The Lady Doth Clarify Too Much: Parsing the CFPB’s ECOA Final Rule
So that’s what the law really meant, all along! Thank you, CFPB, for finally clearing up that little misunderstanding. Or…on second thought…is this actually less a clarification than a strategic narrowing? Because, rhetoric aside, the harder truth running underneath this final rule might not really be that the law has suddenly become clearer, but that proving harm may now become considerably more difficult.
Indeed, this final rule is both a major fair-lending pivot and the end of a key anti-discrimination protection. Because the law will now seemingly focus more heavily on proving intent (rather than examining discriminatory outcomes from facially neutral policies), the burden of proving discrimination gets materially heavier; this, at a time when lending systems as a whole are becoming more complex and automated.
That is to say, there may be a real concern that removing disparate-impact liability under ECOA could leave algorithms and AI-driven systems, which are already ubiquitous, with fewer legal checks, because those systems can produce discriminatory results without leaving behind the sort of incriminating paper trail that makes intent easy to prove. Opponents could argue that this is precisely the kind of modern credit discrimination risk that outcomes-based analysis was built to catch because neutral-looking systems, data inputs, or underwriting frameworks could wind up producing systematically unequal results, whether intentional or not.
Those same concerns send their tendrils into the discouragement rewrite, too, where the final rule narrows a provision that many viewed as useful in redlining-type cases and other pre-application exclusion scenarios. Viewed in this light, the discouragement revisions may be particularly notable, specifically because they scale back a framework that had previously been used to catch exclusion before it learned to clean up after itself. Keep in mind that these are rules that matter most before a credit file even exists – so, once a consumer has self-selected out, never applied, or never saw the opportunity in the first place, the evidence trail is thinner and the harm is harder to measure. The burden begins to look a lot like proving a negative – and for anyone in the field of compliance, you know that is never a comfortable position.
Now, proponents might argue that the “old” Regulation B had become too broad and too willing to treat targeted outreach, branch decisions, and advertising choices as potentially discouraging. But take the usual closer look and the picture may change. There’s also the fact that the final rule might openly conflict with state laws that require disparate-impact analysis – and as a result, could leave banks caught between the two. There’s a fairly straightforward argument that even if the CFPB views this as a simplification, the likely real-world result may be a patchwork, with lighter federal standards in some respects, and continued state exposure in others, resulting in an overall compliance environment where banks may be tempted to relax too much at the federal level (while still facing state-law, FHA, or even litigation risk). I wouldn’t chalk that up as a bank win for “simplification” or “clarity” just yet.
So no, if you’ve gotten his far (and thank you for reading!) you likely can tell that if there’s an issue, it isn’t just that “the CFPB changed a rule.”
The Final Rule, which is effective July 21st, 2026, can be found here: [91 FR 21620]

Brett Goodnack, JD, CAMS
Compliance Advisor
You Don’t Know What You Got ‘Till It’s Gone (..And Your Customers Might Not Either)
FDIC Rescinds Guidance on Multiple Re-Presentment NSF Fees
There has been a clear pattern lately of regulatory pullbacks that banks may be tempted to welcome as a return of discretion, flexibility – heck, maybe even “freedom.” Less guidance, less second-guessing, less pressure on practices that had come under increasing scrutiny. But there is, of course, an important distinction to make – flexibility and certainty aren’t the same thing. When an agency rescinds a meaningful consumer-protection position without replacing it with a clear framework, banks might not actually get a safer runway – in fact, they arguably get a murkier one. And in an area like repeated NSF fees, where the unfairness and deception concerns never really went away (rather, in a sense, they’re just constantly being reframed and passed around like a game of hot potato), that should be less reassuring than it may first appear, especially given how easily the regulatory pendulum could swing back and recast the same conduct as unfair all along.
Which brings us to the latest example.
The FDIC has now done exactly what many expected from this leadership team, and has rescinded FIL-32-2023, the agency’s 2023 guidance on multiple re-presentment NSF fees, effective immediately. In the rescission, the agency says the prior guidance was “overly broad in scope” and created uncertainty about when disclosures regarding re-presentments might still give rise to “unfairness” concerns under Section 5 of the FTC Act. In its place, the FDIC offers a far thinner admonition – institutions should make sure their disclosures accurately reflect their practices and comply with current law (essentially, the regulatory equivalent of removing the highway guardrails and then posting a sign that says “Drive Safely”).
