Legal Alert

Mortgage Banking Update - September 24, 2026

September 24, 2026

September 24 – Read the newsletter below for the latest Mortgage Banking and Consumer Finance industry news, written by Ballard Spahr attorneys. In this issue, our lawyers explore the future of consumer financial services through the lens of agentic AI, highlight new guidance on SAR confidentiality and customer communications, and recap the Inspector General’s report on the impact of CFPB cutbacks, along with other noteworthy updates.

All content can be found previously published on Ballard Spahr’s Insights page.

 


 

Consumer Finance Monitor Podcast: The CFPB Needs Reform, But Not More Regulatory Whiplash

The future of the Consumer Financial Protection Bureau (CFPB or Bureau) has rarely been more uncertain. Since its creation, the CFPB has been at the center of intense political and policy debate, with its priorities changing dramatically as administrations change. The events of the past year or so under the leadership of Acting Directors chosen by President Trump, however, have taken that policy whiplash to a new level.

In our latest Consumer Finance Monitor podcast released today, Alan Kaplinsky (the founder and former leader for 25 years of the Consumer Financial Services Group at our firm) was joined by two former CFPB officials with decades of experience inside the Bureau: Jason Brown, a visiting fellow at the Brookings Institution and former CFPB Assistant Director for Research, and David Silberman, former Acting Deputy Director and longtime Associate Director for Research, Markets and Regulation. We discussed their recent Brookings commentary, “The CFPB: Where to Go From Here,” which proposes a series of structural reforms designed to make the Bureau a more stable and effective financial regulator.

Their recommendations are noteworthy not because they seek to preserve every aspect of the CFPB as it has operated in the past. Rather, they focus on a more fundamental question: How can the CFPB carry out its statutory mission while allowing presidential administrations to pursue different policy agendas without repeatedly dismantling and rebuilding the agency?

The CFPB’s Accomplishments are Worth Preserving

Before discussing reform, Brown and Silberman emphasized that the CFPB has accomplished a great deal since its creation.

Silberman, who was involved with the Bureau from its earliest days, pointed to the extraordinary task of building an entirely new federal agency, including its consumer response function, nonbank supervision program and research infrastructure. He also highlighted the CFPB’s implementation of the Dodd-Frank mortgage provisions in 2013, which he believes provided important clarity to the mortgage market without producing the disruption that otherwise might have occurred.

He also cited the CFPB’s supervision of large consumer reporting agencies and several significant enforcement actions, including cases involving credit-card add-on products and unauthorized account openings of one of the largest banks in the country.

These accomplishments help explain why the question is not simply whether the CFPB should exist. The more important question is what kind of CFPB the country should have going forward.

Policy Change Is Inevitable. Policy Whiplash Is Not

A certain amount of policy change is unavoidable when control of the White House changes. Silberman noted that he personally experienced the dramatic transition from working for Elizabeth Warren to working for Acting Director Mick Mulvaney. But he also pointed out an important distinction: despite their very different philosophies, Mulvaney generally viewed his responsibility as carrying out the laws Congress had entrusted to the Bureau.

The current situation, in the view of Brown and Silberman, goes beyond ordinary policy change. They point to the wholesale withdrawal of prior guidance, advisory opinions and enforcement actions as examples of changes that create substantial uncertainty for both consumers and financial institutions.

That uncertainty matters. Financial institutions need to know what the rules are in order to design products, price them appropriately and build effective compliance programs. If the regulatory environment changes dramatically every four years, or even more frequently, institutions may be forced to price regulatory uncertainty into their products and may become less willing to innovate.

Consumers ultimately bear some of those costs.

Five Structural Reforms

Brown and Silberman’s proposals are aimed at reducing that instability without preventing a future CFPB director from pursuing a different policy agenda.

1. Make Congress More Prescriptive

Their first proposal would have Congress provide greater specificity regarding the CFPB’s statutory responsibilities and establish minimum performance expectations.

For example, if Dodd-Frank requires the Bureau to report on particular areas of activity, Congress could make clear that these are affirmative obligations rather than discretionary activities. Congress also could establish minimum expectations concerning examinations and research.

The authors acknowledge that this is not a perfect solution. A director could theoretically satisfy numerical requirements through superficial “check-the-box” exercises. Nevertheless, minimum statutory expectations could establish useful guardrails against a future administration simply deciding not to perform functions Congress assigned to the Bureau.

2. Put Key Operational Positions in Career Hands

The second proposal would provide greater career continuity for important operational positions, including supervision, enforcement, and certain legal functions.

This would not prevent a director from establishing his or her own policy priorities. Rather, it would preserve institutional expertise and continuity in positions that have statutory and operational responsibilities.

Silberman offered an illuminating example from the transition to the Trump administration in 2017. A career general counsel provided advice concerning who could serve as acting director, allowing the Bureau to navigate the transition with institutional continuity.

Importantly, Brown emphasized that the proposal is not a criticism of individuals who have occupied these positions as political appointees. The objective is structural: creating greater stability and consistency within the Bureau.

3. Make Rulemaking More Attractive Than Policymaking Through Enforcement

This may be the most consequential, and most controversial, of the proposals.

The authors argue that the CFPB needs incentives to use formal rulemaking when it seeks to establish generally applicable regulatory requirements, rather than relying on supervision or enforcement as an alternative mechanism for making policy.

One problem is that rulemaking can be time-consuming and expensive, and rules are subject to judicial challenge. The authors suggest that challenges to CFPB rules could begin at the appellate level, as occurs with certain other federal regulatory schemes, potentially making the rulemaking process more efficient and predictable.

At the same time, they propose an independent appeals mechanism for certain supervisory and enforcement decisions, including Matters Requiring Attention and decisions to authorize litigation. Their concept would involve a neutral and expert panel with experience representing both financial-services firms and consumers.

This proposal does not mean that enforcement should occur only when an agency has previously promulgated a regulation specifically prohibiting the challenged conduct. Silberman made clear that some conduct, such as the unauthorized opening of customer accounts by a major bank, can appropriately be addressed through enforcement even without a regulation specifically prohibiting it.

The concern instead is using enforcement to change established understandings of the law without providing the notice and procedural protections associated with rulemaking.

4. Strengthen Congressional Oversight and Independent Review

The authors also call for stronger oversight of the Bureau.

They specifically point to the Dodd-Frank requirement that the CFPB director testify before the Senate Banking Committee and House Financial Services Committee twice each year. Brown noted that the current acting leadership had not appeared for those required hearings despite making significant changes to the Bureau’s staffing, regulatory policies, and scope of activity. Since we recorded this podcast, Acting Director Vought did appear at hearings before both Committees.

They also favor a more active CFPB Inspector General and the restoration of independent peer review of important CFPB research.

The latter proposal is particularly interesting. The CFPB’s Academic Research Council provided independent review of significant research used to support policymaking. Brown and Silberman believe that such review can help establish the credibility of the Bureau’s methodology even when the underlying data cannot be publicly disclosed because it is confidential or proprietary.

5. Preserve the CFPB’s Existing Funding Structure

The authors reject another frequently suggested reform: subjecting the CFPB to the annual congressional appropriations process.

Their argument is straightforward. Whatever one’s views about congressional control over agency spending, annual appropriations would not necessarily reduce political volatility. Indeed, it could make the Bureau even more vulnerable to political battles over funding and appropriations riders.

Why Not Replace the Director With a Bipartisan Commission?

Another frequently proposed reform would replace the CFPB’s single director with a multi-member commission modeled on the Federal Trade Commission.

Brown and Silberman are skeptical.

Their concern is that a five-member commission does not necessarily produce stability. In recent decades, changes in the chair and the political composition of multi-member commissions have themselves produced significant policy shifts. They view the Federal Reserve’s longer terms and larger membership as a materially different model.

Their preferred solution is therefore not necessarily to eliminate the single-director structure, but to put structural guardrails around it.

Some Reforms Could Happen Without Congress

One particularly important point from the discussion is that not everything requires legislation.

A future CFPB director could voluntarily place career officials in key operational positions and establish an internal appeals process for supervisory and enforcement decisions. Brown noted that other financial regulators, including the OCC and FDIC, are moving in that direction on their own.

Legislation would make such reforms more durable, but a director committed to institutional stability could begin implementing many of them immediately.

A Potential Opportunity With New Leadership

The discussion also turned to Brian Johnson, who has been nominated to serve as CFPB director.

Both Brown and Silberman spoke favorably about Johnson’s commitment to carrying out the Bureau’s statutory responsibilities, even though Silberman emphasized that he and Johnson have very different views on many substantive regulatory issues.

That distinction is important. The goal of structural reform should not be to ensure that every future director adopts the same substantive policies. Presidents are entitled to appoint directors who share their policy objectives.

The goal should be to ensure that those policy differences occur within a stable institutional framework.

The Bottom Line

The debate over the CFPB too often becomes a debate over whether one supports or opposes the agency. That misses the more important institutional question.

The CFPB has demonstrated that it can play an important role in consumer financial protection. At the same time, the dramatic swings in policy and enforcement priorities over successive administrations have undermined predictability and, in the process, confidence in the Bureau.

Good consumer protection does not have to mean regulatory whiplash.

The reforms proposed by Brown and Silberman would not eliminate political differences over consumer financial policy. Nor should they. Instead, they seek to ensure that those differences are expressed through changes in policy rather than repeated disruption of the institution itself.

That is a goal that ought to have bipartisan appeal.

The CFPB needs reform. But perhaps the most important reform is to make it possible for the Bureau to change direction without repeatedly losing its institutional memory, credibility and ability to perform the job Congress assigned to it.

