Innorve Academy · AI Oversight ProgramAcademy edition · tool-neutralAs of 2026-09-28Research, not legal advice

Credit Union AI Obligations Navigator

NCUA has written no AI rule, and says so. What binds a credit union's AI is the law it already follows: its security program, consumer protection, fair lending, BSA, and a growing set of state laws. Set your profile and see which of these apply to you, what to do, and what evidence an examiner will expect.

00 · Read this first

How to read this register

There is no AI rule for credit unions.

NCUA's FAQ says it 'has not issued AI specific rules or regulation' and applies existing, technology-neutral rules. Every item here is an existing duty that AI triggers. source

Guidance cannot be cited as a violation.

Under 12 CFR 791 subpart D, examiners will not criticize a credit union for non-compliance with guidance such as an FAQ or Letter. Findings rest on law, regulation, or an unsafe or unsound practice (12 U.S.C. 1786); GAO reports NCUA has issued an AI-related document of resolution. source

Model risk has a benchmark, not a rule.

NCUA's model guidance covers interest-rate-risk models; SR 26-2 / OCC 2026-13 is bank-only, unenforceable and excludes generative and agentic AI. Use it as a proportionate benchmark with a separate GenAI addendum. source

'Binding' here includes state law and contracts.

State laws bind where the credit union has members or staff in that state (federal-charter preemption is unresolved for some). GSE terms bind sellers and servicers by contract.

02 · By use case

What each kind of AI brings with it

Most credit unions think in projects, not statutes. Each card lists the binding duties specific to that use, on top of the baseline that applies to any AI, plus the security controls that matter most.

03 · Security

AI security controls an examiner would recognize

Each control names the binding duty it helps evidence, usually 12 CFR 748.0(b)(2) as examined through the Part 748 Appendix A guidelines, or says plainly that it is a benchmark. The last column is the honest limit: what a tool on the credit union's side cannot see, such as AI running inside a vendor's own cloud.

IDControlBinding duty it evidencesEvidenceTierWhat a CU-side tool cannot see

04 · Time

What changed and what's next

Changes since the first research pass on September 13, then dated events ahead.

2026-09-29

NFHA v. CFPB: plaintiffs' summary-judgment motion due

Challenge to the 2026 Reg B amendments; briefing runs to Jan 12, 2027. source

2026-09-30

California Governor's deadline: SB 947, SB 690, AB 1609

AI in employment discipline; CIPA pen-register fix (wiretap claims stay open); chatbot disclosure plus a route to a human. Unsigned bills become law. source

2026-09-30

FCC votes on TCPA consent revocation

Would narrow revocations by category, allow a designated revocation channel and widen the fraud-alert exemption. source

2026-10-01

Connecticut PA 26-15 first provisions

Deployer duties for automated employment-decision technology follow on Oct 1, 2027. source

2026-10-09

HUD comments close on removing its Fair Housing Act disparate-impact rule

Leaves disparate impact to the courts; mortgage AI exposure continues. source

2026-10-26

Colorado AG hearing and comment deadline

Rules for SB 26-189 (automated decisions) and HB 26-1263 (chatbots). The revised draft promised for Sept 23 had not been posted as of Sept 28. source

2026-11-16

Comments due: interagency third-party risk guidance

91 FR 58536; first interagency version that expressly covers insured credit unions. source

2027-01-01

Colorado SB 26-189 and HB 26-1263; California ADMT duties

Automated-decision notices, explanations and human review; chatbot duties; CPPA ADMT compliance date. source

2027-01-12

NFHA v. CFPB briefing ends

Vacatur would restore a Reg B effects test for AI credit models. source

2027-01-31

FCC revoke-all waiver ends (if not superseded)

Opt-outs would carry across all robocalls and robotexts. source

2027-10-01

Connecticut automated employment-decision duties

PA 26-15 §§ 7–12; no financial-institution exemption. source

2028-04-01

California risk-assessment attestations

First CPPA attestations due. source

Pending

NCUA proposal to move Part 748 Appendices A and B out of the CFR

Proposed Dec 2025. If finalized, Appendix A content moves to a Letter to Credit Unions and control hooks should cite 748.0(b) directly; the binding 748.0 and 748.1 duties stay.

