Feature AI Risk
The FTC's March 2026 AI Policy Statement: What Financial Services AI Teams Need to Document Under Section 5
On March 7, 2026, the FTC issued its first comprehensive AI enforcement framework using Section 5 of the FTC Act — no new legislation required. Here's what the three-pillar framework means for financial services AI programs, and the four documentation gaps that create the most acute exposure.
Table of Contents
TL;DR:
- On March 7, 2026, the FTC issued its first comprehensive AI enforcement framework using existing Section 5 authority — no new AI legislation required.
- Three enforcement pillars: AI claims substantiation (you need evidence before making the claim), algorithmic discrimination (disparate impact is sufficient — no intent required), and data consent for AI training (broad GLBA notice doesn’t cover all AI training uses).
- Non-bank financial institutions are directly in scope. Nationally chartered banks are generally exempt from FTC jurisdiction but face converging expectations from banking regulators.
- Algorithmic disgorgement — deletion of AI models trained on improperly collected data — is explicitly on the table as an enforcement remedy, not just a monetary fine.
The FTC doesn’t need new AI legislation. It said so plainly on March 7, 2026.
The agency’s first comprehensive AI policy statement doesn’t create new law. It tells you exactly how the FTC intends to apply Section 5 of the FTC Act — the statute it has used against false advertising and consumer fraud for over a century — now systematically directed at AI-powered decisions, algorithmic outputs, and automated practices. The statement is a roadmap, not a surprise.
For financial services teams, the March 2026 statement deserves careful attention. Financial institutions are explicitly identified as “most obviously at risk” because of the sensitivity of data they hold and the severity of potential harm — denied credit, discriminatory pricing, inaccurate underwriting decisions. The FTC has existing enforcement vehicles in ECOA and the FCRA that overlap with Section 5 authority. And it has a concrete settlement precedent for algorithmic disgorgement — deletion of the model itself — that makes the worst-case remedy real.
The Three-Pillar Enforcement Framework
The March 2026 statement organizes FTC AI enforcement around three pillars. Each creates distinct documentation requirements.
Pillar 1: AI Claims Substantiation
If your institution — or an AI vendor you use — claims a specific accuracy rate, fraud reduction percentage, or outperformance of human decision-making for any AI system, that claim requires competent and reliable evidence existing at the time it’s made.
“Competent and reliable” is an existing FTC advertising substantiation standard, now applied to AI performance representations. The enforcement risk isn’t the claim itself; it’s the gap between the claim and the underlying evidence. If your credit AI vendor markets “92% accuracy,” but your internal validation under your use conditions shows 78%, your institution has a problem — not if you repeat “92%” in external materials without disclosing the institution-specific validation results.
The same logic applies to internal governance documents. If a risk committee memo states that a fraud detection model “reduces false positives by 40% versus our previous system,” that claim needs to be backed by testing results in your context, not the vendor’s benchmark data. Governance documentation is an FTC enforcement target, not a safe haven.
Pillar 2: Algorithmic Discrimination
This pillar carries the highest risk for financial services AI programs.
The statement is explicit: deploying AI with known discriminatory outcomes is presumptively unfair under Section 5. The FTC does not require proof of discriminatory intent. If your AI system produces outcomes that disproportionately harm consumers based on race, gender, age, disability, or other protected characteristics — and your team is aware of the disparity without taking adequate remediation steps — that’s presumptively an unfair practice.
The enforcement logic here matters particularly in the current regulatory environment. The CFPB’s elimination of the disparate impact standard from Reg B effective July 21, 2026, reduced CFPB-ECOA disparate impact enforcement risk for credit decisioning AI. What the FTC’s March 2026 statement establishes is that the same conduct creates Section 5 risk — a different enforcement channel that the Reg B change doesn’t reach.
In January 2026, the FTC specifically escalated enforcement on algorithmic discrimination in credit and lending systems, signaling the pattern of conduct it’s looking for: an AI system with documented internal bias findings, known to the deploying institution, put into production without adequate remediation.
Three documentation requirements follow directly:
Pre-deployment bias testing records: Your testing methodology, what protected-class outcome disparities your system produced under those tests, and what you did in response before deployment.
Ongoing demographic monitoring: Post-deployment tracking of demographic parity in AI-driven decisions, with documented escalation thresholds and the response when those thresholds are crossed.
Remediation documentation: When a model produced discriminatory outcomes and was modified, what changed, what post-modification testing showed, and who approved the revised deployment.
Note that “we didn’t find bias in our testing” is a valid response — if the testing was documented. “We don’t know if the model has a bias problem” is not.
Pillar 3: Data Consent for AI Training
This is the pillar most financial services AI programs haven’t thought through.
The March 2026 statement establishes that collecting consumer data for AI training without adequate notice and consent is an unfair or deceptive practice. Broad, general-purpose consent — the kind embedded in most financial services privacy notices — is not sufficient for AI training use if the consumer would not reasonably expect their data to be used to build or retrain an AI model.
For financial institutions, GLBA Regulation P covers nonpublic personal information used for financial services purposes. But GLBA notice doesn’t automatically cover:
- Using historical transaction data to train a fraud detection model
- Using customer service call recordings to train a conversational AI system
- Using behavioral and usage data to train credit risk models for new or different products
- Retraining existing models on newly collected data after an original consent was given
This doesn’t mean existing AI programs are automatically non-compliant. It means financial institutions need to map what consumer data feeds AI model training and trace it back to the consent framework that covered the original data collection — to determine whether a reasonable consumer would have expected that use.
