Freddie Mac AI and Machine-Learning Governance
From Required Governance to Enforceable AI Authority
Freddie Mac Guide Section 1302.8 requires covered sellers and servicers to maintain policies, controls, oversight, monitoring, and audit practices for artificial intelligence and machine learning.
Can your evidence show what the system was allowed to do?
A policy states what should happen. Execution-time controls and records help show whether a sensitive AI action stayed within approved authority.
Direct Answer
What does Freddie Mac require mortgage lenders and servicers to do about AI?
Effective March 3, 2026, Freddie Mac Guide Section 1302.8 requires covered sellers and servicers using AI or machine learning in applicable origination or servicing activities to implement an AI governance framework. The section addresses documented policies, senior-management approval, legal compliance, trustworthy AI, risk management, threat assessment, monitoring, audits, accountability, training, and prompt disclosure when requested.
What the Requirement Covers
Freddie Mac's more explicit control areas
Senior-management approval
Obtain approval from applicable senior-management roles identified in Section 1302.8 or their organizational equivalents.
Threat assessment
Address AI and machine-learning threats including data poisoning and adversarial inputs as part of risk management.
Ongoing monitoring
Monitor AI and machine-learning systems for performance, security breaches, bias, and other relevant risk signals.
Internal and external audits
Conduct regular audit practices and consider the recognized security and control standards identified in the Guide.
Accountability and training
Define roles, segregation of duties, accountability structures, training, and clear communication paths.
Disclosure and contractual exposure
Prepare for requested disclosures and have counsel review the section's indemnification provision and related contractual obligations.
AI Governance Questions
Questions About Freddie Mac Section 1302.8
These answers address Freddie Mac's published Guide requirement and should be checked against the current Guide and the organization's specific activities.
Freddie Mac Guide Section 1302.8 applies to covered AI or machine-learning use in servicing mortgages for Freddie Mac. Applicability to a particular servicing workflow should be assessed against the current Guide.
#freddie-servicing-scopeYes. Freddie Mac Section 1302.8 addresses both artificial intelligence and machine learning, so its scope is not limited to generative AI, large language models, or chatbots.
#freddie-machine-learning-scopeFreddie Mac Section 1302.8 identifies applicable senior-management roles, including the CIO, CTO, CISO, CRO, or organizational equivalents. A seller or servicer should confirm which roles apply to its structure and document the approval.
#freddie-executive-approvalFreddie Mac Section 1302.8 expressly addresses regular monitoring of AI and machine-learning performance, security breaches, and bias. The organization should define owners, metrics, thresholds, escalation, remediation, and evidence appropriate to each use case.
#freddie-monitoringFreddie Mac Section 1302.8 calls for regular internal and external audits of AI and machine-learning systems and references recognized standards such as NIST SP 800-53 and ISO 27001. Audit scope and cadence should be established with qualified compliance, security, audit, and legal teams.
#freddie-auditsYes. Freddie Mac Section 1302.8 expressly identifies risks including data poisoning and adversarial inputs. The organization should include those threats in its risk assessment, security testing, monitoring, response, and governance evidence.
#freddie-adversarial-threatsFreddie Mac Section 1302.8 requires prompt disclosure of requested information concerning the types of AI or machine learning used, their purpose and manner of use, implemented safeguards, and other information Freddie Mac requests.
#freddie-disclosureNo. Crittora Agent Authority Broker is designed to support execution-time authorization and evidence for sensitive AI actions, which is only one part of a broader Freddie Mac governance program. Legal analysis, senior approval, risk assessment, monitoring, audits, security, training, and accountability remain organizational responsibilities.
#crittora-caab-and-freddiePrimary sources
Use the current official documents when assessing applicability, contractual duties, and implementation decisions.
Crittora provides technology controls and operational information. It does not provide legal advice, certify compliance, or guarantee satisfaction of Fannie Mae, Freddie Mac, MISMO, or other requirements. No endorsement by Fannie Mae, Freddie Mac, or MISMO is implied.
Free Consultation
Schedule a Free AI Readiness Call
Talk with Crittora about your AI-governance priorities, the questions your team is facing, and a practical next step. No lengthy preparation is required.