PAN Lab example
Earnest AI underwriting
A neutral-looking feature and the testing no one ran
Earnest's student loan models priced loans by a school's default rate and denied some non-citizens outright. A 2025 settlement bars both and requires fairness testing.
See more
Earnest Operations, a US student loan lender and refinancer, used its own algorithmic models in underwriting: deciding who gets a loan and on what terms. The sources do not name the models. Two of their features are at the center of this case: a school's cohort default rate and a rule automatically denying certain non-citizen applicants.
The two features
The first is a school's cohort default rate: the default history of the school's past borrowers. The models priced it into an individual applicant's terms. It describes a school, not the person applying. It names no protected class, meaning a group the law shields from discrimination, such as a racial group.
The Attorney General alleged that this feature had a disparate impact on Black and Hispanic applicants, in approval rates and loan terms for one Earnest loan product. A disparate impact is harm that falls harder on a protected group, even though the rule behind it looks neutral. The research file behind this example describes the allegation as penalizing applicants for the schools they attended.
The second is a rule that automatically denied certain non-citizen applicants: those without permanent-resident status, known as a green card. The case file calls it a categorical exclusion built into the decision.
What the Attorney General alleged was missing
The Attorney General alleged that Earnest ran no disparate-impact testing, which would compare the models' outcomes for protected groups with outcomes for others. The case file says the cohort default rate's alleged impact therefore went unmeasured until an outside enforcement action raised it.
The Attorney General also alleged that Earnest's adverse-action notices were inadequate. An adverse-action notice is the notice a lender sends an applicant it turns down, with the main reasons. In the allegation, denied applicants were not given the specific, accurate reasons the law requires.
In the case file's reading, the failure was not only the two features. It was also the missing testing that would have caught the first, and the missing explanation that would have told applicants about the second.
What the law asks of a denial notice
The Consumer Financial Protection Bureau, the US federal regulator for consumer finance, explained the rule in guidance issued in 2022 and 2023. Under the Equal Credit Opportunity Act and its Regulation B, a lender must give specific, accurate main reasons for a denial. That holds however complex the model is. A model too complex to explain is no defense. Ticking the closest box on the bureau's sample form does not comply.
The settlement
The Massachusetts Attorney General's office announced a $2.5 million settlement with Earnest on July 10, 2025. It is an Assurance of Discontinuance, a settlement filed in Suffolk County Superior Court. The office's announcement describes unlawful practices through AI use and other consumer protection violations.
The settlement resolves the Attorney General's allegations. Earnest denied them and admitted nothing. Legal analyses listed in the research behind this example say so.
The settlement bars Earnest from using the cohort default rate and the immigration-status rule. It did not simply penalize Earnest and close the matter. It also requires the program the case file says Earnest had never built: model governance, disparate-impact testing, documentation, and reporting controls. Model governance means oversight of how the models are built and used.
How to read this case
The case file calls this the clearest case among its lending cases of alleged failures followed by governance that a settlement required. In its reading, the model was not uniquely bad. The governance around it was missing, and the remedy installed it.
A feature can look neutral one applicant at a time and still sort people by something it stands in for. Only testing of outcomes shows whether it does. The case file's lesson is that a feature built from a group's history brings a duty to test it.
The case file also reads the required program as ordinary governance. In its reading, nothing here required a more accurate model. It required the testing, the documentation, and the explanation the Attorney General alleged Earnest skipped. The case file calls that a resourcing choice made too late, not an unavoidable harm.
What the available tools can and cannot address
A failure pathway is a link between two parts of the network where a mistake made by one part can be passed on to the other. A pathway is closed when mistakes stop passing along it. The work along it may go on.
Explore (No Targets) sets no targets. Under Service Targets Only, the targets can be met. The cheapest way costs 3 of this case's 11 budget units: Mark AI-written records at its stronger setting. At its standard setting it needs a partner, such as Review on schedule, for 4 units. All 16 combinations of tools that meet these targets within the budget include Mark AI-written records.