Again, banks (and industry advocates) can’t be blamed for seeing this as a positive, tidy deregulatory move. One less piece of guidance to worry about, less supervisory friction, more room to lean on disclosure, and less danger that a clearly described practice will still be second-guessed as unfair. It also speaks to a longstanding objection – that banks may be the ones charging the fee, but they are not necessarily the ones deciding whether and when a declined payment is run through again (fair being fair, that is often up to the merchant or payee, which we’ll touch in in just a moment).
But there’s also simply no denying that this is a retreat. The underlying practice here is not hard to understand – a consumer attempts a payment, the bank declines it for insufficient funds, the merchant or payee submits the same item again, and the consumer may be charged another NSF fee on the same failed transaction. The FDIC’s earlier guidance had warned that this practice presented heightened risk under Section 5, including not only deception concerns tied to disclosures, but also potential unfairness concerns, even where disclosures existed. The agency has now stepped back from that position – not because repeated fee stacking has been shown to be harmless, but because the FDIC has decided the guidance itself went “too far.”
Starting to see the problem? A major issue with multiple re-presentment NSF fees was never just that banks might describe them poorly. It was that consumers often have very little practical control over whether the same item gets run again and, with it, whether another fee gets triggered. The Federal Reserve’s Consumer Compliance Outlook laid that logic out plainly in 2023: once a bank declines the transaction, the merchant controls the number and timing of representment – but the bank still decides whether to pay or decline the represented transaction, and whether to assess another NSF fee on it. Merchant control doesn’t make the problem go away; in fact, you could argue that it helps explain why consumers often cannot reasonably avoid the harm, while the bank still retains control over whether to convert that re-presentment into yet another charge. What’s worse is that the problem doesn’t disappear merely because an agency decides the old guidance was too broad.
That might be what makes the rescission feel so conspicuously one-directional. Here, the FDIC isn’t withdrawing a stale procedural memo or cleaning up some obscure, obsolete footnote. It is backing away from guidance aimed at a fee practice that had drawn sustained criticism precisely because of the way it can stack charges onto the same failed transaction. And it is doing so without replacing that guidance with anything remotely comparable. Instead, what remains is little more than a generic, broad reminder.
State regulators, meanwhile, are hardly all moving in the same direction. In January 2025, New York’s Governor and the Department of Financial Services announced proposed regulations aimed at what they described as exploitative overdraft and NSF practices. Among the proposed restrictions was a prohibition on charging multiple NSF or overdraft fees for the same transaction, including when a merchant resubmits a declined item. Now, this author isn’t naïve enough to think that New York speaks for every state – but NY’s premise here was fairly universal, and that premise wasn’t that the problem could be solved by polishing disclosures. It was that repeat-fee structures like these can themselves be abusive and harmful, particularly to vulnerable consumers… and that banks were expected to respond not just with clearer words, but with actual limits on fee practices and more timely notice to consumers.
So, yes – right now, the FDIC is framing this as a course correction against supervisory overbreadth and uncertainty. You could argue that this is also something else: a conscious decision to stop pressing on a fee practice that had already been widely criticized as problematic precisely because disclosure alone may not cure the harm. After all, when the same failed transaction can generate fee after fee after fee, the question is not merely whether the account agreement was artfully drafted. It is whether the system is designed to keep charging for the same miss until the miss becomes profitable.
Many will treat this as a “pro-bank move,” and a deregulatory sigh of relief. But I’ll caution again – like so many similar federal actions of late, those same folks may want to be careful not to mistake the removal of guidance for the removal of risk. Multiple re-presentment NSF fees still live squarely in UDAAP territory, because the core criticisms of the practice have not changed: the harm can be substantial, the consumer often cannot reasonably avoid it, and disclosure alone may not solve either problem. What has changed is that the FDIC has chosen to step back without putting anything meaningful in its place, leaving institutions with more discretion, less certainty, and a cloudier supervisory line to navigate on their own. And when the regulatory pendulum swings back — as it always does — “flexibility” might look a lot like “ambiguity deferred.”

