Why US Bankers Are Asking for the AI Rules Europe Already Has
By Anove
A recent American Banker opinion piece points to an unusual reversal. US bankers, an industry built on decades of prescriptive federal rulebooks, are now the ones asking regulators for clearer, more detailed AI rules. Their European counterparts, who operate under the EU AI Act, are not necessarily happier about their obligations, but they at least know what the obligations are. The gap in comfort is not about who is more or less regulated. It is about who has something concrete to build against.
An industry used to being told exactly what to do
US banking has never lacked for rules. Model risk management under SR 11-7, capital planning under CCAR, and fair lending law are all prescriptive, examined, and well understood by compliance teams who have spent careers working inside them. AI is the first major technology wave where that muscle memory does not have an obvious rulebook to attach to. The NIST AI Risk Management Framework exists, but it is voluntary and deliberately non-prescriptive. Beyond that, banks are largely left to interpret how decades-old model governance guidance applies to large language models, agentic tools, and third-party AI embedded in vendor software.
Why no rules is harder than strict rules
A regulatory vacuum sounds like freedom, but for an examined industry it usually means the opposite. Without a fixed reference point, compliance teams have to build their own AI governance policy and hope it holds up when an examiner looks at it later, possibly under standards nobody has written down yet. That is a much harder position than working against a defined rule, even a demanding one. It also makes internal sign off slower: a risk committee approving an AI use case has no external benchmark to point to, only its own judgment.
What the EU AI Act gives European banks that the US does not have
Whatever their complaints about the EU AI Act's compliance burden, European banks are working from a known map. Credit scoring and other AI used in access to essential services falls under the Act's high-risk category, with defined obligations around documentation, conformity assessment, and registration. Providers of general-purpose AI models have had documentation and risk assessment duties in force since August 2025, and transparency obligations for systems like chatbots land this August, as we covered in our recent look at what the Digital Omnibus delayed and what still applies. The dates have shifted, but the categories, the obligations, and the regulator have not. That certainty is worth more to a compliance function than people often assume.
The signal for GRC teams and for anyone selling into regulated industries
For GRC and AI risk professionals, the lesson is not to wait for a US equivalent of the AI Act before building a governance program. Examiners will eventually ask questions about AI the same way they ask about any other model today, and the banks that already have documented inventories, risk tiers, and evidence trails will be in a far better position than those still waiting for a rulebook to arrive. For entrepreneurs and tech founders selling compliance or governance tooling into banking and other regulated industries, this is a useful data point: buyers are not holding out for a mandate. A prescriptive-minded compliance culture wants structure now, and will pay for a credible framework even in the absence of a formal one.
How insAIght helps
This is precisely the gap Anove's insAIght platform is built to close. It gives risk, compliance, and audit teams a live inventory of the AI systems in use, maps each one against the frameworks that already exist, including SR 11-7, the NIST AI RMF, the EU AI Act, and ISO/IEC 42001, and keeps the supporting evidence current. Banks do not need to wait for a US AI Act to get the same certainty their European peers already have; they can build it themselves, continuously, rather than reconstructing it under an examiner's deadline. For a quick first read on whether the AI tools already in use would hold up to that kind of scrutiny, ExplAIn is a useful starting point.
The takeaway
US bankers asking for more AI regulation is not nostalgia for red tape. It is a request for something to build against, which is exactly what a mature governance program provides whether or not a regulator has written it into law yet.
Source: American Banker, 'Why do US bankers want more AI regulation than Europeans?'
Learn more
- insAIght: Anove's AI governance and risk platform for continuous, audit-ready compliance.
- ExplAIn: check whether the AI tools you use are compliant.
- EU AI Act 2026: What the Digital Omnibus Delayed, and What Still Applies This August: the regulatory certainty US banks are now asking for.
Book a demo to see how insAIght gives your AI governance the same audit-ready structure, with or without a rulebook forcing the issue.