Ginnie Mae’s MBS portfolio surpassed $3 trillion in August 2026 as issuance remained strong, while rising mortgage rates have left roughly 98% of 30-year borrowers without a refinancing incentive, reducing prepayments and pushing much of the Agency MBS market toward positive convexity. Robbie interviews Cinchy’s J. Paul Haynes on helping enterprises safely deploy AI in production, and gain the visibility, runtime policy enforcement, and operational oversight needed to confidently scale AI. And the Fed’s hawkish return to tightening has bolstered its inflation-fighting credibility, but with much of the expected additional tightening already priced in and growth remaining resilient, further hikes are less certain, leaving Treasuries supported near term while fiscal and inflation risks continue to constrain a sustained decline in long-term yields.
This week’s podcasts are sponsored by FirstClose. FirstClose helps lenders accelerate home equity originations with faster property decisioning, streamlined workflows, and a digital borrower experience from application to closing. FirstClose is the only end-to-end digital HELOC and HEL solution built specifically for home equity lending. Learn more at: https://hubs.ly/Q04tLGXh0
Welcome to The Chrisman Commentary, your go-to daily mortgage news podcast, where industry insights meet expert analysis. Hosted by Robbie Chrisman, this podcast delivers the latest updates on mortgage rates, capital markets, and the forces shaping the housing finance landscape. Whether you're a seasoned professional or just looking to stay informed, you'll get clear, concise breakdowns of market trends and economic shifts that impact the mortgage world.
Presented by
FirstClose — FirstClose helps lenders accelerate home equity originations with faster property decisioning, streamlined workflows, and a digital borrower experience from application to closing. FirstClose is the only end-to-end digital HELOC and HEL solution built specifically for home equity lending.
In This Episode
0:00
Full Transcript
Show full episode transcript
Robbie ChrismanWelcome to the Chrisman Commentary, Daily Mortgage News Podcast. I'm your host, Robbie Chrisman. Topics on today's episode include titled Pirates, my interview with Cinchy's J. Paul Haynes on helping enterprises safely deploy AI in production and gain the visibility, runtime policy enforcement, and operational oversight needed to confidently scale AI. And further reaction to the Fed's rate hike on Wednesday. This week's podcasts are sponsored by First Close. First Close helps lenders accelerate home equity originations with faster property decisioning, streamlined workflows, and a digital borrower experience from application to closing. First close is the only end-to-end digital key lock and home equity loan solution built specifically for home equity lending. Learn more at firstclose.com. A pirate walks into a bar with a steering wheel in his pants. When the bartender points it out, the pirate replies, Arg, it's driving me nuts. Talk like a pirate day is tomorrow, the nineteenth. There obviously won't be a podcast on Saturday. But what is a title pirate? It's something that A, I hope you never encounter, and B, every loan originator should tell their borrowers about, especially given the FBI's warning for people who own their homes without any debt. A big thrust by many lenders and originators is helping homeowners use the equity in their home or offering a shared equity product. And why not? There's thirty-six trillion dollars in home equity out there. And in an industry where we'll be lucky to hit two trillion dollars in originations this year, it's a juicy target. You ever wonder what happens to your FHA and VA loans? Ginnie Mae's mortgage-backed securities portfolio outstanding grew to $3.01 trillion as of August 2026. In addition, Ginnie Mae issued $52.14 billion in total MBS, resulting in net portfolio growth of $24.46 billion. Year to date, Ginnie Mae facilitated the pooling and securitization of more than $478,000 first-time homebuyer loans. And the Fed's return to tightening has restored some investor confidence in its commitment to fighting inflation. With Wednesday's unanimous 25 basis point hike and Chair Warsh's hawkish message emphasizing that inflation remains the primary problem, while growth is proving more resilient than expected. MBS and U.S. Treasuries rallied modestly Thursday, led by the long bond, as lower oil prices and the Bank of England's decision to halt long-dated gilt sales supported broader strength in the long-term sovereign debt. Despite the Fed's hawkish stance, the case for additional hikes is less clear-cut because yesterday's move may have served partly to reestablish inflation fighting credibility rather than respond to an economy that clearly demanded tighter policy. Fiscal concerns should continue to provide a headwind to long-duration bonds