Brett Goodnack, JD, CAMS
Compliance Advisor
Something Happening Here…What It Is Ain’t Exactly Clear: FinCEN’s 2026 Proposed Rule on AML / CFT Programs
Well, we can’t exactly say they didn’t warn us. When FinCEN issued its exceptive relief order earlier this year, it described the move as advancing a “more efficient, risk-based approach” while reducing “unnecessary regulatory burden,” and it expressly noted that it “anticipated pursuing further changes […] through the rulemaking process.” That language now looks even less like just a narrowly-applied exemption, and a whole lot more like table-setting for a broader rewrite of how AML / CFT programs are designed, implemented, and supervised.
And, indeed, with FinCEN’s newly released 202-page AML / CFT program proposal (now in the Federal Register at 91 FR 19704), the agency may be trying to escape “check-the-box” compliance – but it may also be slipping into something softer, vaguer, and harder to pin down.
A minor caveat: the following is a “first-impressions” (non-exhaustive) take on the proposal, only because the document itself is sprawling and the changes it proposes are significant; its central ambitions (and ambiguities) arrive well before page 200.
On initial read, and taken in its best light, FinCEN’s new AML / CFT program NPRM looks like a serious attempt to solve a problem that has been collectively shared by banks everywhere: too much AML supervision has drifted into process policing, mountains of documentation, and examiner second-guessing that often seem only loosely connected to actually stopping crime. On that much, the proposal talks the talk, and says a lot of the right things. That is, it talks about effectiveness, risk-based allocation of resources, useful information for law enforcement, innovation, and moving attention away from low-risk busywork and toward higher-risk activity. All of that, you could argue, is sensible. All of that, you could also argue, is long overdue.
And there’s the rub – because in doing so, this proposal may very well have corrected one problem by creating another.
If the 2024 version was vulnerable to criticism for being too prescriptive, too formalized, and too likely to become another compliance “ritual,” this new version may be vulnerable for almost the exact opposite reason. To be sure, it is full of standards that sound modern and flexible, but they aren’t especially precise. “Effective.” “Reasonably designed.” “In all material respects.” “Significant or systemic failure.” “Promptly.” “As appropriate.” Of course, those are not meaningless phrases, but neither are they self-explanatory, or rooted in statutory definition. And FinCEN concedes as much, because the NPRM repeatedly asks whether commenters think these concepts need more clarification. But when a proposal has to ask the public to help define some of its most important terms, that is at least an early sign that the rule may not yet be as clear as its authors think.
And, when paired with the proposal’s arguably most consequential shift for banks, the trouble doubles – for once a bank has “properly established” an AML / CFT program, major supervisory or enforcement action based on the program rule would generally be reserved for “significant or systemic” failures to implement the program, rather than isolated, technical, or immaterial deficiencies. Now, on one level, that sounds appealing enough, especially as a response to no doubt countless complaints about nitpicking and process for process’s sake. On another, it raises an obvious question: what counts as merely technical, and what counts as the beginning of something systemic? AML programs rarely collapse in one dramatic, catastrophic moment. More often, like so many other regulatory violations, they erode by accumulation – weak escalation here, thin staffing there, poor controls, unresolved issues – essentially, known gaps that enough people see, but don’t do anything about. Indeed, that is exactly the sort of “slow-burn” failure FinCEN itself has repeatedly described in its most significant recent enforcement actions. A framework designed to reduce “pointless” process criticism almost will inevitably make it harder to intervene before those weaknesses become undeniable. Rarely is a process “just for process’s sake.” More often, the process is the point.