Pending

Section 1033 reconsideration

Rule enjoined; reconsideration NPRM at White House review since Aug 4, 2026.

Pending

AI in model risk management: RFI and GAO's open NCUA recommendation

Could produce the first AI-specific model-risk expectations.

Pending

H.R. 10184 floor action

Ordered reported 28-21 on Sept 16, 2026; would raise CFPB supervision to $30B.

Pending

H.R. 10230: NCUA authority to examine vendors

Introduced Sept 2, 2026 and framed around AI cyber risk; opposed by credit union groups.

Pending

CISA CIRCIA final rule

September 2026 target passed without publication.

Pending

NIST AI RMF revision and Cyber AI Profile (IR 8596) public draft

No drafts released as of Sept 28.

Pending

NCUA proposal to remove 12 CFR 701.31 (nondiscrimination)

Proposed Jan 14, 2026; comments closed Mar 16; not in the Aug 5 final batch. Would drop the FCU-specific effects test and five banned factors; the Fair Housing Act still applies.

05 · Credibility

Claims that fail on inspection

Each of these circulates in vendor material, board decks or conference talks, or simply sounds plausible. Use them to test what you are told, and what you write.

NCUA has AI rules, an AI examination, or made AI a 2026 exam priority.
NCUA's FAQ: “NCUA has not issued AI specific rules or regulation.” Letter 26-CU-01 does not mention AI.
NCUA's AI Compliance Plan tells credit unions what to do.
It covers NCUA's own internal AI use under OMB M-25-21.
A product or service makes the credit union compliant, certified or NCUA-approved.
Nothing can. NCUA has issued no AI rule, and examiners cannot cite guidance as a violation. A product can only help produce evidence that existing duties are met.
Credit unions must follow SR 11-7, or SR 26-2 applies to them.
SR 11-7 was rescinded Apr 17, 2026; SR 26-2 is bank-only, unenforceable and excludes generative and agentic AI.
The CFPB's AI adverse-action circulars are in force; or their withdrawal ended the duty.
Withdrawn May 12, 2025; Reg B 1002.9(b)(2) is unchanged.
Disparate impact is gone; or Reg B still has an effects test.
Reg B dropped the effects test effective July 21, 2026 (challenged in NFHA v. CFPB). The Fair Housing Act and state law (for example New Jersey) keep effects-based exposure; 12 CFR 701.31 does too for federal credit unions for now, but NCUA proposed removing it in January 2026.
The April 2023 joint statement on automated systems is a current enforcement priority.
It is archived at the CFPB and dormant.
Colorado's AI law is enforceable in 2026, or credit unions are exempt.
SB 26-189 starts Jan 1, 2027 and removed the bank and credit union safe harbor.
Federal action has preempted state AI laws.
EO 14365 preempts nothing on its own terms; no Commerce list has been published.
NCUA examines AI vendors; a vendor's SOC report covers you.
NCUA's vendor authority expired in 2001; your vendor file is what gets reviewed.
Part 748 Appendix A is a binding rule; the FTC Safeguards Rule applies to federally insured credit unions.
Appendix A is guidelines; the FTC rule covers only non-federally insured credit unions.
Section 1033 duties are enforceable now.
The rule is enjoined and under reconsideration.
The CSBS AI framework applies to credit unions.
It covers state banks and nonbanks.
“17% of credit unions have deployed agentic AI.”
Cornerstone's figure is 17% investing in agentic AI.
A platform covers “every agent” and “every action,” with “immutable” or “cryptographically signed” logs, on-premises deployment and tested core integrations.
Ask for a live demonstration and written confirmation, and check the scope: most tools see only the AI routed through them, not AI running inside a vendor's own cloud.