.

The alleged discrimination also did not arise from the advertised automated process. The FTC alleged that the automated process did not exist. It attributed the public-assistance exclusion to a separate eligibility policy.

FloatMe therefore demonstrates enforcement overlap. It does not establish precedent that a functioning AI underwriting model produced unlawful bias.

FTC deception exposure can arise without discriminatory results. Claims that a model is automated, objective, accurate, explainable, unbiased, or consistently applied require substantiation. The claim must match actual model use, data sources, manual intervention, known limitations, and measured performance.

The FTC’s July 2026 proposed AI policy statement follows that deception-oriented path. It addresses unsupported claims about AI accuracy and objectives. It is not a final rule, a lending rule, or a heightened fair-lending standard.

FCRA can govern model inputs, vendors, outputs, and notices

FCRA may attach before the fair-lending analysis begins. Its application depends on statutory definitions and operational facts.

A vendor is a consumer reporting agency only when it regularly engages in assembling or evaluating consumer credit information or other consumer information for the purpose of furnishing consumer reports to third parties. It must also meet the other elements of 15 U.S.C. § 1681a(f).

An output is a consumer report only when it meets 15 U.S.C. § 1681a(d). A marketing score, fraud signal, identity result, income estimate, cash-flow score, or alternative-data assessment does not receive one legal classification solely from its label.

When FCRA applies, a consumer reporting agency must furnish reports only for permissible purposes. It must maintain reasonable procedures to limit furnishing to those purposes. 15 U.S.C. §§ 1681b, 1681e(a).

A consumer reporting agency must also follow reasonable procedures to assure maximum possible accuracy. 15 U.S.C. § 1681e(b). Model errors, incorrect identity matching, stale records, faulty feature transformations, and unverified inferred attributes can implicate that duty.

A user taking adverse action based in whole or part on a consumer report must provide the notice prescribed by 15 U.S.C. § 1681m. That notice remains distinct from the ECOA adverse-action explanation.

Novel data do not fall outside FCRA merely because the source is unconventional. Nor does every data or model provider become a consumer reporting agency. Classification turns on how the provider obtains, assembles, evaluates, and furnishes information, and on the purposes for which recipients use it.

A lender should therefore classify each vendor and output before deployment. The contract’s chosen label does not control the statutory result.

Mortgage models retain separate Fair Housing Act disparate-impact exposure

Residential mortgage underwriting requires a separate Fair Housing Act analysis.

FHA Section 805 prohibits discrimination in residential real-estate-related transactions. Covered conduct includes making or purchasing loans for acquiring, constructing, improving, repairing, or maintaining a dwelling. It also includes loans secured by residential real estate. 42 U.S.C. § 3605.

The Supreme Court held that disparate-impact claims are cognizable under the FHA. The Court also imposed causation, business-justification, and remedial limits. Texas Department of Housing & Community Affairs v. Inclusive Communities Project, Inc., 576 U.S. 519, 533–46 (2015).

Current HUD regulations state a discriminatory-effects test. They address causation, legitimate interests, and less-discriminatory alternatives. 24 C.F.R. § 100.500.

HUD proposed removing Section 100.500 in January 2026. The proposal did not itself change the regulation. No final removal appeared in the official materials reviewed through August 2, 2026.

A future regulatory removal also would not overrule the Supreme Court’s interpretation of the statute. It could alter HUD’s regulatory implementation and litigation arguments, but Inclusive Communities would remain judicial authority unless later limited or overruled.

A mortgage model can therefore face two materially different federal tests. Current ECOA administration centers on intentional discrimination. The FHA continues to recognize disparate-impact claims for covered residential transactions.

This distinction prevents a single answer for all lending models. Product classification can affect the legal exposure more than the model architecture.

Outsourcing does not merge the parties’ statutory roles

Use of a third-party model does not transfer all liability to the vendor. Each participant retains duties attached to its statutory role.

The creditor remains responsible for ECOA compliance. That responsibility includes the decision criteria, prohibited-basis treatment, and adverse-action reasons communicated to applicants.

When a creditor relies on a qualifying empirically derived scoring system that uses age, Regulation B commentary assigns validation and revalidation responsibility based on the creditor’s own data. 12 C.F.R. pt. 1002, Supp. I, cmt. 2(p)-2 to -3.

A vendor may separately qualify as a consumer reporting agency under FCRA. It may qualify as a covered service provider under the Consumer Financial Protection Act. It may face FTC liability for its own deceptive statements or unfair conduct.

