โ†
AI for Banking & Lending
Aware ยท M16 ยท lesson 16 of 19 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
What AI Is and Isn't for Bankers
๐Ÿ“–
now learning

What AI Is and Isn't for Bankers

15 min

In the spring of 2024, a regional bank in the Midwest rolled out an AI-assisted underwriting platform from a vendor promising to cut time-to-decision by 60 percent. Six months later, the compliance team was staring at a complaint from a borrower who had been denied a home-equity loan and received an adverse-action notice that listed "insufficient rental history" as a reason. The applicant owned her home outright. She had never rented in her life. The AI had confidently generated a reason code that did not match her file, her credit profile, or the bank's own underwriting notes. The denial itself may have been correct. The stated reason was fabricated. Under the Equal Credit Opportunity Act (ECOA, the federal law that prohibits creditors from discriminating against credit applicants and requires specific, accurate reasons for adverse actions) and Regulation B (the Federal Reserve's implementing regulation for ECOA, which governs credit applications, adverse-action notices, and record retention), a wrong reason on a denial notice is not a paperwork error. It is a statutory violation that can trigger a regulatory examination, a class-action claim, or both. The bank's compliance officer called it "the most expensive way to save time I've ever seen." This lesson exists so you never have to say that sentence.

Why the Framing Matters Before the Tools

Before any bank can use AI responsibly, its people need a working mental model of what AI is and what it is not. This is not philosophy. It is a regulatory and operational necessity. In April 2026, the Office of the Comptroller of the Currency (OCC), Federal Reserve, and Federal Deposit Insurance Corporation (FDIC) released OCC Bulletin 2026-13, an interagency model-risk management update that superseded OCC 2011-12 and explicitly pulled AI and generative AI under the same model-risk, fair-lending, third-party, and board-governance expectations that apply to traditional credit models. The guidance assumes that banks are already using AI. The adoption data confirms it: 38 percent of mortgage lenders used AI or machine learning in 2024, up from 15 percent in 2023. The question is no longer whether AI is in your institution. The question is whether your people understand it well enough to use it without creating a consent order.

The mental model failure that causes the most damage in banking is simple: treating all AI as a single technology. A loan officer who hears "AI" and thinks "the computer that approves loans" is as confused as a branch manager who hears "the internet" and thinks only of email. AI is a family of related but fundamentally different tools, and the distinction between those tools is the difference between a productivity gain and a fair-lending examination finding.

This lesson maps the three AI types that matter in lending, names the specific failure modes of each, and anchors everything in the legal framework that makes getting this right a financial and career-level necessity. After this lesson, you will be able to look at any AI tool deployed at your institution, ask the right questions about which category it belongs to, and immediately understand what regulatory obligations that category carries.

The Three AI Types in Lending

Every AI application inside a lending shop falls into one of three categories: scoring and classification, document extraction, or generative drafting. These categories behave differently, fail differently, and carry different compliance obligations. Conflating them is the single most common mistake banks make when buying, deploying, or explaining AI to regulators.

Scoring and Classification Models

A scoring or classification model takes structured inputs (numbers, categories, flags) and produces a numerical output or a categorical label. This is the oldest form of AI in banking, and it includes the traditional credit scorecard alongside more modern machine-learning approaches. A classic FICO score is a scoring model. A logistic regression that predicts the probability of 90-day delinquency within 12 months is a scoring model. A gradient-boosted tree that flags a mortgage application as "low risk," "moderate risk," or "elevated risk" is a classification model. What they have in common: they consume structured data, they produce a number or a label, and they do not produce prose.

The compliance obligation attached to these models is severe and specific. Under ECOA and Regulation B, if a credit application is denied in whole or in part, the adverse-action notice must include the specific, accurate principal reasons for the denial. "Insufficient score" is acceptable only if the model score is the actual operative reason. "High risk profile" is not a Reg B reason. A vague gestural reference to the model's output is not a Reg B reason. The OCC's model-risk framework, now updated under OCC Bulletin 2026-13, requires that every scoring model be documented, validated, and subject to ongoing performance monitoring. Fair-lending scrutiny is the deepest here: a neutral-looking model can produce outcomes that disparately affect protected classes under the Fair Housing Act (FHA) or ECOA through what regulators call proxy variables (inputs that are correlated with protected characteristics, such as ZIP code, which can correlate with race or national origin). The model did not "use race." It used a variable that tracks race. In a disparate-impact analysis, that distinction does not save the bank.

