Reflections on US Treasury Department Report on AI in Financial Services
SUMMARY
The New York City Bar Association’s Presidential Task Force on Artificial Intelligence and Digital Technologies released a report discussing the United States Department of the Treasury report on Artificial Intelligence in Financial Services – Report on the Uses, Opportunities, and Risks of Artificial Intelligence in Financial Services. The Task Force’s report highlights the Treasury’s top policy considerations and provides reflections on those recommendations.
The U.S. Treasury’s report outlines the evolving landscape of artificial intelligence (AI) in the financial sector, particularly the shift from traditional AI to Generative AI, which allows the creation of new content. Key challenges include the need for substantial training data, reliance on third-party developers, the complexity of Generative AI models, and the risk of inaccuracies (“hallucinations”). The report highlights recommendations from industry stakeholders, such as aligning AI definitions across jurisdictions, enhancing consumer protections, and establishing consistent regulatory frameworks to prevent regulatory arbitrage. The Treasury calls for improved interagency coordination, public-private partnerships, and international collaboration, while acknowledging the need for clear guidelines on AI governance, data privacy, and consumer protection. The Task Force believes that regulatory clarity and consistency of approach should be seen as “must-haves” to ensure responsible AI adoption and technical innovation in the financial services sector. The report also suggests a regulatory gap analysis and the importance of risk management frameworks, especially for smaller financial firms, to ensure responsible AI adoption.
REPORT
REFLECTIONS ON US TREASURY DEPARTMENT DECEMBER 2024 REPORT ON ARTIFICIAL INTELLIGENCE IN FINANCIAL SERVICES
In December 2024, the United States Department of the Treasury (Treasury) issued its report on Artificial Intelligence in Financial Services – Report on the Uses, Opportunities, and Risks of Artificial Intelligence in Financial Services (Report).[1] The Report is the result of a request for information (RFI) that Treasury issued on June 12, 2024, seeking input from various stakeholders on the deployment of artificial intelligence (AI) within the financial services sector.[2] The Report summarizes comments received in response to the RFI, followed by Treasury’s own policy considerations and proposed next steps. In this summary, the New York City Bar Association’s Presidential Task Force on Artificial Intelligence and Digital Technologies (Task Force)[3] highlights Treasury’s top policy considerations and provides reflections[4] on those recommendations.
I. BACKGROUND PROVIDED BY TREASURY’S REPORT
The Report notes that financial firms have long deployed AI systems within their operations, although almost all uses were what the Report terms “traditional AI”, namely, using AI to analyze statistical models where the AI was trained on a dataset with defined input and output parameters. However, the broad introduction of “Generative AI” – marked by its ability to create new content based on learnings from training data – in the last two years has shifted this paradigm by allowing financial service firms to use AI to generate entirely new content. The responses to the RFI revealed that financial firms are still adapting to this new reality, presenting certain unique differentiators from “traditional AI”:
- Generative AI models require vast amounts of training data as well as different training methodologies;
- Financial firms often rely on third-parties to develop and deploy these models, exposing firms to the risks associated with reliance on third-parties;
- Many models are open-source (while the exact definition of the term “open-source” is often contentious, it may be generally understood as certain aspects of a model’s code may be publicly available);
- Generative AI models require “significantly more advanced expertise, higher computational power, and more substantial financial investment” than traditional AI models, possibly resulting in smaller financial firms being placed at a disadvantage;
- Generative AI models are more complex and can generate false, but seemingly correct, information (a result commonly referred to as “hallucinations”), presenting challenges for AI governance and management.
The Report further highlighted the work that Treasury has done to date relating to both traditional and Generative AI, including addressing issues of concern relating to AI and financial stability via the Financial Stability Oversight Council as well as the role of AI in anti-money laundering, and countering the financing of terrorism.
II. RECOMMENDATIONS BASED ON RFI RESPONSES
Treasury summarized the recommendations made by various RFI respondents including:
- Aligning definitions of AI models and systems applicable to the financial services sector, including considering definitions adopted by the Organization for Economic Co-operation and Development and the European Union.
- Providing additional clarification on standards for data privacy, security, and quality for financial firms developing and deploying AI, specifically methods and strategies for fine tuning and data curation to ensure the availability of high-quality data for training. Respondents also raised concerns regarding data security and the risk of “data poisoning.”
- Expanding consumer protections to mitigate consumer harm from opaque data collection, privacy violations, and exacerbation of biases.
