A generic AI governance framework provides a starting point. Regulatory obligations, however, are sector-specific – and the gap between a general policy and a compliant program widens quickly once you enter a regulated industry. This chapter covers the requirements that apply directly to financial services (with particular focus on credit unions), healthcare, employment, insurance, and critical infrastructure.
Financial Services: Model Risk Management Baselines
The model risk management (MRM) discipline – the practice of identifying, assessing, and managing risks that arise from the use of analytical models in business decisions – is the most established form of AI governance in financial services, predating the current wave of generative AI by more than a decade.
In the United States, the Federal Reserve’s Supervisory Guidance on Model Risk Management (SR 11-7), originally issued in 2011 and updated with revised guidance issued jointly by the Fed, OCC, and FDIC in April 2026, remains the foundational framework for bank model risk. It covers model development and testing, independent model validation, and board-level governance and controls. The updated April 2026 guidance confirms that the framework applies to complex quantitative AI and machine learning models used in core business and risk decisions. Senior management is explicitly responsible for regularly reporting to the board on significant model risk from individual models and in the aggregate.
In Canada, OSFI Guideline E-23 – Model Risk Management, substantially revised in September 2025, is the primary MRM obligation for federally regulated financial institutions (FRFIs). It takes effect on May 1, 2027. The Guideline applies to all FRFIs – including banks, foreign bank branches, life insurance and fraternal companies, property and casualty companies, and trust and loan companies – and covers all models regardless of whether they are developed internally or procured from third parties. As McCarthy Tétrault’s analysis notes, this explicitly includes AI and machine learning models, agentic AI systems, off-the-shelf supplier AI products, and AI embedded in vendor software. Key requirements include: a model identification registry covering the full lifecycle; risk-based governance proportionate to each model’s inherent risk; robust data governance with attention to bias and fairness; independent model review and validation; defined escalation standards; and multidisciplinary team involvement. Third parties that supply AI-enabled products to FRFIs must be prepared to meet heightened MRM expectations because FRFIs cannot comply without appropriate contractual commitments from their vendors.
In the European Union, AI systems used in credit scoring and creditworthiness assessment of natural persons are classified as high-risk systems under Annex III of the EU AI Act, triggering the full set of high-risk obligations: conformity assessments, data governance standards, technical documentation, transparency, human oversight, and registration in the EU AI database. Full obligations for high-risk systems apply from August 2, 2026.
Credit Unions: Federal and Provincial Dimensions
Federal credit unions (FCUs) – those incorporated and regulated under the Bank Act – are FRFIs and therefore subject to OSFI Guideline E-23 in full, with the May 2027 compliance deadline. This is a material change from prior practice. FCUs deploying AI in credit decisioning, fraud detection, or member service operations must now build out model risk management frameworks meeting OSFI’s standards.
The vast majority of Canadian credit unions are provincially regulated, not federally regulated. These institutions fall under provincial credit union regulators and their deposit insurer (typically the Credit Union Deposit Insurance Corporation, or CUDIC, in each province). CUDIC is not equivalent to CDIC (Canada Deposit Insurance Corporation), which covers federal deposit-taking institutions. Provincial regulators have not yet issued AI-specific guidance at the same level of specificity as OSFI E-23, but organizations should monitor their provincial regulator’s communications. The Financial and Consumer Affairs Authority (FCAA) in Saskatchewan and equivalent bodies in other provinces are increasingly active on technology risk. In the absence of binding provincial AI guidance, provincially regulated credit unions would be well advised to adopt OSFI E-23 as a benchmark – both because it represents the recognized Canadian standard for financial institution model risk management and because many provincially regulated credit unions seek alignment with national standards to maintain competitive credibility.
Healthcare
The U.S. Food and Drug Administration regulates AI used in Software as a Medical Device (SaMD). The FDA published its AI/ML-Based Software as a Medical Device Action Plan and, on January 6, 2025, published a Draft Guidance on AI-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations. This draft guidance addresses predetermined change control plans – a mechanism that allows manufacturers to define in advance what types of changes to an AI algorithm can be made post-market without requiring a new regulatory submission. Health Canada regulates AI-enabled medical devices under the Medical Devices Regulations and has issued guiding principles for machine learning-enabled medical devices, though its framework is less prescriptive than the FDA’s.
Employment and HR
Employment AI has attracted more regulatory action than any sector outside financial services.
NYC Local Law 144 requires any employer or employment agency using an automated employment decision tool (AEDT) in New York City hiring or promotion decisions to conduct an annual bias audit by an independent auditor, publish the results on their website, and provide advance notice to candidates. Enforcement began July 5, 2023. Civil penalties of $500 to $1,500 per day per violation apply.
The Illinois AI Video Interview Act, in force since January 1, 2020, requires employers who record video interviews and use AI to analyze applicant suitability to inform applicants, provide a written explanation of how the technology works, obtain prior consent, and destroy video copies within 30 days if an applicant requests it. Illinois has since expanded its AI employment rules: under amendments to the Illinois Human Rights Act in force for 2026, as analyzed by Hinshaw & Culbertson, employers must provide notice whenever AI influences or facilitates a covered employment decision – broadly defined to include resume screening, targeted job advertising, and analysis of facial expressions or voice during video interviews.
Ontario’s Bill 149, the Working for Workers Four Act, 2024, received Royal Assent on March 21, 2024, and its AI disclosure provisions come into force on January 1, 2026. Under the amendments to the Employment Standards Act, 2000, Ontario employers with 25 or more employees must disclose in publicly advertised job postings whether AI is used to screen, assess, or select applicants. As Osler’s analysis explains, the definition of AI used is broad, covering any machine-based system that infers from inputs to generate outputs such as predictions, recommendations, or decisions.
Insurance
The National Association of Insurance Commissioners (NAIC) Model Bulletin on the Use of Artificial Intelligence Systems by Insurers was adopted in December 2023. It is not a law but a template bulletin that individual state insurance regulators can adopt. As of early 2025, Quarles & Brady reports that 24 states had adopted the bulletin with little or no material changes, including Alaska, Connecticut, Illinois, Maryland, Michigan, Pennsylvania, Virginia, and Washington. The bulletin requires insurers to develop a written AI System program that: maintains inventories of AI systems used in regulated decisions; establishes governance, risk management, and internal audit functions; validates and tests models for bias and errors; and ensures that all AI-driven decisions comply with existing unfair trade practice laws. Insurers can expect state regulators to inquire about their AI governance frameworks during market conduct examinations.
Critical Infrastructure
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Transportation Security Administration (TSA) have issued sector-specific guidance addressing AI use in critical infrastructure. CISA’s AI roadmap addresses AI-related threats to critical infrastructure and promotes AI use by CISA itself in alignment with civil rights and privacy principles. The broader context is established by the U.S. national security framework for critical infrastructure, which identifies AI’s role in both protecting and threatening critical systems. Canadian critical infrastructure operators should monitor guidance from the Canadian Centre for Cyber Security and the Communications Security Establishment, which address AI-enabled threats to critical systems in their annual threat assessments.