Document Extraction Models

A document extraction model, also called an optical character recognition (OCR) or intelligent document processing (IDP) tool, reads an unstructured source document (a PDF paystub, a scanned tax return, a bank statement) and pulls specific fields into structured data. The model is not making a credit judgment. It is reading a page and copying numbers into boxes. This sounds simple. In practice, it is the source of some of the most expensive AI errors in lending.

An extraction model trained on typical paystubs has learned what a paystub usually looks like. When it encounters a non-standard layout (a first-generation gig-economy income statement, a handwritten ledger from a small business, a two-column bilingual tax form), the model may extract numbers from the wrong fields. It will do so confidently, without error flags, because it does not know it is confused. The extracted gross monthly income might be the net income column. The "monthly" figure might be a biweekly pay period that was not converted. In the loan origination system (LOS, the software platform that manages the loan application from intake through closing), these extracted fields flow directly into underwriting calculations. A $3,600 income that should be $5,400 changes the debt-to-income ratio. A changed debt-to-income ratio changes the credit decision. A wrong credit decision based on a wrong extraction is a real harm to a real borrower, and the bank's name is on the denial notice regardless of which model made the error.

The compliance obligation for extraction is straightforward but demanding: every extracted number must be verified against the source document. This is not optional. It is not a quality-control nicety. It is the minimum professional standard for using an extraction tool in a regulated lending environment.

Generative Drafting Models

A generative AI model (a large language model or LLM) takes a text prompt and produces text output. It can draft a credit memo, summarize a loan file, write a plain-language adverse-action notice, or answer a question about credit policy. Generative AI is the category that has attracted the most attention in 2025 and 2026, and it is the category with the most complex failure mode: confident fabrication.

A generative model does not look up facts. It predicts the most plausible next word given everything it has been trained on. When it is asked to summarize a borrower's income from a loan file, it will produce a plausible-sounding summary. If the file clearly shows $7,200 per month in W-2 income, the summary will probably say $7,200 per month. If the file is ambiguous, or if the model is not grounded on the actual document and is instead working from memory, the model may produce a figure that sounds right and is wrong. It will not signal the difference. The borrower's income in the summary will be stated with the same confident fluency regardless of whether the model read it accurately or generated it from statistical patterns in its training data.

This failure mode is called hallucination in the AI literature. In a lending context, the consequences are not abstract. An invented income figure in a credit memo can support a decision the actual income does not support. A fabricated loan covenant in a commercial credit summary can expose the bank to a claim that the covenant was agreed to. A wrong adverse-action reason, like the one that started this lesson, can generate a regulatory examination and a borrower complaint that takes six months and significant legal cost to resolve.

The model did not lie. It generated the most plausible text given its training. In lending, "most plausible" and "most accurate" are not the same thing, and the difference costs money.

The single most important concept for a banker deploying any form of AI is what the compliance community calls the legal asymmetry of lending decisions. An approval needs no explanation. A denial does. This is not a preference or a best practice. It is federal law.

When a bank approves a credit application, no statute requires it to explain why. The applicant got the credit they wanted. When a bank denies or counterproposes (offering less credit, a higher rate, or different terms than the applicant requested), the ECOA and Regulation B framework kicks in immediately. The adverse-action notice must be provided within specific timeframes (30 days for a complete application), must name specific, accurate reasons, and must not be the product of a process that produced disparate impact on protected classes. The word "specific" matters. The word "accurate" matters. A reason that is specific but inaccurate, like the rental history example at the beginning of this lesson, satisfies neither requirement.

This asymmetry creates a fundamental design constraint for AI in lending: any model that influences a denial must be explainable enough to generate specific, accurate adverse-action reasons. A "black box" model that produces a score without a mechanism for translating that score into specific reasons tied to the applicant's actual data is not just a technical inconvenience. It is a legal liability. The bank using it cannot generate compliant adverse-action notices. It cannot defend against a disparate-impact claim without understanding what factors drove decisions across the protected-class population. It cannot satisfy OCC Bulletin 2026-13's expectation that models be documented, validated, and subject to ongoing performance monitoring.

