Law / United States / Michigan

Michigan DIFS Bulletin 2026-03-BT/CF/CU, Use of Artificial Intelligence Systems by Financial Service Providers

DIFS Bulletin 2026-03-BT/CF/CU

Guidance, not a law: the Michigan Department of Insurance and Financial Services's reading of Elliott-Larsen Civil Rights Act, public accommodations, public service and real estate financing (Act 453 of 1976). It binds nobody by itself; the law it reads does.

Guidance on an AI sector rules rule, addressed to private bodies.

Enforcement body
Michigan Department of Insurance and Financial Services
Instrument type
guidance published by a regulator
Obligation class
Governance, Disclosure
Audit expectation
on_request
Who audits it
Regulator

As of .

What the regulator expects

  • It reaches you if you operate as a Financial Service Provider, which the bulletin defines as a depository institution as defined in MCL 445.1852(e); a mortgage broker, lender, or servicer licensed or registered under the Mortgage Brokers, Lenders, and Servicers Licensing Act or the Secondary Mortgage Loan Act; a money transmission services provider licensed under the Money Transmission Services Act; a person licensed to make loans under the Regulatory Loan Act; an installment seller or sales finance company licensed under the Motor Vehicle Sales Finance Act; a person licensed to make or negotiate a credit card arrangement under MCL 493.101 to 493.114; a person licensed to engage in debt management under the Debt Management Act; a person licensed to provide deferred presentment service transactions under the Deferred Presentment Service Transactions Act; or a class I or class II licensee under the Consumer Financial Services Act.
  • Comply with all applicable federal and state laws and regulations in decisions and actions made with AI Systems that may impact consumers; the bulletin states that the use of AI does not relieve a provider of its obligation to refrain from discrimination under the Elliott-Larsen Civil Rights Act.
  • The Department expects you to develop, implement, and maintain a written AI Systems Program (an AIS Program) for the responsible use of AI Systems that make or support decisions related to regulated Financial Service Provider practices, designed to mitigate the risk of Adverse Consumer Outcomes.
  • If you choose not to formally engage in the use of AI Systems, you should, at a minimum, establish a policy for employee acceptable use of such AI systems.
  • Your AIS Program should vest responsibility for its development, implementation, monitoring, and oversight, and for your strategy for AI Systems, with senior management accountable to the board or an appropriate committee of the board (guideline 1.3).
  • Your AIS Program should address governance, risk management controls, and internal audit functions, and all phases of an AI System’s business cycle, whether the system is developed by you or by a third party (guidelines 1.2, 1.7 and 1.8).
  • Your AIS Program should include processes and procedures to provide notice to impacted consumers that AI Systems are in use, and access to appropriate levels of information based on the phase of the business cycle in which the AI Systems are being used (guideline 1.9).
  • Your AIS Program should include a governance framework for the oversight of AI Systems, with the policies, processes, procedures, risk management, and internal controls to be followed at each stage of an AI System life cycle, and an internal accountability structure (guidelines 2.1 to 2.3).
  • Your AIS Program should document your risk identification, mitigation, and management framework and internal controls, including inventories and descriptions of Predictive Models, validation, testing, and retesting, protection of non-public information, and data and record retention (guidelines 3.1 to 3.7).
  • Your AIS Program should address your process for acquiring, using, or relying on third-party data and AI Systems, including due diligence and, where appropriate and available, contract terms for audit rights, cooperation with regulators, prompt written notice of unauthorized access, and clear responsibilities for safeguarding data (guidelines 4.1 to 4.3).
  • You cannot outsource your fundamental risk management responsibility, even when a third party performs a service, and you should have clear policies and expectations for use of AI Systems, including permissible use by employees (guideline 1.10).

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Bulletin 2026-03-BT/CF/CU was issued and entered by the Director of the Michigan Department of Insurance and Financial Services on . The Department regulates the insurance and financial services industries, including banks, credit unions, mortgage companies, and other consumer financial services entities.

The bulletin is addressed to Financial Service Providers, which it defines as a depository institution as defined in MCL 445.1852(e) together with mortgage, secondary mortgage loan, money transmission, regulatory loan, motor vehicle sales finance, credit card arrangement, debt management, deferred presentment, and consumer financial services licensees.

The bulletin states that decisions and actions made with advanced analytical and computational technologies, including AI Systems, that may impact consumers must comply with all applicable laws and regulations. All Financial Service Providers are expected to develop, implement, and maintain a written AI Systems Program for the responsible use of AI Systems that make or support decisions related to regulated Financial Service Providers practices.

A provider that chooses not to formally engage in the use of AI Systems should, at a minimum, establish a policy for employee acceptable use of such AI systems. The program guidelines say responsibility for the program should rest with senior management accountable to the board or an appropriate committee of the board. The guidelines also say the program should include processes and procedures to provide notice to impacted consumers that AI Systems are in use.

The guidelines on third-party AI Systems and data include, where appropriate and available, contract terms that provide audit rights or entitle the provider to receive audit reports. In an investigation or examination, a provider can expect to be asked about its development, deployment, and use of AI Systems. The information an examiner may request begins with the written AIS Program. The bulletin states that it does not prescribe specific practices or documentation requirements.

The bulletin adds that providers may demonstrate compliance with the laws that regulate their conduct through alternative means, including practices that differ from those it describes. The Department’s release states that the bulletin clarifies how existing laws and regulations apply to AI.

The bulletin cites the Elliott-Larsen Civil Rights Act as the state law that prohibits a Financial Service Provider from discriminating on the basis of religion, race, color, national origin, age, sex, sexual orientation, gender identity or expression, height, weight, familial status, or marital status. It states that the use of AI does not relieve providers of their obligation to refrain from discrimination under that Act.

The Department states that nothing in the bulletin limits its authority to conduct any examination or enforcement action.

Back to the example  ·  Lint your app