Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature AI Risk

The FTC's March 2026 AI Policy Statement: What Financial Services AI Teams Need to Document Under Section 5

On March 7, 2026, the FTC issued its first comprehensive AI enforcement framework using Section 5 of the FTC Act — no new legislation required. Here's what the three-pillar framework means for financial services AI programs, and the four documentation gaps that create the most acute exposure.

Table of Contents

TL;DR:

  • On March 7, 2026, the FTC issued its first comprehensive AI enforcement framework using existing Section 5 authority — no new AI legislation required.
  • Three enforcement pillars: AI claims substantiation (you need evidence before making the claim), algorithmic discrimination (disparate impact is sufficient — no intent required), and data consent for AI training (broad GLBA notice doesn’t cover all AI training uses).
  • Non-bank financial institutions are directly in scope. Nationally chartered banks are generally exempt from FTC jurisdiction but face converging expectations from banking regulators.
  • Algorithmic disgorgement — deletion of AI models trained on improperly collected data — is explicitly on the table as an enforcement remedy, not just a monetary fine.

The FTC doesn’t need new AI legislation. It said so plainly on March 7, 2026.

The agency’s first comprehensive AI policy statement doesn’t create new law. It tells you exactly how the FTC intends to apply Section 5 of the FTC Act — the statute it has used against false advertising and consumer fraud for over a century — now systematically directed at AI-powered decisions, algorithmic outputs, and automated practices. The statement is a roadmap, not a surprise.

For financial services teams, the March 2026 statement deserves careful attention. Financial institutions are explicitly identified as “most obviously at risk” because of the sensitivity of data they hold and the severity of potential harm — denied credit, discriminatory pricing, inaccurate underwriting decisions. The FTC has existing enforcement vehicles in ECOA and the FCRA that overlap with Section 5 authority. And it has a concrete settlement precedent for algorithmic disgorgement — deletion of the model itself — that makes the worst-case remedy real.

The Three-Pillar Enforcement Framework

The March 2026 statement organizes FTC AI enforcement around three pillars. Each creates distinct documentation requirements.

Pillar 1: AI Claims Substantiation

If your institution — or an AI vendor you use — claims a specific accuracy rate, fraud reduction percentage, or outperformance of human decision-making for any AI system, that claim requires competent and reliable evidence existing at the time it’s made.

“Competent and reliable” is an existing FTC advertising substantiation standard, now applied to AI performance representations. The enforcement risk isn’t the claim itself; it’s the gap between the claim and the underlying evidence. If your credit AI vendor markets “92% accuracy,” but your internal validation under your use conditions shows 78%, your institution has a problem — not if you repeat “92%” in external materials without disclosing the institution-specific validation results.

The same logic applies to internal governance documents. If a risk committee memo states that a fraud detection model “reduces false positives by 40% versus our previous system,” that claim needs to be backed by testing results in your context, not the vendor’s benchmark data. Governance documentation is an FTC enforcement target, not a safe haven.

Pillar 2: Algorithmic Discrimination

This pillar carries the highest risk for financial services AI programs.

The statement is explicit: deploying AI with known discriminatory outcomes is presumptively unfair under Section 5. The FTC does not require proof of discriminatory intent. If your AI system produces outcomes that disproportionately harm consumers based on race, gender, age, disability, or other protected characteristics — and your team is aware of the disparity without taking adequate remediation steps — that’s presumptively an unfair practice.

The enforcement logic here matters particularly in the current regulatory environment. The CFPB’s elimination of the disparate impact standard from Reg B effective July 21, 2026, reduced CFPB-ECOA disparate impact enforcement risk for credit decisioning AI. What the FTC’s March 2026 statement establishes is that the same conduct creates Section 5 risk — a different enforcement channel that the Reg B change doesn’t reach.

In January 2026, the FTC specifically escalated enforcement on algorithmic discrimination in credit and lending systems, signaling the pattern of conduct it’s looking for: an AI system with documented internal bias findings, known to the deploying institution, put into production without adequate remediation.

Three documentation requirements follow directly:

Pre-deployment bias testing records: Your testing methodology, what protected-class outcome disparities your system produced under those tests, and what you did in response before deployment.

