United States — Federal
CFPB and AI-Driven Credit Decisions: What Adverse Action Notices Require
When an AI model denies credit, the CFPB expects a specific, non-generic reason under ECOA and Regulation B — not a black-box shrug.
A machine-learning underwriting model returns a single word: decline. Nobody on staff can point to a line of code and say why — the model weighed hundreds of variables against each other in ways no loan officer will ever see. ECOA doesn't care. The Equal Credit Opportunity Act has required a specific, accurate reason for every credit denial since 1974, and that requirement doesn't have a carve-out for "the model is too complex to explain." If your compliance program is treating explainability as a nice-to-have for your underwriting model rather than a hard legal floor, you're one denied applicant away from finding out otherwise.
The CFPB spent 2022 and 2023 saying exactly that, in writing, in two separate circulars aimed squarely at AI-driven and algorithmic credit decisions. Both were withdrawn in 2025 — which has left more than one lending compliance team wondering whether the underlying obligation went with them. It didn't, and understanding why requires separating the statute from the agency's explanation of the statute.
What ECOA and Regulation B actually require
The requirement itself is old and specific. Under 15 U.S.C. § 1691(d), every applicant against whom a creditor takes adverse action — a denial, a reduced credit line, a less favorable rate — is entitled to a statement of reasons for that action. Regulation B, the implementing rule at 12 CFR § 1002.9, spells out what "statement of reasons" actually means: the reasons must be specific and must indicate the principal reason(s) for the adverse action, not a vague category.
Two limits matter in practice. First, the reasons disclosed have to relate to and accurately describe the factors the creditor actually considered or scored — not a generic catch-all. Regulation B's own commentary rules out boilerplate like "failed to meet our internal standards" or "did not achieve a qualifying score on our credit scoring system" as insufficient on their own; those tell an applicant nothing about what to fix. Second, more isn't automatically better — disclosing more than about four reasons typically isn't considered helpful to the applicant, so a notice is supposed to name the real drivers, not bury them in a long list. None of this is new law written for AI. It predates every machine-learning underwriting model in production today by decades, and it applies to a human loan officer's decision exactly as much as it applies to a model's.
Two circulars, one consistent message: "the model decided" isn't a reason
The CFPB didn't have to write new law to reach AI-driven lending — it applied Regulation B directly, in two circulars three years apart, each closing a specific loophole a lender might otherwise have tried.
Circular 2022-03, released May 26, 2022 and published in the Federal Register on June 14, 2022 (87 Fed. Reg. 35864), addressed the "black box" excuse head-on: does ECOA still require specific reasons when a creditor's model is so complex — sometimes literally uninterpretable even to the people who built it — that identifying the exact reason for a denial is genuinely difficult? The CFPB's answer was an unambiguous yes. Complex algorithms, including AI and machine-learning models, don't get an exception from the specific-reasons requirement, and a creditor's own lack of understanding of its model isn't a defense to noncompliance. If a lender can't explain what its model actually weighed, that's a problem with how the lender deployed the model — not a legal escape hatch from Regulation B.
Circular 2023-03, released September 19, 2023 and published in the Federal Register on April 17, 2024 (89 Fed. Reg. 27,361), closed a narrower but more common gap: creditors reaching for the checklist of sample reasons in Regulation B's own official sample forms (Appendix C) and treating a checked box as automatic compliance, even when none of the boilerplate options actually matches what the model considered. The CFPB gave a concrete example worth quoting directly, because it's the clearest illustration of the whole problem: if a complex algorithm results in a denial because of an applicant's chosen profession, disclosing "insufficient income" or "income insufficient for amount of credit requested" from the sample-form checklist likely does not satisfy ECOA — because income isn't what actually drove the decision. The sample forms are a starting template, not a shield; a reason has to be true to the model's own logic, not just plausible-sounding.
