Fannie Mae Makes AI Governance Part of the Mortgage Operating System
The two-page lender letter does not approve a model or rewrite fair-lending law. It makes documented ownership, vendor controls, and explainable operating discipline a condition of using AI in covered mortgage work.

Sources: Fannie Mae Lender Letter LL-2026-04, Fannie Mae Information Security and Business Resiliency Supplement, Fannie Mae selling and servicing communications index, Cooley analysis of the effective date and framework.
Fannie Mae’s single-family AI and machine-learning governance framework became effective on August 6, 120 days after Lender Letter LL-2026-04 was published on April 8. It applies when an approved seller or servicer uses AI or ML to originate loans sold to or guaranteed by Fannie Mae or to service loans on Fannie Mae’s behalf. The letter leaves existing law and the Lender Contract in place rather than creating a separate automated-underwriting permission.
Covered firms must maintain policies for developing, implementing, using, and maintaining AI systems and for measuring and managing their risks. Those policies must be communicated to appropriate staff, reflect legal and regulatory duties and the firm’s risk tolerance, incorporate trustworthy and ethical AI characteristics, and have owners who review them at least annually.
A vendor model is still the lender’s governance problem
The framework extends to subcontractors and vendors: their AI governance must be no less protective than the requirements applied to the seller or servicer. That closes an easy accountability gap. Buying a fraud score, document classifier, customer-service assistant, or servicing workflow from a third party does not outsource the obligation to understand how it is used and what can go wrong.
A defensible inventory therefore needs more than a vendor name. It should connect each system to its purpose, data inputs, decision influence, human review, failure modes, monitoring, change history, and contract controls. Fannie Mae can request prompt disclosure of the AI or ML types used, their purpose and manner of use, safeguards, and other information it requires.
Governance reaches privacy and resilience, not only model accuracy
LL-2026-04 also requires compliance with Fannie Mae’s Information Security and Business Resiliency Supplement. That supplement treats cyber risk as business risk, applies controls to service providers handling Fannie Mae confidential information, and requires covered cybersecurity incidents to be reported without undue delay and no later than 36 hours after identification or a reasonable conclusion that one may have occurred.
For borrowers, this matters because mortgage workflows assemble unusually sensitive records: income, assets, debts, identity documents, employment, addresses, and payment history. A model can be accurate on average while a surrounding workflow still over-collects data, leaks it to an unapproved tool, produces an unactionable explanation, or fails during a servicing event. Governance has to cover the whole system.
What the framework does—and does not—promise borrowers
The letter does not name approved AI products, mandate one technical standard, or guarantee that an automated result is fair or correct. It also does not replace rights and duties under fair-lending, credit-reporting, privacy, consumer-protection, and adverse-action rules. Its value is operational: someone must own the policy, vendors must be governed, and the institution must be ready to explain the system and its safeguards to Fannie Mae.
A borrower who encounters a suspicious mortgage decision should still request the specific reasons and records available under applicable law, correct inaccurate credit or application data, and escalate through the lender’s complaint process or an appropriate regulator when necessary. The new framework gives institutions a clearer governance obligation; it does not shift the burden of detecting every automated error onto the borrower.
Quick questions
When did Fannie Mae’s AI governance framework take effect?
LL-2026-04 was published April 8, 2026 and states an effective date 120 days after publication, which is August 6, 2026.
Does the framework apply to third-party AI vendors?
Yes. Seller/servicers must manage subcontractor and vendor AI risks with governance that is no less protective than the framework’s requirements.
Does Fannie Mae now allow AI to make mortgage decisions without human review?
The letter does not grant that permission or prescribe a human-review rule for every use. It requires compliance with existing law and contracts plus documented AI governance, risk management, security, vendor oversight, and disclosure to Fannie Mae on request.