The NCUA has issued no AI-specific rules. It also cannot examine the third-party vendors that build and sell credit unions their AI. What still binds you sits in Part 748, the 72-hour incident rule and Regulation B, and this article maps all of it into one table.
NCUA says so itself, in writing
The agency keeps an artificial intelligence page, last updated in April 2026. Asked on that page whether it has AI-specific regulations, NCUA answers: "No. NCUA has not issued AI specific rules or regulation. However, existing regulations are technology-neutral and apply to AI use."
The same page tells you where to go for AI vendor due diligence. The only NCUA-issued documents it points to are Letter 07-CU-13, "Evaluating Third Party Relationships," from December 2007, and Letter 01-CU-20, "Due Diligence Over Third Party Service Providers," from November 2001. A page refreshed in 2026 governs AI vendor risk with guidance written in 2001 and 2007.
Ninety percent of the assets, none of the authority
The reason that 2007 letter is still doing the work is structural. NCUA cannot examine third-party technology providers. The federal banking agencies can, under the Bank Service Company Act. NCUA lost the equivalent authority when the Examination Parity and Year 2000 Readiness for Financial Institutions Act expired, and for years it asked Congress to restore it.
In October 2024, then-Chairman Todd Harper put a number on the consequence. "Approximately 90 percent of the industry's assets are managed by third-party service providers with no NCUA oversight," he said in a statement following the agency's annual cybersecurity briefing. In the same statement he noted that credit unions had reported nearly 1,100 cyber incidents over the prior year, and that seven out of ten involved a third party.
Be careful with that seven-in-ten figure, because most people quoting it have not checked the date. It covers the window ending August 2024. NCUA has not published the third-party share since. Its most recent report to Congress, covering May 2025 through April 2026, gives a total of 588 incidents and leaves the vendor split out entirely.
Credit unions do have one lever, and it is narrow. Under 12 CFR 712.3(d)(3), a credit union that lends to, invests in, or holds a contract for products or services with a CUSO must obtain a written agreement giving NCUA and the state supervisory authority "complete access to any books and records of the CUSO." That third prong is the one most likely to cover an AI product, so read your agreements before assuming you have no reach at all. A core processor you have no CUSO relationship with sits outside it, and so does the cloud underneath.
The GAO has said all of this in an AI context specifically. Its May 2025 report on AI use and oversight in financial services found that NCUA "lacks the authority to examine technology service providers, despite credit unions' increasing reliance on them for AI-driven services," and separately that NCUA's model risk guidance "is limited in scope and detail and does not provide its staff or credit unions with sufficient detail on how credit unions should manage model risks, including AI models." Both recommendations remain open. GAO first asked Congress to grant the vendor authority in 2015, and reported that as of February 2025 Congress still had not.
NCUA stopped asking. Congress just started.
NCUA's June 2024 report to Congress made the request explicitly. It called the situation a growing regulatory blind spot, and Harper wrote that he "respectfully ask[ed] for this Committee's support in restoring the NCUA's vendor authority over third-party service providers."
The 2025 report does not contain the phrase "vendor authority." Neither does the June 2026 report. Chairman Kyle Hauptman's written testimony to the Senate Banking Committee in February 2026 leaves it out too; vendors come up there only in a digital assets context. Across three consecutive documents, the agency has gone quiet about the thing it spent years calling a blind spot.
Context a reader deserves: those documents come from an NCUA board reduced to Hauptman alone since April 2025, when the other two members were removed. Their removal is in litigation. Read the silence as the current board's posture rather than a settled agency position.
Meanwhile, on September 2, 2026, Representative Bill Foster introduced H.R. 10230, the Strengthening Oversight for the Financial Sector Act of 2026, which would amend the Federal Credit Union Act to give NCUA exactly that authority over credit union service providers. Foster's stated rationale is AI. "As AI makes cyberattacks more sophisticated, it is even more important to ensure that third-party vendors don't become a weak link in our financial system," he said, per FedScoop.
It is a bill, introduced, with no committee action. A similar Foster bill reportedly cleared committee in 2022 and never got a floor vote. At least one credit union trade group is against this one: the Defense Credit Union Council's CEO Anthony Hernandez said that "granting NCUA sweeping authority over the full range of credit union service providers is not a narrowly tailored cybersecurity solution," per Credit Union Daily.
Plan for the gap staying open. If it closes, your own diligence still stands.