You can see a similar “tension” in the proposal’s treatment of risk assessments. The 2024 NPRM would have centered a more formalized risk assessment process and expressly required consideration of business risks, AML / CFT Priorities, and BSA reports. This new version backs away from that structure. It speaks instead of “risk assessment processes,” allows institutions to rely on one or more processes, and drops the explicit requirement that BSA reports be a required input. Sure, you could argue that that may be more realistic for how most banks actually operate. But there’s almost no denying that it likely also means fewer objective anchors. The proposal still requires institutions to evaluate products, services, distribution channels, customers, and geographies, and to review and, as appropriate, incorporate the AML / CFT Priorities. But the overall direction is unmistakable, less formal architecture, more discretion – and discretion without clear, objective standards can quickly become a source of inconsistency and supervisory risk.
That same kind of “looseness” shows up in the proposal’s repeated invocation of “outcomes.” The NPRM speaks in terms of “better outcomes,” “highly useful information,” “demonstrable outputs,” and “advancing the AML / CFT priorities.” Again, those are all attractive ideas, and sound like they came from the lips of Dudley Do-Right himself. But they are not self-defining, and perhaps more importantly, these are not all just interchangeable ways of saying “outcomes.” That is to say – a bank can control the quality of its monitoring, escalation, due diligence, staffing, and reporting. What it cannot control is whether law enforcement uses a SAR effectively, whether prosecutors pursue a case, or whether a filing turns out to be tactically or strategically valuable months later. So, if the proposal wants to move toward an “outcomes” model, it still has not fully drawn the line between what a private institution can actually influence and what it cannot. Things can get very muddy, very quickly – because a standard that blurs outputs, outcomes, and aspirations risks becoming more subjective, not less.
Next, in handling the AML / CFT Priorities (oh, those pesky Priorities…), the proposal outlines that institutions would be required to review and, as appropriate, incorporate them into their risk assessment processes. The NPRM also acknowledges that some priorities are broad, high-level, and tied to a particular moment in time, and that institutions may lack enough context to know what threats or timeframes to emphasize. That admission likely shouldn’t be ignored. The priorities may be important as policy signals, but they aren’t really a full operating blueprint yet. Requiring institutions to incorporate them while also conceding that they may be too broad or too stale to operationalize cleanly isn’t quite the same thing as solving the priorities problem altogether.
There are also “smaller” signals in the proposal (with perhaps just as big of an impact) that point in the same direction. For example, the AML / CFT officer language now refers to “an individual,” not “an individual or individuals,” and makes that person responsible for “establishing and implementing” the program and coordinating day-to-day compliance (this individual must also live in the U.S., for what it’s worth). FinCEN describes that as making a longstanding expectation explicit. That may be so, but it also compresses institution-wide responsibility into language that sounds cleaner than reality could possibly allow. No “one person” “implements” an AML program alone. The board may still ultimately bear responsibility if something goes wrong, but one could argue that wording like this could risk creating a convenient “straw man” – a single officer made to carry the appearance of responsibility for failures that are, in truth, institutional.
This is obviously a major proposal, one that plainly takes a different path than the 2024 NPRM. But different is not the same thing as resolved (or even “better”). If the argument was that the earlier draft risked turning AML modernization into more process, then the clear retort is that this one risks turning it into more discretion. That may be the more attractive approach, but it is not necessarily the safer one. Because discretion without sufficiently objective boundaries can become just as problematic as formalism without judgment.
I’ll caveat again: these are only first takes, of course – but this proposal looks likely to give us quite a bit more to write about in the weeks and months ahead.
Comments on the NPRM are due by June 9, 2026. The NPRM can be found here: [91 FR 19704], and for posterity’s sake, you can find the 2024 NPRM here: [89 FR 55428].

Brett Goodnack, JD, CAMS
Compliance Advisor
There’s No “I” in Team (But There’s a Big One in “Interagency”): GAO Highlights Coordination and Data Failures in Federal Anti-Scam Efforts
“None of us is as smart as all of us.” – Ken Blanchard
The United States Government Accountability Office’s (GAO) recent testimony before the Joint Economic Committee may not have said it quite so elegantly, but it arrived at a fairly similar conclusion – the federal government is still trying to fight scams like a loose association of agencies rather than like a unified government.