[Subsequent to the recording of this podcast, two Republican members of the House Financial Services Committee have introduced H.R. 10184, the Consumer Financial Protection Accountability Act and Reform Act of 2026. The legislation addresses a variety of subjects across five titles covering CFPB governance and funding; legal clarity and procedural fairness, including UDAAP; innovation in consumer financial markets; supervision of banks and nonbanks; and regulation by enforcement. Among other provisions, the bill would move the CFPB into the congressional appropriations process, expand rulemaking and retrospective-review requirements, require rulemaking concerning the meaning of “abusive,” revise aspects of bank and nonbank supervision, distinguish nonbinding guidance from enforceable law, and make changes to civil penalties and the Bureau’s complaint framework. It includes only one provision that is part of the 5-point proposal of our guests — namely, increasing oversight of the Bureau by requiring that the CFPB have its own Inspector General rather than having to share with the Federal Reserve Board the same Inspector General.]

Listen to the episode here.

Consumer Financial Services Group

Back to Top


Consumer Finance Monitor Podcast: The End of Shopping? Agentic AI and the Future of Consumer Financial Services Introduction

Artificial intelligence is rapidly moving from helping consumers make purchasing decisions to making those decisions for them. So-called “agentic AI” or “AI shopping agents” could search for financial products, compare prices and terms, negotiate with providers, open or close accounts, switch providers, and complete transactions without the consumer participating in each step.

In the Consumer Finance Monitor podcast we are releasing today, Alan Kaplinsky (founder, former chair for 25 years, and now senior counsel of the Consumer Financial Services Group at our firm) spoke with Professor Mark Bartholomew of the University at Buffalo School of Law, co-author with Professor Samuel Becher of “The End of Shopping,” a forthcoming article in the William & Mary Law Review. The article explores how autonomous shopping agents could transform consumer commerce and raises fundamental questions concerning consumer autonomy, privacy, competition, and consumer protection.

The implications for financial services are especially significant. Consumers could use AI agents to select credit cards, auto loans, mortgages, insurance policies, bank accounts, certificates of deposit and investment products. An agent potentially could compare thousands of offerings in seconds and execute a transaction that a consumer might otherwise never undertake because of the time and complexity involved.

For banks, lenders, insurers, credit-card issuers, and investment firms, agentic AI could reduce customer-acquisition costs, increase switching and intensify competition. But it also could make technology companies the principal gatekeepers between financial institutions and their customers. The company controlling the agent could determine which products consumers see, how those products are compared and whether a particular provider receives the consumer’s business.

Agentic AI also presents difficult legal and policy questions. Who is responsible when an AI agent makes a mistake? What happens when an agent has a financial incentive to steer a consumer toward a particular provider? Are existing disclosure, fair-lending, privacy, advertising and investor-protection rules adequate when the “consumer” making the initial decision is effectively an algorithm?

Professor Bartholomew argues that policymakers should address these issues before agentic commerce becomes entrenched. Among the potential guardrails he discusses are independent audits, “algorithmic nutrition labels,” data portability, protections against self-dealing, meaningful consumer control—including an “off” switch—and periodic review or sunset provisions for new regulation.

The central question for financial services providers and regulators is whether the existing consumer-protection framework will work if AI agents become the principal interface through which consumers select and purchase financial products.

This episode builds on our earlier March 12, 2026, podcast with Professor Oren Bar-Gill of NYU Law School discussing Agentic AI in Consumer Financial Services: Opportunities, Risks and Emerging Legal Frameworks, our May 21, 2026, podcast with Professor Mark Geistfeld discussing the American Law Institute’s Principles of the Law, Civil Liability for Artificial Intelligence. Together, these three programs examine the tort law, contract law, and other legal challenges posed by increasingly autonomous AI systems.

From Financial Shopping to Financial Decisions Made for Us

For decades, technology has made financial shopping increasingly convenient. Consumers moved from bank branches and paper applications to online banking, mobile apps and digital comparison tools. They can now receive personalized recommendations, prequalified offers, and automated investment advice.

Agentic AI could represent the next—and much more consequential—step. There is an important distinction between an AI assistant and an AI shopping agent. Today, a consumer can ask an AI assistant to recommend a credit card, mortgage, insurance policy, or investment product. The consumer still evaluates the recommendation, makes the decision and completes the transaction.

An agentic system potentially could do all of that itself. A consumer might tell an AI agent: “Find me the lowest-cost auto insurance policy that provides the coverage I need.” Or: “Find me the best one-year CD with FDIC insurance.” Or: “Find me a credit card with no annual fee, a low introductory rate and rewards that fit my spending.” The agent could search available alternatives, compare prices and terms, make a recommendation—or make the decision pursuant to instructions the consumer previously provided—and complete the transaction. It also could monitor the consumer’s accounts and act later. An agent might move funds when a CD matures, refinance a loan when rates fall, switch insurance carriers after a premium increase or cancel a credit card that no longer offers competitive terms.

For financial institutions, this could change the customer relationship fundamentally. The consumer may no longer begin with a bank’s website, a lender’s advertisement or an insurer’s agent. The consumer may begin with an AI platform that decides which providers and products deserve consideration.

Why Financial Services May Be an Especially Attractive Use Case

The financial services industry may be one of the areas in which consumers are most willing to delegate shopping decisions to AI.

Comparing credit cards, deposit accounts, auto loans, mortgages, insurance policies, and investment products can be considerably more complicated than comparing consumer goods. Terms and conditions may be lengthy and difficult to compare. Pricing may depend on individualized underwriting. Consumers frequently lack the time or expertise to evaluate competing products.

An AI agent could theoretically examine hundreds or thousands of offerings, compare rates, fees, coverage, eligibility requirements, and other terms, and identify products that best fit a consumer’s stated preferences. The potential benefits could be substantial.

Consumers frequently remain with their existing bank, insurer, lender, or credit-card issuer not because it offers the best product but because switching is difficult. An agent that could handle the process of comparing alternatives and switching providers could dramatically reduce those switching costs.

For example, an agent could identify a higher-yield deposit account, transfer funds, update direct-deposit instructions, and close the old account. It could compare mortgage-refinancing offers, gather documents, and submit applications. It could evaluate insurance premiums and coverage, select a new carrier, and cancel the existing policy. It could compare credit-card rewards and fees and recommend a replacement card. That could increase competition and pressure financial institutions to offer better prices and service.

But financial-services providers should recognize that the party making the initial decision about which products consumers see may no longer be the consumer or even a human intermediary. It may be an AI agent operating according to an algorithm supplied by another company. That creates an entirely new potential gatekeeper.

Implications for Banks, Lenders, Insurers, and Investment Firms

Agentic AI could affect nearly every stage of the financial services relationship.

Banks may face more frequent movement of deposits as agents compare interest rates, fees, account features, and convenience. A bank’s ability to retain customers through inertia or the difficulty of switching could diminish. At the same time, banks may gain access to new customers if their products perform well under objective comparisons.

Lenders may encounter a more efficient but more demanding marketplace. An AI agent could compare mortgage, auto-loan, and personal-loan offers based on annual percentage rates, fees, repayment terms, underwriting requirements, and closing costs. Lenders may need to make pricing and eligibility information more accessible to automated systems and may face greater scrutiny if their offers are difficult for agents to evaluate.

Insurers could see similar changes. Agents might compare premiums, deductibles, exclusions, coverage limits, claims practices, and renewal terms. Insurers may need to explain complex coverage in machine-readable formats while ensuring that automated comparisons do not omit material limitations.

Credit-card issuers could face rapid customer switching based on annual fees, interest rates, rewards, introductory offers, balance-transfer terms, and penalty provisions. Issuers also may seek to influence the agents that determine which cards consumers see. That could create questions about referral payments, sponsored placement, and whether an agent’s recommendation is genuinely based on consumer benefit.

Investment firms may confront particularly sensitive issues. An agent could select mutual funds, exchange-traded funds, brokerage accounts, retirement products, or advisory services. The agent’s recommendations could affect asset allocation, risk exposure, fees, and long-term financial outcomes. Investment firms and regulators will need to consider how existing suitability, best-interest, and fiduciary principles apply when an AI system makes or implements recommendations.

Across all sectors, financial institutions may need to compete not only for consumers but also for favorable treatment by the platforms controlling the agents.

Who Is Making the Decision?

One of the most difficult legal questions raised by agentic AI is determining who is actually acting when an AI agent completes a financial transaction.

Suppose a consumer instructs an AI agent to find the best mortgage available, but the agent submits an application to a lender with a higher rate because that lender pays the platform a referral fee. Is the consumer bound by the application? Is the AI platform responsible? Is the lender responsible for accepting business generated through a conflicted recommendation?

Professor Bartholomew views this in part as a delegation problem. The consumer has delegated authority to the AI system, but traditional agency law may not provide a complete answer. Traditional agency doctrine developed around relationships involving human principals and human agents. An AI system does not have the same incentives, motivations, or ability to respond to liability that a human agent does. The company operating the system, the company developing the underlying model and the financial institution receiving the business may each play a role, but existing law may not clearly allocate responsibility among them.

The issue is especially important in financial services because transactions can create long-term obligations. A mistaken purchase of a consumer product may be inconvenient. A mistaken mortgage, insurance policy, investment, or credit-card application can affect a consumer’s finances, credit history and legal rights for years.

Financial institutions therefore may need to determine what authority an AI agent has, how that authority is verified, and when a transaction requires meaningful consumer confirmation.

Conflicts of Interest and Self-Dealing

The legal questions become even more complicated when an AI agent has commercial relationships with the businesses whose products it recommends.

An agent supposedly working for the consumer could receive referral fees, advertising payments, data benefits or other compensation from a bank, lender, insurer, credit-card issuer, or investment firm. It might then have an incentive to recommend that provider even though another provider offers a better product for the consumer.

