Newsletter·Q2 · May 2026

The AI Regulatory Roundup: Mythos changes everything.

Cutting through the noise of federal guidance, state legislation, and evolving supervisory expectations around AI.

Welcome to the first Verapath Regulatory Roundup. For US financial-services executives, risk leaders, and compliance officers, each quarterly issue delivers what matters most: what’s new, what it means for your institution, and what you need to do about it. Every section follows a consistent format — context, what happened, implications, and concrete action items — so you can scan quickly and go deep where it counts.

The current administration had encouraged AI use, with lighter-touch enforcement. Then Mythos happened. Starting with Treasury Secretary Scott Bessent, the administration has become deeply concerned about the effect of advanced AI on cybersecurity — and, by extension, the banking system and other regulated financials. Be prepared.

What you need to know

  • CRI FS AI RMF. The Cyber Risk Institute’s Financial Services AI Risk Management Framework — released February 2026 with FDIC and US Treasury backing — provides 230 control objectives mapped to NIST’s AI RMF.
  • Colorado AI Act (SB 24-205). Effective June 30, 2026; explicitly provides a safe harbor for institutions that adopt the NIST AI RMF or ISO/IEC 42001.
  • New York RAISE Act. Signed December 19, 2025, effective January 1, 2027; targets large frontier-model developers, but institutions using covered models should monitor obligations and vendor-contract implications.
  • Michigan DIFS Bulletin 2026-03. Effective January 14, 2026; requires a written AI Systems Program for all state-regulated financial-service providers.
  • SEC 2026 Exam Priorities. Embed AI governance across all major categories — from accurate disclosures and anti-“AI washing” to cybersecurity and Regulation S-P.
  • The takeaway. Multi-state institutions face overlapping, sometimes conflicting requirements. Adopting the CRI FS AI RMF is currently the strongest single strategy for demonstrating compliance across jurisdictions.

Inside this issue

Contents

  • Federal: NIST AI RMF & the CRI FS AI RMF; US Treasury AI resources; SEC AI governance, cybersecurity & Regulation S-P; the White House National AI Policy Framework
  • State: Colorado AI Act; New York RAISE Act; California’s layered landscape; Michigan DIFS Bulletin 2026-03
  • Putting it together: a compliance-overlap map
  • Sources & citations

Verapath software facilitates compliance with AI and data-privacy rules — including full audit trails and a built-in e-discovery tool — and includes a CRI AI RMF 1.0 compliance wizard and reporting tool.

Read the full quarterly newsletter, with sources and citations. Download the PDF.
Download the PDF

This newsletter is for informational purposes only and does not constitute legal advice. Please consult qualified legal counsel for guidance specific to your institution.

Back to Resources