Industry Solutions Banking & Finance Healthcare Manufacturing Legal Government & Defense How It Works Cost Savings Knowledge Blog About Request Demo
6 min read

Federal AI Deregulation Doesn't Reach Your Examiner

Two executive orders, a Justice Department task force, and a courtroom fight over state AI laws. None of it moved the rules your institution is examined under. Here's what changed this year and what didn't.

A newspaper headline about AI deregulation next to an unchanged examiner checklist
The preemption fight runs through courtrooms and funding notices. Exam expectations run on a different track, and that track didn't loosen.

Since December, Washington has been loud about AI. Two executive orders. A Justice Department task force built to sue states. A court fight in Colorado. A steady run of deregulation headlines. Inside credit unions and community banks, I keep hearing the same takeaway: the pressure around AI compliance is easing.

It isn't. The policy fight is real, and it's loud. But it runs on a track that never touches NCUA guidance, FINRA rules, or the model risk rules your examiner uses. Those moved this year too. They got tighter, not looser.

The quick version

Executive Order 14365 wants one national AI rulebook. It tells the DOJ to fight state AI laws in court. But an order can't erase those laws on its own. Preemption takes an act of Congress, and Congress hasn't acted. Meanwhile, the rules that govern examined institutions kept tightening. NCUA named the NIST AI RMF as its benchmark. FINRA issued Notice 24-09. The agencies updated model risk guidance in SR 26-2. If your AI plan is waiting for Washington to settle, you are watching the wrong agencies.

What did the December executive order actually do?

It set a goal and built a legal weapon. On December 11, 2025, the White House signed Executive Order 14365. The order calls for one light national AI framework in place of state-by-state rules. To get there, it tells the Attorney General to build an AI Litigation Task Force. That task force has one job: challenge state AI laws in court.

The order also tells Commerce to publish a list of "onerous" state laws. And it puts leftover BEAD broadband money at risk for states that keep enforcing theirs. DOJ created the task force on January 9.

The order still can't preempt state law. That power belongs to Congress, and Congress went the other way. The Senate voted 99 to 1 to strip a ten-year ban on state AI laws out of last year's budget bill. Law firms across the field read it the same way. State AI laws stay valid until a court or Congress says otherwise. That answer is years away.

What has the preemption fight produced so far?

Not much yet, plus one telling case. Commerce missed its March 11 deadline to name onerous state laws, and it still hasn't published the list. The first real fight came in Colorado. It did not go the way the order wanted.

xAI sued to block the Colorado AI Act in April. DOJ then moved to join the case on xAI's side. It was the first time the federal government stepped into a challenge to a state AI law. Colorado did not fold. The legislature repealed the law and passed a narrower one, SB 26-189. The governor signed it on May 14, and it takes effect January 1, 2027. It covers automated decisions that affect consumers, and lending is on the list.

One detail matters for banks and credit unions. The old Colorado law let some federally regulated firms off the hook. The new law dropped that break. A law rewritten under heavy federal pressure came back with federally regulated firms more squarely in scope.

States kept passing laws through all of it. Texas and Utah rules are in force. New York signed the RAISE Act in December. California's AI transparency law took effect over the weekend. The field the order set out to clear has more laws on it now than it did in December.

What changed for examined institutions this year?

Nothing loosened. Several rules got tighter. NCUA updated its AI resource hub in December. It told examiners to use the NIST AI Risk Management Framework as the benchmark for AI at federally insured credit unions. That framework is the standard your exam will measure against.

FINRA put AI inside exam scope back in 2024 with Regulatory Notice 24-09. Supervision under Rule 3110 follows the tool, whatever the tool is. The SEC's 2026 exam priorities name AI governance in several areas. That is how shadow AI became an exam finding for investment advisers.

In April, while the deregulation headlines ran, the banking agencies issued SR 26-2. It is the first update to model risk guidance in over a decade. Generative and agentic AI got set aside for their own future rule. More oversight is coming for this category, and it has a schedule.

None of these agencies waited on the fight, and none of them will. They did not need new AI laws. They tied AI to powers they already had: safety and soundness, third-party risk, supervision, and model risk. An order about state law does not reach any of that.

What does waiting cost?

More than it looks. The easy read is that the rules are in flux, so it makes sense to hold off. That flux is real at the policy level. At the examiner level, there is none. The expectations are published and the framework is named. The exam cycle does not pause for the courts.

Most institutions still can't hand an examiner two basic things: a written AI policy, and a current list of the AI tools their staff already use. Exam pressure on AI is arriving before that paperwork exists. That gap is the real risk, and it grows on a clock the courts don't control.

What should a credit union or community bank do now?

Build governance that holds no matter how the fight ends. The NIST AI RMF is the named benchmark, so map to it. Write a policy. List every AI tool in use or under review. Add vendor rules that ask where data goes and what gets logged. Keep a person in the loop on big calls.

All of that survives any court outcome. It answers to your examiner, not to the winner of a legal argument.

Then look at your architecture, because architecture decides how much of that policy you can enforce. A policy that says member data stays governed is just a sentence. A setup where member data never leaves your network is a real control. Examiners can tell the two apart.

The deregulation story will keep making headlines. The lawsuits will keep making legal bills. Both will outlast several of your exam cycles. Prepare for the one that has a date on it.

Walk into the exam with the paperwork done

Our AI Governance Starter Framework for credit unions covers the policy areas NCUA exam staff ask about, with templates mapped to the NIST AI RMF and current supervisory expectations.

Get the Governance Framework
Keith Kennedy

Keith Kennedy, CISSP

Founder & CEO, Cognetryx

Keith is an IT thought leader with nearly 20 years of experience architecting secure technology solutions for regulated industries. He holds a CISSP certification and advises institutions on secure AI architecture, access control, and keeping sensitive data inside the network. About Keith

AI Deregulation, Answered

No. An executive order directs federal agencies; it can't repeal state statutes. Preemption requires an act of Congress, and the Senate voted 99 to 1 against a state AI moratorium in 2025. The order created a DOJ task force to challenge state laws in court, and that litigation will run for years. State AI laws remain enforceable unless a court or Congress says otherwise.

No. After xAI sued and the Department of Justice intervened, Colorado repealed the original act and replaced it with SB 26-189, signed May 14, 2026. The replacement takes effect January 1, 2027, regulates automated decision-making in consequential decisions about consumers, and dropped the original law's conditional exemptions for some federally regulated entities.

No. The orders address state law and national policy. NCUA's December 2025 AI resources point examiners to the NIST AI Risk Management Framework. FINRA Regulatory Notice 24-09 keeps AI inside existing supervision rules, including Rule 3110. The April 2026 interagency model risk guidance, SR 26-2, added expectations rather than removing any.

Document it now. Examiners are benchmarking against the NIST AI RMF, so a written policy and a complete inventory of AI tools in use are the first two artifacts to have ready. Add vendor risk criteria covering data location and audit logging, and keep human review on consequential decisions. Deployment architecture then decides how much of that policy you can enforce.