The SAFE Act Line for AI Mortgage Assistants: When Quoting a Rate Becomes Loan Origination and What NMLS Cares About
The Question Nobody Wanted to Ask First
The SAFE Act and its implementing regulations Reg G (federal banking agencies, 12 CFR 1007) and Reg H (HUD/CFPB for state-regulated institutions, 12 CFR 1008) require any individual who acts as a "mortgage loan originator" to be either federally registered or state-licensed through the Nationwide Multistate Licensing System. The definition of "mortgage loan originator" at the federal level 12 U.S.C. 5102(4) and in Reg G/H is "an individual who (i) takes a residential mortgage loan application and (ii) offers or negotiates terms of a residential mortgage loan for compensation or gain." Both prongs have to be present, the activity has to be by an individual, and the activity has to be in connection with a residential mortgage loan.
The drafters of the statute did not imagine that a question would arise about whether an AI agent qualifies as an "individual." The state regulators that supervise NMLS licensees have started asking it anyway, because the AI assistant that engages a borrower, captures the application information, and discusses program eligibility and rate looks operationally like the human MLO whose work it is partly replacing. The state regulators' interest is partly about consumer protection (the licensing regime exists for borrower-facing accountability) and partly about license-fee revenue (a licensed institution's MLO roster is a regulatory data point and a financial one). The institutions we work with have to decide where their AI assistant sits on this line before a state examiner decides for them.
We build the agent that handles mortgage origination intake and ongoing communication on lender, broker, and bank platforms. The framework below is the one our customers' legal teams have validated against the SAFE Act, against state-specific MLO licensing regimes, and against the early commentary from the Conference of State Bank Supervisors on AI in mortgage origination.
What "Takes an Application" Means and What It Does Not
The first prong of the MLO definition is "takes a residential mortgage loan application." The HUD commentary, carried forward into the CFPB's interpretation, defines an application as the submission of information required to make a credit decision, and "taking" the application as receiving the information from the applicant for the purpose of making the credit decision. A clerical worker who enters a fax into the LOS does not "take" the application in the SAFE Act sense, because the worker is not the recipient of the information in the originating moment; the lender is. A loan officer who sits with the applicant and gathers the information for the lender's decision does "take" the application, because the loan officer is the recipient in the operational sense the rule cares about.
The AI agent that engages a borrower over voice or chat and gathers the application information from the borrower in real time is, on a fair reading, taking the application in the operational sense. The information is being received from the applicant in the moment that defines the application's existence. The agent is not a "clerical worker" because the agent is the originating recipient, not a downstream processor of paper someone else gathered.
What the agent is not, on the same reading, is an "individual." The SAFE Act's term is "individual," which the statute and the implementing regulations interpret as a natural person. Software is not a natural person. The licensing regime does not contemplate licensing a software product; the NMLS database is structured around natural persons and supports identity verification, background checks, education, and testing that only apply to humans. The state regulators we have spoken with treat this as the dispositive point. The agent does not need an NMLS license because the agent is not a natural person eligible for one.
That answer is necessary but not sufficient. The next question is who the institution holds responsible for the activity the agent performed, and the institution's answer has to put the activity inside the supervisory perimeter of a licensed natural person. The agent is an extension of the licensed MLO who supervises it, and the licensed MLO is the locus of accountability for the activity.
The Supervising MLO Model the State Regulators Will Accept
The model that has cleared review in the state-by-state conversations we have run is that each conversation the agent conducts is logically attributed to a supervising MLO whose license covers the activity. The supervising MLO is not a fiction; the supervising MLO is a real person at the institution who is licensed in the state where the borrower is located, who has been credentialed in NMLS for the institution, whose name and NMLS ID can be disclosed to the borrower on request, and who is operationally responsible for the application the agent participated in originating.
The supervising MLO does not have to be on the call or in the chat in real time. The supervising MLO has to be available to handle escalations, to review the agent's output for the loans they supervise, and to be the natural-person accountability anchor that the licensing regime expects. The CSBS commentary and the early state guidance contemplate that a single MLO can supervise multiple agent-conducted conversations, the same way a senior loan officer can supervise more junior staff. The supervisory ratio is a state-specific question, but no state has published a specific cap as of mid-2026.
We instrument the agent to record the supervising MLO assignment per conversation, to log the MLO's NMLS ID in the conversation metadata, and to disclose the MLO's identity to the borrower if the borrower asks. The disclosure has to be accurate; the agent that names a fictitious MLO or that names an MLO who is not actually licensed for the state in question is creating a Reg G/H violation the institution will own. The MLO-assignment logic is hardened in the conversation routing layer and audited at the agent level, because the cost of the assignment being wrong is felt at the state-by-state license-coverage layer.