On this network, Mark AI-written records marks what the models wrote in the record, so staff and the models can weigh it. Mistakes stop passing along the record data the models use. They also stop passing when compliance staff and the governance program read the record. Fewer pass along the school cohort default rate, and none at the stronger setting.
Under Service and Safety Targets and under All Governance Targets, this case is not fully addressable with the available tools. Both levels ask you to close every failure pathway, among other targets. Every combination of tools was checked, with the budget lifted, and none meets the targets at either level.
Two failure pathways stay open under every combination. One is the immigration-status rule denying applications. The other is compliance findings used on the models. None of the tools offered here acts on either pathway. The service reading shows whether the work keeps up with demand. It also stays at strained under every combination.
The tools offered are the ordinary functions the settlement required: governance, testing, documentation, and reporting. That is a finding about the deployment, not a flaw in your choices.
Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.
What this models
This example runs on the Automated-underwriting-class with the governance an order had to write network: 6 components and 13 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.
Evidence base: 3 assumed · 2 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.
Show all 5 assumptions
- assumed
The settlement names two features of Earnest's models, and this example draws each as its own part. The school cohort default rate comes from outside the applicant's own file. It describes a group of past borrowers, not the applicant. That is why a review of the inputs alone passes it, and only testing of outcomes catches it. The immigration-status rule is drawn as an automatic action, because the Attorney General described it denying applications outright. A rule of that kind applies to everyone it names, so nothing is left for a person to weigh. This example treats both as acting on every application they touch, because the alleged disparate impact and the denials run through them. Drawn this way, one part turns a group statistic into one person's price. The other reaches an outcome automatically.
- baseline
This example follows the pattern the case file documents: alleged failures, then governance that a settlement required. It does not rebuild Earnest's actual models. The Massachusetts Attorney General reached a $2.5 million settlement with Earnest over its AI underwriting. The settlement resolves the Attorney General's allegations. The Attorney General alleged that a cohort default rate feature disparately impacted Black and Hispanic applicants. The office alleged that an immigration-status rule automatically denied certain non-citizen applicants. It also alleged that Earnest ran no disparate-impact testing and sent inadequate denial notices. Earnest denied the allegations, and the settlement is not an admission. It bars both features and requires model governance, testing, documentation, and reporting.
- assumed
This example also draws the cohort default rate on the pathway where the models use data from the application and decision record. That is where a group's history enters one person's decision. A school's default rate names no protected class. The Attorney General alleged it still carried protected-class impact, which only testing of outcomes would reveal. This example draws the testing the Attorney General alleged was missing as the disparate-impact check on the models. In the case file's reading, that missing testing is the failure, because a neutral-looking input does not guarantee a fair outcome.
- baseline
This example draws the program the settlement required as a check by that program on Earnest's compliance staff. In the case file's reading, the settlement did not invent new controls. It installed standard ones the Attorney General alleged Earnest had skipped: model governance, disparate-impact testing, documentation, and reporting. These ordinary, nameable functions were available from the start. So the case file reads the harm as a resourcing choice made too late, not an unavoidable one.
- assumed
This example computes no credit outcome, and it draws no applicant. It shows how mistakes move among Earnest's models, staff, and records, with applicants outside it. The two features, the alleged gaps in testing and notices, and the required program come from the case file. Nothing in this diagram computes them.
What this example does not show
Show all 2 limitations
- This example computes no credit outcome and draws no applicant. It shows how mistakes move among Earnest's models, staff, and records. The two features, the alleged gaps in disparate-impact testing and denial notices, and the required program come from the case file. Nothing on this diagram computes them.
- The settlement resolves allegations about two features of the models and two gaps in governance, and requires a program to close the gaps. The features are the cohort default rate and the immigration-status denial rule. The alleged gaps are missing disparate-impact testing and inadequate denial notices. This example draws them as parts and pathways, with two checks: the testing and the required program. It does not compute the harm.
