Regulation — housing-specific
CFPB Circulars 2022-03 + 2023-03 — AI adverse-action + AI-marketing UDAAP
Two CFPB circulars put AI-driven lending inside supervisory enforcement reach without waiting for new statute. Circular 2022-03 addresses adverse-action reason-code accuracy. Circular 2023-03 addresses AI-marketing steering as UDAAP. Both are actively cited in CFPB supervisory exams as of 2025-2026.
What the regulations actually say
"ECOA and Regulation B require creditors to provide statements of specific reasons to applicants against whom adverse action is taken. Creditors cannot justify noncompliance with ECOA and Regulation B's requirements based on the mere fact that the technology they use to evaluate credit applications is too complicated or opaque to understand."
CFPB Circular 2022-03 (May 2022) — adverse-action reason-code accuracy
"The CFPB is issuing this Circular to affirm that consumer financial protection law requires companies to take responsibility for their business practices, including the use of chatbots and generative AI. … A representation by a covered person that the technology could not have made an error … or that the technology's output is beyond the company's control, is unlikely to relieve the covered person of liability."
CFPB Circular 2023-03 (September 2023) — AI-marketing + chatbot UDAAP
What this means in plain English
- "The model is a black box" is not a defense. If the AI drives an adverse action, the lender still owes the applicant a specific, accurate reason. Vendor opacity does not shift the liability.
- AI-driven steering is UDAAP-reachable. Marketing audience generation, pre-approval routing, and chat-driven guidance all sit inside the same unfair / deceptive standard as human-driven equivalents.
What triggers the exposure in the sample
Every H3 decline notice from the drift window carries a reason code produced by an AI whose distributional-shape had already drifted. If the stated reason was "credit tier" or "DTI" but the actual driver was a model-baked H3 offset amplified by shifted inputs, the reason code is not accurate under Circular 2022-03. Circular 2023-03 adds a second track for any AI-marketing outreach that pre-qualified H3 files before submission.
What the $499 Snapshot shows against these rules
- Model version + input snapshot + decision hash per sampled decision — the reason-code traceability record
- Dated distributional-drift record showing the model was operating outside baseline — the accuracy-check foundation
- 3 fix-first items scoped to freeze / hold + notification chain — the "reasonable action taken" record
- Independent-verifier declaration — the "we did not rely on the vendor's opaque module" record
$499 Snapshot. 3 business days.
Independent-verifier determination + reason-code traceability record + 3 fix-first items.
Buy $499
Snapshot credit applies to Baseline ($2,500) or Enterprise Attestation ($35-55K) upgrade within 30 days.