GSE AI Governance RequirementsReview the requirements
Home
Developers
GSE AI Governance Hub

GSE AI Governance Comparison

Both Require AI Governance. The Details Differ.

Fannie Mae and Freddie Mac share core governance expectations, but their effective dates and detailed provisions are not interchangeable. Organizations working with both need one control foundation with traceable GSE-specific overlays.

Schedule a Free AI Readiness CallReview the GSE Hub

One program does not mean one undifferentiated rule.

Build common controls once, then map each control and evidence record to the Fannie Mae or Freddie Mac requirement it supports.

Direct Answer

Are the Fannie Mae and Freddie Mac AI governance requirements the same?

No. Fannie Mae LL-2026-04 and Freddie Mac Guide Section 1302.8 share expectations for documented governance, legal compliance, risk management, oversight, review, and disclosure, but they are separate documents with different effective dates and details. Freddie Mac is more explicit in areas such as senior-management approval, adversarial threats, monitoring, audits, segregation of duties, training, and indemnification.

Side-by-side requirement comparison

TopicFannie Mae LL-2026-04Freddie Mac Section 1302.8
Effective dateAugust 6, 2026March 3, 2026
Covered technologyArtificial intelligence and machine learningArtificial intelligence and machine learning
Mortgage activitiesApplicable origination and servicing activity connected to Fannie MaeApplicable origination and servicing activity connected to Freddie Mac
Policy ownership and reviewDesignated owner and at least annual reviewDefined accountability, ongoing review, and at least annual policy review
Senior-management approvalNo named executive roles expressly assigned in LL-2026-04Applicable senior-management roles or organizational equivalents expressly identified
Vendor languageExplicit no-less-protective governance requirement for vendor and subcontractor AI useEvaluate Section 1302.8 with applicable related-party, security, vendor, and contractual requirements
Adversarial threatsData poisoning and adversarial inputs are not expressly named in LL-2026-04Data poisoning and adversarial inputs are expressly identified
Monitoring and auditRisk measurement and management required; not prescribed in the same detailPerformance, breach and bias monitoring plus internal and external audits expressly identified
Disclosure on requestRequiredRequired
IndemnificationNo comparable clause in LL-2026-04Express indemnification provision in Section 1302.8

What a unified program can share

An authoritative inventory of AI and machine-learning use cases

Accountable business, risk, security, and technical owners

Documented purpose, data access, tools, and prohibited actions

Legal, compliance, security, model-risk, and fair-lending review

Vendor and subcontractor due diligence and change management

Human-approval thresholds and exception handling

Performance, security, incident, and bias monitoring

Reviewable execution and decision evidence

Incident response, escalation, and periodic reassessment

GSE-specific disclosure and evidence packages

AI Governance Questions

Questions Comparing Fannie Mae and Freddie Mac

Each comparison identifies the governing documents by name so the answer can stand alone in search and answer engines.

No. Fannie Mae LL-2026-04 and Freddie Mac Guide Section 1302.8 are separate enterprise requirements. They share several governance themes, but their effective dates and detailed control language differ.

#same-gse-ai-requirement

Fannie Mae LL-2026-04 emphasizes documented governance, risk tolerance, annual ownership and review, information security, no-less-protective vendor governance, and requested disclosure. Freddie Mac Section 1302.8 includes more explicit provisions for senior approval, adversarial threats, performance, security and bias monitoring, internal and external audits, segregation of duties, training, and indemnification.

#difference-between-gse-ai-rules

A lender working with both enterprises should account for both dates: Freddie Mac Section 1302.8 became effective March 3, 2026, and Fannie Mae LL-2026-04 became effective August 6, 2026. Applicability depends on the organization's covered activities with each enterprise.

#gse-deadlines-for-dual-seller

Yes, for covered activity. Fannie Mae LL-2026-04 and Freddie Mac Section 1302.8 both expressly address artificial intelligence and machine learning used in applicable mortgage origination.

#both-gses-cover-machine-learning

Yes, for covered activity. Fannie Mae LL-2026-04 addresses AI and machine learning used to service loans on Fannie Mae's behalf, while Freddie Mac Section 1302.8 addresses applicable servicing activity for Freddie Mac.

#both-gses-cover-servicing

Freddie Mac Section 1302.8 is more explicit in its published language about monitoring performance, security breaches and bias, as well as regular internal and external audits. Fannie Mae LL-2026-04 requires risk measurement and management but does not list those controls in the same prescriptive form.

#freddie-more-detailed-monitoring

Freddie Mac Section 1302.8 expressly identifies applicable senior-management roles or their equivalents for approval. Fannie Mae LL-2026-04 identifies accountable ownership and annual review but does not assign approval to the same named executive roles.

#gse-senior-management-approval

Fannie Mae LL-2026-04 expressly requires seller-servicer governance of vendor and subcontractor AI or machine-learning use to be no less protective than the organization's own controls. Freddie Mac organizations should evaluate Section 1302.8 together with all applicable Freddie Mac related-party, vendor, information-security, and contractual requirements.

#gse-third-party-vendors

One enterprise program can provide a common control foundation for both GSEs, but it should not erase their differences. The organization should map shared policies and controls to each source, retain enterprise-specific approvals and evidence, and confirm sufficiency with qualified counsel and the current Guides.

#one-program-for-both-gses

A lender should consider retaining its AI inventory, policies, owners, approvals, risk assessments, legal reviews, vendor records, safeguards, monitoring and audit results, incidents, training, exceptions, and action-level evidence. Each artifact should be traceable to the applicable Fannie Mae or Freddie Mac requirement.

#evidence-for-both-gses

Primary sources

Use the current official documents when assessing applicability, contractual duties, and implementation decisions.

  • Fannie Mae Lender Letter LL-2026-04
  • Freddie Mac Guide Section 1302.8
  • Freddie Mac Bulletin 2025-16

Crittora provides technology controls and operational information. It does not provide legal advice, certify compliance, or guarantee satisfaction of Fannie Mae, Freddie Mac, MISMO, or other requirements. No endorsement by Fannie Mae, Freddie Mac, or MISMO is implied.

Free Consultation

Schedule a Free AI Readiness Call

Talk with Crittora about your AI-governance priorities, the questions your team is facing, and a practical next step. No lengthy preparation is required.

Crittora Secure logo

Signed. Secured. Insured.

© 2025 Crittora LLC. All rights reserved.

AWS Partner | Patent Pending | Underwritten by Lloyd’s of London.