Federal AI/ML guidance for mortgage lending remains a patchwork. The CFPB has issued interpretive guidance, the GSEs have published AI governance frameworks, and Congress has considered — but not passed — federal AI legislation. In the absence of a unified federal standard, state regulators have moved ahead with their own rules.
For mortgage lenders operating in multiple states, the practical effect is a growing set of state-specific AI/ML obligations layered on top of federal and GSE requirements. This article walks through the state rules that affect mortgage lenders in 2026, how they interact with each other and with federal frameworks, and what a defensible multi-state AI compliance program looks like.
Why State AI/ML Regulation Matters for Mortgage Lenders
State AI/ML rules were not written with mortgage lending as the primary use case. Most originate in consumer protection, employment, or insurance contexts. But the definitions of “automated decision tool,” “high-risk AI system,” and “consumer” are broad enough to capture mortgage lending activity — and state regulators have signaled that they will apply their AI rules to financial services, not just to the originally-targeted industries.
The compliance exposure is not theoretical. State AGs have been active in 2025 and 2026, with several settlements against financial services firms involving AI/ML use. Mortgage lenders that treat state AI compliance as a low-priority “tech company” issue are misreading the landscape.
Colorado AI Act (SB 24-205)
The Colorado AI Act took effect on February 1, 2026. It is the most comprehensive state AI statute in the United States and the one most likely to set a template for other states.
Who It Applies To
The Act applies to “developers” and “deployers” of “high-risk AI systems” used in Colorado. A deployer is any entity that uses a high-risk AI system to make decisions that affect Colorado residents. Mortgage lenders that use AI/ML systems for Colorado residents — including in origination, servicing, marketing, or customer service — are deployers under the Act.
What Counts as a High-Risk AI System
The Act specifies categories of high-risk systems. The relevant categories for mortgage lenders include:
- AI systems used to make decisions about access to financial services, including credit
- AI systems used for employment decisions (relevant for HR, recruiting, and internal loan officer evaluation)
- AI systems that materially affect access to housing
Automated underwriting systems, AI-driven pricing tools, lead scoring systems that influence credit decisions, and AI-driven appraisal valuation models are all high-risk under the Act.
What Deployers Must Do
Deployers must implement a risk management program and policy, complete an impact assessment for each high-risk system, provide notice to consumers that an AI system is being used, and allow consumers to request human review of an AI-driven decision. The impact assessment must be made available to the Colorado AG on request.
The Act also prohibits algorithmic discrimination — defined in ways that overlap significantly with federal fair lending law but include additional categories of protected activity.
California AI Rules
California does not yet have a comprehensive AI statute, but the state has a layered set of AI-related rules that affect mortgage lenders.
AB 2013 (Generative AI Training Data)
AB 2013 requires developers of generative AI systems to publish a summary of the training data used. The rule is targeted at generative AI providers, not at deployers. For mortgage lenders, the relevance is downstream: if you use a generative AI tool (e.g., for document drafting, customer service), the underlying provider’s compliance affects your vendor risk profile.
SB 942 (AI Transparency)
SB 942 requires AI providers to offer a free AI detection tool to users. The rule is targeted at AI providers, not at deployers. The relevance is the same as AB 2013 — vendor due diligence.
California Department of Financial Protection and Innovation (DFPI)
The California DFPI has been the most active state financial regulator on AI/ML. The DFPI has issued multiple guidance documents on AI use in lending, conducted examinations focused on AI/ML systems, and entered into consent orders with lenders involving AI/ML model risk management and fair lending testing.
The DFPI’s approach is consistent with the federal and GSE frameworks, but it includes California-specific requirements on consumer notification, model documentation, and the right to human review. For lenders operating in California, DFPI expectations are effectively a fourth layer of AI/ML governance on top of CFPB, GSE, and other state rules.
New York State and City
New York has not passed a comprehensive state AI statute, but the New York Department of Financial Services (DFS) has issued guidance on AI/ML use by regulated financial institutions. The DFS guidance is supervisory in nature — not a binding regulation — but it sets the expectation for AI/ML governance programs for insurers and banks under DFS jurisdiction.
For mortgage lenders operating in New York, the DFS guidance effectively requires an AI/ML governance program consistent with the GSE frameworks. Examiners will look for documentation of model risk management, fair lending testing, and consumer protection controls.
New York City Local Law 144 (automated employment decision tools) affects mortgage lenders that use AI in hiring — for loan officer recruiting, underwriting staff screening, or any other employment decision. The law requires an annual bias audit and public posting of the audit results.
