Navigating AI Governance: Divergent Paths in US Credit and Medical Device Regulation
This article highlights the critical differences in AI governance between the US consumer financial services and healthcare technology sectors. For internal audit and assurance professionals, understanding these divergent regulatory philosophies is crucial for assessing compliance risks, particularly concerning AI model explainability in credit decisions and adaptive AI in medical devices. The withdrawal of CFPB circulars does not negate statutory obligations, shifting enforcement to a more distributed and complex landscape.
The Evolving Landscape of Sectoral AI Governance
The absence of a unified federal AI Act in the United States has led to a fragmented regulatory environment, where sector-specific agencies dictate the terms of AI deployment. This article draws a sharp contrast between the approaches taken in consumer financial services and healthcare technology, emphasizing that what was once perceived as a difference between aggressive and collaborative enforcement has evolved into a more fundamental divergence. Internal audit professionals must recognize that regulatory expectations are deeply rooted in each sector's historical statutory boundaries, enforcement theories, and technical requirements.
Credit Sector: Explainability as a Statutory Imperative
In the credit market, the Equal Credit Opportunity Act (ECOA) and Regulation B mandate that creditors provide specific reasons for adverse actions. This requirement, designed to ensure transparency, detect discrimination, and empower consumers, remains a cornerstone of the regulatory framework. Even with the withdrawal of CFPB Circulars 2022-03 and 2023-03 in May 2025, the underlying statutory obligation for model explainability persists. These circulars were interpretations, not the source, of the duty. Consequently, the enforcement landscape has shifted from a centralized federal bureau to a more distributed network of state regulators and private plaintiffs. For internal auditors, this means that AI models used in credit decisions must still be capable of generating specific, accurate, and individualized principal reasons for adverse actions, regardless of their statistical performance or the absence of direct federal supervisory attention. The risk of non-compliance, including private rights of action and class litigation, remains significant.
Medical Device Sector: A Framework for Adaptive AI
Conversely, the medical device sector, under the guidance of the FDA, has developed a distinct approach that authorizes adaptive medical AI to evolve in production. This flexibility is contingent upon a robust change control architecture, which was finalized between December 2024 and February 2026. This framework is anchored in Section 515C of the FD&C Act and requires Predetermined Change Control Plans to incorporate three structural pillars, adhere to international principles, and comply with quality system rules that took effect in 2026. For audit and assurance professionals, understanding this architecture is vital for evaluating the compliance of AI-powered medical devices, ensuring that changes in production are managed within pre-authorized boundaries and regulatory expectations.
Key Takeaways for Internal Audit and Assurance
- Statutory vs. Guidance-Based Obligations: Recognize that some AI governance requirements are deeply embedded in statute (e.g., ECOA for credit), making them resilient to changes in agency guidance or enforcement priorities. Others are more dependent on active agency engagement and guidance (e.g., FDA's adaptive AI framework).
- Distributed Enforcement Risk: In sectors like credit, the withdrawal of federal guidance can lead to a more fragmented and unpredictable enforcement environment, with increased risk from state regulators and private litigation.
- Model Explainability: For credit, ensure AI models can provide clear, specific, and individualized reasons for adverse actions. The "black box" defense is not viable.
- Adaptive AI Control: For medical devices, verify that adaptive AI systems operate within established change control architectures, including predetermined boundaries and adherence to quality system rules.
Read more