- Clarifying how to ensure uniform compliance with current consumer protection laws as applied to emerging technologies.
- Creating uniformity of regulation to avoid regulatory arbitrage from varying levels of oversight across financial firms and jurisdictions.
- Pursuing public-private partnerships to share information and best practices both between the financial sector and the government, but also across various industries.
It remains to be seen whether Treasury or other government agencies will act on these recommendations.
III. TREASURY’S KEY POLICY CONSIDERATIONS
Treasury identified a series of policy areas for further consideration based on its analysis of RFI comments and its broader internal reviews of AI developments and deployment. These policy considerations are organized at the federal, state, and international levels.
A. Regulatory Framework
A common theme among RFI respondents was that different firms are subject to different regulatory standards for the same activities, particularly with respect to banks and non-banks. Respondents, therefore, advocated for Treasury to prioritize coordination with other agencies to foster cohesive and coordinated regulation. Respondents also supported public-private partnerships “to share trends, risks, and best practices.”
The Report acknowledges this varied approach, noting that a wide range of government agencies have offered guidelines and risk management frameworks for financial firms, including state governments, the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Financial Crimes Enforcement Network, the Office of Foreign Assets Control, the Office of the Comptroller of the Currency, the National Credit Union Administration, the Securities and Exchange Commission, the Commodity Futures Trading Commission, the Consumer Finance Protection Bureau, and the National Institute of Science and Technology (NIST). These agencies have also taken a variety of approaches to AI, including voluntary guidelines, proposed standards, supervisory guidance, and rulemaking. In other cases, agencies have reminded their regulated entities that activities involving AI are subject to existing laws and regulations.
Given the foregoing, Treasury states in the Report that it will look to enhance interagency coordination, including addressing the regulatory gaps identified by respondents, and improving information sharing between government agencies and the financial services sector. The Task Force notes that such regulatory coordination will be critical to allow US financial firms to take advantage of the opportunities presented by AI adoption and for technological innovation to take place, while at the same time guarding against the risks presented by this relatively nascent technology. While financial regulations are often technology agnostic, the reality is that AI creates unique opportunities and risks. A coordinated regulatory approach, including with respect to the terminology used, defined terms, and an identification of risks will be essential to achieving this goal. This is particularly important, as RFI respondents stressed, with respect to multiple agencies issuing different regulations or guidance, and different approaches to regulation, covering the same activity.
B. Federal, State and Other Legislative Efforts
RFI respondents were also concerned that an absence of federal regulation will mean that individual states will fill this regulatory void, resulting in conflicting state laws and uneven application of AI policy depending, among other factors, on the type of AI usage and the type and size of the financial firm. As respondents noted, this could result in regulatory arbitrage to the detriment of responsible AI innovation and adoption. The Report acknowledges the rapid development of state law, highlighting, for example, guidance issued by the New York State Department of Financial Services on the use of AI by insurers.
The Task Force observes that a patchwork of state laws and regulations will make AI compliance difficult for financial firms. US companies are already experiencing this in areas such as data privacy and cybersecurity where divergent state laws have been enacted in the absence of a federal approach. In 2024, we saw the start of this state law trend with individual states such as California enacting their own AI laws, and numerous other states introducing such legislation. While not all of these laws are specific to financial service firms, their broad application will, in many cases, cover this sector as well.
C. International Standards
Another common concern among RFI respondents was that AI-regulatory frameworks enacted in foreign jurisdictions could impact the ability of US financial service firms to offer global AI-based products and services. An inconsistent international regulatory regime would mean that financial firms need to instead tailor their products, third-party due diligence, and risk management on a jurisdiction-by-jurisdiction basis which could hamper enterprise-level approaches. The overall result could be different levels of consumer or other customer protection and access to AI-powered products and services depending on the jurisdiction where a customer resides.
While the Report does not mention the EU AI Act in this regard, the Task Force observes that this omnibus Act has been the focus of most international financial firms as they parse the AI regulatory landscape. While enforcement of the EU AI Act will roll out over the next two years, financial firms are already mindful of the impact that this Act will have on their deployment of AI-based tools in Europe. International coordination will, therefore, be critical in the short term if financial firms are to be able to adopt global approaches. Companies have already experienced the difficulties of managing disparate global laws in areas such as data privacy with the enactment of the General Data Protection Regulation in Europe and various other comparable national laws.
