AI credit decisioning is one of the higher-reward, higher-risk applications of AI in banking. Done well, it can evaluate a thinner credit file more accurately than a traditional score, catching creditworthy borrowers that legacy models would reject. Done poorly, it can quietly bake historical bias into a black-box model — and regulators have made clear they will act on it, even as the federal enforcement posture shifts.

The Massachusetts case that started the conversation

In July 2025, the Massachusetts Attorney General settled a fair-lending action against a student loan company over its AI underwriting model. The investigation centered on the lender's use of a Cohort Default Rate variable, which the state argued produced disparate approval rates and worse loan terms for Black and Hispanic applicants — along with an automatic denial rule for applicants without a green card, which created national-origin disparate impact exposure. The lender paid $2.5 million and agreed to build an ongoing fair-lending testing and governance program specifically for its AI models.

The case is instructive less for the dollar amount than for the mechanism: the model wasn't designed to discriminate. A facially neutral variable correlated with protected characteristics closely enough to produce a discriminatory outcome. That's the core fair-lending risk in any AI underwriting model — proxy variables that reintroduce what the model was never given permission to consider directly.

$2.5M
Massachusetts AI underwriting settlement (July 2025)
$68M
Separate DOJ fair-lending settlement (March 2026)
46%
of credit unions now using AI in lending functions (Cornerstone, 2026)

Enforcement hasn't gone away — it's shifted

A March 2026 Department of Justice fair-lending settlement, resolving allegations unrelated to AI specifically but consistent with the broader redlining and pricing-discretion enforcement pattern, totaled $68 million — a reminder that federal fair-lending enforcement is still very much active even as some agencies have pulled back from disparate-impact theories more broadly. Meanwhile, state attorneys general have signaled they intend to fill any enforcement gap themselves, specifically calling out AI underwriting models, digital marketing targeting, and pricing discretion as areas of active review.

The practical implication for any institution using or piloting AI underwriting: don't assume reduced federal appetite for disparate-impact theories means reduced enforcement risk. State regulators are the ones actively bringing AI-specific cases right now.

"The model wasn't built to discriminate. That's exactly the point — proxy variables don't announce themselves."

The ECOA and Reg B obligation that doesn't go away

Whatever the underwriting method, the Equal Credit Opportunity Act and Regulation B require a specific, plain-language reason when an application is denied or a term is adversely changed. Many of the model architectures that produce the best predictive accuracy — gradient boosting, ensemble methods, neural networks — are the hardest to explain in those terms. An institution should be able to answer a simple question before deploying any AI underwriting model: can this model produce an adverse action notice specific enough to survive a regulator's or a plaintiff's scrutiny? If the honest answer is "we're not sure," that's the gap to close before the model reaches production, not after.

What this looks like by institution size

For credit unions, lending is now the third most common AI use case behind contact centers and fraud management, with 46% of institutions using it according to Cornerstone Advisors' 2026 research — meaning most exposure sits with core and fintech lending partners rather than in-house models. That doesn't eliminate the fair-lending obligation; it shifts the governance question to vendor oversight: can your lending technology partner show you their model's disparate-impact testing, and do you have the contractual right to see it?

Sources