The conflict could take several forms:

  • A bank could pay for preferred placement in searches for deposit accounts.
  • A credit-card issuer could compensate an agent for completed applications.
  • An insurer could provide data or other benefits in exchange for favorable treatment.
  • A lender could pay for leads generated by an agent.
  • An investment firm could compensate an agent for directing assets into particular products.
  • A platform could favor affiliated financial institutions over unaffiliated competitors.

These arrangements could resemble familiar forms of advertising or referral compensation, but agentic AI may make the conflict more difficult for consumers to detect. The agent may not display a conventional advertisement. It may simply omit certain products, rank one provider more favorably, or describe competing products less prominently.

That raises a fundamental question: Is the AI agent actually working for the consumer?

For financial regulators, the issue may require more than disclosure. If an agent’s incentives are fundamentally inconsistent with the consumer’s interests, a disclosure may not be sufficient. Regulators may need to consider restrictions on compensation arrangements, requirements for independent comparison, or duties requiring the agent to act in the consumer’s best interest.

Consumer Protection Law May Have to Change

Much of consumer protection law assumes that a human consumer is on the other side of the transaction.

Disclosures are provided so that consumers can read and understand them. Advertising laws are designed in part to prevent businesses from exploiting consumers’ cognitive biases. Regulation often focuses on whether consumers have received sufficient information to make an informed decision.

Financial-services laws similarly rely on consumer interaction with disclosures, applications, notices and explanations. Truth-in-lending disclosures, deposit-account disclosures, insurance documents, privacy notices, and investment disclosures are generally designed for human review.

Agentic AI changes that model. An AI agent does not become confused because a price ends in “.99.” It does not necessarily respond to an emotionally manipulative advertisement. It can theoretically process far more information than an individual consumer.

But that does not mean the agent is invulnerable. The relevant vulnerabilities may instead be algorithmic. An agent could be programmed to favor a particular financial institution. It could be manipulated by a business seeking to influence how its products are presented to AI systems. It could fail to search a sufficiently broad universe of alternatives. It could misunderstand a consumer’s financial objectives or risk tolerance. Or its operator could use the enormous amount of personal information accumulated about the consumer to steer purchasing decisions in ways the consumer does not understand.

The focus of consumer protection therefore may need to shift from protecting the human consumer’s cognitive processes to protecting the integrity of the algorithm making decisions on the consumer’s behalf.

Regulators also may need to reconsider what it means for a consumer to receive a disclosure. If an AI agent reads and processes a disclosure but the consumer never sees it, has the purpose of the disclosure requirement been satisfied? If the agent summarizes a complex loan term incorrectly, who is responsible? If the agent rejects a product because it cannot interpret the provider’s disclosures, does that create an unfair competitive advantage for institutions with more machine-readable documentation?

Fair Lending, Insurance, and Investment Concerns

Agentic AI could create new risks under existing financial services laws.

For lenders, an agent’s search and recommendation process could affect which consumers apply for credit and which lenders receive applications. If an agent systematically excludes certain lenders or products, the effects could have implications under fair-lending and fair-access principles.

The agent itself also could use sensitive information in ways that influence recommendations. A consumer’s location, financial history, family circumstances, or purchasing patterns could affect which products the agent presents. Even if the agent does not use a protected characteristic directly, its use of related information could produce discriminatory outcomes.

Insurers may face similar concerns. An agent could compare policies using individualized pricing, claims history, location, and other data. Regulators may need to examine whether automated recommendations reinforce unfair distinctions or obscure the factors driving coverage and pricing decisions.

Investment firms face additional concerns involving risk tolerance, suitability, best-interest obligations, and the possibility that an agent will favor products generating higher compensation. An agent that automatically reallocates a consumer’s portfolio could make decisions that are technically consistent with historical preferences but inappropriate in light of changed circumstances.

These issues suggest that financial regulators may need to examine not only the conduct of financial institutions but also the design and operation of the AI platforms that influence financial decisions.

The Need for Guardrails

Professor Bartholomew’s principal concern is not simply determining liability after an AI agent causes harm. He emphasizes the need for ex ante safeguards that make it more likely that the system will operate in the consumer’s interest from the beginning.

One proposal is independent auditing. AI shopping agents could be tested against standardized benchmarks to determine, for example, how broadly they search, whether they consistently identify competitive rates and terms, whether they accurately represent fees and limitations, whether they favor particular financial institutions, and whether their recommendations vary based on protected or sensitive characteristics.

For financial regulators, audits could provide a way to evaluate agentic systems without requiring regulators to review every individual transaction. Audits also could help institutions demonstrate that their systems are not designed to manipulate consumers or evade existing legal requirements.

Another proposal is an “algorithmic nutrition label.” Just as consumers can look at a nutrition label to evaluate food without independently testing its contents, consumers could receive standardized information about an AI shopping agent. Such information might disclose:

  • How many banks, lenders, insurers, or investment firms the agent typically searches.
  • Whether the agent includes affiliated or paying providers.
  • How the agent is compensated.
  • Whether the agent receives referral fees or other benefits.
  • How the agent performs against benchmark rates, fees, and terms.
  • What consumer data the agent uses.
  • Whether the agent can open, close, or transfer accounts without additional approval.
  • How consumers can challenge or reverse an agent’s decision.

The objective would be to give consumers and regulators meaningful information with which to evaluate competing AI agents.

Competition and Data Portability

Agentic AI also raises significant competition concerns. The company controlling an AI shopping agent could become the gatekeeper through which consumers access an enormous portion of the financial marketplace. That could give already dominant technology companies an even greater competitive advantage.

A platform that controls the consumer interface could influence which banks, lenders, insurers, credit-card issuers, and investment firms receive business. It also could use transaction data to develop competing financial products or negotiate more favorable terms for affiliated providers.

Financial institutions may therefore need to consider whether access to consumers is becoming dependent on a small number of technology platforms. Regulators may need to examine exclusive arrangements, preferred placement, interoperability and the possibility that dominant platforms will discriminate against smaller financial institutions.

Data portability could be particularly important. Suppose a consumer has used one AI agent for years. The agent has accumulated extensive information about the consumer’s preferences, purchasing history, financial circumstances, risk tolerance, and account relationships. If the consumer wants to switch to a competing agent, the consumer should not necessarily have to start over.

Professor Bartholomew therefore advocates data portability so that consumers can take their information with them when they switch providers. Portability could also promote competition among financial institutions. If consumers can easily transfer account histories, preferences and authorization information, they may be more willing to switch banks, lenders, insurers, or investment firms. Without portability, the companies that establish an early lead in agentic commerce could make it extremely difficult for consumers to leave.

Privacy and Cybersecurity Risks Will Increase

The benefits of agentic AI depend heavily on access to information about the consumer. The more an agent knows about a consumer’s purchasing history, financial circumstances, preferences and personal life, the better it potentially can tailor its decisions.

But that same information creates substantial privacy and cybersecurity risks. An AI shopping agent could become a comprehensive repository of information about virtually everything a consumer buys, considers buying or can afford to buy. It could know the consumer’s income, debts, savings, insurance coverage, investment objectives, medical expenses and financial vulnerabilities. The aggregation of that information could make an agent particularly attractive to hackers, data brokers and businesses seeking to influence consumers.

Banks, lenders, insurers, credit-card issuers, and investment firms will need to determine what information they share with agents, how they authenticate an agent’s authority and how they prevent unauthorized transactions. They also may need to distinguish between information necessary to complete a transaction and information that could be used to profile or manipulate a consumer.

Financial regulators may need to address whether existing privacy and cybersecurity requirements adequately cover data held by AI platforms that are not themselves traditional financial institutions.

The challenge will be finding the right balance between allowing AI agents to access enough information to provide meaningful benefits and preventing that information from being exploited.

Consumers Need an Off Switch

One of the simplest proposals discussed in the podcast is also one of the most important: Consumers should be able to turn the agent off.

There may be many financial decisions that consumers want an AI system to handle automatically. A consumer may want an agent to move idle cash into a higher-yield account, monitor insurance premiums or identify lower-cost refinancing opportunities.

But there are other decisions where consumers want to participate directly. A consumer may want to approve a mortgage application, select an investment strategy, purchase life insurance, or close a long-standing bank account personally. Consumers also may want to prevent an agent from acting during periods of financial stress, illness or unusual market volatility. Meaningful consumer control should include clear limits on the agent’s authority, advance notice of significant transactions, the ability to require human approval and a practical way to reverse or challenge decisions.

Professor Bartholomew also suggests features such as “explore” or “surprise” modes that would prevent an agent from relying exclusively on a consumer’s historical preferences. In financial services, that could mean requiring an agent to consider new providers, alternative products, or different investment approaches rather than continually recommending the same institutions and products. Otherwise, the very personalization that makes agentic AI useful could become a mechanism that continually reinforces past behavior.

What Should Financial Institutions Do Now?

Banks, lenders, insurers, credit-card issuers, and investment firms should not wait for regulators to resolve every legal question before preparing for agentic commerce.

They should consider whether their product information is accurate, complete and machine-readable. Rates, fees, eligibility requirements, exclusions, rewards terms, risk disclosures, and other material information should be presented in formats that AI systems can interpret without losing important context.

Institutions also should review relationships with AI platforms. Referral fees, preferred placement, sponsored recommendations and data-sharing arrangements may create conflicts that are difficult to explain to consumers. Firms should be prepared to demonstrate that their arrangements do not result in deceptive steering or unfair treatment.

Governance programs should address:

  • How the institution authenticates AI agents.
  • What authority an agent has to open, close or modify an account.
  • When human confirmation is required.
  • How the institution records and explains agent-generated transactions.
  • How errors are corrected.
  • How complaints involving AI agents are investigated.
  • How the institution monitors disparate impacts.
  • How third-party AI platforms are supervised.
  • How consumer data is protected and deleted.