Texas: UDAP Authority
Texas has not passed a state AI statute, but the Texas Attorney General and state financial regulators have used existing Unfair, Deceptive, or Abusive Acts or Practices (UDAP) authority to bring AI/ML-related actions. The state has been particularly active on AI-driven decisions that result in disparate impact on protected classes — using UDAP rather than a separate AI statute.
For Texas-licensed mortgage lenders, the practical implication is that AI/ML use is regulated — even without a specific AI statute. The compliance program that satisfies the Texas SML for the SSSF, the GSE AI/ML frameworks, and the federal fair lending rules is the foundation for UDAP defensibility.
Other State Activity
State AI/ML activity is moving fast. The states that have either passed AI rules or have active rulemaking in 2026 include Illinois, New Jersey, Virginia, Washington, and Oregon. The rules vary in scope and approach, but the direction is consistent: more state regulation, with mortgage lending in scope.
A practical approach for mortgage lenders operating nationally: design the AI/ML governance program to the strictest applicable state requirement, and apply it uniformly. The marginal cost of running a single, conservative program is much lower than the cost of running multiple state-specific programs.
How State AI Rules Interact with Federal and GSE Frameworks
A consolidated view of the AI/ML compliance landscape for mortgage lenders in 2026:
- CFPB: interpretive guidance, focus on adverse action notices, fair lending, and accuracy of AI-driven decisions. Exam focus in 2026.
- Fannie Mae LL-2026-04: AI/ML governance framework, effective August 6, 2026. Six governance obligations, annual attestation.
- Freddie Mac Section 1302.8: companion AI/ML governance framework, effective March 3, 2026. Substantively similar to LL-2026-04.
- Colorado AI Act: high-risk AI system requirements, impact assessments, consumer notice, right to human review. Effective February 1, 2026.
- California DFPI: AI/ML supervisory guidance, focused on documentation, fair lending testing, and consumer protection.
- New York DFS: supervisory guidance, treated as effective standard for New York-licensed institutions.
- State AGs: UDAP authority, used to bring AI/ML-related actions in states without specific AI statutes.
These frameworks are additive. A lender that satisfies Fannie Mae LL-2026-04 still has separate Colorado, California, and New York obligations. The Colorado impact assessment is not a substitute for the LL-2026-04 attestation.
Building a Multi-State AI/ML Compliance Program
A defensible program has five components.
1. Unified AI/ML Use Case Inventory
Maintain a single inventory that flags which systems are in scope under which state rules. The inventory is the foundation — without it, you cannot determine your compliance obligations.
2. State-Overlay Documentation
For each state with AI/ML rules, maintain an overlay document that maps the state requirements to your existing governance program. The overlay identifies the gaps and the remediation work.
3. Consumer Notice and Human Review Workflows
Colorado and other state rules require consumer notice of AI use and a right to human review. The workflows should be designed to comply with the strictest applicable state requirement.
4. Impact Assessment Library
Maintain an impact assessment for each high-risk AI system, updated annually or after material model changes. The assessment is a state regulatory document, not a federal one — different states may require different formats.
5. Multi-State Vendor Oversight
Your vendor oversight program must cover state-specific requirements. A vendor providing AI/ML services in Colorado has different disclosure obligations than a vendor providing the same services in Texas.
Frequently Asked Questions
Does the Colorado AI Act Apply If We Don’t Have a Physical Office in Colorado?
Yes. The Act applies to any deployer that uses a high-risk AI system to make decisions affecting Colorado residents. If you originate or service a mortgage for a Colorado resident and use an AI/ML system in connection with that loan, the Act applies.
How Do State AI Rules Interact with Fair Lending Law?
State AI rules typically add anti-discrimination requirements that overlap with federal fair lending law but are not identical. A fair lending test that satisfies the CFPB may not satisfy the Colorado AI Act. The conservative approach is to test to the strictest applicable standard.
What If a Vendor Provides Our AI/ML System? Are We Still Liable?
Yes. Under the Colorado AI Act, the GSE frameworks, and most state-level approaches, the lender is the deployer and remains accountable for the system’s compliance. Vendor contracts can shift some financial risk, but not regulatory risk.
What Records Must We Retain?
Three years for most state requirements, but some state rules require longer retention for impact assessments. Document the retention requirement for each state in scope and apply the longest applicable period uniformly.
Need help designing or auditing your multi-state AI/ML compliance program? Synergy supports mortgage lenders with state overlay documentation, impact assessment design, and multi-state governance program reviews. Book a 30-minute program review.


