Colorado this spring signed into state law the nation’s first rules governing higher-stakes artificial intelligence (AI) inside companies. It covers what AI might mean for bias in lending decisions and other transactions at banks and credit unions. And it requires making available documentation revealing what data informed the AI, and how the system performance was evaluated.
Colorado’s law follows less-restrictive consumer AI protections advanced in Utah and comes as bellwether California mulls its own actions this summer that could impact financial services. New York and Connecticut, too, have been contemplating state regulation on the matter but have not passed a law. Other states have moved to protect creative performers from AI. All told, AI, especially fast-expanding generative AI, which has the potential to upend many business practices, dominates statehouse dialogue around the country.
The banking industry’s approach to tighter scrutiny of AI practices so far mostly relies on the threat of regulation by litigation. At a minimum, banks and credit unions must use an AI policy to protect themselves from this largely unregulated business practice, weighing up the risk and reward. That means banks can’t shrug off responsibility.
The Federal Reserve, for its part, says AI use is on a list of periodic risk discussions it holds with banks and the OCC has flagged AI among emerging risks. So far, federal legislation hasn’t gotten off the ground. The U.S. may also take its cues from AI regulatory responses by the European Union and other formidable powers given the global nature of financial transactions and the reach of international fraud risks.
Why all the buzz? Last year, a group of state lawmakers from almost 30 states engaged in an AI working group. They met seven times and heard from a range of experts across multiple AI fields. Regulation watchers anticipate a potential domino effect of state AI law passage, which tends to move much faster than Washington.
Operating in the unknown
For now, the lack of uniformity challenges banks and credit unions operating across multiple states, as well as those looking for best-practice guidance to stay well ahead of regulations in a shifting AI environment. These unknowns can strain operational budgets and they risk potential extra costs in legal defense, fines, soured customer confidence and more.
Yet the demand for ramping up financial services use of AI, which is seen saving money through operational efficiencies, is only growing. With that comes pressure for balanced rulemaking and sound internal policies.
AI use within the bank varies these days, but real-life examples have expanded beyond popular early applications when, for instance, AI in contact centers fed human agents product suggestions based on breadcrumbs a phone customer might leave in a vague conversation.
Nowadays AI increasingly might help compliance departments check off first-line requirements, leaving tougher rules adherence to human experts. And AI has potential in filling scores of open jobs in policing cybersecurity crime.
What can regulation achieve?
Regulation, broadly speaking, has been crafted to minimize bias from AI and to push for transparency. Yet when it comes to fraud, AI is seen as both a potential pathway for bad actors and the very tool needed to keep pace with crime, a paradox that may complicate rulemaking.
As for action to date, Utah’s main push was for companies to disclose AI use to the public, while proponents in Colorado wanted accountable change “to minimize discrimination,” say attorneys Owen Davis and David Strauss of Husch Blackwell.
California’s approach is more comprehensive, with as many as 30 separate pieces of legislation still alive in a summer session that wraps at the end of August, although not all of those will be especially relevant to financial services. The first bill is much like the anti-bias push in Colorado, Davis and Strauss write in a status briefing of California’s pending legislation.
How banks can respond with AI policy right now
Chris Boersma, a product manager in compliance with BAI, points to the existing gap between state and federal rules on a separate topic — privacy — for hints on how complicated the spotty AI regulatory field is.
“For instance, 14 states have passed privacy bills, with another 18 that have introduced legislation, and meanwhile, the federal government is a little behind the curve on privacy,” he says. “That’s happened just over the last three or so years. I could see a similar approach with AI if the federal government doesn’t step in quickly to address this need.”
Boersma and Sylwia Czajkowska, an associate director at RMA, addressed AI policy, risk management and the lack of uniform rules during BAI’s spring Deep Dive: A practical approach to AI.
Meantime, Boersma says, in addition to the third-party, or vendor, compliance example, there are other categories that bank regulators will draw from as they scrutinize an organization that may be already using AI: copyright issues, data accuracy, fair lending concerns and equal opportunities in employment, to name some.
“The big thing I want institutions to focus on if you’re considering using AI or already using AI is to know you cannot just implement AI and leave it be or treat it like a third-party risk,” Boersma says. “Have controls in place to monitor activities so that you know, and can prove, that AI is performing exactly how you want it to.”
Rachel Koning Beals is Senior Editor at BAI.