State-Specific Variations the Architecture Has to Respect
The SAFE Act sets a federal floor; the states implement their own licensing regimes on top, and the variations matter. California's Department of Financial Protection and Innovation licenses MLOs under the California Financing Law and the California Residential Mortgage Lending Act, and the state's interpretation of who is a loan originator has nuances around in-house loan processors that affect how the supervising-MLO model plays out. Texas's Department of Savings and Mortgage Lending licenses under the Texas SAFE Act and has been active on borrower-facing accountability in mortgage origination. New York's Department of Financial Services licenses under Banking Law Article 12-E and has issued guidance on AI in financial services that overlaps the MLO question on the consumer-disclosure side.
The institutions we serve maintain a state-by-state coverage matrix that maps every state where they originate loans to the specific MLO license category required, the supervising-MLO roster qualified for each state, and any state-specific disclosure requirements the agent has to render. A state where the institution does not have a licensed MLO is a state where the agent does not originate. A state where the institution has a single licensed MLO whose schedule does not support real-time escalation is a state where the agent's supervising-MLO assignment has to either route to that MLO or queue the application for handoff rather than progressing it.
The federal-registration regime for depository-institution employees runs through Reg G (12 CFR 1007.103) and is a registration rather than a state license. Depository institutions and their subsidiaries register their MLOs federally and the registration covers the MLO across states. The depository institution's AI agent operates under the supervising-MLO model with federally registered MLOs as the supervising natural persons. The framework is the same; the licensing layer underneath is different.
"Offers or Negotiates Terms" and Why the Agent's Script Matters
The second prong of the MLO definition is "offers or negotiates terms of a residential mortgage loan for compensation or gain." The CFPB commentary clarifies that "offering terms" is something more than discussing a loan in general; it is presenting specific loan terms to a specific applicant for the applicant's consideration. "Negotiating terms" is engaging with the applicant about the terms in a way that affects the eventual loan structure.
The line is the substance of what the agent says. An agent that recites the institution's published rate sheet to an applicant is not negotiating; it is communicating the institution's posted information. An agent that quotes a specific rate to a specific applicant based on the applicant's circumstances is offering terms. An agent that responds to an applicant's request for a lower rate by floating a buy-down or a different program is negotiating terms. The first activity is on the safe side of the licensing line. The second and third are squarely on the MLO-licensed side.
The agent's script and the agent's autonomous behavior have to be designed against this line. The institutions we work with split the agent's allowed conversation moves into three tiers. Tier one is information-only, where the agent recites published information, schedules appointments, and answers factual questions about the institution's offerings; this is clerical and the agent operates with broad latitude. Tier two is application-intake, where the agent receives the application information and is operating as an extension of a supervising MLO; the agent is allowed broader interaction but does not make pricing decisions. Tier three is offers and negotiation, where any pricing-specific or term-specific conversation is conducted only under the active supervision of an MLO and any specific quote the agent renders has been approved by the supervising MLO for the applicant's profile.
The tier-three rule does not require the MLO to verbally approve each conversation in real time. The MLO can approve a pricing approach for an applicant profile that the agent then communicates, and the MLO's approval is the licensed activity that the agent is communicating on. The agent that renders specific terms outside the MLO's pre-approved scope is operating outside the supervisory perimeter and exposing the institution. The validator stops the agent's response generation when the agent's intended next utterance would render terms that the supervising MLO has not pre-approved for the conversation. The validator's rules are tight enough that the conversation either fits the pre-approved envelope or pauses for MLO interaction.
The Loan Processor or Underwriter Exclusion and Why It Does Not Save the Conversation
The SAFE Act exempts loan processors and underwriters from the MLO definition under specific conditions. The exemption at Reg G 1007.102(d) and Reg H 1008.103(c) covers persons who perform clerical or support duties at the direction of and under the supervision of an MLO and who do not represent to the public, through advertising or other means, that they can or will perform any of the activities of a loan originator.
The institutions that try to argue that the AI agent fits this exemption have to make two showings. First, that the agent's activities are limited to clerical or support functions. Second, that the agent does not represent to the public that it performs loan-originator activities. The first showing is hard for an agent that engages in application-intake conversations, because the application intake is the substantive activity at the heart of the MLO definition's first prong. The second showing is hard for an agent that the institution markets as helping borrowers through the application process.
The loan-processor exemption is not the right doctrinal hook for an AI conversational agent. The right hook is that the agent is software operating under the supervision of a licensed MLO, with the MLO as the natural-person locus of accountability. The supervising-MLO model does not depend on the agent fitting an exemption; it depends on the activity being attributed to the licensed person whose supervision and accountability the regime exists to ensure.
Disclosure to the Borrower and the State NMLS Lookup
The state licensing regimes require MLOs to provide their NMLS unique identifier to consumers and to include it on certain consumer documents. The borrower has the right to look up the MLO's record on the NMLS Consumer Access site and see the MLO's license status, employment history, and any public disciplinary record. The agent's interaction has to support this right.