Algorithmic Disgorgement: The Remedy That Changes the Risk Calculation
The FTC’s enforcement toolkit extends beyond monetary penalties. The remedy getting the most attention from legal teams is algorithmic disgorgement: deletion of AI models trained on improperly collected or used data.
The FTC has applied this remedy since 2019, including against Cambridge Analytica and several subsequent targets. The legal basis sits in Section 5(b) cease-and-desist authority, Section 13(b) injunction power, and Section 18 rulemaking. The FTC has described algorithmic disgorgement as increasingly significant in its AI enforcement strategy.
For financial services AI teams, the practical implication isn’t that disgorgement is likely in a given situation. It’s that disgorgement changes the economics of AI data governance. A model trained on improperly consented data isn’t just a compliance risk — it’s potentially an asset the FTC can require you to destroy. The business case for getting data governance right at model-build time now includes protecting the model from enforcement-mandated deletion, not just avoiding a fine.
The Morgan Lewis April 2026 analysis notes that AI enforcement is accelerating as federal policy development stalls. Financial services teams shouldn’t wait for a comprehensive federal AI law to clarify obligations — the FTC’s Section 5 enforcement authority is active now.
The Four Documentation Categories That Reduce FTC Exposure
Based on the March 2026 framework’s three pillars, the documentation gaps creating the highest acute FTC exposure in financial services AI programs fall into four categories:
1. AI use inventory
An inventory of every production AI system, third-party AI tool, and consumer-facing AI-assisted decision point — with the consumer data inputs, the decision outputs, and the population affected. Without this, you can’t demonstrate what’s covered by what consent framework or what performance substantiation requirements apply to which systems.
This is also the starting point for the OCC Bulletin 2026-13 model risk management program — an inventory of AI use cases is now required under both OCC MRM guidance and FTC enforcement logic.
2. AI performance substantiation records
Validation testing results corresponding to any internal or external claim about AI performance. If your AI underwriting model performs differently for thin-file customers than for established credit customers, and you’ve represented overall model accuracy without distinguishing the two populations, that’s a substantiation gap. Institution-specific validation results need to be documented and retained for each performance claim in each context where that claim was made.
3. Bias and fairness testing records
Pre-deployment disparate impact testing across protected classes, with documented methodology. Post-deployment demographic monitoring results and the escalation decisions those results triggered. Remediation documentation when models were modified in response to bias findings. For detailed disparate impact testing methodology, our post on statistical testing techniques for AI models covers the approaches banking examiners and the FTC expect to see.
4. Data consent mapping for AI training
A written inventory of which consumer data is used in AI model training — by system — what consent authority covers each data category, and whether the original collection purpose reasonably encompasses the AI training use. Where gaps exist, a documented legal and business decision about how to address them.
The AI Risk Assessment Template & Guide includes an AI Use Case Inventory with fields for consumer data inputs, performance substantiation status, bias testing results, consent mapping, and third-party vendor documentation — built to satisfy the compliance documentation requirements that banking regulators and now the FTC are both examining. For the governance framework that houses these requirements, see our post on AI governance programs for financial services.
So What?
The March 2026 FTC AI policy statement doesn’t change what the FTC can do. It tells you what the FTC is going to do with what it already has.
For non-bank financial institutions — fintechs, consumer lenders, mortgage companies, credit bureaus — the risk is direct. For nationally chartered banks, the enforcement channel is different but the practical conduct expectations are converging.
Two documentation gaps create the highest immediate exposure: a bias testing program that has no records of what was found and what action was taken, and AI performance representations — in vendor marketing you repeated, internal risk committee memos, or regulatory filings — that aren’t backed by institution-specific validation results.
Neither is expensive to fix. Both are expensive to explain after an enforcement action.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the FTC's March 2026 AI policy statement actually establish?
Are banks and financial institutions subject to FTC Section 5 AI enforcement?
What is algorithmic disgorgement and has the FTC actually used it?
Why doesn't the FTC need to prove discriminatory intent to bring an AI bias enforcement action?
What data consent framework covers AI model training in financial services?
What four documentation categories reduce FTC AI enforcement risk for financial services firms?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
AI Risk
NIST AI RMF Implementation: The Minimum Artifact Set for a Team That Cannot Build 200 Controls
What a small risk team actually needs to produce for NIST AI RMF and FS AI RMF compliance — 12 artifacts across GOVERN, MAP, MEASURE, and MANAGE that hold up to examiner scrutiny.
Jul 24, 2026
AI Risk
AI Governance Decision Log: The Missing Artifact Between Committee Meetings and Production Approval
An AI governance framework example for logging approval conditions, dissent, evidence, owners, and expiry dates before an AI use case goes live.
Jul 23, 2026
AI Risk
August 2 Is Ten Days Away: What the EU AI Act's High-Risk Deadline Actually Requires from Financial Services AI
The EU AI Act's Annex III high-risk AI obligations take effect August 2, 2026. Credit scoring models, creditworthiness assessment systems, and insurance risk pricing AI are all in scope. Here's what providers and deployers in financial services must have in place before the deadline—and what the Digital Omnibus deferred.
Jul 22, 2026