What the 2026 supervisory priorities letter actually says
Several vendor blogs currently claim that NCUA named AI oversight as an examiner focus area in its January 2026 supervisory priorities letter. It did not. Open 26-CU-01 and search it. The words "artificial intelligence" are absent. So is "AI." So is "ACET."
What the letter says about cybersecurity deserves quoting properly, because the opposite exaggeration is also circulating. Cybersecurity was not removed. It lost its own section and became a paragraph, and that paragraph still reads: "cybersecurity is one of the NCUA's top supervisory priorities and a top-tier risk under the agency's enterprise risk-management program." Examiners will assess "effective governance, risk assessments, vendor management, and security frameworks."
There is a sharper piece of evidence in NCUA's own words. In the eighteen-page cybersecurity report it transmitted to Congress in June 2026, artificial intelligence appears as something attackers have. Malicious actors are "increasingly leveraging generative AI to accelerate the speed, precision, and sophistication of attacks against financial institutions," the report says, and emerging agentic capabilities "further reduce the need for human intervention, enabling attackers to operate at greater scale." AI as a technology credit unions deploy, and must therefore govern, does not appear. The same report names the structural problem without connecting it to AI: institutions face "system integration complexity, lack of service provider diversity, and vendor lock-in."
The closest thing NCUA has published to an AI governance expectation is Letter 24-CU-02 from October 2024, on board engagement in cybersecurity oversight. It tells boards to establish a framework for periodic reporting, set expectations for third-party vendor due diligence, require contracts to include specific cybersecurity requirements like timely notification, and run tabletop exercises. Every one of those maps cleanly onto an AI deployment. The letter was written about cybersecurity oversight generally, not about AI.
Where AI will actually land in your exam
Since AI has no section in the priorities letter, the practical question is which examination artifact carries the questions. For most credit unions that is the Information Security Examination procedures, rolled out in 2023 and built to scale by asset size and complexity. NCUA describes the ISE as "a risk-focused, scalable approach tailored to each credit union's business model," with an examiner toolbox drawing on NIST, CIS and CISA material.
ACET, the maturity assessment, sits alongside it and remains voluntary. NCUA's own language: "The ACET maturity assessment is completely voluntary and does not introduce any new requirements or expectations on credit unions." It was remapped to NIST Cybersecurity Framework 2.0 in September 2025.
The useful implication is that an AI question will reach you dressed as an information security question. Not "show us your AI policy," but show us the risk assessment, the vendor due diligence file, the access controls on member information, the incident response plan. Prepare the evidence in that shape and you have answered both.
Worth knowing how long the gap between looks can be. A federal credit union under $1 billion in assets, rated CAMELS 1 or 2 and not under an enforcement action, is on a cycle of 14 to under 18 months. A model can go into production and run through two Novembers before an examiner sees it.
Adverse action: the one AI duty that survived
Three things changed in the last eighteen months, and most coverage gets at least one of them wrong.
The CFPB withdrew both of its adverse-action circulars on May 12, 2025. Circular 2022-03, the one that said yes, you still owe specific reasons even when a complex algorithm made the decision, is gone from the Bureau's enforcement posture. So is Circular 2023-03. The withdrawal notice says the Bureau "does not intend to prioritize the enforcement of such guidance," and that the withdrawal "is not necessarily final."
Regulation B itself was then rewritten. A final rule at 91 FR 21620, published April 22, 2026 and effective July 21, 2026, amended section 1002.6(a) to state that the Act "does not provide that the 'effects test' applies for determining whether there is discrimination in violation of the Act." Disparate impact under ECOA is disclaimed in the regulation's own text. That rule faces an Administrative Procedure Act challenge, National Fair Housing Alliance et al. v. CFPB in the District of Columbia, but plaintiffs did not seek a preliminary injunction, so it is in force.
NCUA then told its own examiners to stop. Letter 25-CU-04, September 2025, removed disparate impact from the Fair Lending Guide and directed examiners to cease requesting, reviewing, or concluding on disparate impact analysis, citing Executive Order 14281. Fair lending exams continue for disparate treatment and HMDA analysis.
Now the part that held. 12 CFR 1002.9(b)(2) still reads: "The statement of reasons for adverse action required by paragraph (a)(2)(i) of this section must be specific and indicate the principal reason(s) for the adverse action. Statements that the adverse action was based on the creditor's internal standards or policies or that the applicant, joint applicant, or similar party failed to achieve a qualifying score on the creditor's credit scoring system are insufficient." The 2026 rewrite left that section alone.
