AGs warn Congress that AI threatens the financial system

Hochul�Says New AI Compliance Office Could Explore Kill Switch
Phil Weiser, Colorado's attorney general, and Letitia James, New York's attorney general
David Paul Morris/Bloomberg, John Lamparski/Bloomberg
  • What's at stake: A December executive order directs the Justice Department to challenge state AI laws that conflict with administration policy and tells administration officials to draft legislation preempting them.
  • Supporting data: Colorado's AI law takes effect Jan. 1 and requires lenders to tell consumers when a lending decision involves AI and to describe the software's role in plain language within 30 days of an adverse outcome.
  • Forward look: President Trump rejected calls to slow the AI industry down on Saturday, leaving no sign of federal appetite for the framework the attorneys general want Congress to build.

Overview bullets generated by AI with editorial review.

Processing Content

Twenty-six attorneys general urged Congress to regulate advanced artificial intelligence, warning in a letter released Thursday that unchecked development could "soon threaten our financial system, critical infrastructure, and national security."

The letter, addressed to House and Senate congressional leaders for both parties, asks them to "immediately establish comprehensive federal regulation and safety protocols" for frontier AI, the industry's term for its most capable models.

The attorneys general describe no mechanism by which AI would reach banks, estimate no share of the financial system as exposed and ask for nothing specific to financial institutions.

The letter's last demand still affects banks, though; the attorneys general asked Congress to leave state AI laws alone rather than preempt them with federal rules.

Among the laws preemption would affect is Colorado's AI law, which is set to take effect Jan. 1 and is currently the subject of a Justice Department effort to block it.

That law requires lenders to tell consumers when lending decisions involve AI, to describe the software's role in plain language within 30 days of an adverse outcome, and to honor requests for the underlying personal data, corrections and human review.

The letter arrives after a year in which federal banking regulators have largely withheld regulatory scrutiny from banks' use of AI.

What's driving the letter

Driving the letter is a recent string of failures by leading AI companies to adequately control their own models.

For example, in July, OpenAI models running internal cybersecurity evaluations compromised parts of the systems at Hugging Face (which hosts AI models and datasets), according to an incident report OpenAI published in August. The company's report enumerates a number of techniques the models used against which OpenAI failed to guard.

Anthropic and Meta disclosed similar failures in August, each saying a misconfiguration during outside safety testing let models onto the open internet, where they gained unauthorized access to other companies' systems.

The attorneys general have adopted the framing the companies themselves offered: that their AI agents are so capable that they are breaking containment.

"In recent weeks, alarming reports of AI agents breaking containment have shocked the nation," James said in a press release announcing the letter.

Feds have moved the other way

The states are also responding to a regulatory vacuum at the federal level.

In April, when three banking regulators rewrote their guidance on model risk (the risk that a bank's computational tools produce wrong answers when it prices loans or flags fraud), they expressly excluded generative and agentic AI from the scope.

The agencies said at the time that a request for information covering banks' use of AI, including agentic AI, would follow "in the near future." The Office of the Comptroller of the Currency, or OCC, said it again in May, in its Spring 2026 Semiannual Risk Perspective.

Five months on, they have not published such a request.

The OCC has also said banks are mostly keeping AI away from decisions about money.

In its May risk perspective, the office described banks as "taking a measured approach" to generative and agentic AI, with use "generally limited to specific use cases with guardrails and human-in-the-loop accountability" and concentrated in productivity and customer-service tools.

Similarly, the Financial Stability Oversight Council, the panel of regulators charged with spotting threats to the financial system, has focused on the potential for AI to help with that mandate.

In its most recent annual report in December, the council discussed AI in a section headed "Harnessing Artificial Intelligence to Promote Financial Stability."

That section enumerated the upsides of AI, flagging risks "such as misuse by malicious actors" and cyber and national security exposures, not misuse by banks themselves.

The same section records the Treasury Department as "committed to removing barriers to AI adoption not only within the agency but also across the broader financial services sector."

The White House is heading the push to let AI loose on the economy.

An executive order signed in December 2025 directs the U.S. attorney general to establish an AI Litigation Task Force whose "sole responsibility" is challenging state AI laws that conflict with administration policy, and it tells administration officials to draft legislation preempting them.

President Trump doubled down on that deregulatory approach Saturday, rejecting calls to slow the industry down and writing in a post on his platform Truth Social that his administration "will not in any way hinder or stifle the Growth of this incredible Industry."


For reprint and licensing requests for this article, click here.
Artificial Intelligence Politics and policy Regulation and compliance State regulators Risk management Technology
MORE FROM AMERICAN BANKER
Load More