The asymmetry also explains why "the model said no" is never a legally sufficient adverse-action reason. ECOA and Regulation B do not recognize AI models as decision-makers. They recognize the creditor as the decision-maker. The lender, underwriter, or analyst who signs the adverse-action notice is accountable for the stated reasons. That accountability does not transfer to the model vendor, the LOS platform, or the algorithm. It stays with the institution and, in specific circumstances, with named individuals within it.

What AI Is Not in a Lending Context

Clearing away the wrong mental models is as important as building the right ones. Four misconceptions cause the most operational and compliance damage.

AI does not approve or deny loans. This is the most common misframing and the most dangerous. An AI model produces a score, a recommendation, a pre-qualification flag, or a draft document. The credit decision under ECOA is made by the creditor, which is the institution. The human underwriter who reviews the pre-score, applies policy exceptions, and signs the file is the decision-maker. A bank that allows an AI model to function as the operative decision-maker without a documented human review has designed a workflow that cannot produce defensible adverse-action notices and will not survive a fair-lending examination under OCC Bulletin 2026-13.

AI does not know what it does not know. A scoring model trained on 2019 to 2023 data does not know that a borrower's industry was disrupted in 2024 and that the historical income patterns no longer reflect current earning capacity. A generative model asked to summarize a file does not know that the paystub in the file is from a different employer than the one listed on the application. The models produce outputs that are internally consistent with their training and inputs. They do not flag their own blind spots. The banker's job is to bring contextual knowledge that the model cannot have.

AI does not replace domain expertise; it requires it. A loan officer who does not know what a compliant adverse-action notice looks like cannot tell when an AI-generated draft is wrong. An underwriter who has never seen a self-employed borrower's tax return cannot spot an extraction error on Schedule C. The value of AI in lending increases directly with the user's domain knowledge, because domain knowledge is the tool the user has to catch errors before they become regulatory problems. The banker who is most at risk from AI is not the most experienced one. It is the newest analyst who does not yet know what "plausible" looks like versus "accurate."

AI is not a compliance shortcut. Banks that deploy AI hoping to process more applications with less compliance review are running the analysis backward. AI can increase the volume of decisions a team processes. It cannot reduce the compliance obligation attached to each decision. Each adverse action still requires a specific, accurate reason. Each model still requires validation and ongoing monitoring under OCC Bulletin 2026-13. Each use of data that could serve as a proxy variable still requires disparate-impact testing. The speed gain from AI does not reduce any of these obligations. It multiplies them across a larger volume of decisions, which means the cost of a systematic error is higher, not lower.

The Three AIs in Your Loan Origination System

To make the abstract concrete, consider a single mortgage application moving through a modern LOS from intake to decision. It is almost certainly being touched by all three AI types described above, often without the loan officer's awareness of which is which.

When the application comes in and the borrower uploads a PDF paystub, an extraction model reads the document and populates income fields in the LOS. This is category two: document extraction. The model is doing OCR plus field classification, and its output flows directly into the underwriting engine's income calculation. If the model misread the period (monthly versus biweekly) or extracted from the wrong field, the income figure in the LOS is wrong before a human has seen it.

Once the income and asset fields are populated, the LOS may run a pre-scoring model that takes the structured application data (credit score, debt-to-income ratio, loan-to-value ratio, income stability indicators) and produces a risk score or a tiered recommendation (approve, refer, decline). This is category one: scoring and classification. The model is consuming structured data and producing a score. Its output is not a credit decision. It is an input to a credit decision. The underwriter who receives the referred file is the one who makes the decision, applies exceptions, weighs non-quantitative factors, and signs the adverse-action notice if the answer is no.

If the answer is no, the loan officer or underwriter may use a generative AI tool to draft the adverse-action notice or the credit memo explaining the denial. This is category three: generative drafting. The model produces prose. If it is given the actual underwriting notes and the actual reason for denial, it will probably produce an accurate draft. If it is generating from general patterns about what adverse-action notices usually say, it may produce a fluent, confident notice that states a different reason than the one that actually drove the decision. That is the scenario from the first paragraph of this lesson, and it happens regularly enough that it deserves a specific name: the fabricated reason code failure mode.