Institutions also should consider whether their existing customer-service models are adequate when the customer’s first interaction is with an AI agent rather than a human consumer.

Do We Need a New AI Regulator?

The Federal Trade Commission clearly has a role to play in policing deceptive claims and other misconduct involving AI shopping agents. But Professor Bartholomew questions whether existing agencies are equipped to address all of the issues raised by agentic commerce.

Financial regulators—including the Consumer Financial Protection Bureau, federal banking agencies, state banking, and insurance regulators, the Securities and Exchange Commission and the Financial Industry Regulatory Authority—also may have important roles.

Some issues involve technical standards, interoperability, data portability, and auditing. Others involve potentially complex questions concerning fiduciary duties, self-dealing, and the relationship between consumers and the companies operating AI agents.

Regulators will need to determine whether existing laws can be applied to AI platforms that influence financial decisions but are not themselves banks, lenders, insurers, broker-dealers, or investment advisers. They also will need to determine how responsibility should be allocated when a financial institution relies on an agent operated by a third party.

Congress may ultimately need to establish a broader framework, potentially including a specialized regulatory body or assigning additional responsibilities to existing agencies.

There is also an important institutional question: How should AI regulation be structured so that the rules do not change dramatically with every change in administration?

Whatever regulatory structure emerges, the financial-services industry and technology companies may benefit from having relatively stable rules of the road. Banks, lenders, insurers, credit-card issuers, and investment firms need to know what standards will apply as they make investments in agentic commerce.

Don’t Lock in the Wrong Rules

One of the more unusual recommendations in “The End of Shopping” is that some AI regulations should contain sunset provisions.

The rationale is straightforward. We do not yet know exactly how agentic commerce will develop or whether particular regulatory approaches will work as intended.

Rather than adopting rules that remain in place indefinitely, policymakers could require the rules to be reconsidered after a specified period, perhaps three or five years. That would allow regulators and Congress to evaluate what actually happened, identify unintended consequences and modify the regulatory framework as the technology develops.

For financial regulators, periodic review could be especially useful. Regulators could assess whether agents are increasing competition or merely shifting market power to technology platforms; whether consumers are receiving better rates and terms; whether automated recommendations are producing discriminatory outcomes; and whether disclosures and consent mechanisms are meaningful in practice.

It is a particularly sensible concept for a technology whose capabilities may change substantially within a few years.

What Does the Future Hold?

It is difficult to predict how quickly consumers will embrace agentic shopping. But it seems increasingly likely that AI systems will move beyond recommending products and services and begin performing transactions on consumers’ behalf. If that happens, the implications for consumer financial services could be enormous.

An AI agent could become the consumer’s principal interface with banks, credit-card issuers, lenders, insurers, and investment firms. A consumer might no longer visit a bank’s website, compare credit cards, or call competing mortgage lenders. The consumer might simply tell an AI agent what outcome is desired and allow the agent to determine how to achieve it. That could reduce search costs, increase competition, and make it substantially easier for consumers to switch providers. It also could change how financial institutions compete. Product pricing, transparency, machine-readable information, and the ability to integrate with AI platforms may become as important as branch networks, advertising, and brand recognition.

But agentic AI could also create a new class of gatekeepers with unprecedented access to consumer information and unprecedented ability to influence financial decisions. The central policy question therefore should not be whether agentic AI is good or bad. It is how to ensure that the technology actually serves the consumer whose interests it purports to represent.

That will require regulators, courts, businesses, and policymakers to rethink some fundamental assumptions underlying consumer protection law. It also will require financial institutions to reconsider how they market products, obtain consent, manage third-party relationships, and demonstrate compliance.

For decades, the law has assumed that the consumer is the person making the purchase.

The era of agentic commerce may force us to confront a very different question:

What Happens When the Consumer no Longer Does the Financial Shopping?

Professor Bartholomew’s article, “The End of Shopping,” provides a provocative starting point for answering that question.

Listen to the podcast here.

Consumer Financial Services Group

Back to Top


Senate Banking Committee Advances Brian Johnson’s Nomination to Lead CFPB

The Senate Banking, Housing, and Urban Affairs Committee voted 13-11 along strict party lines on September 17 to advance Brian Johnson’s nomination to become Director of the Consumer Financial Protection Bureau (CFPB). The vote took place during an executive session at which the Committee also considered several other presidential nominations and legislation reauthorizing the Terrorism Risk Insurance Program.

Johnson’s nomination now moves to the full Senate. The Committee’s action was the next step following Johnson’s July 23 confirmation hearing. The Senate has not yet scheduled a floor vote on the nomination.

What Happens Next?

Following the Committee’s favorable vote, Johnson’s nomination will be placed on the Senate Executive Calendar for consideration by the full Senate. The principal remaining step in the confirmation process is therefore a vote by the full Senate.

Timing will depend on Senate floor scheduling. Under the Senate’s tentative 2026 schedule, the Senate is scheduled to be in a state work period for the mid-term elections from October 5 through November 6. Thus, unless the schedule changes, there is a relatively short period between the Committee’s September 17 action and the beginning of the pre-election recess in which the Senate could consider Johnson’s nomination.

If the full Senate confirms Johnson, however, he would not automatically assume the position immediately upon the Senate’s vote. President Trump would need to complete the appointment process, and Johnson would need to take the oath of office before assuming the duties of CFPB Director.

That is significant because Mark Paoletta is currently serving as Acting CFPB Director. Paoletta became Acting Director on August 1, 2026, when Russell Vought’s tenure as Acting Director ended. Johnson therefore would replace Paoletta only after Johnson has been confirmed, appointed, and taken the required oath of office.

For now, the key question is when Senate leadership will schedule the full Senate vote. If the Senate acts before its scheduled October 5 recess, the CFPB could have a Senate-confirmed Director in place before the November 3 midterm elections.

Alan S. Kaplinsky

Back to Top


House Financial Services Committee Approves Legislation to Place CFPB Under Congressional Appropriations Process

The House Financial Services Committee on September 16 approved H.R. 10184, the Consumer Financial Protection Accountability and Reform Act of 2026, by a 28-21 vote. The legislation, sponsored by Rep. Andy Barr (R-Ky.), would make significant changes to the structure, funding, rulemaking, supervision, enforcement, and other authorities of the Consumer Financial Protection Bureau (CFPB).

Most significantly, the bill would place the CFPB under the congressional appropriations process. The CFPB currently obtains its funding directly from the Federal Reserve, subject to statutory limits. H.R. 10184 would instead require the Bureau to obtain its funding through annual congressional appropriations.

The bill also would impose additional requirements on CFPB rulemaking and retrospective review of its regulations; require rulemaking concerning the meaning of “abusive” under the Consumer Financial Protection Act; make changes to bank and nonbank supervision; clarify the legal status of CFPB guidance; revise civil penalty provisions; make changes to the Bureau’s market-monitoring authority; and revise aspects of its consumer complaint process.

Our Consumer Financial Services Group in August produced a webinar about a Discussion Draft of the bill featuring David McGrath, a member of the Professional Staff of the Committee.

Barr Substitute Changes the Bill

An important development at the markup was the adoption of an amendment in the nature of a substitute offered by Rep. Barr. Designated BARR_154, the substitute replaced the introduced version of H.R. 10184 and was adopted by voice vote. The Committee subsequently approved H.R. 10184, as amended, by a 28-21 recorded vote.

The substitute retains the basic structure and principal provisions of the introduced bill but makes several substantive changes.

One of the more significant changes concerns the retrospective review of CFPB regulations. Under the revised bill, if the Office of Management and Budget (OMB) determines that a major CFPB rule fails to demonstrate net benefits, the CFPB generally would have one year to undertake corrective rulemaking. The substitute also provides that, during the period before the corrective rule becomes effective, the CFPB and other federal or state agencies could not enforce the portion of the rule that OMB determined failed to demonstrate net benefits.

The substitute also modifies the proposed safe harbor for certain small-dollar credit products. Among other changes, it permits a lender to make another covered small-dollar loan when the consumer’s aggregate outstanding principal after the new loan does not exceed $3,500, subject to the bill’s inflation adjustment. It also permits certain rollovers when initiated by the consumer or provided as a hardship accommodation.

The substitute makes a related change concerning small-dollar lines of credit. Rather than the limitation contained in the introduced bill, the revised language permits a single-payment draw of up to 20% of the consumer’s average monthly direct deposits.

The substitute also revises the provision addressing CFPB guidance. It provides that nonconformity with CFPB guidance may not be used to establish a violation of applicable law.

These changes should be distinguished from provisions that were already contained in the introduced bill, including the proposed $30 billion asset threshold for certain CFPB supervisory authority and the provisions concerning earned-wage access and buy-now-pay-later products.

Democratic Amendments Rejected

The Committee rejected five Democratic amendments to H.R. 10184, all by votes of 21-28. Two were offered by Rep. Stephen Lynch (D-Mass.), and three were offered by Rep. Bill Foster (D-Ill.).

Lynch’s first amendment would have clarified that the CFPB’s authority under Section 1031 of the Consumer Financial Protection Act to prohibit unfair, deceptive, or abusive acts or practices includes discriminatory practices. His second would have preserved concurrent enforcement authority for state attorneys general and state regulators when the CFPB was pursuing an action involving the same entity.

Foster’s three amendments would have required Treasury studies addressing the potential effects of the legislation on the CFPB’s ability (i) to address scams, fraud, and other UDAAPs affecting older Americans; (ii) to protect servicemembers, veterans, and their families; and (iii) to monitor emerging technologies, including artificial intelligence, for unfair, deceptive, or abusive practices.