The study, bluntly titled “Government-wide Strategy Expeditiously Needed to Counter Scams,” outlines that scams are proliferating, increasingly sophisticated, and often devastating to victims, with some consumers losing tens of thousands of dollars – or, in the worst cases, their entire life savings. It also stresses that – as many of us in the community banking world are becoming increasingly aware – these are not quaint one-off cons run out of a basement anymore. These scams are often tied to organized criminal networks operating both domestically and abroad, and they move money through the usual modern channels (e.g., P2P apps, gift cards, wire transfers, cryptocurrency, and electronic payments through bank accounts) where interdiction (i.e., the ability for the bank to “get in there and stop it”) is virtually impossible. The visuals in the report make that point especially clear, with charts laying out the basic scam pipeline, from contact, to deception, to payment, to laundering – as well as giving the now-familiar lineup of scam types – impersonation, tech support, grandparent, romance, investment, business email compromise, and lottery / inheritance scams.
As the report title suggests, GAO’s central criticism is coordination – or, more precisely, the lack of it. At least 13 federal agencies (including all of our favorite regulators – FDIC, OCC, FRB, and even CFPB and FinCEN) are involved in some aspect of scam prevention, detection, education, investigation, or response, but they are still largely operating within their own lanes and authorities. Nearly a year ago, GAO proposed a government-wide anti-scam strategy, recommended that the FBI lead the effort, and urged CFPB and FTC (and “other agencies”) to work alongside it on a common definition of scams, as well as “consumer complaint reporting; related types/granularity/aggregation of data, risks, and responses; a government-wide estimate of this type of crime; and coordination of federal and business activities.”
Yet in its latest update to Congress, GAO makes clear that little of that (in fact, very little of that) has actually materialized. The FBI and FTC have raised concerns about the recommendations, citing differing authorities and mandates, while CFPB has essentially said it will “wait and see” what the others do before deciding whether to act at all. So, it could be argued that the core problem is the same as before – lots of agencies, lots of activity, lots of overlap, but still no unified federal playbook. GAO therefore reiterates its earlier recommendation that the FBI lead a coordinated federal effort, and while the FBI has now sketched out some preliminary steps – a multi-agency working group, possible legislative and regulatory changes, collaboration with private-sector and consumer groups, and requests for added funding, tools, staffing, and analytic capacity – GAO’s message is, effectively: “yeah, okay – but ya really should have done something by now.”
The second major theme is (complaint) data – and here the report seems equally unimpressed. CFPB, FBI, and FTC all collect scam-related complaint information, and several agencies publish reports, but the testimony says that data is too fragmented and inconsistent to produce anything like a single, government-wide estimate of scam volume and losses. The FBI’s IC3 system, for example, does not use predefined scam fields and instead relies heavily on narrative descriptions, which makes clean aggregation difficult. CFPB can estimate some scam complaints involving P2P platforms, but not associated losses because it doesn’t require consumers to include dollar-loss information. FTC has broader fraud-loss estimates, but not a scam-specific, government-wide total. Underreporting only makes matters worse, as the DOJ has estimated that only a small share of fraud victims report to law enforcement, and FTC-cited research suggests only a tiny fraction of mass-market consumer fraud victims complain to a BBB or government agency.
That is seemingly why GAO keeps returning to the need for a common definition of scams. The testimony points to the Federal Reserve’s work group definition – “the use of deception or manipulation intended to achieve financial gain” – as at least a plausible baseline, while acknowledging that it has not been adopted government-wide. In a true “apples and oranges” type-scenario, GAO’s view is that without a common definition, agencies cannot reliably compare data, aggregate results, measure trends, or build a coherent national strategy. Said differently, if agencies aren’t even counting the same thing, it would be difficult to ultimately claim that they are jointly solving the same problem.
GAO therefore reiterates four core recommendations for CFPB, FBI, and FTC:
“1. explore ways to harmonize data collection to better identify scams,
2. use the agency’s data collection and analysis to produce and report an estimate of the number of complaints it receives and the associated financial losses resulting from scams,
3. collaborate, develop, and report on a single, government-wide estimate of the number of consumers affected by, and a dollar losses resulting from, scams, factoring in an estimate of incidents not reported and
4. develop a government-wide definition of scams.”