and make a sustained move below 5% in the 30-year difficult without a meaningful deterioration in growth or risk assets. Sixteen of eighteen policymakers see 50 basis points to 75 basis points of accumulative tightening in 2026. Eight see a four and three-eighths percent terminal rate in 2027, and the market is pricing roughly 75 basis points of additional tightening by mid-year next year. The near-term question is whether the Fed hikes again in October, with markets assigning roughly a 53% probability versus 75% for December. Economic data, not concerns about political optics around the midterms, should ultimately determine the pace of further tightening. Since much of the expected tightening is already priced in, bond yields are expected to drift lower as investors reassess how much additional tightening can realistically restrain an economy, supported by resilient growth and inflationary pressures tied to geopolitics, energy, and AI-driven demand. Because homeowners effectively hold a prepayment option. When rates fall, they can refinance and repay their mortgages at par, accelerating investors' cash flows just as mortgage-backed security prices would otherwise rise. While when rates rise, prepayments slow and investors remain exposed to longer duration assets. This makes MBS prices and duration more sensitive to rate moves than comparable option-free bonds, and helps explain their yield premium. Not as compensation for credit risk, since agency mortgage-backed securities carry an implicit or explicit government guarantee, but for uncertainty over the timing of principal repayment and the resulting hedging costs. Mortgage investors therefore generally prefer range-bound rates, which keep duration more stable, while deeply out-of-the-money mortgages can become positively convex when rates rise enough to eliminate refinancing incentives. That dynamic became especially pronounced after the Fed's 2022 tightening pushed mortgage rates sharply higher, leaving much of the low coupon mortgage-backed security universe with little or no refinancing incentive and unusually positive convexity. With mortgage rates rising again, roughly 98% of the 30-year borrowers reportedly now lack a refinancing incentive, pushing the sector's convexity back toward, or in some cases into, positive territory. Particularly in higher coupons, 5.5% mortgages, while 4.5% coupons are approaching the same threshold. He's helped build and scale some of cybersecurity's most recognized organizations, including playing a leadership role in the growth of eCentire from an emerging startup into one of the industry's leading managed detection and response providers. You'll have to forgive me because I'm going to start rudimentary and then we'll work our way. Yeah, sure. But when we say AI governance, are we talking about the government governing companies? Are we talking about companies' own internal governance over their AI? What is it? Is both those things? How would you describe AI governance? J. Paul HaynesWell, you actually have hit a really uh important topic because everyone has their own definition. It's sort of, you know, make your own adventure uh in in the marketing department. So everybody's got a version of governance. Um, but I would um I would uh break it down a couple different ways. Governance is is a proxy for trust. Um, and um and what you do in typical governance programs, you know, leaving AI aside is you identify risk areas, you develop mitigating controls, monitoring and mitigating controls, and then you report on those periodically. And that imputes uh trust. Like you can't look at every single activity, you have to do sampling, just like auditing works in accounting. So you're doing sampling, you're um demonstrating that the identified risks were detected and the mitigating control actually contained it. And and this is you know whether it's cybersecurity or uh there's a version of this in lending, and there's uh formulas and ways that this that this has been done for years. So when you apply that to AI, AI is a very rapidly changing space, but uh you have decisions that are being made autonomously, and some of those are okay, uh, where you have like a hundred percent deterministic, you know, yes or no, and you can decompose the decision down to something as simple as that, and then you chain them together and you and you get to the right answer. And that represents a lot of human work processes in a work environment. And then you get into autonomous decision making that is non-deterministic, where um it's relying on generative AI. So when a lot of people speak about AI and governance, today they're actually uh implicitly referring to uh generative AI or LLMs. And um in those scenarios, you have uh a much wider range of outcomes. They're based on the data that they're uh provided and whatever additional scope is provided to the decision making that