Skip to content
AI Foundations for Bankers
0%

Responsible AI & Fairness

intermediate12 min readUpdated responsible-aifairnessbiasfair-lendingecoasr-26-2
Jump to a section

The Obligation Has Not Changed -- The Technology Has

Fair lending is not a new concept in banking. The Equal Credit Opportunity Act (ECOA) of 1974 and the Fair Housing Act (FHA) of 1968 have governed lending decisions for decades. Every banker understands that credit decisions cannot discriminate on the basis of race, color, religion, national origin, sex, marital status, age, or receipt of public assistance.

What has changed is the technology making those decisions -- or influencing them. When an AI system helps evaluate loan applications, generate customer communications, or prioritize collections outreach, it must comply with the same fair lending obligations that apply to human decision-makers. The technology is new, but the core legal framework is not. What has shifted in the US since 2025 is how federal regulators enforce one part of it -- disparate impact -- and that shift is covered below. It changes where the exposure comes from, not whether fairness matters.

BANKING ANALOGY

Responsible AI is like fair lending compliance -- the technology changes, but the obligation to treat customers equitably does not. When banks moved from manual underwriting to credit scoring models in the 1990s, the fair lending laws did not change. Banks had to prove that their models did not discriminate, even unintentionally. The same transition is happening now with AI. Whether a credit decision is made by a human loan officer, a logistic regression model, or a Large Language Model, the obligation is identical: treat customers fairly regardless of protected characteristics.

Types of Bias in AI Systems

Bias in AI is not always intentional -- in fact, the most dangerous forms of bias are the ones no one intended to create. Understanding the sources of bias is the first step toward detecting and mitigating it.

Training Data Bias

Foundation models are trained on internet-scale data that reflects the biases present in human-generated text. If the training data contains stereotypical associations -- and it almost certainly does -- those associations become embedded in the model's behavior. An LLM may generate different language, tone, or recommendations when processing requests that vary only by names, locations, or other proxies for protected characteristics.

Historical Decision Bias

When AI systems are fine-tuned on historical banking data, they can learn and perpetuate patterns of past discrimination. If an institution's historical lending data reflects disparities -- even disparities that were legal at the time -- an AI trained on that data will reproduce those patterns.

Proxy Discrimination

Even when protected characteristics are excluded from AI inputs, the model may use correlated variables as proxies. ZIP codes correlate with race. Names correlate with ethnicity. Employment patterns correlate with gender. An AI system that appears race-neutral in its inputs can still produce racially disparate outcomes through these proxy variables.

Representation Bias

If certain customer segments are underrepresented in training data, the AI will perform less accurately for those segments. A customer service AI trained primarily on interactions with affluent customers may provide lower-quality assistance to customers in underserved communities -- precisely the populations that fair lending laws are designed to protect.

KEY TERM

Disparate Impact: A legal theory that treats a practice as discriminatory if it has a disproportionately adverse effect on a protected class, even if the practice appears neutral on its face and there was no intent to discriminate. It contrasts with disparate treatment -- treating people differently because of a protected characteristic. As of October 2026, the CFPB's rule says the Equal Credit Opportunity Act does not support disparate impact claims, and the OCC and FDIC have stopped examining for it, but the theory remains contested and live elsewhere (see below). For AI systems, testing the model's outcomes -- not just its inputs -- across protected groups remains prudent risk management.

Regulatory Expectations for AI Fairness

The US federal posture on fair lending changed sharply in 2025-2026. Know both what changed and what did not.

What Changed: Federal Disparate-Impact Enforcement

  • CFPB rule on Regulation B: A final rule published in April 2026 and effective July 2026 removes the "effects test" from Regulation B and states that the Equal Credit Opportunity Act (ECOA) does not authorize disparate-impact liability.
  • OCC examinations: In July 2025 the OCC told its examiners (Bulletin 2025-16) to stop requesting, reviewing or concluding on disparate-impact risk in fair lending exams.
  • FDIC examinations: In August 2025 the FDIC updated its consumer compliance examination manual to evaluate disparate treatment only.
  • CFPB AI guidance withdrawn: In May 2025 the CFPB withdrew its two circulars on adverse action notices for complex algorithms and AI.

What Did Not Change

  • Disparate treatment is still illegal. The CFPB rule expressly keeps disparate-treatment liability -- including using neutral-looking criteria as an intentional proxy for a protected characteristic. An AI system can still produce disparate treatment.
  • Adverse action notices still need specific reasons. Regulation B still requires lenders to give applicants the specific reasons for a denial, whatever model made or informed the decision.
  • Other exposure persists. The Reg B rule changes ECOA only. Banks still face fair-lending exposure under other laws such as the Fair Housing Act, under state laws and state attorneys general, through private litigation, and abroad. Federal policy could also reverse.
  • Reputational risk is unchanged. A model that systematically disadvantages a community is a headline and a customer problem, whatever the exam manual says.

Model Risk Guidance (SR 26-2 / OCC Bulletin 2026-13)

In April 2026 the Federal Reserve, OCC and FDIC replaced SR 11-7 (and OCC Bulletin 2011-12) with updated model risk management guidance -- SR 26-2, OCC Bulletin 2026-13 and FDIC FIL-15-2026. The new guidance is aimed mainly at banks with over $30 billion in assets, and it explicitly places generative and agentic AI outside its scope while the agencies gather input on how banks use AI (the OCC said a request for information is coming). That is not a free pass: examiners can still act on unsafe or unsound practices or violations of law, and most banks continue to apply model-risk disciplines -- inventory, validation, monitoring, documentation -- to their AI systems.