The FBI agreed with the first two but not as much with the government-wide estimate and common-definition pieces as framed; FTC raised its own concerns about adopting the Federal Reserve’s definition and leaned on the practical difficulty of harmonization; CFPB, true to form, initially “did not provide comments,” but then, as mentioned earlier, largely said it would watch what the others do before deciding on further action.
It’s worth noting that GAO isn’t asking for “more enforcement” in the abstract, or some other lofty, ethereal goal. It is asking for something more basic – a federal government that can define the problem consistently, count it coherently, assign agency roles clearly, identify needed resources honestly, and then act like all of those pieces belong to the same strategy. That omission might be all the more striking given how publicly (and at times relentlessly) federal agencies have spent the last several years talking about fraud, scams, and consumer harm. The testimony even points to Australia’s National Anti-Scam Centre as an example of a centralized, coordinated model that reportedly helped reduce scam losses. Or, in other words, other governments have apparently put a center of gravity around this issue; the United States, at least according to GAO, is still mostly passing the file around.
We all know that scams are growing, scam tactics are evolving with technology, the victim counts and loss figures are still incomplete – and the federal response remains fragmented. GAO is essentially telling Congress that the current model – multiple agencies, partial coordination, inconsistent data, no common definition, and no government-wide strategy – is not good enough for a threat environment this large and this adaptive. Or, put a little more plainly – if Washington wants to say it is “fighting scams,” it may first need to agree on what a scam is, how many there are, and who is actually in charge of doing something about them. It doesn’t exactly sound like rocket science – but then again, none of us is as smart as all of us.
Written by:

Brett Goodnack, JD, CAMS
Compliance Advisor
White House Unveils National Policy Framework for Artificial Intelligence
“History doesn’t repeat itself, but it often rhymes.” And whether Mark Twain actually said this or not, the sentiment seems to fit the White House’s new AI Policy Framework rather aptly. For not only does the document resemble the Administration’s recent habit of issuing broad, directional policy blueprints (instead of, say, effective concrete changes), it also reads like the latest attempt to clear the field for AI with as little AI-specific regulation as possible – this time by leaning heavily on federal preemption.
In that regard, this document serves as another reflection of what this Administration wants Congress to prioritize (and, just as importantly, what it wants Congress not to do), and moves across seven broad areas of focus: protecting children and empowering parents; supporting communities through AI infrastructure, fraud prevention, and energy policy; respecting intellectual property without legislatively pre-judging the fair-use fight; preventing censorship and protecting speech; enabling innovation through sandboxes, datasets, and existing agencies rather than a new AI regulator; developing an AI-ready workforce; and, finally, building a federal framework that prevents a fragmented patchwork of state AI laws. So, before we even dive into the heat of the meat, it shouldn’t be understated that this “framework” is trying to marry child safety, anti-fraud enforcement, infrastructure buildout, copyright caution, speech protection, and industrial policy into a wish list – all of 4 pages long.
Looking at this section by section (because, why not – it’s 4 pages long), on children and families, the framework pushes Congress to require AI platforms likely to be accessed by minors to adopt “commercially reasonable” and privacy-protective age assurance, parental controls, and features aimed at reducing sexual exploitation and self-harm, while also building on the First Lady’s Take It Down Act (the backronym-titled law formally known as “The Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks,” which criminalizes the online publication of intimate images and deepfakes) and preserving state child-protection laws of “general applicability” (more on that later).
On infrastructure, it wants Congress to protect residential ratepayers from seeing electricity costs rise because of AI data centers, while simultaneously streamlining permitting so AI infrastructure can be built more quickly and, where possible, supported with on-site or behind-the-meter power. It also urges more law-enforcement support for AI-enabled impersonation scams (particularly those that target “vulnerable populations such as seniors”), more technical capacity within the national-security apparatus to understand frontier model risks, and grants, tax incentives, and technical assistance to help small businesses deploy AI tools.
