GSE AI Governance Comparison
Both Require AI Governance. The Details Differ.
Fannie Mae and Freddie Mac share core governance expectations, but their effective dates and detailed provisions are not interchangeable. Organizations working with both need one control foundation with traceable GSE-specific overlays.
One program does not mean one undifferentiated rule.
Build common controls once, then map each control and evidence record to the Fannie Mae or Freddie Mac requirement it supports.
Direct Answer
Are the Fannie Mae and Freddie Mac AI governance requirements the same?
No. Fannie Mae LL-2026-04 and Freddie Mac Guide Section 1302.8 share expectations for documented governance, legal compliance, risk management, oversight, review, and disclosure, but they are separate documents with different effective dates and details. Freddie Mac is more explicit in areas such as senior-management approval, adversarial threats, monitoring, audits, segregation of duties, training, and indemnification.
Side-by-side requirement comparison
| Topic | Fannie Mae LL-2026-04 | Freddie Mac Section 1302.8 |
|---|---|---|
| Effective date | August 6, 2026 | March 3, 2026 |
| Covered technology | Artificial intelligence and machine learning | Artificial intelligence and machine learning |
| Mortgage activities | Applicable origination and servicing activity connected to Fannie Mae | Applicable origination and servicing activity connected to Freddie Mac |
| Policy ownership and review | Designated owner and at least annual review | Defined accountability, ongoing review, and at least annual policy review |
| Senior-management approval | No named executive roles expressly assigned in LL-2026-04 | Applicable senior-management roles or organizational equivalents expressly identified |
| Vendor language | Explicit no-less-protective governance requirement for vendor and subcontractor AI use | Evaluate Section 1302.8 with applicable related-party, security, vendor, and contractual requirements |
| Adversarial threats | Data poisoning and adversarial inputs are not expressly named in LL-2026-04 | Data poisoning and adversarial inputs are expressly identified |
| Monitoring and audit | Risk measurement and management required; not prescribed in the same detail | Performance, breach and bias monitoring plus internal and external audits expressly identified |
| Disclosure on request | Required | Required |
| Indemnification | No comparable clause in LL-2026-04 | Express indemnification provision in Section 1302.8 |
What a unified program can share
An authoritative inventory of AI and machine-learning use cases
Accountable business, risk, security, and technical owners
Documented purpose, data access, tools, and prohibited actions
Legal, compliance, security, model-risk, and fair-lending review
Vendor and subcontractor due diligence and change management
Human-approval thresholds and exception handling
Performance, security, incident, and bias monitoring
Reviewable execution and decision evidence
Incident response, escalation, and periodic reassessment
GSE-specific disclosure and evidence packages
AI Governance Questions
Questions Comparing Fannie Mae and Freddie Mac
Each comparison identifies the governing documents by name so the answer can stand alone in search and answer engines.
Yes, for covered activity. Fannie Mae LL-2026-04 and Freddie Mac Section 1302.8 both expressly address artificial intelligence and machine learning used in applicable mortgage origination.
#both-gses-cover-machine-learningYes, for covered activity. Fannie Mae LL-2026-04 addresses AI and machine learning used to service loans on Fannie Mae's behalf, while Freddie Mac Section 1302.8 addresses applicable servicing activity for Freddie Mac.
#both-gses-cover-servicingFreddie Mac Section 1302.8 is more explicit in its published language about monitoring performance, security breaches and bias, as well as regular internal and external audits. Fannie Mae LL-2026-04 requires risk measurement and management but does not list those controls in the same prescriptive form.
#freddie-more-detailed-monitoringFreddie Mac Section 1302.8 expressly identifies applicable senior-management roles or their equivalents for approval. Fannie Mae LL-2026-04 identifies accountable ownership and annual review but does not assign approval to the same named executive roles.
#gse-senior-management-approvalFannie Mae LL-2026-04 expressly requires seller-servicer governance of vendor and subcontractor AI or machine-learning use to be no less protective than the organization's own controls. Freddie Mac organizations should evaluate Section 1302.8 together with all applicable Freddie Mac related-party, vendor, information-security, and contractual requirements.
#gse-third-party-vendorsOne enterprise program can provide a common control foundation for both GSEs, but it should not erase their differences. The organization should map shared policies and controls to each source, retain enterprise-specific approvals and evidence, and confirm sufficiency with qualified counsel and the current Guides.
#one-program-for-both-gsesA lender should consider retaining its AI inventory, policies, owners, approvals, risk assessments, legal reviews, vendor records, safeguards, monitoring and audit results, incidents, training, exceptions, and action-level evidence. Each artifact should be traceable to the applicable Fannie Mae or Freddie Mac requirement.
#evidence-for-both-gsesPrimary sources
Use the current official documents when assessing applicability, contractual duties, and implementation decisions.
Crittora provides technology controls and operational information. It does not provide legal advice, certify compliance, or guarantee satisfaction of Fannie Mae, Freddie Mac, MISMO, or other requirements. No endorsement by Fannie Mae, Freddie Mac, or MISMO is implied.
Free Consultation
Schedule a Free AI Readiness Call
Talk with Crittora about your AI-governance priorities, the questions your team is facing, and a practical next step. No lengthy preparation is required.