The Committee’s final vote on H.R. 10184 also was strictly along party lines. All 28 members voting in favor were Republicans, and all 21 members voting against were Democrats. Thus, no Democratic member voted for the legislation.

Rep. Barr said the CFPB’s current structure does not provide sufficient accountability and transparency. Democratic members argued that the legislation would weaken the Bureau’s ability to protect consumers. Rep. Bill Foster said Congress had deliberately established the CFPB’s existing funding mechanism through the Federal Reserve to provide the Bureau with independence from congressional pressure, while Rep. Sylvia Garcia (D-Texas) characterized the legislation as an attempt to eliminate the Bureau.

What Happens Next?

The Financial Services Committee has completed its consideration of H.R. 10184 and ordered the bill, as amended, reported favorably to the House by a 28-21 vote. The bill was originally referred to the Financial Services, Judiciary, Small Business, and Oversight and Government Reform Committees.

As of today’s date, the Financial Services Committee is the only one of those committees to have acted on H.R. 10184. The bill remains subject to its referrals to the Judiciary, Small Business, and Oversight and Government Reform Committees, and there has been no House floor vote. Accordingly, the next significant steps would be consideration by any of the other committees with jurisdiction, followed by possible consideration by the full House.

If the House ultimately passes H.R. 10184, the Senate would then have to consider the legislation before it could be presented to the President.

In light of the fact that there are few legislative days left in this Congressional session (considering that the House is on recess until November 9, the Senate will go on recess in early October until November 9, and both the House and Senate will adjourn for this session on or about December 18) and that this legislation will need 60 favorable votes in the Senate, it is very unlikely that the legislation will pass this year.

John L. Culhane, Jr. and Alan S. Kaplinsky

Back to Top


Inspector General Releases Report on Impact of CFPB Cutbacks

Changes at the CFPB have caused a backlog of consumer complaints, the CFPB’s Office of Inspector (OIG) said, in a report.

Stop-work orders also resulted in CFPB staff temporarily not performing enforcement, supervision and other functions, but workforce-reduction actions had limited impact on bureau operations because of court intervention, the OIG said.

In addition, cancellations of contracts with third parties resulted in service disruptions that affected the consumer complaint database and other operational processes.

“From February to April 2025, we received multiple congressional requests to review the impact on the Consumer Financial Protection Bureau’s operations resulting from the agency’s recent workforce and contract actions, including stop-work orders, dismissals of probationary and term employees, planned reductions in force (RIFs), and contract cancellations,” the OIG said.

The OIG said it did not assess whether the CFPB actions complied with applicable laws, regulations or policies since that is the subject of pending litigation.

“Moreover, our role in this review was not to second-guess policy judgments by CFPB leadership, past or present, about the appropriate number of CFPB personnel or level of enforcement or other activities conducted by the CFPB—such policy decisions are outside the scope of our jurisdiction under the Inspector General Act,” the OIG said. The OIG added, that, as requested by various members of Congress, the review provides factual information about the impact that workforce and cancellations taken in early 2025 had on the CFPB’s operations, which have been the subject of multiple recent reports.

CFPB officials refused to meet with OIG officials, citing the pending litigation. However, they did provide a written response to the report.

The OIG reported that:

During one pay period in February, employees charged 115,726 hours of administrative leave; that is the equivalent of about 1,447 employees being paid while not working.”

In response to the February stop-work orders, Supervision staff initially ceased all supervision and examination activities, pausing 274 examinations and 189 monitoring events, for a total of 463 supervisory events. Since March 2025, Supervision has resumed some activities, such as closing supervisory events, coordinating with other federal regulatory agencies, and participating in Federal Financial Institutions Examination Council projects.”

In April 2025, the CFPB chief legal officer issued a memorandum outlining the agency’s supervision and enforcement priorities for 2025. The memorandum said that the number of supervisory events should decrease by 50% and that supervision staff should shift 70% of its focus to depository institutions and 30% to non-depository institutions. In April 2025, CFPB leadership authorized staff to close certain matters requiring attention that did not align with these 2025 priorities.

Under Section 1013(b)(3) of Dodd-Frank, the CFPB is required to establish a unit that has a telephone number, a website, and a database to centrally collect, monitor, and respond to consumer complaints regarding consumer financial products or services. According to a CFPB official, between February 10 and March 3, 2025, the Office of Consumer Response ceased monitoring and responding to consumer complaints related to consumer financial products and services. The OIG went on to note that according to data provided by the CFPB, as of June 2026 the agency had about 17,100 consumer complaints that require manual routing, of which about 3,800, or about 22%, have been pending for more than 30 days.

In response to a draft of the report, CFPB General Counsel Victoria Dorfman defended the CFPB’s actions. “In early 2025, the Bureau needed to pause its work to allow then-Acting Director Vought and his team to thoroughly review CFPB’s activities,” she wrote. “It provided time for the new Bureau leadership to identify and implement much needed changes. The Bureau subsequently took extensive action to correct for the overreach of the prior administration, implement a robust deregulatory agenda, and streamline its bloated operations.”

She said that the Bureau has continued to process consumer complaints efficiently while making extensive improvements to its complaint process. The consumer complaint process has long been plagued by users abusing the system, according to Dorfman. For instance, the Bureau launched two-factor authentication, requiring users who create online accounts to verify both their email addresses and mobile phone numbers, she wrote. She added that the CFPB also plans to implement address validation at the complaint submission step.

The Bureau also is taking a new approach to its supervisory and enforcement work, Dorfman wrote. “The Bureau [will] no longer pursue matters based on novel legal theories and it [will] avoid burdensome duplicative actions,” she said. She added, “Instead of chasing headlines by targeting companies based on dubious legal theories and extortionate penalties, the Bureau now focuses its enforcement on addressing actual harm to consumers and providing them with relief as quickly as possible.”

Dorfman also criticized the OIG’s work. “The Draft Report does not account for the Bureau’s bold and aggressive agenda and the extensive work it has done to correct the misguided approach of the prior administration,” she concluded.

John L. Culhane, Jr., Alan S. Kaplinsky, and Richard J. Andreano, Jr.

Back to Top


Colorado Publishes Draft ADMT Regulations

On August 11, 2026, the Colorado Department of Law published its much anticipated Automated Decision-Making Technology (ADMT) and Conversational AI Service Rules (the Draft Rules). The ADMT Draft Rules provide guidance on the newly amended Colorado AI Act.

The Draft Rules–which were required to be written on an expedited basis by the amended Act–cover various different issues that will be critical to deployer and developer compliance. Because the Colorado Act applies to various data sets that are exempted under the CCPA’s ADMT rules, the Draft Rules will be a driver of AI policy more generally.

The Colorado Attorney General’s Office now invites formal rulemaking comments from all members of the public regarding the Draft Rules, and a public hearing will be held on October 26.

Gregory P. Szewczyk, Mudasar Khan, Alan S. Kaplinsky, Kelsey Fayer, Madison Etherington, and Megan H. Bryan

Back to Top


House Financial Services Committee Advances DIDMCA Opt-Out Clarification Bill

On September 16, 2026, the House Financial Services Committee (Committee) approved H.R. 7866, the American Lending Fairness Act of 2026, legislation introduced by Rep. Warren Davidson (R-Ohio) and Rep. Andy Barr (R-KY) that would address the effect of state opt-outs under Section 525 of the Depository Institutions Deregulation and Monetary Control Act of 1980 (DIDMCA) on interest-rate exportation by state-chartered banks and credit unions located outside an opt-out state and making loans to a resident of the opt-out state. There is a companion bill with the same short title and text introduced by Senator Bernie Moreno (R-Ohio) in the Senate which has not yet been acted upon.

The Committee considered H.R. 7866 during its September 16 markup and approved it, as amended, by a vote of 31-18. All Republicans voted for the bill, along with Democrats Joyce Beatty (D-Ohio), Bill Foster (D-Ill.), and Brad Sherman (D-Calif.). The Committee’s official materials identify an amendment in the nature of a substitute offered by Rep. Davidson. The amended bill made technical, non-substantive changes to the bill before it was voted upon.

The bill would repeal DIDMCA Section 525 and amend Section 27 of the Federal Deposit Insurance Act to provide that, if a state adopts a law or certifies that its voters have approved a provision stating that the state does not want Section 27 to apply to loans made by institutions chartered by that state, Section 27(a) would not apply to loans made by those institutions after the opt-out. The bill contains a parallel provision for state-chartered federally insured credit unions.

The legislation is being considered against the backdrop of litigation brought in federal district court by financial-services trade associations challenging Colorado’s and Oregon’s interpretations of the effect of their DIDMCA opt-outs. In Colorado, trade associations representing banks and other financial institutions have challenged the state’s position that its opt-out empowers it to regulate interest rates charged by out-of-state state banks making loans to Colorado residents. The 10th Circuit en banc court is considering whether to affirm a district court’s award of a preliminary injunction precluding the state of Colorado from enforcing the Colorado usury law against out-of-state state banks making loans to Colorado residents. Similar litigation has been filed in Oregon concerning that state’s opt-out. Those cases raise questions about the legal effect of state opt-outs and whether they can limit the ability of state-chartered banks and credit unions in other states to export their home-state interest rates to borrowers in the opt-out state. The litigation could affect the legal landscape while Congress considers whether to address the issue legislatively. It should be noted that H.R. 7866’s stated purpose is “To restore and clarify the intent of the Federal interest rate exportation parity for State-chartered banks by allowing States to opt out of preemption only with respect to loans made by their own chartered institutions, and for other purposes.”

The Committee’s action represents an important step for legislation that is intended to restore what its proponents describe as interest-rate exportation parity between state-chartered and national banks. Committee Chairman French Hill said the bill would “preserve charter choice” by allowing state-chartered banks and credit unions to offer loans nationwide under the interest-rate rules of their home states.

