AI Without The Chaos: What Responsible AI Actually Looks Like For Lenders
What Responsible AI Actually Looks Like for Lenders
Lenders are being sold AI from every direction. It's in their vendors' platforms, their LOs' phones, and the loans they sell to investors. Most don't yet have the governance to evaluate it, let alone control it. The result is chaos: tools nobody approved, risks nobody owns and exposure nobody can see. That's not a knock on lenders. It's where the market is right now.
That's the problem we tackled in our latest webinar, "AI Without the Chaos." Brian Vieaux, President of MISMO, and Melissa Grindel, Head of Compliance and Industry Strategy at ActiveComply, skipped the theory and got specific about what responsible AI looks like inside a real mortgage operation.
The Risk Is Now Contractual, Not Just Regulatory
Automated decisioning isn't new. DU and LPA were helping lenders make credit decisions long before anyone called it AI. What's changed is how fast and how deep AI now reaches into loan manufacturing. As Brian put it during the webinar, it's now harder to find a loan without AI in its manufacturing process than one with it. With Fannie Mae's guidelines on AI in loan manufacturing now in effect, that matters.
When a loan defaults, the agencies and aggregators QC it. If they can tie the default to a defect caused or amplified by AI, the lender is looking at an indemnification or a repurchase. Reps and warrants roll downhill, and they stop at the originator.
Investors are even using AI to find those defects. Melissa's counter: lenders can use AI to check their own work first.
Compliance And Production Are Looking At Two Different Pictures
Ask a compliance team how exposed they are to AI, and Melissa says the honest answer is usually "very." They don't know what they don't know. Ask production staff, and you'll hear the opposite. AI is built into Zoom, Canva, LinkedIn, and the other tools they use every day, so now AI feels like a routine, and just another low-risk feature.
Those two groups sit at opposite ends of the spectrum, and they rarely meet in the middle. That disconnect, the panel agreed, is the real exposure.
The Tools Nobody Approved
LOs are already using AI, often tools the company never vetted. Melissa walked through what can go wrong when one ends up in front of a borrower. What data is it referencing when it quotes today's rates? Does its answer change if a borrower mentions she's a single woman, or that part of her income comes from federal assistance? Will it promise "the lowest rate" to anyone who asks? Each one is a fair lending or UDAP finding waiting to happen.
Brian added that shadow tools are a fast path to TCPA liability, and he expects liability to eventually reach the individual license holder.
So should lenders ban them? The panel's answer was no, and the webinar gets into what to do instead. The short version: the goal is visibility, not punishment.
There Is No Single Examiner
Part of what makes AI governance hard is that there's no one regulator to satisfy. The CFPB, FHFA, the GSEs and every state bring their own approach. Melissa, fresh from a conference full of state regulators, heard answers ranging from "still evaluating" to "we've hired third-party auditors."
Some states are already moving. Colorado has issued guidance on the risks of using chatbots with consumers. New York now requires disclosures when ads feature a "synthetic performer," which applies to any LO licensed in or located in the state who creates that kind of content. On the webinar, the panel breaks down where else regulators are concentrating their attention.
A Foundation To Build On
About a year ago, the MBA's Residential Board of Governors made responsible AI guardrails a priority for 2026. MISMO already had the infrastructure to act on it: an AI community of practice with 100+ members across the industry. In under six months, they published FRAME, the Framework for Responsible AI in Mortgage Ecosystems.
Brian was clear about what FRAME is and isn't. It's not a magic wand that makes you compliant. It's the foundation to build your own AI guidance and governance. Your risk appetite determines those particulars and how you leverage FRAME to get there
From Chaos To Control
AI isn't going to slow down, and lenders shouldn't either. But chaos isn't a strategy. Every unapproved chatbot, untracked vendor feature and unreviewed use case is a risk your organization holds whether it knows about it or not.
Governance is how you take that back. Not a policy in a drawer, but a working system: knowing where AI lives in your business, who owns it, how it's tested and how you'll explain it when a regulator or investor asks. Lenders who build that now get to say yes to AI with confidence. Lenders who don't will be explaining it in a repurchase demand or an exam.
FRAME is the starting point. Training is the floor. Vendor diligence is the filter. Get those right, and you get AI without the chaos.
Because the mission hasn't changed: put more people in homes.