The agent renders the supervising MLO's NMLS ID on demand, includes it on disclosures the agent generates, and ensures the lookup the borrower performs returns a record consistent with the institution's representation. An institution whose AI workflow attributes conversations to an MLO whose NMLS record shows the MLO is no longer with the institution, or who is licensed in different states than the institution's footprint suggests, is creating a public-facing inconsistency that the borrower will see immediately. The MLO-attribution data has to come from the NMLS-of-record rather than from a stale internal directory, and the agent's NMLS lookup at conversation start is the discipline that keeps the two in sync.
Compensation and the Section 1026.36 Layer Above the License
The SAFE Act licensing question runs alongside the Regulation Z LO compensation rules at 1026.36, which prohibit compensating an MLO based on the terms of a transaction other than the loan amount, and which prohibit a consumer from paying both the lender and a separate party as MLO compensation in the same transaction (the "dual compensation" rule). The compensation rules do not directly bind the AI agent because the agent is not compensated, but they bind the supervising MLO whose activity the agent supports, and they bind the institution whose compensation structure pays the supervising MLO.
The institutions we work with run the compensation structure against the AI workflow as a single design problem. An institution that compensates its MLOs based on loan volume can use the AI agent to expand the volume each MLO can supervise without changing the compensation structure. An institution that ties compensation to specific loan products or pricing tiers has to ensure the AI workflow does not steer borrowers to those products or tiers in ways that produce the compensation outcome the rule prohibits. The agent's recommendation and pricing logic feeds into the MLO compensation analysis, and the institution that has not connected the two is the institution whose first 1026.36 finding will be the moment they connect them retroactively under examination pressure.
The Examination Posture Coming Together
State examiners have started asking institutions about AI in mortgage origination during routine MLO examination cycles. The questions we have seen so far focus on a few clean points. Who is the licensed MLO responsible for each application the AI agent participated in. What was the agent's scope of activity on the application, and how was the supervising MLO involved. What disclosures were made to the borrower about the role of the AI agent and about the supervising MLO's identity. What controls limit the agent from offering or negotiating terms outside the supervising MLO's authority. What documentation supports the supervising MLO's actual supervision of the application.
The institutions that have answers to these questions ready in the form of audit artifacts have had short examination conversations on this topic. The institutions that improvise are the ones whose examination cycles have extended into multi-day deep dives on AI controls that, the examiner concluded, did not have the documentation the regime expects.
The audit artifact we keep per application includes the agent's per-conversation log with the supervising-MLO assignment and the tier-classification of each agent activity, the supervising MLO's NMLS identifier and license status at the time of the conversation, the borrower-facing disclosure the agent rendered about its role, any specific terms or quotes the agent communicated and the supervising MLO's pre-approval that authorized them, the validator's stop events showing where the agent's intended response was blocked because it exceeded the supervisory perimeter, and the application's outcome with the MLO's final signoff. The artifact is generated automatically by the agent's logging architecture and is part of the loan file from boarding.
The Marketing Posture That Sometimes Defeats the Architecture
A pattern we have seen produce supervisory attention is the institution that markets its AI agent in language suggesting the agent is acting as a loan originator. Marketing copy that says "our AI loan officer will help you find the right loan" presents the agent as the originator. State examiners read marketing copy, and an institution whose copy presents the agent as the locus of the origination activity is an institution whose practice the examiner will assume matches the copy.
The institutions we serve align marketing copy with the actual operational model. The agent is described as an assistant that helps with the application and connects the borrower to a licensed loan officer. The licensed MLO is named in the consumer-facing materials. The agent's activity is presented as support for the MLO rather than as origination by the agent. The substance of the language is calibrated to what the institution can defend under examination, because the marketing copy is the cheapest piece of evidence the regulator collects and it sets the framing for everything else.
The Honest Read
The SAFE Act question for AI mortgage assistants does not have a definitive federal answer yet, and the state-by-state interpretations are still developing. What the institutions we serve have settled on is a posture that anticipates how the question will resolve and that puts the agent's activity inside the supervisory perimeter of a real, licensed natural person whose accountability the regime expects. The supervising-MLO model is the answer that aligns with the licensing regime's purpose, that handles the federal-state coverage variations cleanly, and that produces the documentation the state examiners are starting to ask for.
The institutions that wait for the federal regulators or the CSBS to publish a definitive interpretation are not necessarily wrong to wait, but the wait does not protect them in the interim. A state examiner does not need a federal interpretation to ask the institution who supervised the AI agent on a specific loan, and the institution whose answer to that question is improvised under examination is the institution whose practice will be questioned more broadly. The architecture is not hard to build, and the cost of building it before the question is asked is meaningfully lower than the cost of building it after.
We have written separately on the Regulation Z 1026.36 compensation rules that interact with the licensing regime, on the TRID disclosure clocks that run on the application moment, and on the fair-lending program that depends on the agent's pricing and offering activity being attributed cleanly to the licensed person whose decisions the rules govern. The licensing layer is the foundation underneath the rest. The institution that gets the licensing layer right has a clean foundation. The institution that gets it wrong has a foundation problem that propagates through every other compliance question the regime cares about.
Pranay Shetty
CEO & Co-Founder