Four regulator signals from the past two weeks, each verified and each with one action. NCUA itself was quiet in this window (its August deregulation batch was covered in an earlier roundup), so this edition runs through FinCEN and the CFPB. For the standing pre-deployment checklist, see What NCUA Expects Before You Deploy AI on Member Data and the compliance pillar.

1. FinCEN permanently ends BOI reporting for US companies

On August 11, FinCEN issued a final rule that permanently removes the requirement for US companies and US persons to report beneficial ownership information under the Corporate Transparency Act, and said it will delete previously reported US person data from the BOI database. Foreign reporting companies must still report for foreign individuals. Do not misread this: the rule kills the government database, not your obligations. Your credit union still collects and verifies beneficial ownership on legal entity accounts under the CDD Rule, which this rule does not touch.

Do this month: have your BSA officer brief lending and new accounts staff that business members may claim “BOI is gone” at account opening. Your CDD collection stands.

2. A $5 billion human smuggling signal, and depository institutions carry the dollars

FinCEN’s August 13 Financial Trend Analysis reviewed 67,540 BSA reports from 2023 to 2025 tied to suspected human smuggling. The detail that matters for credit unions: depository institutions filed only about 3 percent of the reports but accounted for roughly 61 percent of the flagged dollars. Typologies include structured cash deposits, funnel accounts receiving funds from numerous individuals, and travel agencies (sham and legitimate) arranging migrant travel.

Do this month: confirm your transaction monitoring, automated or not, has a funnel account scenario and that it is tuned, not just switched on. If you are evaluating AI-based AML tools, this FTA is a ready-made test case to put in front of the vendor.

3. The CFPB stops publishing complaint narratives

On August 14, the CFPB announced it is ceasing discretionary publication of consumer complaint narratives and data visualizations, calling the narratives unverified and one-sided. Complaints are still collected, still routed to companies, and still shared with prudential regulators, including NCUA. What changes is public visibility: if your team benchmarked complaint patterns against peers or watched vendors through the public database, that window is closing.

Do this month: make sure your own complaint analytics can stand alone, because the public yardstick is going away while the supervisory data flow to your regulator continues unchanged.

4. Healthcare benefits fraud moves up FinCEN’s priority list

FinCEN convened law enforcement and financial institutions on August 17 for an engagement on healthcare benefits fraud, including hospice fraud schemes, and ran a BSA data training for law enforcement the next day. The readout points institutions to FinCEN’s March advisory on schemes targeting Medicare, Medicaid, and other benefit programs. Fraud proceeds move through ordinary deposit accounts, which puts community institutions in the flow.

Do this month: route the March healthcare fraud advisory to your BSA officer and confirm its red flags are reflected in your monitoring rules, especially around rapid movement of government benefit deposits.

That is the fortnight. Get this briefing in your inbox every Thursday: subscribe to the AiForCU newsletter.