Invest1 distinct publisher3 min readUpdated
The amended law narrows to loan and account decisions, then demands disclosure up front, source-level explanation after a denial, and a correction path. The build lands on core vendors.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
The hardest sentence in the statute is the one about naming. A denied consumer can demand that every data source be identified by name, including data brokers and intermediaries, along with the specific pieces of personal data used, a way to correct inaccurate data, and meaningful human review [8]. At a typical bank, none of those data relationships belong to the bank. Credit and account-opening decisions run through a core system, most likely from FIS, Fiserv or Jack Henry, with account-opening software such as Alloy's alongside it, and Frank Trotter, CEO of Battle Bank in Avon, Colorado, says all of the vendors banks use are using AI [10][11]. The list a Colorado bank hands a rejected applicant is therefore assembled out of its vendor's suppliers, and quite possibly its vendor's suppliers' suppliers [2]. Trotter expects the vendors to build automated processes for it [11].
Scott Kosnoff of Faegre Drinker told American Banker that the source-naming granularity is a big deal, and that data correction and meaningful human review may require new infrastructure [12]. That sits oddly beside the fact that AI decisioning software usually ships with explainability already in it: Trotter says he can open any denial in his own system and see every factor, an address that does not match a driver's license, or 20 Social Security numbers associated with one license, which reads as fraud [13]. The model is not the gap. The gap is the plumbing around it, an identity-checked request channel and a correction route that writes back into whatever the model consumed [3].
Trotter's own example shows why handing that detail over is uncomfortable. An explanation naming the fraud signal that fired tells whoever receives it exactly which check to defeat next time, and Trotter raised the risk of a criminal impersonating the applicant to get it [14].
The front-end obligation is cheaper, and still not free. Obrea Poindexter of Orrick says "clear and conspicuous" is contextual, and that nine times out of ten the disclosure will not sit in a footnote [4]. Kosnoff says the proposed regulations get specific: plain, straightforward language, readable on all devices including mobile, and no smaller than 12-point font in print [5]. That is a change to the application screen itself, made before the model is consulted rather than after it decides [3][1].
Regulation B already obliges a bank to say why it said no [6]. Colorado adds a second envelope inside the first, carrying instructions on how to ask for the system's name, its developer, and the categories and sources of data behind the outcome [7]. "The concept is fair," Trotter said. "If you've been denied for one reason or another, you should at least have the opportunity to know why" [9]. The bill for that fairness is a file format, an audit trail and a human reviewer, and it is due in January [1].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Obrea Poindexter, a partner at Orrick, said what "clear and conspicuous" means is contextual, and that nine times out of 10 the disclosure will not be in a footnote but presented so the consumer notices it.
Scott Kosnoff, partner at Faegre Drinker, said the proposed regulations add specifics: disclosures must use "plain, straightforward language," be readable on all devices including mobile, and printed disclosures must be in no less than 12-point font.
Colorado recently narrowed its AI Act, which is due to take effect in January, limiting the statute's scope to automated decision-making technology that materially influences "consequential decisions" including approvals for loans and new accounts.
Financial institutions that use AI to make decisions must provide "clear and conspicuous" disclosure to any Colorado customers beforehand.
Any time a bank denies a loan or account it already has to explain why and provide an adverse action notice under federal Regulation B.
Under Colorado's new law, if an AI model materially influenced a denial, the bank must include instructions for the consumer to request additional information about the system used, including its name, its developer, and the types, categories and sources of personal data used.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One trade outlet, named practitioners, no primary text
Requirement descriptions are specific and attributed to two identified law firm partners and a named bank CEO, which is better than anonymous sourcing. But the cluster contains a single publisher, quotes no statutory or regulatory text directly, gives no citation or precise effective date, and leaves the disclosure specifics resting on regulations described as merely proposed. Burden and vendor-behavior claims have no documentary support at all.
AI already pervasive in decisioning; compliance build unobserved
The only adoption signal is one bank CEO's account that decisions already run through AI-using core and onboarding vendors, which establishes that the law lands on live production systems. Nothing in the cluster shows any vendor or bank actually building the required disclosure, by-name lineage, correction or human-review capability — no product announcement, project, or spend. Adoption of the underlying technology is credible and broad; adoption of the compliance response is at zero observed.
Sober reporting with a modestly oversold burden
The account is restrained: it flags that the law was narrowed, quotes a banker calling the concept fair, and hedges the infrastructure question with 'may require'. Mild overstatement comes from the framing of scale and severity — 'significant changes' to core, lending and onboarding software and a top-three-most-aggressive ranking — with no cost, timeline, vendor confirmation or ranking criteria behind it, and with the strictest specifics drawn from proposed rather than final regulations.
Compliance advisers and a regulated CEO in a bank trade outlet
The burden and complexity assessments come from two law firm partners whose practices sell exactly the regulatory-readiness advice the story implies is needed, and from the CEO of a Colorado bank subject to the rule who argues human review would wreck efficiency and that a single federal law would beat a 50-state patchwork. The venue is a banking trade publication whose readership is the regulated industry. No regulator, consumer advocate or vendor counterweight appears.
Requirements clear, consequences unverified
Confidence is moderate: the mechanics of the obligations are described consistently and specifically enough to act on, and the affected production surface is identified. It is held down by single-publisher sourcing, absent primary text, proposed-not-final regulations, an imprecise effective date, an interested source set, no vendor or cost corroboration for the build claims, and a truncated article body.
invest
The card networks just picked the referee for agent checkout, and it looks like EMVCo2 distinct publishers
invest
Model the correspondent line as a decaying annuity, not fixed plumbing1 distinct publisher
invest
Banking's 2026 problem is less the Senate majority than the Banking Committee roster1 distinct publisher
invest
BayFirst's $41.5M cleanup shows what a bad lending niche costs to exit1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 24, 2026