Ashgrove Credit Union: when a vendor's score isn't a reason
Picture Ashgrove Credit Union, a 40,000-member institution that licenses a third-party machine-learning underwriting model for consumer auto loans. The vendor's dashboard returns a single output per application: an overall risk score and a decline or approve flag. When Ashgrove denies an application, its loan-origination system auto-populates the adverse action notice with the vendor's generic default reason: "Overall credit risk score below approval threshold."
That single line fails Regulation B on both of the limits described above. It doesn't identify a principal reason — a risk score is an output, not a reason, the same way "failed to achieve a qualifying score" was already ruled insufficient in Regulation B's own commentary decades before this vendor's model existed. And it doesn't relate to the specific factors the model actually weighed for this applicant, whatever those turn out to be — utilization on revolving accounts, recent delinquency, length of file, or something else entirely. Ashgrove's compliance exposure here doesn't come from using a vendor model; it comes from accepting an output that can't be translated into the applicant-specific reasons Regulation B requires. Under Circular 2022-03's own logic, "the vendor's model is proprietary and we can't see inside it" is not a defense — Ashgrove is the creditor of record, and the notice obligation runs to Ashgrove regardless of who built the scoring engine. The fix isn't switching vendors; it's requiring, contractually, that the model surface its top-weighted adverse factors per decision, not just a score, before Ashgrove ever puts it into production.
The guidance was withdrawn in 2025 — Regulation B wasn't
On May 12, 2025, the CFPB withdrew 67 guidance documents in a single Federal Register notice, citing Executive Order 13891's directive to agencies to avoid using informal guidance to create de facto regulatory obligations. Both Circular 2022-03 and Circular 2023-03 were named in that withdrawal (the 2023-03 withdrawal specifically published at 90 Fed. Reg. 20,084). Read quickly, that looks like the CFPB reversing its own position on AI-driven adverse action — and that reading is wrong in an important way.
The withdrawal notice itself described the action as not final: the CFPB said the withdrawn guidance would not be enforced during a review period while the agency decided which documents to keep withdrawn permanently, reissue, or restore. That's a materially different posture than repealing a rule. And critically, a circular was never itself binding law — it was the CFPB's own stated interpretation of how Regulation B applies to a specific fact pattern (complex algorithms, sample-form checklists). Withdrawing that interpretation doesn't touch 15 U.S.C. § 1691(d) or 12 CFR § 1002.9, neither of which Congress or the CFPB's own rulemaking process has amended. The specific-reasons requirement is exactly as binding today as it was in 2021, before either circular existed. A lender that reverts to generic reason codes because "the CFPB guidance is gone" is reading a change in the agency's public communications as a change in the statute — and the statute is what a court, or a private plaintiff's lawyer, will actually apply.
What getting this wrong actually costs
ECOA's civil liability provision, 15 U.S.C. § 1691e, doesn't depend on the CFPB bringing an enforcement action at all — it creates a private right of action a denied applicant (or their attorney) can use directly. A creditor found to have violated the specific-reasons requirement is liable for the applicant's actual damages, plus punitive damages up to $10,000 for an individual claim. In a class action, total punitive exposure is capped at the lesser of $500,000 or 1% of the creditor's net worth — a formula that can produce a large number fast for any lender running a single flawed reason-code template across thousands of applications. Courts weigh factors including how intentional the noncompliance was and how frequently it recurred, which means a documented, systemic practice of issuing generic model-output reasons is worse exposure than a one-off drafting error. Separately, the U.S. Attorney General retains authority to bring its own pattern-or-practice action under the same statute, independent of whatever priority the CFPB itself currently assigns to AI-related fair lending. None of that exposure runs through the CFPB's own guidance page at all — it runs through the statute, which is why the 2025 withdrawal changes less than it appears to.
Building a reason code that actually survives scrutiny
Before any ML underwriting or pricing model goes into production, confirm it can produce an applicant-specific, top-weighted adverse factor per decision — not just a score or a pass/fail flag — and build the adverse-action notice template around that output, not around a generic default. If the model comes from a vendor, get its explainability and testing methodology in writing before signing, the same way the NIST AI RMF's Govern function recommends documenting any high-stakes model's development and validation trail; a lender that can produce dated evidence of how its reason codes map to actual model factors is in a fundamentally stronger position than one that can't, whether or not the CFPB is actively enforcing this at a given moment.