What Happens Next?

H.R. 7866 now moves beyond the Committee. The next major step would be consideration by the full House of Representatives. If the House passes the legislation, it would then have to be considered by the Senate and, if approved there in identical form, presented to the President for signature.

The timing of a House vote has not yet been announced. We will continue to follow the legislation, particularly because its next stages, and the pending litigation in Colorado and Oregon, will help determine whether Congress ultimately acts to clarify the effect of state DIDMCA opt-outs on interstate lending by state-chartered financial institutions.

Alan S. Kaplinsky and Burt M. Rublin

Back to Top


CSBS Supports DIDMCA Legislation as House Committee Prepares to Mark Up Bill

Executive Summary

The Conference of State Bank Supervisors (CSBS), the nationwide organization representing state banking and financial regulators, has endorsed legislation that would clarify a critical issue concerning the scope of Section 525 of the Depository Institutions Deregulation and Monetary Control Act of 1980 (DIDMCA). The development comes as the House Financial Services Committee prepares to mark up H.R. 7866, the American Lending Fairness Act of 2026, on Wednesday, September 16, 2026, at 10 a.m. ET.

The CSBS letter rejects the interpretation advanced by Colorado and Oregon that a state’s DIDMCA opt-out under Section 525 permits it to regulate loans made by out-of-state state-chartered banks merely because the borrowers are located in the opt-out state.

That is the central issue in litigation pending before the 10th Circuit and in a more recently filed case in Oregon, in which Ballard Spahr represents the trade association plaintiffs. The FDIC and OCC have filed amicus briefs in both cases, advancing the same basic interpretation of Section 525 of DIDMCA that CSBS now supports.

CSBS Endorses the Narrow Interpretation of DIDMCA’s Opt-Out

Section 521 of DIDMCA permits a federally insured state-chartered bank to export the interest rate permitted by the law of its home state when making loans across state lines. Section 525 permits a state to opt out of that federal interest-rate preemption for “loans made in such State.”

The parties disagree about what that phrase means.

Colorado and Oregon contend that a loan is “made” in their states when the borrower is located there. On that view, their interest-rate restrictions apply to loans made by out-of-state state-chartered banks. The plaintiffs in both cases contend that Section 525 does not authorize an opt-out state to regulate banks chartered by other states because the loan is “made” only in the bank’s state.

CSBS has now endorsed the plaintiffs’ interpretation.

In a September 2 letter to House Financial Services Committee Chairman French Hill and Ranking Member Maxine Waters, CSBS urged Congress to enact H.R. 7866. The letter explains that the legislation would “preserve each state’s authority to establish the rules governing its own chartered institutions” while maintaining competitive equality between state-chartered and national banks.

CSBS also warned that a broader interpretation of the opt-out provision could disrupt the dual banking system. As the letter states, “[a] state’s decision to opt out of DIDMCA should not allow it to regulate the activities of banks chartered by other states.” CSBS further explained that such an interpretation could “undermine the competitive balance between state and national banks” and create uncertainty for banks, regulators, and consumers.

Those concerns help explain why CSBS has weighed in. Its position is not limited to the interests of individual state-chartered banks. Rather, CSBS is focused on preserving the allocation of regulatory authority within the dual banking system: states should be able to establish the rules governing institutions they charter, but one state should not be able to regulate banks chartered by another state simply because those banks lend to its residents.

Congress May Clarify the Issue

The CSBS letter comes as the House Financial Services Committee prepares to mark up H.R. 7866 on September 16.

The bill would clarify that a state’s DIDMCA opt-out applies only to institutions chartered by that state. An opt-out therefore would prevent a state-chartered bank located in the opt-out state from relying on DIDMCA to export its home-state interest rate. It would not, however, authorize that state to impose its interest-rate restrictions on an out-of-state state-chartered bank lending to one of its residents.

As Stated Above, The Issue Is Also Before the Courts

The issue is pending before the 10th Circuit in National Association of Industrial Bankers v. Weiser, which concerns Colorado’s attempt to apply its DIDMCA opt-out to loans made by out-of-state state-chartered banks to Colorado residents. The 10th Circuit granted rehearing en banc in April and heard oral argument on August 18. Ballard Spahr represents several bank trade associations that filed amicus briefs supporting the plaintiffs.

The same fundamental issue is presented in Oregon. In June, the National Association of Industrial Bankers, the American Financial Services Association, and the Online Lenders Alliance sued to block enforcement of Oregon’s recently enacted DIDMCA opt-out law. The plaintiffs moved for a preliminary injunction on July 9, and the motion is fully briefed.

The federal banking regulators have supported the plaintiff bank trade associations in both cases. The FDIC and OCC each filed amicus briefs supporting the plaintiffs in the Oregon litigation, and both agencies previously submitted amicus briefs in the Colorado litigation. Their briefs advance the same basic interpretation of Section 525 that CSBS has now endorsed: an opt-out state cannot use Section 525 to regulate loans made by an out-of-state state-chartered bank merely because the borrower is located in the opt-out state.

An Important Convergence

CSBS’s letter reflects an important convergence among state and federal banking regulators, the affected trade associations, and the financial institutions challenging the Colorado and Oregon laws.

The federal banking agencies have urged the courts to reject the states’ interpretation of Section 525. CSBS, speaking for the state banking regulatory community, has now urged Congress to enact legislation that would clarify the limited scope of Section 525 opt-out. And the House Financial Services Committee is poised to consider that legislation. A companion bill has also been introduced in the Senate.

Whether the issue is ultimately resolved by Congress or the courts, these developments reaffirm a basic principle underlying DIDMCA: a state may determine the rules applicable to institutions it charters, but its decision to opt out of DIDMCA should not give it regulatory authority over banks chartered by other states.

Alan S. Kaplinsky, Burt M. Rublin, and Ronald K. Vaske

Back to Top


MBA Sues New Jersey Over Disparate Impact Rule

The Mortgage Bankers Association (MBA) recently filed a lawsuit in the U.S. district court for the district of New Jersey challenging the disparate impact rules adopted by the state.

In December 2025, the New Jersey Division on Civil Rights (DCR) adopted Rules Pertaining to Disparate Impact Discrimination under the New Jersey Law Against Discrimination. In a press release announcing the adoption of the Rules, then New Jersey Attorney General Matthew J. Platkin and the DCR stated that the “DCR has adopted landmark new rules that codify the prohibition against disparate impact discrimination under the New Jersey Law Against Discrimination (LAD), the oldest and strongest state civil rights law in the country.” In addition to housing financial assistance, the Rules apply to employment, housing, places of public accommodation, and contracting. In connection with housing financial assistance, the LAD prohibits discrimination on the basis of race, creed, color, national origin, ancestry, marital status, civil union status, domestic partnership status, pregnancy or breastfeeding, sex, gender identity or expression, affectional or sexual orientation, disability, liability for service in the Armed Forces of the United States, familial status, or nationality.

Addressing the Trump administration’s efforts to roll back disparate impact liability, which we have addressed extensively, including here, here, here, and here, the press release provides that “[t]he rules adopted today confirm that New Jersey’s civil rights laws continue to prohibit disparate impact discrimination—notwithstanding the Trump administration’s unprecedented attempts to dismantle disparate impact standards at the federal level. Not only are those federal attempts to roll back disparate impact liability standards inconsistent with existing federal law, but they cannot and do not change the standards applicable under state law—standards that today’s landmark rules now codify in New Jersey.”

While it is asserted in the press release that the Rules “codify existing case law,” the MBA asserts in its complaint that the Rules are inconsistent not only with existing federal case law, but also the Equal Protection Clause of the U.S. Constitution and federal statutes. A key theme of the MBA’s position is that the U.S. Supreme Court “has permitted disparate impact liability only in conjunction with certain safeguards,” and that, citing the Court’s Texas Dep’t of Hous. & Cmty. Affs. v. Inclusive Communities Project, Inc., in the absence of such safeguards disparate impact regimes “inexorably lead” to serious constitutional concerns. In the Inclusive Communities case decided in 2015, the Supreme Court held that disparate impact claims may be brought under the federal Fair Housing Act, subject to safeguards to avoid constitutional issues. Citing Inclusive Communities, the complaint provides that “[t]hese safeguards include: a robust requirement that a challenger identify a specific policy of the business that caused the disparity; leeway for businesses to defend their nondiscriminatory policies on the grounds that they advance ‘valid’ interest[s];’ and a challenger’s burden to identify an alternative that serves those interests as effectively.” The complaint asserts that the Rules lack the applicable safeguards and, thus, are not consistent with federal law.

The complaint asserts that under the Rules, “a facially neutral practice adopted with no discriminatory intent violates the LAD if it ‘actually or predictably results in a disproportionately negative effect on members of a protected class,’ even if the effect is neither substantial nor statistically significant, and even if the practice has not yet been implemented, unless the covered entity carries a demanding burden of justification,” and that “a challenger need not show that the covered entity’s policy caused a disparity among the entity’s own applicants or customers, or within any relevant qualified population. Instead, disparate impact may be established with ‘[n]ational, State, and local statistics,’ ‘[d]emographic or census data,’ ‘[s]urvey data,’ and other aggregate material, supplemented by anecdotal evidence.”

The Rule also asserts that once a covered entity establishes that a practice that is challenged under the Rules is “necessary” to achieve a “substantial, legitimate, nondiscriminatory interest,” in the housing and housing financial assistance context the covered entity would then have to demonstrate “that there is not a less discriminatory alternative means of achieving the substantial, legitimate, nondiscriminatory interest.” Thus, the Rules place on the entity, and not the challenger of a practice, the burden to establish that there is no less discriminatory means to achieve the intended interest to be served by a practice. In short, the entity must prove a negative.