For fairness, the split matters. Traditional and non-generative AI credit models (such as machine-learning scorecards) remain within the guidance's principles of sound development, validation and monitoring. For LLMs, the bank's own framework governs -- including whether and how it tests for bias.

Fair Lending Testing Techniques

Whatever the exam focus, the established techniques remain the right tools for testing AI:

  • Comparative analysis: Do similarly situated applicants from different demographic groups receive similar outcomes?
  • Regression analysis: After controlling for legitimate credit factors, do protected characteristics (or their proxies) predict different outcomes?
  • Matched-pair testing: Do AI systems respond differently to otherwise identical scenarios when only demographic indicators change?

State and International Direction

  • Colorado: The original Colorado AI Act never took effect -- a federal magistrate judge blocked its enforcement in April 2026 in a challenge brought by xAI and supported by the Department of Justice. It was repealed and replaced by a new law (signed May 2026, effective January 2027) that covers lending and requires notice at the point of use, a plain-language explanation within 30 days of an adverse outcome, and a right to meaningful human review.
  • EU AI Act: Credit scoring remains a "high-risk" use, requiring conformity assessments, human oversight and bias testing. After the Digital Omnibus on AI (in force since July 2026), those obligations apply from December 2027. The Omnibus also lets providers and deployers process sensitive personal data, under safeguards, to detect and correct bias -- which helps fairness testing.

Implementing Fairness in Practice

Pre-Deployment Bias Testing

Before any AI system influences customer-facing decisions, the institution must conduct comprehensive bias testing:

  1. Define protected groups: Identify all protected characteristics relevant to your use case (race, ethnicity, gender, age, disability status, etc.)
  2. Establish baseline metrics: What are the current approval rates, pricing outcomes, and service quality metrics across protected groups?
  3. Test AI outputs: Run the AI system against a representative dataset and analyze outcomes across protected groups
  4. Apply statistical tests: Use standard disparate impact ratios (the four-fifths rule), regression analysis, and matched-pair comparisons
  5. Document findings: Maintain comprehensive documentation of testing methodology, results, and any identified disparities

Ongoing Monitoring

Bias testing is not a one-time activity. AI models can develop new biases as input data shifts, as the provider updates the underlying model, or as user behavior and products change. Establish automated monitoring that continuously evaluates AI outcomes across protected groups and alerts the model risk team when disparities emerge or worsen.

Explainability Requirements

When AI influences decisions that affect consumers, the institution must be able to explain them. For traditional models, explainability techniques are well-established; for LLMs it is harder but no less required:

  • Retrieval-based explanations: If the AI uses RAG, document which sources informed the response
  • Prompt logging: Maintain complete records of prompts and responses for audit purposes
  • Decision decomposition: For complex AI workflows, document each step where the AI contributed to the decision
  • Plain language explanations: Regulation B requires adverse action notices to give the specific reasons for a decision, whatever model was used -- "the model decided" is not an acceptable explanation

Warning

The fact that an AI model was developed by a third party does not transfer your institution's fair lending obligations. If your bank deploys an AI system that produces discriminatory outcomes, your institution is liable -- regardless of who built the model. Due diligence on AI vendors must include fair lending testing, and your institution must independently validate that the AI produces equitable outcomes for your specific customer population.

The Responsible AI Framework

A practical responsible AI framework for banking institutions should include:

ComponentOwnerFrequencyKey Activities
Bias testingModel ValidationPre-deployment + quarterlyDisparate impact analysis, matched-pair testing
Fairness monitoringModel RiskContinuousAutomated outcome tracking across protected groups
Explainability reviewCompliancePer use caseAdverse action notice adequacy, audit trail completeness
Ethics assessmentAI Ethics CommitteePre-deploymentBroader ethical implications beyond legal compliance
Vendor due diligenceThird-party RiskAnnual + trigger-basedAI vendor fairness claims verification
Training and awarenessHR / ComplianceAnnualFair lending in the AI context for all AI users

Tip

Do not wait for perfect fairness metrics before deploying AI. Establish a monitoring and remediation process that catches and corrects disparities as they emerge. The standard is not perfection -- it is good faith effort, rigorous testing, and prompt remediation. What examiners, courts and customers will not accept is an institution that deployed AI without testing for bias at all.

Quick Recap

  • Fair lending laws apply to AI the same way they apply to human decisions: ECOA and the Fair Housing Act prohibit discrimination regardless of the technology used, and disparate treatment remains illegal
  • AI bias has multiple sources: training data reflects societal biases, historical banking data can perpetuate past discrimination, and proxy variables can create disparate impact even when protected characteristics are excluded
  • The US federal posture changed, the risk did not disappear: the OCC and FDIC no longer examine for disparate impact, but testing for it remains prudent risk management because state, private-litigation, reputational and EU exposure persists
  • Explainability is a regulatory requirement: "the model decided" is not an acceptable explanation -- institutions must document and explain AI-influenced decisions in terms consumers and examiners can understand
  • Third-party AI does not transfer liability: your institution is responsible for fair lending compliance regardless of who built the model

KNOWLEDGE CHECK

A bank deploys an AI system to pre-screen mortgage applications. The system does not use race as an input variable, but analysis reveals that applicants from predominantly minority ZIP codes are denied at twice the rate of applicants from non-minority ZIP codes with similar credit profiles. What type of bias does this represent?

Which statement BEST describes the obligation of a bank that uses a model from a third-party AI vendor for credit decisions?

Why is ongoing bias monitoring particularly important for AI systems, compared to traditional credit scoring models?