One application, three AI types, three failure modes, and a single adverse-action notice at the end that must be specific, accurate, and defensible. This is why understanding the categories matters. The compliance obligation at the end of the pipeline does not care which model made the error.

OCC Bulletin 2026-13 and What It Means for Each AI Type

OCC Bulletin 2026-13, issued in April 2026 as an interagency joint guidance, did three things that directly affect how banks must operate AI in lending. First, it superseded OCC Bulletin 2011-12 (the previous model-risk management guidance) and updated the framework to explicitly cover AI models and generative AI systems. Second, it extended model-risk expectations (documentation, validation, ongoing performance monitoring, independent review, and board governance) to AI tools that were previously treated as technology products rather than models. Third, it pulled AI under fair-lending and third-party risk expectations, meaning that a vendor's AI model used in a credit decision carries the same fair-lending scrutiny as a model built internally.

For scoring and classification models, OCC Bulletin 2026-13 reinforces existing model-risk management expectations and adds specific AI-related requirements around explainability documentation, validation against protected-class outcomes, and ongoing disparate-impact monitoring. A model that was validated in 2022 and has not been re-evaluated since is not compliant with OCC 2026-13 if its performance, data, or operating environment has changed.

For document extraction models, OCC Bulletin 2026-13 is less explicit but the model-risk framework applies: the tool must be documented, its error rates must be understood, and there must be a governance process for reviewing and correcting extraction errors before they reach the credit decision. An extraction tool that has never been evaluated for its error rate on non-standard document formats is an undocumented model risk.

For generative AI models, OCC Bulletin 2026-13 is the most significant change from the prior framework. GenAI tools were not contemplated in OCC 2011-12. The 2026 update treats a generative model used to draft credit-related documents as a model subject to model-risk management requirements: documentation, validation, performance monitoring, and appropriate human review before output is used in a credit decision or sent to a borrower. "The vendor manages the model" is not a sufficient governance answer under OCC 2026-13. The bank is accountable.

Beyond model risk, OCC Bulletin 2026-13 raised the bar for board governance of AI. The board and senior management are expected to understand the AI tools in use, the risks they present, and the controls in place to manage those risks. A board that was briefed on the bank's AI program in 2023 and has not received an update since the 2026 guidance was issued has a governance gap that an examiner will find.

Key Takeaways

  • There are three distinct AI types in lending: scoring and classification models (structured inputs to a score or label), document extraction models (reading unstructured documents to populate structured fields), and generative drafting models (producing prose from prompts). They fail differently and carry different compliance obligations. Treating them as one technology is the root cause of most AI-related compliance problems in banks.
  • The legal asymmetry of lending is the governing constraint for all AI use: an approval needs no explanation, but a denial under ECOA and Regulation B must carry specific, accurate reasons. Any AI model that influences a denial must be explainable enough to support specific reasons tied to the applicant's actual file.
  • "The model said no" is never a legally sufficient adverse-action reason. Accountability for a credit decision stays with the institution and the individuals who sign the file, regardless of how much AI touched the underlying analysis.
  • Generative AI's most dangerous failure mode in lending is the fabricated reason code: a confident, plausible adverse-action notice that states a reason the actual file does not support. This is a statutory violation under ECOA and Regulation B, not a paperwork error.
  • Document extraction models fail silently: a misread paystub populates the LOS with a wrong income figure, which flows into underwriting calculations without flags or error messages. Every extracted number must be verified against the source document before it reaches a credit decision.
  • OCC Bulletin 2026-13, issued April 2026, superseded OCC 2011-12 and extended model-risk, fair-lending, third-party, and board-governance expectations to AI and generative AI. All three AI types described in this lesson are now explicitly covered. "The vendor manages it" is not a sufficient governance position under OCC 2026-13.
  • AI increases the volume of decisions a team can process but does not reduce the compliance obligation attached to each decision. A systematic error in a model that processes 10,000 applications is proportionally more expensive than the same error in a manual process that handles 500. Speed amplifies the cost of being wrong, not the cost of being right.
  • The banker with the most domain expertise gets the most value from AI, because domain expertise is the tool that catches model errors before they reach the borrower. AI literacy and lending expertise are complements, not substitutes.