Rail Governance

Regulation E Error Resolution Obligations for AI-Initiated Electronic Fund Transfers

Banks face strict error-resolution deadlines regardless of who initiates transfers.

Contributing Editor · · 10 min read
Cover illustration for “Regulation E Error Resolution Obligations for AI-Initiated Electronic Fund Transfers”
OCC and Fed Rulemaking · October 1, 2026 · 10 min read · 2,251 words

Regulation E's error-resolution rules were built around a simple question: did the consumer authorize this transfer or not. AI agents that initiate payments on a consumer's behalf don't sit cleanly on either side of that question, and the statute never anticipated them.

Regulation E's authorization framework and AI-initiated transfers

Start with the word that does the heaviest lifting in the whole statute: "person." EFTA and Regulation E define an unauthorized EFT as one "initiated by a person other than the consumer without actual authority to initiate such transfer and from which the consumer receives no benefit". That definition assumes a human being on the other end of the keystroke, someone who either is the consumer, or is a stranger acting against the consumer's wishes.

An AI agent acting on a consumer's delegated instructions doesn't fit either slot. The consumer is not the actor here, an agent operating on a grant of access that may or may not cover the specific thing it just did. Whether that grant of access counts as "actual authority" once the agent acts in a way the consumer didn't specifically intend is a question nobody has answered yet.

This isn't a hypothetical waiting for some future court case. As the Sei AI compliance analysis framed it, existing financial and consumer protection laws were built around human-decisioned transactions and do not provide clear answers to questions arising in agentic payments, including who is responsible if an incorrect or fraudulent payment is made: the user, the AI developer, the bank, or the merchant.

What Regulation E requires of financial institutions in AI deployments

The authorization layer may be ambiguous, but the procedural obligations that follow it are spelled out precisely. Regulation E's error-resolution duties are spelled out in exact numbers of days, and no amount of automation, no enforcement lull, and no private network rule changes them.

Under 12 CFR 1005.11, a financial institution that receives a notice of error has to investigate and determine within a set number of business days of that notice whether an error occurred, with a longer window allowed if the account is new. Once the investigation is done, the institution has three business days to report results to the consumer. If it finds a confirmed error, it has one business day to fix it.

If the investigation can't wrap up within the initial window, the institution can take more time, but only on one condition: it has to provisionally credit the disputed amount within that initial period, and it has to tell the consumer the amount and date of that credit within a few business days. The consumer, for their part, has a defined window measured from their periodic statement to report the error in the first place. And if an institution wants written confirmation of a spoken complaint, it can only require that if it told the consumer about the requirement, and gave them an address, at the moment the consumer first reported the problem.

None of this bends for convenience. The CFPB's January 2025 Compliance Aid confirms that financial institutions cannot consider consumer negligence when determining liability for unauthorized EFTs, and cannot rely on private network rules that offer less protection than federal law. Institutions also cannot sit on an investigation waiting for more paperwork from the consumer, and they cannot demand a police report before they'll even start looking.

None of this depends on whether an examiner happens to be watching. The EFTA gives consumers a private right of action, with statutory damages and attorney's fees built in. A missed deadline is a claim a consumer's lawyer can bring regardless of what the CFPB's enforcement priorities happen to be that year.

Who carries the obligation when an AI agent initiates the transfer

The obligations above don't shift just because an AI agent, rather than a human, typed in the transfer request. Whichever bank or credit union holds the consumer's account carries full Regulation E responsibility no matter who or what initiated the transfer. In a lot of agentic payment setups, though, more than one institution can end up holding that same responsibility at the same time.

Regulation E's definition of "financial institution" is broad. It covers banks, savings associations, and credit unions, but also any other entity that directly or indirectly holds a consumer's account or issues an access device tied to EFT services. That means a non-bank peer-to-peer payment provider can qualify as a financial institution too, if it holds consumer funds or issues its own access device. When that happens, both the non-bank provider and the depository institution behind it can carry error-resolution obligations at the same time.

Where the AI agent lives changes how that plays out. An agent built into a bank's own app or website keeps the obligation where it's always been, with the bank. Whether a consumer's grant of access to an AI agent satisfies "actual authority" when the agent later acts beyond the consumer's intent is unresolved, and banks handing payment execution to outside AI platforms need to know it's open before they sign the deal.

The IMF has described agentic AI as capable of running an entire cross-border payment chain end to end, from initiating the payment through routing, compliance checks, and monitoring after settlement. Picture a consumer's dispute having to pass through that same chain in reverse, hopping from one institutional layer to the next before it reaches whichever party actually has the authority to investigate. Every layer in that chain adds a place where the notice could get lost or delayed.

Vendors serving this space are already responding. Fiserv's agentOS and FIS's Financial Crimes AI Agent, the latter being built with BMO and Amalgamated Bank, both put heavy emphasis on governed, traceable, auditable decisions made by the agent. That emphasis isn't incidental. Vendors know the liability for whatever the agent does stays with the depository institution, no matter which company built the technology layer sitting on top of it.

The verbal-notice problem: where agentic intake systems are most likely to accumulate unrecognized liability

Diagram: How a Missed Verbal Notice Quietly Resets the Clock. Visualizes: Illustrate the gap between when Regulation E's investigation clock legally starts versus when an AI intake system actually logs the dispute.

One specific moment in this whole chain creates more risk than any other: the first time a consumer tells an AI system something is wrong. Regulation E doesn't require a written complaint to start the clock. A spoken description is enough. An AI dispute-intake system that waits for a consumer to complete a structured form before logging that notice is already running behind, because the clock started the moment the consumer first said something.

