US lenders are routing more consumer credit decisions through AI underwriting models, and the main federal theory used to challenge those models on their results has just been removed. A Consumer Financial Protection Bureau final rule that took effect on 21 July 2026 ends disparate impact liability under the Equal Credit Opportunity Act, the legal basis regulators and plaintiffs had used to argue that a credit model’s outcome, not only a lender’s intent, could amount to discrimination.

What the CFPB rule changes

The rule was published in the Federal Register on 22 April 2026 under Docket CFPB-2025-0039, amending Regulation B, which implements ECOA. The Bureau concludes that the statute does not support disparate impact liability and removes the regulation’s long-standing “effects test,” the provision that allowed a lender to be challenged over a decision’s outcome across a protected class without proof of intent to discriminate. The rule itself leaves disparate treatment, intentional discrimination, untouched, and does not resolve whether the Fair Housing Act or state fair lending laws still permit a disparate impact claim against a lender’s algorithm, a question raised during the rulemaking.

The Bureau had previously gone the other way on algorithmic underwriting specifically. Circular 2022-03, issued in June 2022, told lenders that using a complex algorithm does not excuse them from giving an applicant the specific, accurate reasons behind an adverse credit decision, guidance aimed squarely at so-called black box underwriting models. A Federal Register notice withdrew that circular on 12 May 2025 along with fifteen other circulars, though the Bureau described the withdrawal as not necessarily final and said it was continuing to review the guidance.

AI underwriting keeps expanding regardless

None of this has slowed deployment. Upstart Holdings, the publicly traded AI lending platform, reports more than 100 bank and credit union partners and over $61 billion in loan originations as of 30 June 2026, with 91% of its loans fully automated in the second quarter. The company says its underwriting model weighs more than 3,000 variables per applicant and is trained on 117 million monthly repayment events, built to estimate default or prepayment risk for each month of a loan’s term.

Zest AI, an underwriting software vendor used directly by banks and credit unions rather than a lender in its own right, says it now runs more than 600 active underwriting models for client institutions, including First Hawaiian Bank, Suncoast Credit Union and CCCU. Zest AI’s own account of its client base frames the technology as widening approval rates rather than narrowing them, a claim the company has not had independently audited.

Model governance remains a separate layer

The fair lending change does not touch the supervisory track banks already operate under for any statistical model, including one used for underwriting. The Federal Reserve, the Office of the Comptroller of the Currency and the Federal Deposit Insurance Corporation jointly issued SR 26-2 on 17 April 2026, replacing the 2011 and 2021 model risk frameworks banks had worked under for underwriting, fraud and anti-money-laundering models alike. Fintechly reported in detail on what the new letter changes: it keeps validation and governance obligations in place for AI and machine learning models used in lending, independent of whatever discrimination theory applies to the outcome.

SR 26-2 was issued five days before the CFPB’s rule was published, though the two documents address different things. The Federal Reserve’s own guidance library describes SR 26-2 as risk based and proportional to an institution’s size and complexity, and most relevant to banking organisations above $30 billion in assets, a threshold that sets which lenders face the closest supervisory review of their underwriting models regardless of the ECOA change. That threshold leaves a gap around the smaller, often community and regional banks that act as balance sheet partners for AI driven lending platforms, a structure common across the sector since many underwriting technology providers hold no banking charter of their own.

What changes for lenders now

For a bank or fintech already running an AI underwriting model, the practical change is narrower than the political debate around the rule suggests. Fair lending testing, adverse action notice obligations under the Fair Credit Reporting Act, and OCC and FDIC examination of model validation have not disappeared. What has gone is the ability of a regulator or a private plaintiff to bring an ECOA claim based solely on a model’s statistical outcome across a protected class, without evidence the lender intended that outcome. Finance leaders already under pressure to automate decision-making now have one less compliance variable to weigh as they expand where AI underwriting sits in the credit process.

Where the next scrutiny is likely to land

The rule change does not remove scrutiny of AI underwriting, it relocates it. Lenders combining AI underwriting with cash flow data instead of relying on a FICO score alone, the approach behind a wave of alternative credit scoring products aimed at thin-file borrowers, still have to justify why a model weighted a given variable the way it did if challenged under disparate treatment or a state law. Fintechly has covered how alternative credit scoring is narrowing that gap, and the underwriting models built for it face the same governance expectations under SR 26-2 as any other statistical lending tool, whatever federal fair lending theory happens to apply to the result.

How far AI underwriting extends through US consumer lending over the next year will depend less on which legal theory applies and more on how examiners enforce SR 26-2 in practice, since that letter, not Regulation B’s now-removed disparate impact test, is what governs how a bank validates the model doing the lending. A broader view of the lenders and underwriting-technology vendors active in this market sits on Fintechly’s lending sector directory.