Auditen
sector watch

The AI is operational. The State AGs are unimpressed.

I’ve spent enough time on both sides of the audit table to know that when a CISO describes their programme as 'mature', it's time to start looking for the bodies. In my experience, 'mature' is usually shorthand for 'we have a very expensive PDF that no one has read since 2023'.

This week, the pressure isn't coming from new, futuristic legislation. It’s coming from State Attorneys General using laws written decades ago to dismantle the current AI implementations in credit unions.

The claim from most financial services firms is that they’re waiting for a specific 'AI Framework' to tell them how to behave. They think they're safe because there isn't a dedicated federal "Robot Act" yet. The evidence suggests otherwise. State AGs are simply applying existing consumer protection and fair lending laws to AI outputs. They don't care if the bias was generated by a neural network or a grumpy loan officer in a basement; the result is an illegal outcome.

Here is where most firms fail my Tuesday test: If I walked into your office on a random Tuesday afternoon and asked you to show me the specific evidence that your AI isn't violating consumer privacy or fair lending laws for a sample of ten loans from last month, what would you actually hand me?

Most will point to a vendor's SOC 2 report or a signed contract where the provider promises the tool is 'compliant'. That doesn't satisfy an auditor. A vendor's assertion that their tool is safe isn't evidence; it's a brochure. Evidence is a log of the inputs, the weightings used for the decision, and a human-led review of the output to ensure it hasn't hallucinated a reason to deny a loan.

The strongest objection I hear is that these systems are 'black boxes' and providing that level of transparency is technically impossible without compromising intellectual property.

That’s a convenient excuse for the vendor, but it’s a legal liability for the firm using the tool. If you can't explain how your system reached a conclusion, you shouldn't be using it to make decisions that affect people's lives. The regulator isn't interested in the 'magic' of the algorithm; they're interested in the legality of the result.

The second-order effect here is already starting to bleed into the supply chain. We're seeing a ripple effect where the pressure on credit unions is turning into an existential crisis for Managed Service Providers (MSPs).

Look at the CMMC Phase II suspension. Government contractors are already sweating over their compliance risks, and the MSPs who support them are caught in the middle. When the State AGs finish with the credit unions, they'll move up the chain to the software providers. We’re moving toward a world where 'the vendor told me it was fine' becomes an admission of negligence rather than a defense.

We've seen this pattern before. Just look at the SplitVPN breach that exposed personal records for just over 865,000 users. The failure wasn't some exotic new hack; it was basic hygiene. Now, we're seeing similar gaps in AI governance. Firms are deploying tools that can process millions of data points but can't produce a single audit trail that survives five minutes of scrutiny.

The financial stakes are becoming visible too. While we see firms like ZeroStack reporting revenues around $13.6 million, the volatility of these 'AI-first' companies is often masked by growth figures that ignore the looming cost of regulatory correction. If you're spending your budget on more GPU power instead of a human who knows how to sample a dataset for bias, you're just building a faster car with no brakes.

I suspect we’ll see a surge in 'compliance consulting' firms promising to fix this with new dashboards. Ignore them. A dashboard is just a picture of the problem; it isn't a control.

The only thing that matters is what happens when the auditor asks for the raw data. If your answer involves a PowerPoint slide about your 'AI journey', you've already lost.

Watch the State AGs over the next few months. The moment one of them successfully sues a credit union for an AI-driven lending violation, every single MSP in the sector will find their contracts being rewritten overnight to shift 100% of the liability onto the vendor.

I wonder how many vendors are actually prepared to sign those indemnity clauses.