Ongoing demographic monitoring: Post-deployment tracking of demographic parity in AI-driven decisions, with documented escalation thresholds and the response when those thresholds are crossed.

Remediation documentation: When a model produced discriminatory outcomes and was modified, what changed, what post-modification testing showed, and who approved the revised deployment.

Note that “we didn’t find bias in our testing” is a valid response — if the testing was documented. “We don’t know if the model has a bias problem” is not.

This is the pillar most financial services AI programs haven’t thought through.

The March 2026 statement establishes that collecting consumer data for AI training without adequate notice and consent is an unfair or deceptive practice. Broad, general-purpose consent — the kind embedded in most financial services privacy notices — is not sufficient for AI training use if the consumer would not reasonably expect their data to be used to build or retrain an AI model.

For financial institutions, GLBA Regulation P covers nonpublic personal information used for financial services purposes. But GLBA notice doesn’t automatically cover:

  • Using historical transaction data to train a fraud detection model
  • Using customer service call recordings to train a conversational AI system
  • Using behavioral and usage data to train credit risk models for new or different products
  • Retraining existing models on newly collected data after an original consent was given

This doesn’t mean existing AI programs are automatically non-compliant. It means financial institutions need to map what consumer data feeds AI model training and trace it back to the consent framework that covered the original data collection — to determine whether a reasonable consumer would have expected that use.

Algorithmic Disgorgement: The Remedy That Changes the Risk Calculation

The FTC’s enforcement toolkit extends beyond monetary penalties. The remedy getting the most attention from legal teams is algorithmic disgorgement: deletion of AI models trained on improperly collected or used data.

The FTC has applied this remedy since 2019, including against Cambridge Analytica and several subsequent targets. The legal basis sits in Section 5(b) cease-and-desist authority, Section 13(b) injunction power, and Section 18 rulemaking. The FTC has described algorithmic disgorgement as increasingly significant in its AI enforcement strategy.

For financial services AI teams, the practical implication isn’t that disgorgement is likely in a given situation. It’s that disgorgement changes the economics of AI data governance. A model trained on improperly consented data isn’t just a compliance risk — it’s potentially an asset the FTC can require you to destroy. The business case for getting data governance right at model-build time now includes protecting the model from enforcement-mandated deletion, not just avoiding a fine.

The Morgan Lewis April 2026 analysis notes that AI enforcement is accelerating as federal policy development stalls. Financial services teams shouldn’t wait for a comprehensive federal AI law to clarify obligations — the FTC’s Section 5 enforcement authority is active now.

The Four Documentation Categories That Reduce FTC Exposure

Based on the March 2026 framework’s three pillars, the documentation gaps creating the highest acute FTC exposure in financial services AI programs fall into four categories:

1. AI use inventory

An inventory of every production AI system, third-party AI tool, and consumer-facing AI-assisted decision point — with the consumer data inputs, the decision outputs, and the population affected. Without this, you can’t demonstrate what’s covered by what consent framework or what performance substantiation requirements apply to which systems.

This is also the starting point for the OCC Bulletin 2026-13 model risk management program — an inventory of AI use cases is now required under both OCC MRM guidance and FTC enforcement logic.

2. AI performance substantiation records

Validation testing results corresponding to any internal or external claim about AI performance. If your AI underwriting model performs differently for thin-file customers than for established credit customers, and you’ve represented overall model accuracy without distinguishing the two populations, that’s a substantiation gap. Institution-specific validation results need to be documented and retained for each performance claim in each context where that claim was made.

3. Bias and fairness testing records

Pre-deployment disparate impact testing across protected classes, with documented methodology. Post-deployment demographic monitoring results and the escalation decisions those results triggered. Remediation documentation when models were modified in response to bias findings. For detailed disparate impact testing methodology, our post on statistical testing techniques for AI models covers the approaches banking examiners and the FTC expect to see.

4. Data consent mapping for AI training

A written inventory of which consumer data is used in AI model training — by system — what consent authority covers each data category, and whether the original collection purpose reasonably encompasses the AI training use. Where gaps exist, a documented legal and business decision about how to address them.