A credit union that cannot say why its model declined a member is out of compliance, with or without a circular saying so. The duty runs to every creditor under ECOA whatever the charter. Who examines you for it depends on the charter: NCUA enforces ECOA and Regulation B directly in federal credit unions, 2,672 of the 4,250 federally insured institutions, while federally insured state-chartered credit unions sit on a different supervisory path. For anyone below $10 billion in assets, the CFPB's retreat is not what determines the exposure.
The interagency Quality Control Standards for Automated Valuation Models are also in force, with NCUA one of six promulgating agencies. That one is a rule rather than guidance, it governs a category of model plenty of credit unions use in mortgage lending, and the withdrawal wave left it untouched.
What still binds a credit union using AI
| Obligation | Where it comes from | Status as of September 2026 |
|---|---|---|
| Written security program; board-approved information security policy; service-provider due diligence, contract terms and monitoring | 12 CFR 748.0 and Part 748, Appendix A | In force |
| 72-hour notification of a reportable cyber incident, including one caused by a CUSO, cloud provider or other third-party data host | 12 CFR 748.1(c) | In force since September 1, 2023 |
| Specific reasons for adverse action; a failed model score is not enough | 12 CFR 1002.9(b)(2) | Unchanged by the 2026 Regulation B rewrite |
| Quality control standards for automated valuation models | Interagency rule; NCUA one of six promulgating agencies | In force |
| Board oversight, vendor contract terms, tabletop exercises | Letter 24-CU-02, October 2024 | Guidance |
| AI-specific requirements | None | NCUA: "has not issued AI specific rules or regulation" |
The 72-hour clock starts when your vendor calls
The incident rule has three triggers. The third, at 748.1(c)(1)(i)(C), covers "a disruption of business operations or unauthorized access to sensitive data facilitated through, or caused by, a compromise of a credit union service organization, cloud service provider, or other third-party data hosting provider or by a supply chain compromise."
Read that against how credit unions actually acquire AI. Most do not build models. They get AI because a core processor shipped a feature, a CUSO added a product, or a member-service platform turned on an assistant. As of December 2025 there were 1,127 registered CUSOs, 258 of them providing IT services. The clock in that rule can start when a third party notifies you, and the notification obligation is yours either way.
Concentration makes this sharper. Callahan's market data, self-reported by the participating vendors, puts Fiserv at 25.9% of credit union core clients and Jack Henry at 12.0% as of midyear 2025, together serving 37.9% of all credit unions. The Symitar platform alone runs at 699 credit unions across three providers, roughly 15.7% of the industry.
Two events show what that looks like in practice. On November 26, 2023, an attack on Ongoing Operations, a cloud provider owned by Trellance, disrupted daily operations at about sixty credit unions at once; trade coverage attributed it to ransomware. Harper cited the event, without naming the vendor, in his October 2024 statement: "a single third-party service provider's cybersecurity incident disrupted the daily operations of 60 credit unions."
The second is quieter and, for this rule, more instructive. Marquis Software Solutions was breached on August 14, 2025 through a compromised SonicWall device, affecting 74 banks and credit unions and 672,075 individuals per state attorney general filings. Reporting indicates the institutions were not notified until late October. Your 72 hours are fast. Ten weeks of vendor silence in front of them is the part no policy document controls.
Small teams, volunteer boards, and no staffing data
Generic banking advice fails here for reasons that have nothing to do with regulation.
There were 4,250 federally insured credit unions as of March 31, 2026. The median holds $66.1 million in assets. Three quarters are smaller than $275 million and nine in ten are smaller than $1.1 billion, so an institution in the low billions is already in the top tier of a very small industry. The 466 credit unions at $1 billion and above hold 79% of system assets between them. Everyone else is dividing the rest.
NCUA leaned on this when it argued for vendor authority. In its March 2022 position paper the agency wrote that many credit unions are small, with volunteer-based boards, and that those volunteers "do not possess the clout and subject matter expertise necessary to fully monitor their service providers." The regulator's own case for more power rests on its supervised institutions being outgunned by their vendors.
Adoption is running ahead of governance. In a survey of 100 credit union executives fielded in late 2025, Wipfli found 66% actively implementing AI solutions while only 16% reported an enterprise-wide AI roadmap that includes governance frameworks and measurable business impact. The top barriers named were cybersecurity concerns at 70% and fraud risk at 65%. A further 2% reported that individuals and teams are experimenting with AI tools independently, which is the only credit-union-specific shadow AI figure we could find that rests on a real sample.
