Navigating the Legal Gray Areas of AI Credit Scoring Across International Borders
The accelerated development of Artificial Intelligence (AI) has led to widespread integration, and huge efforts to modernize and streamline operations through AI. As governing bodies continue to tackle the challenge of properly regulating mass AI use, varying policies have arisen, especially across international borders. Among all international relationships, one of the most crucial is that between the United States and the European Union, with the two entities sharing the largest Foreign Direct Investment (FDI) relationship in the world. Considering this, a curious case study here is the integration of AI into credit scoring systems by major financial institutions that operate in both regions. Cross-border regulatory inconsistencies create compliance burdens for financial institutions and obscure accountability when conflicts arise. For consumers, regulatory inconsistency raises critical questions about data collection, transparency, and their legal recourse against automated decisions. With this in mind, an equivalence agreement with characteristics of a mutual recognition agreement (MRA) would be beneficial allowing individual countries to retain their existing laws, while ensuring the proper enforcement of mutually agreed upon standards and the revision of laws to an equivalent standard.
The sharp divide between EU and U.S. approaches to AI policy, both broadly and within the financial sector, poses a fundamental barrier to such an international regulatory framework. Examining the European Artificial Intelligence Act, it is apparent that the EU is extremely strict in its approach to AI implementation. Under Section III of the EU Artificial Intelligence Act, the European Union considers “AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score” as high-risk, meaning companies must assign human oversight, maintain logs for up to six months, and inform individuals that they are being subject to an automated process, among other requirements. This risk-based classification system generally ensures that financial institutions remain transparent about their intentions, processes, and the impacts any system will have on consumers. Consequently, any violation of these policies carries huge fines and penalties, with further prosecution varying between member states. For example, the 2023 ruling OQ v. Land Hessen by the Court of Justice of the European Union (CJEU) determined that while the production of a credit score through an automated AI agent was not a decision in and of itself, it constitutes a “decision” that is subject to the strict scrutiny of the EU AI Act because a vast majority of banks almost solely relied on these generated scores to make lending decisions. This specifically ensured that consumers cannot be subject to “black-box” automation without their legal rights of human oversight and a clear log and explanation of such decisions.
On the other hand, the United States aims to maintain a “minimally burdensome national policy” and views state laws that aim to prevent “algorithmic discrimination” and “differential treatment or impact” unfavorably (Executive Order 14365). In general, America has shown that it is keen on limiting bureaucratic “red tape” in private-sector AI development and is encouraging a “try-first culture for AI across American industry,” as exemplified in efforts to accelerate AI adoption within the federal government and Department of Defense. As one of the world's most developed financial systems, the U.S. has established meaningful consumer protections through the Equal Credit Opportunity Act (ECOA), enforced by the Consumer Financial Protection Bureau (CFPB). The CFPB now requires financial institutions to “[disclose] the specific principal reasons” if adverse action is taken, but the lack of a concrete explanation of these reasons generates a near-black box situation for consumers, in which they are unable to see why such action was taken. Specifically, the New York State Department of Financial Services released a regulatory investigative report in 2021 regarding the Apple Card Investigation. The initial investigation spurred from complaints that Apple and Goldman Sachs used biased algorithms to grant men higher credit limits than women. Although the investigation looked into what variables were being used, the final decision was based upon the exact output of the algorithm, with limited consideration for how the algorithm approached the data. As a result, because the output of Goldman Sachs’ data showed limited statistical evidence of discrimination, the company was ultimately absolved. From a legal standpoint, U.S. policies are much more lenient with the forced disclosure of specific information or processes, which allows for such outcomes in violation of EU AI Act policies. The results of the Apple Card Investigation demonstrate that U.S. policy on AI systems is much more focused on the algorithmic outcome, rather than its internal workings and reasoning, paving way for decreased consumer confidence in financial systems and cross-border legal challenges.
To compensate for the lack of consumer protection between the federal government and financial policymakers, numerous states have developed policies, including California’s Transparency in Frontier AI Act, that require publicly published frameworks and call for the protection of whistleblowers. These are attempts to ensure the users and associates of AI systems are protected thoroughly, and are not taken advantage of, including during the training of AI datasets. Generally, U.S. policy on broad AI implementation, especially the financial sector, remains fragmented and conflicting, paving the way for consumers to be blindsided by fully autonomous decisions without any clear, definitive explanation of the detailed decision-making process behind the automated systems.
With the establishment of strict policy, or lack thereof, between the EU and U.S., it becomes evident that an equivalence agreement must be established regarding the integration of AI into credit scoring systems and the extent of that integration and the amount of protection consumers receive. An equivalence agreement would allow the EU and U.S. to establish that their existing laws result in similar outcomes, implying the compliance of an AI-based credit scoring system in the EU would make it compliant in the U.S. However, given existing differences in approaches to AI-policy, a blanket equivalence agreement would be extremely difficult to accomplish. As such, a potential solution is an equivalence agreement with characteristics of Mutual Recognition Agreements (MRAs). In this format, both parties would first agree to accept each other's compliance tests–a core principle of MRAs. In the context of credit-scoring, this means first agreeing to an auditing process that satisfies both parties, then moving towards an equivalence agreement that aligns with both parties’ laws.