Significantly, the complaint asserts that under the Rules an “interest in achieving diversity or increasing access for underrepresented or underserved members of a protected class” may itself supply the substantial, legitimate, nondiscriminatory interest that justifies a challenged practice. Based on this provision, the complaint asserts that the Rules have “blessed race-conscious activity,” which is prohibited by federal law.

Addressing the impact of the Rules on the MBA and MBA members, the complaint asserts that:

  • MBA members underwrite loans using facially neutral criteria that measure credit risk and the cost of originating and servicing a loan and that under the Rules every MBA member that lends in New Jersey must immediately spend resources assessing their underwriting, pricing, servicing, and other policies to determine whether any produces a statistical disparity that could expose them to liability under the Rules, and that these costs are unrecoverable and ongoing.
  • MBA’s lender members operating in New Jersey and other states may be required to adopt policies for New Jersey mortgages that differ from the policies used in other states. These members will incur operational costs implementing separate policies in separate states.
  • MBA members that own, operate, and manage residential rental housing choose tenants using a variety of standard practices to evaluate potential tenants, including criminal history, income, and credit history (in all cases, consistent with other state and federal law), and also have policies on pets and occupancy limitations. Under the requirements of the Rules regarding how such members choose tenants, the members must immediately spend resources assessing these and other policies to determine whether any produces a statistical disparity that could expose them to liability under the Rules, and that these costs are unrecoverable and ongoing.
  • MBA’s core service to its members involves compliance assistance, member working groups, and guidance on new regulatory requirements. The Rules undermine these services and make it impossible for MBA to provide clear guidance to its members on what the law requires.

In its request for relief the MBA seeks:

  • A declaration that the Rules violate the Equal Protection Clause of the 14th Amendment to the U.S. Constitution.
  • A declaration that the Rules are preempted by federal law, including the Fair Housing Act and the Equal Credit Opportunity Act.
  • A permanent injunction against the New Jersey Attorney General and DCR, their agents, and their successors from enforcing the Rules.
  • In the alternative, a declaration that the Rules’ housing and housing financial assistance provisions are invalid and a permanent injunction against the enforcement of the provisions.

Richard J. Andreano, Jr. and John L. Culhane, Jr.

Back to Top


FinCEN Clarifies Use of Digital Credentials Under CIP

FinCEN and the staffs of the Fed, FDIC, OCC, and NCUA, have jointly issued two FAQs addressing the use of verifiable digital credentials (VDCs), including state-issued mobile driver’s licenses (mDLs), to verify customer identities under the Customer Identification Program (CIP) Rule.

The principal clarification is that an unexpired, government-issued VDC, such as an mDL, may qualify as “government-issued identification” for purposes of the CIP Rule, provided that the VDC evidences nationality or residence and bears a photograph, the institution has the technology or systems necessary to extract the appropriate information, and the institution’s CIP permits its use. As with physical identification cards, however, a VDC is not automatically sufficient if there are indications of fraud. The institution must still be able to form a reasonable belief that it knows the customer’s true identity.

The agencies also updated an existing FAQ to clarify that VDCs issued or maintained by private third parties may be used as a non-documentary means of verification, but the financial institution remains responsible for ensuring that the third party uses the same level of authentication that the institution itself would use. Before relying on a third-party credential, the institution should therefore understand how the provider authenticates an individual and satisfy itself that the process is consistent with the institution’s CIP requirements.

The agencies emphasize that the FAQs “neither alter existing BSA [Bank Secrecy Act] legal or regulatory requirements nor establish new supervisory expectations” and that institutions are not required to accept digital credentials. The FAQs merely confirm that the existing CIP framework is technologically neutral and can accommodate digital forms of identification.

John L. Culhane, Jr. and Alan S. Kaplinsky

Back to Top


CSBS Releases Artificial Intelligence Supervisory Framework for State Examiners

The Conference of State Bank Supervisors (CSBS) on September 16, 2026, released an Artificial Intelligence Supervisory Framework designed to help state financial examiners identify and understand how the bank and nonbank institutions they regulate are using artificial intelligence, assess the associated risks, and determine when a more in-depth review may be appropriate.

The framework is significant because it provides state examiners with a common approach to AI supervision at a time when banks and nonbanks are rapidly expanding their use of AI, including generative and agentic AI. At the same time, CSBS emphasizes that the framework is a discretionary supervisory tool and does not establish new substantive requirements governing the use of AI.

CSBS is not the only group of regulators focused on artificial intelligence. The American Association of Residential Mortgage Regulators (AARMR), which is comprised of the state agencies who are responsible for supervising nonbank residential mortgage lenders, collaborated with the Mortgage Bankers Association on an industry survey conducted by the Boston Consulting Group as part of AARMR’s goal of understanding how mortgage companies are deploying AI across operations, risk management and compliance, while continuing to ensure consumers are protected. These same regulators will be determining whether they want to adopt the framework for the nonbank mortgage industry, and, if the past is any indication, we should expect wide-spread adoption and implementation of the framework.

A Risk-Based Supervisory Framework

CSBS says the framework is intended to take into account an institution’s size, complexity, risk profile, and particular uses of AI. It draws upon existing AI risk-management resources, including the National Institute of Standards and Technology’s AI Risk Management Framework, the Cyber Risk Institute’s Financial Services AI Risk Management Framework, and the U.S. Department of the Treasury’s AI Lexicon.

The framework consists of several components. The Core Examiner Guide provides the basic examination approach, including initial scoping questions, a document request list, and procedures addressing AI governance and oversight, AI inventories and use cases, and generative AI and other emerging uses.

The Examiner Work Program provides additional guidance for applying the Core Examiner Guide. For nonbanks, the Nonbank AI Supplements address third-party and vendor risk, model risk, and consumer protection. CSBS also has developed an optional AI Use Case Risk Tiering Worksheet that can be used to assess individual AI applications and determine whether additional review may be appropriate.

The framework was approved by the CSBS State Supervisory Processes Committee and Nondepository Supervisory Committee in August. Each state financial regulatory agency will determine the extent to which it incorporates the framework into its supervisory program.

Why the Framework Matters

The most important point for financial institutions is that the framework does not itself impose new legal requirements. Rather, it gives state examiners a structured way to inquire into an institution’s use of AI and determine whether its existing governance, risk-management, and compliance processes adequately address the risks presented by those uses.

That distinction is important. CSBS expressly describes the framework as a “discretionary tool.” It also emphasizes that the supervisory approach should reflect the institution’s size, complexity, risk profile, and use of AI.

Thus, the framework appears designed to avoid a one-size-fits-all approach. The supervisory concerns presented by an employee using a generative AI application to summarize documents, for example, are quite different from those presented by an AI system that materially influences credit decisions or determines how a consumer is treated.

AI Inventories and Third-Party Risk

One practical consequence of the framework is that financial institutions should be able to identify where AI is being used throughout their organizations.

An institution should know what its material AI use cases are, which business functions use AI, whether the technology was developed internally or supplied by a third party, and what risks each use case presents. Institutions also should be prepared to explain who is responsible for AI governance and how AI-related risks fit within existing risk-management and compliance programs.

The framework’s specific attention to third-party and vendor risk will be particularly important for nonbanks. Many financial services companies will not develop their own AI systems. Instead, AI capabilities increasingly will be incorporated into products and services provided by vendors. State examiners therefore may focus on how institutions evaluate and monitor those vendors and determine whether their AI-related practices create risks for the institution or its customers.

This effort to identify third-party risk management issues in AI systems appears to fill a gap in guidance from federal banking regulators. The Interagency Guidance on Third-Party Relationships issued in 2023 by the OCC, FDIC, and Federal Reserve takes a “broad, principles-based approach [without addressing] specific topics or types of relationships,” and opted to avoid AI-specific guidance. The agencies most recent TPRM proposal to replace the 2023 guidance, which we wrote about here, also takes a broad approach, focusing broadly on “material financial risks and violations of laws and regulations rather than ineffective and counter-productive check the-box exercises.” Similarly, the 2026 revisions to the OCC, FDIC, and Federal Reserve’s Supervisory Guidance on Model Risk Management expressly excludes generative and agentic AI. So, even if imperfect, the framework provides financial institutions with targeted governance measures to consider—and sets potential supervisory expectations—as they develop and deploy a variety of AI tools.

Generative and Agentic AI

The framework’s treatment of generative AI and other emerging AI applications also is noteworthy. Traditional model-risk-management concepts do not necessarily fit neatly with every use of generative or agentic AI.

Financial institutions increasingly are using these technologies for customer service, fraud detection, document review, coding, marketing, underwriting support, and other functions that may not resemble traditional models. The supervisory questions therefore cannot be limited to conventional model validation.

The challenge for regulators and financial institutions will be developing controls that address genuine risks without imposing unnecessarily burdensome requirements on relatively low-risk uses of AI.

What Financial Institutions Should Do Now

Although the framework does not establish new regulatory requirements, institutions subject to state supervision may want to use it as a roadmap for preparing for their next examination.

In particular, institutions should consider whether they can readily answer basic questions concerning their AI inventory, governance structure, risk assessments, third-party providers, consumer-protection controls, and use of generative and other emerging AI technologies.

The significance of the framework ultimately will depend on how individual state regulators implement it. CSBS has made clear that each state agency will determine the extent to which it incorporates the framework into its supervisory program. The framework therefore does not necessarily mean that every state examiner will immediately conduct a separate AI examination.

Nevertheless, it gives state regulators a common set of tools and questions that can be incorporated into existing examinations. For financial institutions, that means AI supervision is moving from a largely conceptual issue toward a more concrete component of state supervisory examinations.

The CSBS Artificial Intelligence Supervisory Framework and its component materials are available from CSBS.