On staffing, there is no published data on how many people run security at a $500 million credit union. We looked. Not headcount, not the share with a dedicated CISO, not security spend as a share of operating expense. Cornerstone sells that benchmark and does not publish it. Anyone quoting you a credit union security staffing number is quoting something they cannot source.
One structural point that deserves more attention than it gets: the supervisory committee is the body that would own an AI audit engagement at most credit unions, and Part 715 governs what it can outsource. If your AI governance plan has no line for the supervisory committee, it has no internal audit path.
Seven questions for the vendor selling you AI
- If your product contributes to a credit decision, can it produce the specific principal reasons for a denial in the form 12 CFR 1002.9(b)(2) requires, for every declined application, without us reconstructing it?
- Does our contract oblige you to notify us fast enough that we can still meet a 72-hour clock that starts when you tell us?
- Which of your subprocessors can reach member information, and does our right to review controls survive down to them?
- Where does member data go at inference time, is it retained, and is it used for training?
- If you are a CUSO, does our agreement carry the 712.3(d)(3) access language, and has it ever been exercised?
- What changed in your model in the last twelve months, and how would we have known?
- Can you give us an exportable log of every AI-assisted action taken on our members' accounts, in a form an examiner can read?
A vendor that cannot answer the first and the last has not made the AI governable at your institution yet, whatever the contract says. Our 50-question AI vendor security questionnaire covers the rest of the diligence set, and the financial services AI security playbook covers the wider regulatory picture. If you are comparing notes with a bank peer, the banking side of this story runs the opposite way: more rulebook, same exposure.
Where to start this quarter
Inventory, and not the one your core processor hands you. Every control after this presumes you know which AI is running, who turned it on, and what member data it can reach. That includes the assistants your staff opened in a browser tab, the category with no contract behind it.
Then map what you find onto the obligations in the table above rather than onto an AI framework. Examiners will ask about your security program, your vendor due diligence, your incident response and your adverse-action notices. AI is simply where those questions now land. Workforce AI Governance answers the first two with evidence rather than an assertion, and our financial services overview covers the rest of the sector.
The practical version of everything above: a security function of one to five people, a volunteer supervisory committee, an examiner every 14 to 18 months, and an AI capability that arrived inside somebody else's product. None of the documents in this article is going to change that arrangement this year. The inventory is the one piece of it you control.
What credit union teams ask us about this
Does NCUA examine our AI vendor?
No. NCUA has no authority to examine third-party technology service providers, which is why GAO has recommended since 2015 that Congress grant it. Your direct reach is contractual, and under 12 CFR 712.3(d)(3) it applies to CUSOs you have lent to, invested in, or contracted with.
Our core processor added AI features. Do we have to do anything?
Yes. Part 748 Appendix A requires due diligence in selecting service providers, contract terms requiring appropriate safeguards, and monitoring to confirm they satisfied those obligations. A feature you did not procure is still a service your members' data flows through. NCUA's AI page sets the expectation directly: understand how the product functions, the risks it introduces, and the vendor's safeguards and controls.
Is an AI chatbot outage a reportable cyber incident?
It depends on cause and effect rather than on the technology. The rule is triggered by a disruption of business operations or vital member services from a cyberattack or exploitation of a vulnerability, or by a third-party compromise. A vendor capacity problem with no security cause falls outside it. A vendor breach that takes the assistant down is inside it, and your 72 hours can start when the vendor notifies you.
Did the CFPB changes remove our adverse-action obligation?
No. The circulars interpreting it were withdrawn in May 2025 and Regulation B's disparate-impact language changed in July 2026, but 12 CFR 1002.9(b)(2) is untouched and still says a failed score on a credit scoring system is an insufficient reason for a denial.
We have no AI policy. Is that an examination finding?
There is no rule requiring one, because NCUA has issued no AI-specific regulation. What an examiner can cite you for already exists: an information security program that does not cover the tool, vendor due diligence you cannot evidence, an incident response plan that ignores third-party compromise, or adverse-action notices a model cannot explain. Write the policy if it helps you organize those. The findings will come from the older obligations.
Regulatory positions in this article were verified against primary sources on September 11, 2026. Several items are moving: NCUA has proposed relocating Part 748 Appendix A out of the CFR, the 2026 Regulation B rule is under litigation, and H.R. 10230 has only been introduced. Check current status before relying on any of them.