Sources and evidence
What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.
A state attorney general reached a $2.5 million settlement with a student-loan lender over its AI underwriting. The alleged conduct, which the lender denied without admission, is the domain's cleanest failure-then-mandated-governance arc: the model used a cohort-default-rate feature — a school's aggregate default rate priced into an individual applicant's terms — that disparately impacted Black and Hispanic applicants, and an immigration-status rule that automatically denied certain non-citizen applicants, while the organization ran no disparate-impact testing and gave inadequate adverse-action notices. The remedy did not fine-and-close: it barred both features and mandated the missing program — model governance, disparate-impact testing, documentation, and reporting controls — so the enforcement action wrote the governance the deployment had never built.
empirical- Government Office of the Massachusetts Attorney General (2025, July 10). AG Campbell Announces $2.5 Million Settlement With Student Loan Lender For Unlawful Practices Through AI Use (Assurance of Discontinuance, Earnest Operations LLC). https://www.mass.gov/news/ag-campbell-announces-25-million-settlement-with-student-loan-lender-for-unlawful-practices-through-ai-use-other-consumer-protection-violations
The mechanism the case turns on is the facially-neutral aggregate feature: a cohort default rate is a property of a school, not of the applicant, and no input names a protected class — yet pricing a group's aggregate history into an individual's terms can carry protected-class impact, which is exactly what disparate-impact testing exists to catch. Here, the attorney general alleged, that testing was not done, so the impact went unmeasured until an enforcement action found it. The remedy installed the program the deployment lacked, which is the governable reading: an aggregate feature can look neutral input-by-input and still produce a disparity only outcome testing would reveal, and the absence of that testing is itself the failure.
empirical- Government Office of the Massachusetts Attorney General (2025, July 10). AG Campbell Announces $2.5 Million Settlement With Student Loan Lender For Unlawful Practices Through AI Use (Assurance of Discontinuance, Earnest Operations LLC). https://www.mass.gov/news/ag-campbell-announces-25-million-settlement-with-student-loan-lender-for-unlawful-practices-through-ai-use-other-consumer-protection-violations
- Regulatory Consumer Financial Protection Bureau (2022, 2023). Circular 2022-03: Adverse action notification requirements in connection with credit decisions based on complex algorithms; and Circular 2023-03 on Regulation B sample forms. https://www.consumerfinance.gov/compliance/circulars/circular-2023-03-adverse-action-notification-requirements-and-the-proper-use-of-the-cfpbs-sample-forms-provided-in-regulation-b/
Where this connects
Institutional pressures in this domain
- Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
- Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
- Data & policy drift — The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).
- Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
- Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
All of them in context on the Lending & credit collections AI domain page.
Levers available here and the patterns behind them
- Review on schedule — Oversight cadence & retrospectives
- Check with a second model — Cross-model verification
- Gate record entries — Human-in-the-loop write gating
- Mark AI-written records — Provenance labeling
- Pause AI on alarms — Deployment circuit-breaker
- Store less data — Data minimization
- Upgrade model — Improve the model
Documented case histories
- The governance an enforcement action had to write
- Automated underwriting with its fair-lending testing on the record
- Cleared on the numbers but faulted on the explanation
- M-Shwari & Kenya's Digital Credit Market
- Citi Retail Services Judgmental Review & the Armenian surname screen
- Santander Consumer USA subprime vehicle loan scoring
- Credit Acceptance Corporation's net-collections score
- Wells Fargo refinance underwriting & the bridge nobody could build
- Navy Federal mortgage underwriting & three readings of one gap
- Enova International servicing defects & the debits nobody authorised
- Equifax Online Model Server coding error (2022)
- TransUnion's OFAC Name Screen & the people who could not sue
- Dave ExtraCash: an advertised ceiling, an automated amount, and a case that never asks how the amount is set
- Hello Digit's automated-savings algorithm
- Oportun's legal-collections filing pipeline