Contract terms can allocate access, testing, notice, indemnity, and remediation obligations. They do not alter the parties’ statutory identities.

The operational map should identify the creditor, model developer, data provider, consumer reporting agency, service provider, loan purchaser, servicer, and final decision-maker. The map should also identify which party selects features, sets thresholds, approves overrides, generates reasons, and monitors outcomes.

AI increases the compliance burden without changing the statutory standard

AI can create a higher practical burden when features are numerous, nonintuitive, unstable, inferred, or controlled by a vendor. That burden concerns evidence and operational controls. It is not a heightened legal test.

A defensible control system begins with an inventory of models and decision uses. The inventory should cover eligibility, pricing, line assignment, fraud screening, marketing, servicing, collection, hardship, and account management.

Records should identify each model version, deployment date, data source, feature transformation, threshold, override, output, and notice. The records should permit reconstruction of the decision made for a particular applicant.

Data controls should identify provenance, permissible purpose, retention, correction pathways, missing-value treatment, identity matching, and inferred attributes. FCRA classification should occur before consumer-report data or outputs enter production.

Fair-lending testing should examine direct protected-basis use, intentional proxies, feature-selection objectives, manual overrides, and inconsistent exceptions. Mortgage models should also undergo FHA disparate-impact assessment.

Outcome testing remains useful after the CFPB’s ECOA change. It can reveal intentional selection, pretext, override patterns, FHA exposure, inaccurate data, or unstable model performance. The legal significance of a disparity depends on the governing statute and evidence.

Reason-code testing should compare disclosed reasons with the model’s actual principal factors. Testing should cover production data, transformed features, threshold effects, model updates, and manual intervention.

Performance controls should address validation, drift, recalibration, override rates, error distribution, and changes in the applicant population. The legal basis for each control should be stated rather than attributed generically to AI regulation.

Vendor contracts should require feature documentation, change notices, test access, reason-generation support, data provenance, incident reporting, and audit rights. A lender should assess whether trade-secret restrictions prevent it from meeting statutory duties.

Marketing review should test every claim about automation, objectivity, accuracy, approval likelihood, speed, explainability, and bias. The evidence should support the precise claim made to consumers or business customers.

Complaint and appeal data should feed the monitoring process. Repeated disputes about the same feature, reason, data source, or population can identify a model defect or a disclosure failure.

Illia Prokopiev

Written by

Illia Prokopiev

Co-Founder and CEO

Illia is the Managing Partner and founder of Licentium. With over 11 years of practice, he has guided innovators through cross-border M&A deals and the disputes that follow, combining transactional skill with courtroom resolve. Admitted to the bar in 2017, he pivoted early to Web3, serving as legal advisor to prominent crypto projects and carrying AML/MLRO duties that anchored complex token, DAO, and compliance questions on solid regulatory ground. Certified in money laundering prevention and an active crypto investor, Illia blends market intuition with a global network of specialists, enabling Licentium to untangle licensing knots for crypto and AI ventures anywhere in the world.

More from the journal

See all

Regulation (EU) 2026/1744 Extends AI Act High-Risk Deadlines, European Union, 27 July 2026

On 27 July 2026, Regulation (EU) 2026/1744, the Digital Omnibus on Artificial Intelligence, entered into force following its publication in the Official Journal on 24 July 2026. The regulation amends the AI Act's application timetable, extending the compliance deadline for most Annex III high-risk systems from 2 August 2026 to 2 December 2027. Article 50 transparency obligations and Article 5 prohibitions retain their original application dates.

Munich District Court Rules AI Music Training Infringes Copyright, GEMA v. Suno, Germany, 31 July 2026

On 31 July 2026, the Munich District Court I (Landgericht München I) delivered judgment in case no. 42 O 763/25, ruling that Suno's training of its AI music generation model on protected musical works without a licence infringes reproduction rights under German copyright law. The decision is the first in Europe to impose copyright liability on an AI company for training-data use, and awards GEMA injunctive relief, revenue disclosure, and a right to claim damages.

Pennsylvania HB 2711 Proposes State Regulation of Prediction Market Platforms, United States, 22 July 2026

On 22 July 2026, Representative Tarik Khan introduced Pennsylvania HB 2711 with 24 co-sponsors, proposing a state regulatory regime for prediction market platform operators. The bipartisan bill sets the minimum participation age at 21, restricts trading by persons holding material nonpublic information, and grants the Pennsylvania Attorney General enforcement authority including fines of up to $10,000 per violation and the power to ban non-compliant platforms.