IV. TREASURY NEXT STEPS
Given the foregoing policy considerations and RFI comments, Treasury describes in the Report a series of potential next steps:
- The Report acknowledges the importance of collaboration at the international and domestic levels as well as the need for international standards, and, therefore, recommends continuing collaboration among governments, regulators, and the financial services sector. While not a “collaboration” point per se, Treasury also recommends continued coordination among the financial sector, financial regulators, and government agencies to develop disclosure mechanisms to help firms assess AI risks. Treasury cites the “nutritional label approach” from its AI Cybersecurity Report as an example of this approach.[5] The Task Force notes that the Report is short on specifics as to how it will achieve collaboration, other than recommending further coordination with NIST, and using input from the RFI to inform this work. Financial firms will want to continue urging their respective regulators, through formal and informal channels, to make such collaboration a priority so as to yield tangible results as opposed to general pronouncements by the regulatory community both in the US and abroad about the importance of collaboration.
- Regulatory Gap Analysis. The Report notes that further analysis and engagement with stakeholders is important to identify gaps and inconsistencies in existing regulations that touch on AI deployment. In this area, the Report does provide a series of concrete next step proposals, including: (1) government agencies and regulators should work with financial firms to ensure consistent approaches to AI usage by banks and nonbanks; (2) given the expanding usage of consumer data in AI models, agencies should explore whether existing consumer protections (e.g,, Fair Credit Reporting Act, Equal Credit Opportunity Act, and Gramm-Leach-Bliley Act) provide consumers and other customers with a sufficient understanding of how their data is used and whether they can control how it is used; (3) regulators should clarify how to assess AI models for discriminatory effects; (4) after the gap analysis has been completed, regulators and stakeholders should consider clarifying or supplementing standards for data privacy, security, and quality; and (5) Congress should pass legislation that ensures agencies have adequate examination and enforcement powers to oversee third-party service providers to financial firms.[6]
The Task Force agrees that the foregoing steps are important to fostering the responsible use of AI in financial firms and providing regulatory clarity. It remains to be seen what approach the Trump Administration will take to these proposals since, to date, the Trump Administration,[7] and key Congressional Committee Chairs[8] have signaled a lighter regulatory approach to AI. The Task Force believes that regulatory clarity and consistency of approach should be seen as “must-haves” to ensure responsible AI adoption and technical innovation in the financial services sector.
- Enhancements to Existing Risk Management Frameworks. The Report loosely recommends that financial regulators coordinate their efforts to enhance existing risk management frameworks and how they are applied to AI such as how the NIST AI Risk Management Framework fits within prudential risk-management expectations. The Task Force believes that risk management clarity and expectations are critical to responsible AI adoption and that financial firms should continue to press for better and consistent guidance in this area going forward.
- Information Sharing. The Report recommends ongoing development of public-private partnerships to enable information sharing in areas such as risk management best practices and enhancing understanding of emerging AI technologies. The Task Force agrees that such information sharing is critical and encourages regulators and financial firms to take concrete steps in this regard. The financial sector has benefited greatly in areas such as cybersecurity, when the public and private sector have worked together to share threat information and best practices.
The Report also recommends that government agencies explore ways for smaller financial firms to develop and deploy AI and monitor concentration risks associated with AI providers. The Task Force agrees that one of the key risks of AI adoption is that the attendant costs of AI deployment could result in a significant gap in products and services and risk management between large and small financial firms. This gap may be difficult to close if left ignored.
- Compliance With Existing Laws. As with guidance and reports by other financial regulators, the Report concludes with an admonition that financial firms ensure that their AI usage complies with existing laws and regulations. The Task Force observes that most financial firms are cognizant of their existing compliance obligations and that the use of AI does not alleviate them of these obligations. Those obligations may include, in the context of collaboration, compliance with antitrust and anti-competition laws. However, as the RFI comments made apparent, and as acknowledged by the Report, clarity as to how certain regulations apply to AI and consistency with respect to a regulatory approach will be critical for successful AI deployment for US financial firms.
Presidential Task Force on Artificial Intelligence and Digital Technologies
Lorraine McGowen, Co-Chair
Edward So, Co-Chair
Jerome Walker, Co-Chair
Footnotes
[1] United States Department of Treasury, Artificial Intelligence in Financial Services – Report on the Uses, Opportunities, and Risks of Artificial Intelligence in Financial Services (December 2024), available at https://home.treasury.gov/system/files/136/Artificial-Intelligence-in-Financial-Services.pdf (All websites last accessed on Feb. 20, 2025).