will affect the results. And you'll get a very confident answer that could be obviously wrong, but not to the AI. So from a governance perspective, there you have to figure out what decisions am I uh okay with happening happening autonomously, and which ones do I need to have a human validating, or the so-called human in the loop. Every decision that's made should be tracked and recorded and um and reproducible. So this is a sort of a transparency concept that would sort of characterize where we where we see governance in general terms. There's other specific branches of governance, which is where you've got company policies that you can basically implement in code and you can enforce this like a runtime decision making, such as if there's PII, which is rampant in the in the mortgage market, if there's PII exfiltrating the organization, it may be okay if you're sending it to the client who who's the PII is about, but not if it's going to, I don't know, uh another mortgage broker or a different company or something like that's getting traded, and you need to have permissions. So things like that you can programmatically enforce. You can actually test the flow of data going in and out of the LLMs for whether it contains uh PII and then make a decision on the fly. Other things are uh permissions. A lot of AI implementations, the original days would provide access to the um the model at the sort of highest level of permission, like an administrator. Yet the person, you know, John Smith working in his cubicle is now seeing answers that are above his pay grade, effectively. So there's a governance required about enforcing access and permissions at runtime. Those are a couple examples. Those are the the the things that uh when we talk about governance, uh managing that programmatically at runtime is one of the areas that that my firm focuses on. Robbie ChrismanIt would seem to me, at least philosophically, the the operative word here is confidence or trust. Trust is the word, yeah. Yeah, trust. How do we instill trust both in, I guess, the I mean good data in to get good data out as its own category. But when it comes to the governance around the AI, trusting that it's going to keep you in the proper lane, not running astray of your counterparties or regulators or whoever powers that be. How do we instill trust? How do we check, how do we make sure that's engendered? J. Paul HaynesWell, trust is a is a great topic um in itself. It's um generally earned over time. And uh in this AI world, you are basically being asked to trust something that you haven't had a lot of time to get uh to see action. So the um sort of the proxy for trust is um you know certifications and regulations where they they do um spot checking, like we're talking about with accounting. You would have ISO 42001 is probably the emerging uh standard. Um, in Europe, you're going to be subject to the EU AI Act and uh NIST has the risk management framework. NIST is the is a US organization, think tank kind of organization that comes up with these kinds of standards. So being able to assert that you comply with the standard or actually getting a certification from a third party, such as one of the big four accounting firms, is one way that you can expedite trust. So if you if you're in an initial relationship with a company supplying software and that software is using AI, I'm gonna say, well, I love what your software is doing, but how can I trust it? Oh, I've got this uh audit report from one of the big four accounting firms that says that we're certified against the 42,001 standards. So that would be the proxy for trust. And um in um in in industries like in financial services, uh the counterparty uh operational due diligence and DDQs, which are flowing back and forth, are actually a hunting license. You can't even engage with the counterparty if you don't, if you're not this tall, you can't take the right kind of thing. You have to comply with many different standards, ISO 27,000 and cybersecurity, and on top of that, you're now gonna have 42,000 in one. Robbie ChrismanThis next question could probably be broken into three parts. And I was I was gonna say the first part would be how to make sure AI is operating within policy. The second part would be interacting with enterprise systems responsibly, and the third part would be not introducing unnecessary risk or cost, and and you could break them up into that triumvirate, or you can you can speak on all three together, but operating within policy, interacting with systems responsibly, and not introducing unnecessary risk or costs, if you could opine on that. Okay. J. Paul HaynesSo on the policy front, you know, you can enforce policy at runtime uh by programmatically inspecting all of the traffic movement. If you look at a lot of AI implementations that have started out as pilots and experimentation and gone into some form