Four regulator signals from the past few weeks, each with one concrete action. For the standing pre-deployment checklist, see What NCUA Expects Before You Deploy AI on Member Data and the compliance pillar.
1. FinCEN: AI-generated “ghost students” are looting federal student aid
FinCEN issued an alert on July 24 warning that fraud rings are using stolen identities and AI-generated synthetic identities to enroll fake students and collect federal aid refunds. The alert notes the refunds often arrive as ACH deposits with transaction references like “LCC REFUND,” and that proceeds are laundered through money mules and fraudulent accounts, which puts your deposit accounts in the flow.
Do this month: have your BSA officer read the full alert and tune monitoring for student aid refund patterns across multiple accounts, especially newer accounts with thin history.
2. Colorado: the first state high-risk AI law is now in effect
The Colorado AI Act took effect June 30, 2026 after a five-month delay. If your credit union deploys a covered high-risk system, the law expects a written risk program, a documented assessment of each system, notice to the consumer when software decides something consequential about them, and a path to appeal that decision to a human. Credit unions have a compliance pathway: the act treats a credit union as in full compliance if it is subject to prudential examination under guidance that meets the act’s criteria, but whether current NCUA guidance qualifies is not settled law.
Do this month: if you serve Colorado members, inventory which systems make consequential decisions (lending, account decisions) and get counsel’s read on the exemption before assuming it covers you.
3. FTC: a federal counterweight to state AI laws, comments close July 31
The FTC is seeking comment on a proposed policy statement arguing that distorting AI outputs away from accuracy can violate Section 5, and that state laws requiring such alterations, naming Colorado’s act specifically, may be federally preempted. Comments are due July 31, 2026.
Do this month: do not architect your AI compliance program around any single state statute; the preemption fight is live. Build to the technology-neutral federal expectations instead, which is exactly where NCUA already points.
4. Interagency: new credit risk guidance touches your underwriting models
The OCC, FDIC, and NCUA issued joint guidance on July 13 on lending to borrowers not legally authorized to work in the United States, pointing institutions to safe and sound underwriting that assesses capacity to repay, and to the CFPB’s June 8 statement on Regulation Z and Regulation B obligations. This is not an AI item, but if your underwriting or decisioning uses automated models, this is the kind of expectation those models must be able to document.
Do this month: route the guidance to your CLO and compliance officer together, and confirm your underwriting criteria (automated or not) are documented well enough to answer an examiner’s question about how repayment capacity is assessed.
That is the week. Get this briefing in your inbox every Thursday: subscribe to the AiForCU newsletter.