[2] TREASURY, REQUEST FOR INFORMATION ON USES, OPPORTUNITIES, AND RISKS OF ARTIFICIAL INTELLIGENCE IN THE FINANCIAL SERVICES SECTOR, 89 Fed. Reg. 50048 (Jun. 12, 2024), https://www.federalregister.gov/documents/2024/06/12/2024-12336/request-for-information-on-uses-opportunities-and-risks-of-artificial-intelligence-in-the-financial (Treasury AI RFI, or the AI RFI). Treasury received 103 comment letters to the RFI.
[3] The Task Force is composed of more than 200 representatives of more than 50 committees, councils, and other task forces of the City Bar and adjunct members, including lawyers, academics, trade association representatives, consultants, technologists, and others. See Task Force Dashboard at https://www.nycbar.org/committees/task-force-on-digital-technologies/ and https://www.nycbar.org/wp-content/uploads/2025/01/PTFAIDT-Leadership-250105.pdf.
[4] This analysis and these reflections were drafted by the Task Force Subcommittee on the Use of Artificial Intelligence in Commerce and Finance (AI in Commerce and Finance Subcommittee) and approved by the Task Force Subcommittee on Articles and Blogs. The AI in Commerce and Finance Subcommittee analyzes the use of artificial intelligence in banking; insurance; securities; commodities; payments; trade; and related global issues for artificial intelligence in commerce and finance. Current members of the AI in Commerce and Finance Subcommittee include (1) Azish Filabi, Executive Director at American College Cary M. Maguire Center for Ethics in Financial Services; (2) Stuart Levi, Partner at Skadden Arps; (3) Corey Goldstein, Associate at Paul, Weiss; (4) Adam Marchuck, Managing Director and General Counsel at Citi; (5) Muyiwa Odeniyide, Director & Associate General Counsel at Nasdaq Regulation; (6) Jordan Miner Romanoff, Senior Director and Senior Managing Counsel, Co-Head Intellectual Property Legal, Head of Marketing & Communications Legal at BNY Mellon; (7) Peggy Tsai, Chief Data Officer at BigID; and (8) Kiran Yalavarthy, Executive Vice President and Head of Enterprise Model Risk Management at Wells Fargo. The Task Force Subcommittee on Articles and Blogs serves as a peer review for Task Force writings, especially articles, blogs, reports, statements and other writings. Current Subcommittee members include (1) Angelena Bradfield, Head of Policy and Government Affairs at Financial Technology Association; (2) Robert Mahari, Harvard Law School and MIT Media Lab; (3) Lorraine McGowen, Task Force Co-Chair and Partner at Orrick, Herrington & Sutcliffe LLP; (4) Robert Schwinger, Partner at Norton Rose Fulbright US LLP; (5) Edwin Smith, Massachusetts Uniform Law Commissioner and Partner at Morgan Lewis; (6) Tiffany Smith, Partner at WilmerHale; and (7) Jerome Walker, Task Force Co-Chair and Partner at Jerome Walker PLLC.
[5] In that report, Treasury had noted interest among financial service firms to require AI model providers to clearly identify what data was used to train a model, where it came from, and how any data submitted to the model will be incorporated. United States Department of Treasury, Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector (March 2024), available at https://home.treasury.gov/system/files/136/Managing-Artificial-Intelligence-Specific-Cybersecurity-Risks-In-The-Financial-Services-Sector.pdf.
[6] The FSOC also made this recommendation in its 2024 Annual Report, available at https://home.treasury.gov/system/files/261/FSOC2024AnnualReport.pdf.
[7] Removing Barriers to American Leadership in Artificial Intelligence Executive Order (January 23, 2025) available at https://www.whitehouse.gov/presidential-actions/2025/01/removing-barriers-to-american-leadership-in-artificial-intelligence/ and Fact Sheet: President Donald J. Trump Launches Massive 10-to-1 Deregulation Initiative (January 31, 2025) available at https://www.whitehouse.gov/fact-sheets/2025/01/fact-sheet-president-donald-j-trump-launches-massive-10-to-1-deregulation-initiative/.
[8] Scott Announces Banking Committee Priorities for the 119th Congress (January 15, 2025) available at https://www.banking.senate.gov/newsroom/majority/scott-announces-banking-committee-priorities-for-the-119th-congress; Hill, Steil Applaud President Trump’s Actions to Maintain America as a Leader in Digital Financial Technology Around the Globe (January 24, 2025) available at https://financialservices.house.gov/news/documentsingle.aspx?DocumentID=409447.