Alan S. Kaplinsky, Adam Maarec, and John D. Socknat

Back to Top


FinCEN Renews Its Focus on Minnesota

On August 11, 2026, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) renewed its Geographic Targeting Order (GTO) Imposing Recordkeeping and Reporting Requirements on Certain Financial Institutions in Minnesota. The GTO requires financial institutions located in Hennepin and Ramsey Counties, Minnesota, to “retain and report records of certain payments of $3,000 or more.”

The initial GTO was announced on January 9, 2026, as part of the Trump administration’s efforts to combat alleged “rampant government benefits fraud in Minnesota.” The first GTO went into effect on February 12, 2026, and was set to expire on August 10, 2026. The renewed GTO has extended this deadline and will remain in effect until February 6, 2027. FinCEN has released frequently asked questions in connection with the renewal that explain the requirements of the renewed GTO.

The renewed GTO is nearly identical to the initial order but, as explained in the Frequently Asked Questions, exempts certain Covered Businesses “that are banks from [the] GTO’s requirement to record or report fund transfers where the originator falls into certain categories[.]” The exemptions are consistent with the Exemptive Relief Order for the Geographic Targeting Order Imposing Recordkeeping and Reporting Requirements on Certain Financial Institutions in Minnesota, which granted “tailored exemptive relief” to “exempt certain categories [of] fund transfers that are lower risk for government benefits fraud, and to allow banks sufficient time to report certain information required by the GTO.”

The renewed GTO continues to exempt banks from funds transfers where the originator falls into one of the sixteen categories excluded under the Customer Due Diligence Rule, but, importantly, it does not extend the temporary relief that had limited banks’ obligations to information already covered by the Recordkeeping Rule.

The renewed GTO, as explained, is otherwise identical to the first GTO. It requires banks and money services businesses (MSBs) located in Hennepin and Ramsey Counties to report international fund transfers of $3,000 or more when the beneficiary or recipient is located outside of the United States. Banks and MSBs located in these counties are “covered businesses,” which is defined as any bank as defined in 31 CFR 1010.100(d), or any money transmitter, as defined in 31 CFR 1010.100(ff)(5), with a branch, subsidiary, or office located in the covered geographic area. The GTO requires covered businesses to report to FinCEN certain information required to be retained under “31 CFR 1020.410(a)(1) and (2), along with certain other additional information, regardless of whether the information is provided with the payment order[.]” This information, which is set forth in the Frequently Asked Questions, includes:

  1. The name and employer identification number of the Covered Business;
  2. The account number of the originator;
  3. The name of the beneficiary;
  4. The address of the beneficiary;
  5. The date of birth of the beneficiary;
  6. A phone number of the beneficiary;
  7. An email address of the beneficiary;
  8. The account number of the beneficiary;
  9. Whether the source of funds for the transfer includes payments that are from any federal, state, or local government contract or benefit program; and,
  10. If the answer to question (9) is yes, whether those payments are from government agencies to entities in which the originator has any ownership interest.

If the Covered Business is a money transmitter, additional information concerning the form of the transmittal is required. If the renewed GTO is “willfully” violated, a business could be subject to civil penalties, with a separate penalty applied for each individual violation. Criminal fines are also available, as well as imprisonment for no more than five years.

This renewed GTO is part of Secretary of the Treasury Scott Bessent’s plan “to follow the money” and should serve as a reminder that the Trump administration appears willing to impose strict reporting requirements and enforcement tools to further its goals.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. And please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

Emily Friedman

Back to Top


New Guidance Addresses SAR Confidentiality and Customer Communications

Banks and their employees face a difficult balancing act when discussing suspected fraud or money laundering activity with a customer on whose account activity the bank has filed a suspicious activity report (SAR). The bank must take practical steps to protect the customer and the institution (for example, verifying transactions, restricting account access, or requesting additional documentation) while strictly preserving SAR confidentiality. If a bank employee discloses—or even inadvertently implies—that a SAR has been filed, that law enforcement is involved, or even that internal investigations are ongoing, the bank can be exposed to regulatory findings, civil penalties, litigation risk, and reputational harm. What’s more, the employees engaged in these conversations may face discipline or termination for violating policy and confidentiality requirements. At the same time, poorly chosen language or a refusal to provide a customer with information about his or her account, can cause customer disputes, prompt complaints, or create safety risks for frontline personnel.

On September 2, 2026, FinCEN and the federal banking agencies (the Federal Reserve, FDIC, NCUA, and OCC) issued a joint statement clarifying the application of SAR confidentiality requirements to communications with customers. The statement explains that SAR confidentiality requirements do not prohibit banks and credit unions from communicating with customers about potentially fraudulent transactions, suspicious activity, account restrictions, or account closures, provided those communications do not disclose the existence of a SAR.

The statement follows a June 2025 Request for Information regarding payments fraud, in which commenters identified questions concerning the extent to which financial institutions may discuss fraud-related matters with customers when a SAR has been or may be filed. It also references Executive Order 14331, “Guaranteeing Fair Banking for All Americans.”

The Guidance

The agencies reiterate that the Bank Secrecy Act (BSA) prohibits the disclosure of a SAR or information that would reveal the existence of a SAR. At the same time, the agencies note that FinCEN’s SAR confidentiality regulations permit the disclosure of the underlying facts, transactions, and documents upon which a SAR is based.

As a result, banks and credit unions may communicate with customers or third parties regarding potentially fraudulent transactions, suspicious activity, account restrictions, and account closures, so long as the communication does not disclose that a SAR has been filed.

The agencies also state that the fact that a customer or third party could potentially infer from the underlying facts that a SAR may have been filed does not, by itself, constitute a prohibited disclosure under the SAR confidentiality requirements.

Relationship to Prior Guidance

The joint statement builds on existing SAR confidentiality guidance. FinCEN’s 2010 final rule addressing SAR confidentiality established that the prohibition on disclosure does not apply to the underlying facts, transactions, and documents on which a SAR is based. More recently, FinCEN’s September 2025 guidance regarding cross-border information sharing (FIN-2025-G001) reiterated that principle in the context of information sharing among affiliated institutions.

The September 2026 joint statement focuses specifically on communications with customers and provides additional clarification regarding how financial institutions may apply existing SAR confidentiality requirements in customer-facing situations.

Examples of Permissible Communications

The statement provides a non-exhaustive list of communications that “would not typically” disclose the existence of a SAR. Examples include:

  • Requesting customer due diligence information to better understand the nature and purpose of a customer relationship;
  • Notifying a customer that a delay, limitation, or account closure may be related to suspected fraud or suspicious activity;
  • Notifying a customer that a deposit, such as an altered or counterfeit check, has been rejected due to suspected fraud;
  • Asking about the purpose of a transaction or the source of funds;
  • Providing educational materials or warnings regarding fraud schemes, typologies, and money mule activity;
  • Communicating account maintenance decisions, including declining transactions or closing accounts; and
  • Requesting information concerning the originator or beneficiary of a funds transfer.

The agencies emphasize that institutions should evaluate communications on a case-by-case basis and exercise caution to avoid revealing the existence of a SAR.

Practical Considerations

The statement does not modify existing legal or regulatory requirements and does not create new supervisory expectations. Instead, it provides additional clarification regarding how existing SAR confidentiality requirements apply in the context of customer communications.

Financial institutions may wish to review existing policies, procedures, and training materials relating to customer communications in situations involving fraud investigations, suspicious activity reviews, account restrictions, and account closures. Institutions should also consider whether additional guidance or training is appropriate to help personnel distinguish between discussing underlying facts and disclosing information that could reveal the existence of a SAR.

Because the agencies’ examples are non-exhaustive and emphasize a facts-and-circumstances analysis, institutions should continue to assess individual situations carefully and document decision-making where appropriate.

Looking Ahead

The joint statement provides additional clarification regarding the scope of SAR confidentiality requirements and confirms that institutions generally may discuss underlying facts, transactions, and documents with customers, provided they do not disclose the existence of a SAR. Financial institutions should consider the guidance when evaluating customer communication practices and related compliance procedures.

If you would like to remain updated on these issues, please click here to subscribe to Money Laundering Watch. And please click here to find out about Ballard Spahr’s Anti-Money Laundering Team.

Matthew T. Smith and Kelly A. Lenahan-Pfahlert

Back to Top


LOOKING AHEAD

MBA Compliance and Risk Management Conference

September 27 – 29, 2026 | Grand Hyatt, Washington, D.C.

COMPLIANCE CONVERSATIONS TRACK: RESPA Section 8
September 27, 2026 – 1:00 PM ET
Speaker: Richard J. Andreano, Jr.

TRENDING COMPLIANCE ISSUES TRACK: Innovation in Mortgage Lending – Balancing Affordability, Compliance, and Risk
September 27, 2026 – 2:15 PM ET
Speaker: John D. Socknat

APPLIED COMPLIANCE TRACK: Contact with Care - Navigating Borrower Communications and Consumer Protection Laws
September 29, 2026 – 10:30 AM ET
Speaker: Daniel J.T. McKenna

Back to Top

Subscribe to Ballard Spahr Mailing Lists

Get the latest significant legal alerts, news, webinars, and insights that affect your industry. 
Subscribe

Copyright © 2026 by Ballard Spahr LLP.
www.ballardspahr.com
(No claim to original U.S. government material.)

All rights reserved. No part of this publication may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, including electronic, mechanical, photocopying, recording, or otherwise, without prior written permission of the author and publisher.

This alert is a periodic publication of Ballard Spahr LLP and is intended to notify recipients of new developments in the law. It should not be construed as legal advice or legal opinion on any specific facts or circumstances. The contents are intended for general informational purposes only, and you are urged to consult your own attorney concerning your situation and specific legal questions you have.