HomeReal EstateColorado’s AI proposal raises new compliance questions for lenders

Colorado’s AI proposal raises new compliance questions for lenders

Colorado lawmakers recently released proposed rules that would establish new requirements for businesses that use automated decision-making technology in consequential decisions, including financial services and mortgage lending.

Senate Bill 26-189 establishes requirements for developers and deployers of automated decision-making technology (ADMT) when the technology “materially influences” decisions affecting consumers. The law applies to consequential decisions made on or after Jan. 1, 2027.

The legislation could have a broad impact on mortgage lenders, although more clarification is needed, according to industry experts. The bill defines ADMT as technology that processes personal data to generate information used to make, guide or assist in “consequential” decisions about an individual. Consequential decisions include those involving housing and lending, as well as employment, insurance, healthcare, education and essential government services.

But Mitch Kider, chairman and managing partner of Weiner Brodsky Kider PC, is concerned that the definitions outlined in the proposed rules are not clear enough.

“If [their] standard is going to be that the burden is on the user to show that a full review of an underwriting determination has to be done each and every time a consumer asks because they were adverse, it’s no different than having a manual underwrite done on every loan … and that becomes somewhat problematic.”

Is the proposal too broad?

In a newsletter published Monday, the Mortgage Bankers Association (MBA) said the proposal needs further refinement to provide clearer guidance for the mortgage industry.

MBA said the rules do not clearly define automated decision-making technology or what constitutes a consequential decision, leaving creditors uncertain about which processes fall under the ADMT Act.

The proposed rules would allow creditors to combine ADMT disclosures with adverse-action notices required under the Equal Credit Opportunity Act or Fair Credit Reporting Act. MBA previously recommended that compliance with these requirements should satisfy the ADMT Act’s notice requirements.

MBA also raised questions about when creditors could deny requests for human review as “commercially unreasonable” and called for clearer distinctions between the responsibilities of ADMT developers and deployers.

Wendy Lee, a partner at Buchalter who specializes in financial services and regulatory compliance, said because financial and lending services are one of the covered domains and are such broad industries, the ADMT rules could include automated underwriting systems and other technology that evaluates loan applications, categorizes information or helps make credit decisions.

“Think about the life cycle of the loan,” she said. “It’s the gathering of information. It’s the assessment of the information. It’s the decisioning on the information. And then, down the line, it would be the servicing.”

Lee said servicing decisions also could fall under the law, including decisions about foreclosure, loss mitigation and whether to extend a loss-mitigation application.

Beginning Jan. 1, 2027, developers of covered ADMTs must provide deployers with documentation describing the technology’s intended uses, categories of training data, known limitations, and instructions for appropriate use and human review. Developers also must notify deployers of material updates or modifications, and they both must retain records needed to demonstrate compliance for at least three years.

“If I was in the middle of deploying any technology in lending right now, I would be waiting for my vendor to send me basically a compliance checklist,” Lee said.

The legislation also establishes new consumer disclosure requirements. Before using a covered ADMT to materially influence a consequential decision, clear and conspicuous notice must be provided to the consumer. If the technology contributes to a decision resulting in an adverse outcome, the deployer generally must provide a plain-language explanation of the decision and the technology’s role within 30 days.

Kider said lenders will need more clarity about when these notices must be delivered, since automated systems can be used at multiple stages of the mortgage process.

The bill also gives consumers who experience an adverse outcome the right to request instructions for correcting factually incorrect or materially inaccurate personal data used in the decision. They could also request meaningful human review and reconsideration of the decision, to the extent that it’s commercially feasible.

Lee said the law’s human review requirement is one of the areas lenders will need to incorporate into their compliance processes, as it requires lenders to maintain records and vet their technology vendors.

Duplicative elements

Kider also questioned whether Colorado‘s requirements duplicate protections already imposed by federal law, including the Equal Credit Opportunity Act (ECOA) and the Fair Credit Reporting Act (FCRA).

“A lot of what is addressed over here is already addressed by other laws. … You would think and hope that if you complied with ECOA and you complied with FCRA that you would be in compliance with this act as well, but as it’s written right now, it’s an add-on to those particular provisions, and I think that’s somewhat problematic.”

Lee agreed that the Colorado law does allow overlap with existing federal requirements. Lenders that issue adverse-action notices under ECOA or FCRA would not necessarily have to issue a completely separate notice, although additional AI-specific disclosures could be required.

The bill does not create a private right of action, meaning individual borrowers cannot sue lenders solely for violating the law. Enforcement instead falls to the Colorado attorney general and regulators. Lee said the lack of a private right of action is “a win” for the mortgage industry.

When a violation can be cured, the attorney general generally must provide 60 days’ notice and an opportunity to cure before bringing an enforcement action. The cure period does not apply when the attorney general determines that a developer or deployer knowingly or repeatedly violated the law.

Lee said that enforcement structure could mean lenders have some time to identify and correct compliance issues rather than facing immediate litigation from individual borrowers.

The bill is intended to give consumers greater transparency and access to human review when automated systems affect consequential decisions. Kider said that goal is sound, even if the implementation needs additional refinement and should be considered on a federal level.

“From a compliance perspective, I think this is going to mandate quite a bit of compliance preparation and compliance review when something like this ultimately becomes effective. And I do question whether it makes any sense at all to have this done on a piecemeal, state-by-state basis, as opposed to having some federal preemptive standards,” he said.

AI safety and implementation

Lee said the law also comes at a time when lenders are still determining how to safely integrate AI into their operations.

One of her biggest concerns is how lenders will defend against consumers using AI in a malicious manner — for example, borrowers who attempt to manipulate automated systems or gain access to information they should not receive.

“How are lenders protecting themselves against borrowers using AI as an attack vector into their worlds?” Lee said. “How are lenders getting real controls in place to manage around what’s going to be more regulation that’s going to want to look at the safety and soundness?”

Lee said lenders that lack strong cybersecurity and information security programs could compound their risks as they deploy more automated systems.

“If a lender doesn’t have a good cybersecurity or information security program that’s monitoring and constantly looking at the automated systems, then deploying AI in an unsafe environment is going to just compound risk,” Lee said.

Kider, meanwhile, warned that overly broad requirements could discourage lenders from adopting technology that could reduce costs and improve efficiency.

“AI is amazing and it’s changing all the time. I think that they’re going to provide tremendous cost savings as well for both consumers and for lenders. … My fear is that this is going to [dampen] the impact that AI can have overall in this industry,” Kider said.

He argued that the rules should address human contact, human review and transparency without creating requirements so broad that the potential benefits of automation are lost.

 

Must Read

spot_img