Industry guide
Finance, credit & lending
Credit scoring, loan approval, fraud detection, tenant and customer screening and robo-advice are classic 'consequential decisions'. The EU AI Act lists creditworthiness assessment of natural persons as high-risk; Colorado's ADMT Act covers lending from 2027; Quebec requires notice and human review of fully automated decisions; and US fair-lending and fair-housing law already impose disparate-impact liability, as the SafeRent settlement shows. Existing sector rules (adverse-action notices, model risk management) apply on top.
Regulated uses
- Credit scoring and loan or credit-limit decisions about individuals
- Tenant, customer or merchant screening scores
- Fraud, AML and transaction-monitoring models that block or flag people
- Robo-advice and automated investment recommendations
- Collections prioritisation and pricing personalisation
Laws by region
| Region | Law | Status |
|---|---|---|
| EU | EU AI ActEU Artificial Intelligence Act (Regulation (EU) 2024/1689) | In force |
| EU | EU AI Omnibus 2026Digital Omnibus on AI (Regulation (EU) 2026/1744) | In force |
| US | Colorado ADMT ActColorado Automated Decision-Making Technology Act (SB 26-189, replacing SB 24-205) | Upcoming |
| US | Texas TRAIGATexas Responsible Artificial Intelligence Governance Act (HB 149) | In force |
| US | Utah AI Policy ActUtah Artificial Intelligence Policy Act (SB 149, as amended by SB 226 and SB 332 in 2025) | In force |
| US | EO 14365 (federal preemption push)Executive Order 14365 — Ensuring a National Policy Framework for Artificial Intelligence | In force |
| Canada | Quebec Law 25Quebec Law 25 — Act respecting the protection of personal information in the private sector (automated decision provisions) | In force |
| Canada | PIPEDA (Canada)Personal Information Protection and Electronic Documents Act (PIPEDA) | In force |
| Standards | NIST AI RMFNIST AI Risk Management Framework 1.0 and Generative AI Profile (NIST AI 600-1) | Voluntary |
| Standards | ISO/IEC 42001ISO/IEC 42001:2023 — Artificial intelligence management system | Voluntary |
Obligations checklist
- Classify each model by whether it materially influences a decision about a person's access to credit, housing or financial services.
- Test outcomes by race, ethnicity, sex, age and income source; keep the results and the remediation record.
- Be able to give the principal reasons for an adverse decision in plain language (US adverse-action, Colorado 30-day notice, Quebec explanation on request).
- Give people a way to correct inaccurate data and to ask for human review.
- Document each input variable's business justification and check for proxies.
- Apply model-risk-management controls: validation, monitoring, change control.
- Prepare EU high-risk documentation for creditworthiness models before 2 December 2027.
Real cases
- Settlement2024 · US-federalLouis v. SafeRent — $2.275 million settlement over algorithmic tenant scoring
Settlement approved by the court on 20 November 2024: SafeRent pays $2.275 million (up to $1.175 million to class members) and, for five years, will not produce a SafeRent Score or accept/deny recommendation for applicants using housing vouchers unless a fair-housing expert validates a new model. The court awarded $1.1 million in attorneys' fees.
Where do you stand in finance, credit & lending?
The screener is pre-filled for this sector — ten minutes to your level and gaps.
Sources
- Colorado rewrites its landmark AI law: Unpacking SB 26-189 — Consumer Finance Monitor ↗
- Louis v. SafeRent Solutions — Civil Rights Litigation Clearinghouse ↗
Last reviewed Sep 25, 2026.