The AI Risk Assessment Template & Guide includes an AI Use Case Inventory with fields for consumer data inputs, performance substantiation status, bias testing results, consent mapping, and third-party vendor documentation — built to satisfy the compliance documentation requirements that banking regulators and now the FTC are both examining. For the governance framework that houses these requirements, see our post on AI governance programs for financial services.

So What?

The March 2026 FTC AI policy statement doesn’t change what the FTC can do. It tells you what the FTC is going to do with what it already has.

For non-bank financial institutions — fintechs, consumer lenders, mortgage companies, credit bureaus — the risk is direct. For nationally chartered banks, the enforcement channel is different but the practical conduct expectations are converging.

Two documentation gaps create the highest immediate exposure: a bias testing program that has no records of what was found and what action was taken, and AI performance representations — in vendor marketing you repeated, internal risk committee memos, or regulatory filings — that aren’t backed by institution-specific validation results.

Neither is expensive to fix. Both are expensive to explain after an enforcement action.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did the FTC's March 2026 AI policy statement actually establish?
On March 7, 2026, the FTC issued its first comprehensive policy statement on AI under Section 5 of the FTC Act. It doesn't create new law — it tells you how the FTC intends to apply its existing unfair and deceptive practices authority to AI conduct. Three enforcement pillars: (1) AI claims substantiation — you need competent and reliable evidence for performance representations about your AI systems at the time the claim is made; (2) Algorithmic discrimination — disparate impact is sufficient, no intent required; and (3) Data consent for AI training — broad privacy notice consent doesn't automatically cover AI model training uses.
Are banks and financial institutions subject to FTC Section 5 AI enforcement?
Nationally chartered banks supervised by the OCC, Federal Reserve, or FDIC are generally exempt from direct FTC jurisdiction. Non-bank financial institutions — fintechs, consumer lenders, mortgage companies, auto lenders, and others — are directly subject to FTC Section 5 authority. The March 2026 statement increases enforcement risk for fintechs and technology-forward financial companies. That said, banking regulators have been converging toward the same conduct standards, so the practical documentation expectations are similar across the sector.
What is algorithmic disgorgement and has the FTC actually used it?
Algorithmic disgorgement is an enforcement remedy requiring the deletion of AI models trained on improperly collected or used data. The FTC has used it in enforcement actions since 2019, grounding the authority in Section 5(b) cease-and-desist power, Section 13(b) injunction authority, and Section 18 rulemaking. As of the March 2026 statement, the FTC has described it as a 'significant part' of its AI enforcement strategy. For financial services teams, the practical implication is that a model built on improperly consented data isn't just a compliance problem — it's potentially an asset that can be ordered destroyed.
Why doesn't the FTC need to prove discriminatory intent to bring an AI bias enforcement action?
The FTC's Section 5 authority covers 'unfair or deceptive acts or practices.' Under the March 2026 statement, deploying an AI system with known discriminatory outcomes — where the institution is aware of a protected-class disparity and hasn't taken adequate remediation steps — is presumptively unfair. Unfairness doesn't require intent; it requires substantial harm to consumers with no countervailing benefit. This mirrors the ECOA and FCRA frameworks the FTC already uses in financial services enforcement.
What data consent framework covers AI model training in financial services?
GLBA Regulation P covers nonpublic personal information used for financial services purposes — but that doesn't automatically cover AI model training if consumers wouldn't reasonably expect their data to be used to build or retrain models. Specific gaps: using transaction data to train fraud models, using service call recordings to train conversational AI, using behavioral data for credit models on different products, and retraining existing models on newly collected data. Before the FTC examines these practices, financial institutions should map what consumer data is used in AI training and whether the original consent framework reasonably covers that use.
What four documentation categories reduce FTC AI enforcement risk for financial services firms?
Four categories: (1) AI use inventory — all production AI systems, third-party AI tools, consumer-facing decision points, and data inputs; (2) Performance substantiation records — the validation evidence that corresponds to any public or internal claims about AI accuracy, cost reduction, or performance; (3) Bias and fairness testing records — pre-deployment disparate impact analysis by protected class, with remediation documentation; and (4) Data consent mapping — written inventory of which consumer data feeds AI model training, what consent authority covers each category, and where gaps exist.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.