The copyright and speech sections appear to tell a similar tale. The Administration says it believes training AI models on copyrighted material “does not violate copyright laws,” but also says Congress should let the courts sort that fight out rather than legislating around it now. At the same time, it leaves room for collective licensing or compensation frameworks and supports federal protections against unauthorized AI-generated digital replicas of a person’s voice or likeness, while insisting on First Amendment carveouts for parody, satire, news reporting, and similar expressive works. On speech more broadly, the framework says Congress should stop the federal government from coercing AI providers to alter or suppress content based on partisan or ideological agendas, and should create redress mechanisms for Americans who believe federal agencies pressured AI platforms to censor lawful expression.
The innovation section is essentially a plea to keep the runway clear – use regulatory sandboxes, open up federal datasets, and do not create a new federal AI super-regulator when existing agencies and industry standards can do the job. In that same vein, the workforce section outlines that rather than pairing AI growth with new employer obligations or worker-protection mandates, the framework prefers training, apprenticeships, youth development, technical assistance, and more federal study of how AI is reshaping work at the task level.
Look at everything to this point, and the picture becomes fairly clear – the administration is striving for light-touch federal oversight, strong anti-censorship rhetoric, no new AI super-regulator, and maximum room for domestic buildout and deployment.
But if the framework has a real center of gravity, it is preemption. The White House says Congress should establish a federal AI policy framework that avoids “a fragmented patchwork” of state regulation and should “preempt state AI laws that impose undue burdens” in favor of a “minimally burdensome national standard,” while still preserving some state powers – traditional police powers to enforce generally applicable laws, zoning authority, and rules governing a state’s own use of AI in procurement, education, or law enforcement. It then goes further, saying states “should not be permitted to regulate AI development itself,” should not unduly burden lawful AI use, and should not penalize developers for a third party’s unlawful use of their models. Consider this where the rubber truly hits the road.
As alluded to earlier, this “Policy Framework” also happens to look like the latest effort to keep the AI field as lightly regulated as possible, this time by way of federal preemption. Notably, earlier versions urged policymakers to build AI policy on “existing laws, rules, regulations and guidance,” and later said that “[e]xisting laws cover many risks associated with the use of AI.” The Computer & Communications Industry Association likewise emphasized that AI systems should operate within “existing” legal frameworks.
States, however, appear to have disagreed rather emphatically – to wit; as of March 2026, state lawmakers in 45 states have already introduced over 1,500 AI-related bills, a strong reflection of the judgment that existing law is not enough. It’s only logical, then, that the “next move” would be preemption and an attempt to block AI-specific state laws and preserve only “generally applicable” ones. This framework, in calling for a “minimally burdensome national standard,” rejecting a new federal AI rulemaking body, and favoring existing regulators and broad displacement of state AI-specific laws, still rests on much the same premise as the first: that AI can be governed on essentially the same terms as other digital technologies, even where its risks differ in kind, scale, and speed.
“Undue burden” is a phrase you’ll find in the Dormant Commerce Clause doctrine – however, that phrase’s use here lacks the balancing structure that normally gives that concept meaning (essentially, if the local benefit is real and the effect on interstate commerce is only incidental, the law usually survives unless the burden on interstate commerce is too great); “generally applicable,” meanwhile, sounds neat enough on paper, but may prove to be a litigation magnet because courts will necessarily have to give it meaning, and parties will inevitably fight over whether a law applying traditional legal norms to AI is truly “general” or instead singles out AI systems specifically (and, in turn, is therefore preempted).
Under the White House’s approach, states could possibly be blocked from regulating AI development or imposing AI-targeted safety obligations, even as the federal government declines to impose much in the way of substantive nationwide safeguards of its own. While the document starts out strong and provides relatively robust detail on child safety, it says decidedly less about several other consequential AI risks – including algorithmic discrimination, and particularly in lending, housing, employment, insurance, and healthcare, where AI tools increasingly drive or influence consequential decisions. In the banking world, these systems can affect underwriting, pricing, fraud detection, and other risk-based decision triggers that carry obvious fair-lending implications. More broadly, they can shape whether someone gets a loan, an apartment, insurance, medical care, or a job.
History might not repeat itself, but this certainly sounds like one of its more familiar rhymes. The full framework can be found here: [National Policy Framework Artificial Intelligence]
Written by:

Brett Goodnack, JD, CAMS
Compliance Advisor