Treat the 2025 guidance withdrawal as a change in what the CFPB is currently publishing, not a change in what ECOA requires — the same distinction that applies to the EEOC's own withdrawn AI hiring guidance, where Title VII and the ADA stayed in force after the agency's technical-assistance pages came down. And the underlying logic here — that a federal agency doesn't need new AI-specific legislation to apply an old statute to a new kind of decision-making tool — is the same one running through the FTC's approach to AI marketing claims under Section 5 and the SEC's "AI-washing" cases against advisers who overstated their models' capabilities. For the fuller landscape of how federal law reaches AI without a dedicated federal AI statute, see our overview of US federal AI regulation.
Frequently asked questions
- Does ECOA require a lender to explain how an AI model reached a credit decision?
- Yes. 12 CFR § 1002.9 (Regulation B), which implements 15 U.S.C. § 1691(d), requires a statement of specific reasons that indicates the principal reason(s) for the adverse action and relates to factors actually considered — regardless of whether a human underwriter or a machine-learning model made the call. 'The algorithm decided' or a bare low score is not a specific reason.
- Can a lender use the CFPB's own sample adverse-action-notice checklist for an AI-driven denial?
- Only if a checklist item actually and specifically matches what the model weighed. CFPB Circular 2023-03 gave a direct example: if a complex algorithm denies an application because of the applicant's chosen profession, disclosing 'insufficient income' or 'income insufficient for amount of credit requested' from the sample-form checklist likely doesn't satisfy the law, because that isn't the real reason.
- Are the CFPB's 2022 and 2023 circulars on AI and adverse action still in effect?
- As hosted guidance documents, no — the CFPB withdrew both Circular 2022-03 and Circular 2023-03 on May 12, 2025, as part of a 67-document guidance rescission, describing the withdrawal as non-final and subject to further review. But a circular is the agency's own explanation of the law, not the law itself: ECOA (15 U.S.C. § 1691(d)) and Regulation B (12 CFR § 1002.9) were not amended and remain fully binding.
- What if a lender genuinely doesn't understand its own AI model well enough to give a specific reason?
- That's not a valid defense. CFPB Circular 2022-03 stated directly that a creditor's lack of understanding of its own complex or 'black-box' algorithm doesn't excuse noncompliance with ECOA's specific-reasons requirement. If a model can't produce an explainable, specific principal reason, that's a problem with deploying the model that way, not a legal exemption from the notice requirement.
- What's the actual financial exposure for an inadequate AI-generated adverse action notice?
- Under 15 U.S.C. § 1691e, a creditor is liable for the applicant's actual damages plus punitive damages up to $10,000 in an individual claim, or the lesser of $500,000 or 1% of the creditor's net worth in a class action, with courts weighing factors like how intentional and how frequent the noncompliance was. The Attorney General also has separate authority to bring pattern-or-practice actions under the statute.
Sources & references
- Official source
- CFPB Circular 2022-03 — Adverse Action Notification Requirements in Connection With Credit Decisions Based on Complex Algorithms
- CFPB Circular 2023-03 — Adverse Action Notification Requirements and the Proper Use of the CFPB's Sample Forms Provided in Regulation B
- 12 CFR § 1002.9 — Notifications (Regulation B)
- 15 U.S.C. § 1691e — Civil liability (ECOA)
- Federal Register — Interpretive Rules, Policy Statements, and Advisory Opinions; Withdrawal (May 12, 2025)
Suggested next reading
regulations us
US Federal AI Regulation: What Actually Exists Today
regulations us
EEOC Guidance on AI in Employment Decisions, Explained
regulations us
SEC AI-Washing Enforcement: What Counts as a Violation
regulations us