Under 1005.11(b), an oral notice from a consumer is enough to trigger the entire error-resolution process. An institution can ask for written confirmation afterward, but the deadlines still run from the date of that first oral notice rather than from whenever the paperwork shows up. The consumer doesn't need legal language, and doesn't need to fill anything out. They just need to identify their account and describe the problem with enough detail that the bank can look into it.

Sei's own review of an intake-agent deployment found this failure mode directly. An early version of the dispute-intake agent waited for customers to file a formal complaint through its structured flow before it ever recorded the dispute. Compliance counsel caught the problem: any verbal statement that met the bar for a notice of error was already, legally, a notice of error, whether or not the customer ever reached the formal submission step. By waiting, the system was quietly backdating its own liability, every single time.

Backtesting against old chat and call transcripts confirmed how often this happened. Verbal notices sat in the transcripts, unflagged, while the form-first process moved on as if nothing had been reported. The gap between that first verbal statement and the eventual formal submission wasn't a matter of minutes. Sometimes it was long enough to matter against a 10-business-day investigation window.

Voice AI carries a particular version of this risk. Voice AI deployments face a particular structural asymmetry: a system designed to automate high-volume routine inquiries applies the same interaction model to fraud disputes and Reg E claims, where the conversational pattern that feels like intake is already, legally, the notice, and the clock is running. That pattern feels like ordinary intake to the people who built it. Legally, it's already the notice, and the clock is already running while the system is still deciding how to categorize the call.

This mistake is most visible in the callback queue. Banks routing Reg E disputes to a callback queue without timestamping the original notice are accumulating provisional-credit liability they have not measured. Every one of those delayed timestamps is a clock that started days before the bank thinks it did.

The provisional-credit dependency that automation can either enforce or quietly dismantle

That timestamp problem feeds straight into the next failure point: provisional credit. Provisional credit is the one thing standing between an institution and the extended 45-day or 90-day investigation window, and an automated workflow that treats it as optional is quietly closing off that extension on every case it touches.

The rule is specific. The extended investigation period, which can run even longer for point-of-sale debit card transactions and out-of-state transfers, is only available if the institution provisionally credits the disputed amount within the initial investigation window and then tells the consumer the amount and date of that credit within a few business days. If the institution misses that window, the extension is no longer available.

Sei's playbook treats provisional credit as a dependency the system has to enforce on its own, without waiting for a human to notice. If the investigation won't finish inside the short window, the system has exactly two paths: provisionally credit the account and automatically send the two-business-day notice, or flag that the institution chose not to credit. In that case the full investigation has to close within the original short window with no extension available. There's no third option sitting in between.

The real danger here is what happens at scale. One missed provisional credit is a single mistake, the kind of thing a bank fixes with an apology and a check. The same faulty logic running across thousands of automated disputes turns that one mistake into a pattern, and a pattern draws an enforcer's attention or fuels a class action under EFTA's private right of action.

The CFPB's Compliance Aid closes off the obvious workaround, too. Institutions cannot delay starting or finishing an investigation while they wait for more documents from the consumer. A provisional credit decision can't be put on hold pending a follow-up response, no matter how automated or backed-up the review queue gets.

What "authorized" means for a misaligned agent action

Whether a transfer counts as authorized determines everything about the procedural machinery described above. The statutory definition handles one kind of case cleanly and leaves another kind genuinely open.

Section 1005.2(m) defines an unauthorized transfer as one initiated by a person other than the consumer, without actual authority, from which the consumer gets no benefit.

Stolen credentials sit squarely inside this definition. A credit-push transfer initiated by a stranger using login details lifted from a data breach is an unauthorized transfer, full stop, because the person who initiated it has no connection to the consumer and no authority from them whatsoever.

Now change one fact. A consumer gives an AI agent standing access to their bank account and tells it to handle recurring bills. The agent, working from that general instruction, makes a payment the consumer later says it had no business making. Does that agent count as "a person furnished the access device by the consumer," which would make the transfer authorized? Or did the agent act without "actual authority" for that one specific payment, which would make it unauthorized? The statute's carve-out language was written with a human in mind, someone who exceeds the permission they were handed. It was never written for a system running on a standing instruction that's broad in scope but supposed to have limits.

Nobody has a firm answer to this yet. Whether handing an AI agent access to an account or to payment credentials satisfies Regulation E's authorization standard for everything that agent later does remains an open question. In practice, that means a consumer who believes an agent acted outside its mandate can still raise an unauthorized-EFT claim, and the bank has to investigate it. The bank cannot dismiss the claim just by pointing out that the agent had general access to the account. Regulation E's bar on weighing consumer negligence closes off that particular defense.

The regulatory oversight gap SR 26-2 left open

Supervisors have noticed the gap without closing it. SR 26-2, the interagency model risk guidance that took effect in April 2026, replaced the older SR 11-7 framework, and it names generative and agentic AI directly, only to say those technologies sit outside its formal scope. The guidance calls them novel and fast-changing, which is accurate, but it leaves banks without a specific supervisory rulebook for exactly the AI payment agents raising the authorization questions described above.

That leaves institutions building their own answer out of the pieces that already exist: the precise deadlines in 1005.11, the provisional-credit dependency that has to fire automatically rather than optionally, and the audit trail that timestamps a verbal notice the moment it happens rather than whenever the paperwork catches up. None of those pieces are new. What's new is applying them to a system that doesn't wait for a human to notice something went wrong before it acts again.

Sources

  1. Regulation E Error Resolution with AI Agents: A 1005.11 Playbook for Dispute Intake - Sei AI Blog - Sei AI
  2. Unauthorized Transactions and Error Resolution Procedures
  3. CFPB Issues Compliance Aid on Electronic Fund Transfers
  4. Electronic Fund Transfers FAQs
  5. How Agentic AI Will Reshape Payments in: IMF Notes Volume 2026 Issue 004 (2026)

More in OCC and Fed Rulemaking