But how has the difficulty of regulation across borders actually manifested itself? For JP Morgan, the largest bank in the United States, AI has played a crucial role in its latest developments. A primary example is its deployment of the Account Confidence Score, an AI-powered system that evaluates accounts based on factors like age, location, and payment history. It generates a score between zero and one thousand (with zero being low confidence and one-thousand being high confidence) to “[help] clients assess fraud risk before initiating a payment.” In a similar fashion, Goldman Sachs has integrated features such as "smart approval” into its Marcus System, which shortens approval cycles through automated decision-making. The most glaring challenge these programs present for establishing an equivalence agreement is how the EU requires a degree of “explainability” behind the system, while U.S. regulators focus much more on the outcome. Specifically, Article 13 of the EU Artificial Intelligence Act requires high-risk systems to “be designed and developed in such a way as to ensure their operation is sufficiently transparent” and “be accompanied by instructions for use.” This policy, combined with regulations for distributors of high-risk systems mentioned in Article 26, means that banks like JP Morgan would need to assign human oversight, provide detailed logs, and ensure clear instruction of how their credit-scoring system operates. However, under existing CFPB policies, the same banks would only be required to disclose the principal reasoning behind their AI system’s action, while not being required to disclose the actual algorithmic reasoning. This eliminates the need for human oversight and provision of any detailed logs. Thus, it is precisely this inconsistency that necessitates the establishment of an equivalence agreement– one that shields financial institutions from conflicting cross-border consequences, and ensures that consumers are consistently protected at an agreed standard, regardless of jurisdiction.
As governing bodies and organizations who use AI recognize the inefficiencies that come from diverging policies, there have been attempts to develop a more unified front. In September 2024, the EU and U.S. signed the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CoE Framework), which was designed to ensure that AI systems are consistent with human rights and democratic principles. Yet, it uses vague language and leaves significant room for subjective interpretation, which is counterproductive to ensuring proper regulation of AI systems and sufficient consumer protections. In particular, the CoE Framework calls for parties to “address risks and impacts arising from activities…by private actors…in a manner conforming with the object and purpose of this Convention.” The language used here is particularly vague, solely requiring private entities to be regulated by the “objects and purpose” of the Convention, which only provides broad guidelines on “[ensuring] that activities within the lifecycle of artificial intelligence systems are fully consistent with human rights, democracy, and the rule of law.” And due to the agreement simply being a framework, it is not self-executing, but rather requires each respective country to enact enforcing legislation. While the EU has its AI Act, the U.S. would need both the Senate and House of Representatives to ratify domestic legislation that implements sections of the CoE framework, which given the existing disagreements across partisan lines and between levels of government, stands as a huge challenge to implementing the basic principles of the CoE. While the CoE was a powerful symbol, in reality, it has limited effectiveness in moving the U.S. and EU towards an agreement on AI implementation and transparency.
A point of regulatory friction for the U.S., given their openness to AI integration, is “regulation” of the private sector through existing laws like the ECOA without actively catering policies towards AI-based systems and their risks, such as those arising from credit scoring processes. Specifically, U.S. policy and action during the Apple Card investigation demonstrates that domestically, the U.S. only looks at the outcome of these algorithms. Because the CoE only broadly requires entities to address things in “a manner conforming with the object and purpose of [the] Convention,” the U.S. would be able to claim supposed regulation through its existing set of laws that require notice of principal reasonings behind automated decisions without directly regulating the algorithmic logic behind AI credit scoring systems . While the EU approach towards AI has been characterized as “hard-line,” this same language also enables European countries to bypass the fundamental purpose of the agreement in a similar manner. In particular, the agreement fails to include national security in its scope. In 2020, the CJEU ruled in La Quadrature du Net and Others v. Premier ministre and Others that data retention and use is justified when there is a “serious threat to national security.” Thus, past precedent of justifying data use under the guise of national security opens up potential loopholes within European nations to operate against the signed CoE due to “national security concerns.” In particular, there is past precedent by European nations to classify financial tracking under anti-money laundering directives. By allowing for the monitoring of large amounts of financial data under the guise of national security, and with the CoE being a legally non-binding agreement, there is a possibility that EU member states end up skirting the overall objectives of the CoE under the guise of national security. Additionally, similar arguments are often made within U.S. Courts. For example, the 1976 case United States v. Miller essentially categorized financial information as “third-party data” (that of the bank) and established precedent for other courts to treat it less privately, making such data much more easily accessible to government agencies without the need for a warrant. As such, the CoE framework, designated as a multinational binding agreement, continues to do little to feasibly protect consumers from the actions of AI systems, which not only risks the livelihoods of consumers but also the public faith put in banks.
Ultimately, major financial institutions operating across the EU and U.S. face conflicting legal obligations with no method for reconciliation, and consumers in both regions lack adequate legal protection against the risk posed by automated credit scoring systems. After analyzing the many flaws within the CoE, an upfront equivalence agreement where the EU and U.S. acknowledge that their laws provide the same protection is highly unlikely (given the differences this analysis has identified). Thus, in order to work towards such a future, characteristics of a Mutual Recognition Agreement (where both entities acknowledge their differing rules, but agree to conformity assessments) would allow both EU and U.S. regulators and consumers to develop a mutual understanding of their respective environments, then gradually move towards an equivalence agreement in which both the U.S. and EU acknowledge that their laws provide equal protection. Regardless of actions taken at a local, state, national, or international level, without explicit language regulating private uses of AI across borders alongside domestic ratification of legislation confirming these equivalence agreements, banks face foreseeable organizational challenges within their own operations and the trust their consumers place in them.
Edited by Jacqueline Hutchins.
This piece was reviewed and finalized by Gabi Fabozzi, Qizhen (Kiara) Ba, and Jasmine Lianalyn Rocha.