of production, it's very typical for a firm to have a uh sort of a hodgepodge of connections and you know, direct connections with APIs and so forth to the LLMs and connecting in data sources. Um, when that number gets into the hundreds, you will find it actually becomes quite untenable. So, about a year and a bit ago, um, Anthropic came up with a standard called uh model uh contacts protocol MCP, and an MCP server actually serves as a gateway. So you drive all of your uh traffic through the gateway, and that gives you uh basically a monitoring point or a choke point, the same way a firewall works. And so um you're gonna see a lot of projects moving from direct access to gated access through an uh an MCP server or multiple MCP servers. Any of the major software firms now, whether it's Salesforce or SAP, will have an S MCP that you can connect into and you can prompt against it using an LLM. So that is already uh sort of evolving quickly in the industry. And then you can control how those MCPs behave using um a combination of tools and skills. These are you know terms that are used in the deployment teams, but the skills actually direct at which tools to use and not don't use all the other tools, just use these three that will answer that type of prompt. And so there's things like that that are happening quite uh quickly. Now, the policy of, you know, we were talking about earlier with exfiltrating uh PII or looking for material non-public information, MNPI, uh, that gets trickier. But um no, those are things like keywords, and it gets into the world world of uh data loss prevention and DSPM. These are a couple of domains where firms have attempted to try and get a data architecture and track all the data flowing within their environment. So data flowing out of the environment or flowing to an LLM will trigger um on keywords, among other and patterns. And so that all applies in AI. This is a known technique that has been used in industry for you know probably going on 20 years uh with varying degrees of success, but AI makes it super critical to get it right. So that's how you how you deal with policy and enforcing it at runtime. You've got to run it through a choke point, inspect the data flowing through, and make decisions so it doesn't actually leave if you don't want it to, or a human uh can approve the the leaving, and that that can then be recorded. And everything in those scenarios should you should persist the trail of what the prompt was, what the data retrieved was, decisions made on the data, and then how it left the organization. That was the first question. Robbie ChrismanWell the second part was interacting responsibly, and I mean they tie together somewhat making sure that it's interacting with enterprise systems responsibly. J. Paul HaynesYeah, so responsibly is there's a couple of different dimensions here. One is managing access policy. So in your organization, your job role will give you entitlements to certain data sets, and whoever is the custodian of those data sets will have uh differing tiers of who's allowed to see or do what with the data. And uh you'll read, write, change, kind of thing, delete. And so those policies have tended to work really well. Now, the thing with with AI is it's data hungry, it's gonna go after everything. You've got to basically be able to propagate those policies into your production environment. So you're you're not giving the AI an extra set of entitlements or capabilities. And this is this is generally hard to do. We have spent our careers at Cinchy building that kind of uh capability for data access. And so for us, migrating that into the AI world has been it's been non-trivial, but it's it's basically using the same methodology where you have to effectively assess what the AI is doing on behalf of Robbie and making sure that it's doing what Robbie's entitled to do. So that's what that's one version of it. Another one is volume of access and gating, and so doing um huge query, like you can prompt uh into very large query scenarios. And aside from whatever costs and tokens, it may actually be an indication of a potential threat or a breach going on. So one of the things that um that you can do is rate limit what it's allowed to do or gate it and have it pause at certain steps. So there's things like that in terms of um ethical access or proper access that an employee doing it as an insider threat might be one thing you want to trap, but I think the bigger risk is uh that employee's credentials have been compromised, and now an adversary is in there acting as the employee and doing it. So so you actually you flip into ethical access and cyber defense, uh detection and and defense in one sentence kind of thing. Robbie ChrismanWell, the then the third part was not introducing unnecessary risk into the equation, which I mean I I'm hearing you talk, and I think in that game Hungry Hungry