Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Organizations
  • Organizations
    • FINANCIAL TECHNOLOGY—Treasury seeks comment on GENIUS Act rules for stablecoins
    • BANKING OPERATIONS—Trump-affiliated crypto bank charter approved amid concern as Democrats pursue legislative response
    • CONSUMER FINANCIAL PROTECTION BUREAU—CFPB stops publishing consumer complaint narratives, visualizations
    • FINANCIAL TECHNOLOGY—CBA, ABA lay out financial services AI framework priorities
    • MERGERS AND ACQUISITIONS—Warren warns regulators about OppFi’s ‘persistent, predatory’ strategies,(Aug. 17, 2026)
    • REGULATION TRACKER—Upcoming comment deadlines and effective dates
  • Articles
  • Articles
  • Organizations
  • Organizations

    Banking and Finance Law Daily Wrap Up, FINANCIAL TECHNOLOGY—CBA, ABA lay out financial services AI framework priorities, (Aug 17, 2026)

    Organizations Mentioned:American Bankers Association | Community Bankers Association

    By Jeff Williams

    The banking groups' responses discuss approaches to validating AI models, privacy protections, and oversight.

    As artificial intelligence (AI) continues to quickly evolve, Congress and policymakers examining the use of AI by financial institutions shou ...

    By Jeff Williams

    The banking groups' responses discuss approaches to validating AI models, privacy protections, and oversight.

    As artificial intelligence (AI) continues to quickly evolve, Congress and policymakers examining the use of AI by financial institutions should take the opportunity to build a national framework for regulating its use by the financial services sectors that guards against a patchwork of state laws, the American Bankers Association (ABA) and the Community Bankers Association (CBA) each said in written responses to a wide-ranging request for information (RFI) issued last month by Rep. Maxine Waters (D-Calif.), the ranking member of the House Financial Services Committee.

    Waters' RFI invited consumer advocates, industry experts, regulators, and the public to submit feedback on numerous issues related to the use of AI in the financial marketplace (see Banking and Finance Law Daily, July 8, 2026).

    ABA Responses.The ABA called for the Congress to establish a "nationally harmonized, risk-based federal AI framework for federally supervised banking activities that preempts conflicting state and local requirements while preserving strong consumer protection, fair-lending, privacy, cybersecurity, operational-resilience, and safety-and-soundness outcomes."

    The Trump administration's efforts to address AI-related cybersecurity issues "represents a sound basis for additional action," the ABA said, but "it will ultimately be necessary for the executive branch to act pursuant to Congressional action in order to fully extend appropriate oversight mechanisms to developers of frontier AI models."

    The group stressed the need for a national review process that focuses on "high-impact findings affecting widely deployed software that supports critical systems" and includes "liability protections that enable firms to share the information necessary to accelerate confidential vulnerability remediation without fear of increased legal exposure." In addition, the ABA said, the process should focus on "core service providers that deliver essential back-end infrastructure for banks, including transaction processing, account management, and digital banking platforms."

    Among its other suggestions, the ABA said that it is "critical" for Congress to reauthorize the Cybersecurity Information Sharing Act of 2015 to "to preserve privacy, liability, and antitrust protections so that banks can confidently share information about cyber threats, vulnerabilities, and incidents with other private-sector firms and U.S. government agencies."

    In response to a question about banks' use of AI frameworks, the ABA said that banks have "established and maintained very strong cybersecurity programs" to protect personal information, the "advanced forms of AI pose a significant test that demands urgency, discipline, and rigor to identify and remediate vulnerabilities at speed and scale."

    The group also said that Globally Systemically Important Banks and other "members of the critical infrastructure" should be included in programs given early access to advanced AI models to identify vulnerabilities. "Ultimately, access to these systems should be tied to the business interest in using them (i.e., either directly or via a service provider) as well as the technological capability to identify and remediate software defects," ABA said.

    Rather than creating new legal frameworks, Congress should clarify that existing regulations regarding explainability and customer disclosures apply to AI. Along with passing other privacy legislation, Congress should also clarify that existing Gramm-Leach-Bliley Act privacy obligations apply to data shared for AI applications, ABA said, adding that the "real challenge" is ensuring that those obligations are "observed by all entities, regardless of what financial services they provide."

    As Congress considers other AI safeguards, "any AI-specific federal laws or provisions must recognize banks’ existing compliance framework and not impose duplicative or inconsistent requirements," ABA said.

    CBA Responses. The CBA urged Congress and federal regulators to create a "balanced regulatory framework that fosters responsible innovation while maintaining robust safeguards," suggesting that such a framework "will help ensure this transformational technology delivers tangible, safe benefits to consumers without stifling innovation."

    The group stated its preference for a "principles-based, technology-neutral" AI-related framework that would apply to all market participants that would "Recognize the valuable principles underpinning existing federal financial statutes and ensure all entities deploying AI in consumer financial markets are held to uniform standards."

    Congress should establish a "clear federal AI standard" for both developers and deployers of AI that " explicitly preempts conflicting state and local requirements as applied to federally regulated banking organizations, replacing a fragmented regulatory patchwork with strong, enforceable, nationally consistent protections implemented by federal banking agencies."

    The CBA also said in its letter that financial regulators should work with industry players to "refine a practical framework for AI models that removes the supervisory friction arising from forcing non-deterministic models into traditional validation frameworks, while retaining core principles such as risk-tailored oversight, continuous monitoring, and real-time validation." They should also "Recognize existing inconsistencies with risk-based guidance implementation, acknowledge the structural and contractual limitations banks face regarding vendor supply chain visibility, encourage standardized vendor data disclosures, and support clear boundaries for bank oversight," the CBA said.

    In addition, it said, consumers should be protected across emerging payment networks using agentic commerce, the CBA said, adding: " Existing payment regulations and private network rules generally apply to transactions initiated by consumer-authorized AI agents. It is unclear whether consumers benefit from similar protections when using emerging crypto-based payment rails, which creates significant risk."

    Among its responses, the CBA called for a risk-based approach to validating AI models "under which firms identify and apply controls that are appropriate to the risks presented by the particular use case." The group also said it supports efforts to modernize the GLBA, adding that Congress needs to "strike the right balance between consumers’ controlling the disclosure of their nonpublic personal information and preserving robust fraud mitigation capabilities.”

    To ensure federal privacy reforms complement fraud prevention efforts, CBA said, "policymakers should consider pairing data modernization efforts with explicit statutory safeguards for covered financial institutions.”

    Companies: American Bankers Association; Community Bankers Association

    IndustryNews: AINews BankingOperations CrimesOffenses FinancialStability FinTech OversightInvestigations Privacy

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use