America’s CUs Urges House Dems to Avoid Imposing Broad New AI Regs on Credit Unions

WASHINGTON — America’s Credit Unions is urging House Democrats to avoid imposing broad new artificial intelligence regulations on credit unions, arguing existing financial laws and supervisory frameworks are already capable of addressing most risks associated with the technology.

In an Aug. 14 letter to Rep. Maxine Waters, ranking Democrat on the House Financial Services Committee, the trade group responded to committee Democrats’ request for information on how current federal laws apply to AI in financial services and housing and what changes may be needed to create a modern federal framework.

Rep. Maxine Waters

America’s Credit Unions said credit unions are already using AI to combat fraud, streamline compliance, expand access to credit and improve member service. It argued that federal financial laws generally regulate outcomes rather than specific technologies and therefore already apply when AI is used.

Rather than adding AI-specific requirements to regulated financial institutions, the group said policymakers should focus on:

  • Differentiating between regulated and unregulated entities. Credit unions and other depository institutions are already subject to extensive federal supervision, while some nonfinancial companies using AI face substantially fewer safeguards.
  • Ensuring smaller institutions have access to advanced AI. The group said smaller credit unions should not be placed at a competitive disadvantage when accessing sophisticated defensive cybersecurity tools.
  • Creating uniform national standards. America’s Credit Unions called for federal privacy and AI standards that preempt what it described as a costly and fragmented patchwork of state requirements.

Existing Cybersecurity Rules Seen as Sufficient

The trade group said credit unions were subject to extensive cybersecurity and technology-risk requirements long before the emergence of advanced AI models.

NCUA regulations require federally insured credit unions to maintain written information security programs and include requirements governing safeguards, incident response and member notification. Credit unions have also been subject since 2023 to a requirement to report certain cyber incidents to the NCUA within 72 hours.

America’s Credit Unions said those rules were deliberately written to be technology-neutral and risk-based, allowing them to accommodate threats ranging from online banking and cloud computing to AI-enabled phishing, deepfakes and accelerated vulnerability discovery.

“What has changed is the threat environment and the defensive toolset, not the soundness of the underlying regulatory architecture,” the group said.

Credit unions are already revisiting threat assessments, patch-management schedules, vendor due diligence and incident-response plans to account for AI-enabled attacks, according to the letter.

Put More Responsibility on AI Vendors

America’s Credit Unions also cautioned against requiring individual credit unions to audit the underlying technology in AI products provided by third parties.

The group said credit unions typically rely on core processors and other technology vendors and often cannot access or modify proprietary source code. Smaller institutions also generally lack the staff, scale and data needed to develop sophisticated AI capabilities internally.

If specialized AI-related software audits or security attestations are required, the group said those obligations should generally fall on large technology providers rather than individual credit unions.

Credit union responsibilities should instead focus on areas they can control, including identity and access management, employee training, configuration of vendor-provided security controls, vendor oversight and incident detection and reporting, the group said.

Calls for Equal Access to Advanced AI

America’s Credit Unions said government policy governing early access to advanced cybersecurity AI models should not favor the largest financial institutions or technology companies.

The group suggested regulators, including the NCUA, Treasury Department and Federal Financial Institutions Examination Council, could potentially establish a controlled-access system through which financial institutions could use advanced defensive AI models.

Such a system could subsidize access for smaller institutions and direct AI capabilities toward vulnerabilities in widely used core platforms, payment interfaces and authentication systems, the group said.

It also said credit union service organizations could play a role in expanding access because they can provide technology and cybersecurity capabilities to multiple credit unions.

Warning Against Broad AI ‘Explainability’ Mandates

The trade group also urged Congress to be cautious about requiring lenders to provide detailed technical explanations of how AI models reach decisions.

America’s Credit Unions said laws including the Equal Credit Opportunity Act and Fair Credit Reporting Act already apply regardless of whether a lending decision is made by a person, traditional scoring model or AI system.

Requiring lenders to explain every model input, inference or element of an AI system’s architecture would increase compliance costs while providing limited additional benefit to consumers, the group argued.

Instead, AI explainability requirements should remain focused on the reasons for a lending decision and compliance with existing disclosure laws rather than the internal architecture of the technology.

National Privacy Standard Sought

America’s Credit Unions also called for Congress to establish a national privacy framework that would preempt state requirements.

The organization said at least 18 states have enacted laws governing automated processing of personal data, including its use in providing or denying financial services. Different definitions, penalties and compliance requirements could significantly increase costs for credit unions, it said.

The group cited the proposed GUARD Financial Data Act and SECURE Data Act as potential approaches for modernizing federal privacy requirements while providing federal preemption.

America’s Credit Unions also argued that requiring institutions to disclose merely that AI was used somewhere in providing a financial product would likely produce boilerplate language without giving consumers meaningful information.

Opposes NCUA Vendor Examination Authority

Despite its focus on risks arising from third-party technology, America’s Credit Unions reiterated its opposition to giving the NCUA direct examination and supervisory authority over vendors and credit union service organizations.

The trade group said expanding NCUA authority would require additional technology expertise and examination resources, with the resulting costs ultimately borne by credit unions and their members.

Instead, it called for greater information sharing between the NCUA and other federal banking regulators that already examine major technology service providers.

Small Credit Unions Should Not Be Left Behind

The organization said smaller institutions, including credit union community development financial institutions and minority depository institutions, should have greater opportunities to access AI through regulatory sandboxes, pilot programs, no-action letters, waivers and CUSOs.

It warned against new supervisory or audit requirements that increase vendor compliance costs that are ultimately passed along to smaller credit unions.

America’s Credit Unions also argued that existing consumer financial laws already provide an adequate liability framework. A credit union remains responsible if its use of AI results in violations of fair lending, credit reporting, disclosure or other federal requirements, it said.

For that reason, the group said broad new AI-specific liability provisions or private rights of action are unnecessary.

America’s Credit Unions Senior Vice President of Advocacy Greg Mesack said in the letter that Congress should concentrate on ensuring community institutions have equitable access to defensive AI, establishing uniform national standards and scrutinizing AI use by entities that do not face the same level of federal supervision as credit unions and other depository institutions.

The full letter can be found here.

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.