Hippos, where it just keeps gobbling up and gobbling like a wildfire that just starts spreading, you know, you say can't get enough data, just starts seeing what you can get access to. So, how do we not introduce unnecessary risk? J. Paul HaynesYeah. So using uh back to the MCP uh concept and using skills, you contain the scope or the context window of the LLM so it doesn't actually have the liberty to go and grab all the data that it that it can find. You actually are directing it. And um, a skill is a simple, like one or two page English uh set of instructions on how to execute and behave, and that is proven to be very effective. You have other risks. If if I kind of run down some of the risks, uh, you would have shadow AI. So you have sanction systems and you have executive leaders. I probably have been in this uh guilty of this, uh, saying, I want everyone to go and experiment and use all the different AIs and all, and so then you've got so what happens is now we've got sanction systems, and these are the ones that we're we're buying enterprise licenses on. You've got, you know, maybe that's anthropic, but you've got someone using Chat GPT and Perplexity and Gemini, and those are all fine, except um what are they allowed to touch and where's the data going? And so the shadow AI needs to be understood and maybe sanctioned, maybe permitted, uh, but needs to be understood, and you actually need to do the same level of tracking on it as you do with uh the sanctioned systems. Then you've got other scenarios like uh local host execution where you've got the LLM just running on your machine and it's not in the um IT estate. So your CISO is going to be responsible for when something goes wrong, but he doesn't even know that you got that running there. So there's there's the shadow AI um embedding credentials, uh a pass sin that I think is getting better, but still quite uh rampant, where uh you're providing your credentials are actually in the in the connection string into the um into the uh data source. And that is that is all risk that should be done in a different way where it's uh it's proxying your entitlements through its access. So there's that kind of risk. Uh obviously the PII and MNPI XFIL, a risk that really showed up only in, I guess, about middle of June when uh Mythos Fable 5 uh had a government order um restricting uh its usage. If you had production systems based on those and you didn't have a plan B when they went offline, like this morning, uh OpenAI and uh Claude were offline because of a cloud flare issue and so it's major outage. What's your BCP? What's your business continuity plan so you can keep delivering the work? This is a this is actually a risk that I see uh is gonna really bite us at some point in time where there's no there's no backup plan. Like the models you know are somewhat interchangeable, but their the performance uh varies depending on the model. If you have a certain tolerable error rate with one model and you're forced because of an outage to go to another model, are you gonna get the same error rate or do you have to do something different? So the whole notion of BCP business continuity planning is a risk that is emerging. And you also will have, like in your population of staff, you're gonna have the power users, the OGs, they're these guys are are gonna be you know delivering a 20 to 1 or 50 to like they're very outweighted. This is a distribution of like 5% doing most of the meaningful value, and certainly token spend, but value, and then you you've got um a risk that that employee, if they were to leave, you may actually lose that capability in that department. And if you uh are building business uh you know, are making business decisions around those capabilities, that's that's a human risk that you have that uh LLMs are are introducing inadvertently. And I guess the um uh another category is the obvious one, which is the financial. How do you rein in uh runaway spend on tokens? Um tokens are very hard to correlate to value. Uh it's more of the input versus the output. So tokenomics is emerging as a as a risk to be managed by uh the for. Or the CFO by the IT teams. Robbie ChrismanGosh, everything's moving so fast. You can feel like a deluge, and am I on top of it? And this and or not. And I'm just putting my head in my hands as I said that. People won't see that. Thoughts on staying on top of this? And maybe this is a call to action to use a company like Cinchi, but but for people that are feeling overwhelmed, like, oh gosh, there's so much, and I don't know how to keep up with it, but best best practices. J. Paul HaynesWe in the industry suffer from this. In my case, and I have peers that would say the same thing. Um, my LinkedIn is turned into you know this massive uh pipe of all the latest uh AI propaganda, some of it legit, some of it not, and it's hard to it's hard to to to separate those. Um, so as a technologist, we got to stay right on the front line. If you're a a user of it, um, you got to rely on your technologists to do this. Robbie ChrismanUm, I guess the thing that would but no, J Paul, you gotta throw in uh that distinction matters after you say what you just said. Yeah, perfect. J. Paul HaynesBut the problem is not this, it's this. Yeah, the the uh users are also uh people that become power users are it's often not the one that you think it's gonna be. So in your organization, you've got somebody who's listening to podcasts on the way home in the car on how to how to write prompts better, and that was just not like you just thought that was an underwriter role, and they were happy doing that, and all of a sudden now they're making their job better and they're building and building agents. We see this happening all the time. They're building an agent that three or four colleagues can make use of. And and this is how AI is is sort of there's a grassroots, it really is democratizing access to IT the way that cloud did um with SaaS applications, and you can put it on the company credit card for you know 20 bucks a month, and um now you've got some new capability. Well, that same thing is happening, but now you are doing things that are actually modifying data, making potentially customer impacting decisions or financial impacting decisions. Um, and that's all and it needs to be encouraged. You just have to put the guardrails around it. So there's you know, there's the the human aspect is is not what you think it is. Yeah. Well, maybe I'll prompt you one more time here. Robbie ChrismanFor people looking for more information, your LinkedIn or website, or but you know, yeah, yeah. J. Paul HaynesSo uh you can hit me up on uh LinkedIn um or cinchie.com. That's our uh company website, and it describes all of our solutions that manage governance and data access. Robbie ChrismanJay Paul, I really appreciate the time. I I know that this is a subject that we could have a four-hour podcast on, so I appreciate you condensing it down into this. But hopefully, yes, this is the first of many conversations on the subject. J. Paul HaynesWell, I look forward to our next one. And if it's a month from now, it'll be there'll be something new to talk about. Uh very different, and I'm sure that'll be true every month because we're we're measuring dog years are now months in in AI. So uh hopefully we can we can have another one of these discussions. Robbie ChrismanU.S. housing economic data yesterday was modestly weaker. August housing starts and building permits both fell short of expectations. Single family construction, the key driver of agency MBS supply, continued its gradual decline seen over the past year. The slowdown is broad-based across regions with single-family starts down nine percent in the northeast, eight percent in the west, and five percent in the south as builders respond to rising inventory and borrowing costs. Permits, the more forward-looking measure, showed softness across all regions for single-family construction. Pending home sales edged up only 0.3% after a downward revision to July. The Philadelphia FedMid index remained strong at 37.8, but it showed renewed price pressures, with both prices paid and prices received rising sharply overall. Growth remains resilient, but the housing sector is losing momentum and inflation pressures are becoming more pronounced. Today's economic calendar kicks off later today with August industrial production and capacity utilization, and will be followed by the August leading index. We begin Friday with agency MBS prices slightly worse than Thursday's close, the two-year yielding at 4.71, and the ten-year yielding 4.96 after closing yesterday at 4.95%. Let's wrap up with a joke and some housekeeping. Since tomorrow's talk like a pirate day, here's some salvo. What's a pirate's favorite letter of the alphabet? Well, the rookie answer would be the R, but the pirate answer would be the C. But um How much does it cost for a pirate to get his ears pierced? Well, obviously it's a buccaneer. And why couldn't the pirate crew play cards? Because the captain was standing on the deck. Okay, one more. Why'd the pirate go to the Apple store? He needed the new iPatch. Thanks again to First Close for sponsoring this week's podcast. First Close provides fintech solutions to KeLock and mortgage lenders nationwide, and their home equity lending platform accelerates the home equity lending process, reducing application to closing times from 45 days to less than 10.
Join 80,000+ mortgage professionals who start their day with Chrisman Commentary.
By submitting this form, you are consenting to receive marketing emails from: . You can revoke your consent to receive emails at any time by using the SafeUnsubscribe® link, found at the bottom of every email. Emails are serviced by Constant Contact