AI Regulation Tracker · Global (28 jurisdictions)

How does the Basel Committee regulate AI in banking?

Last updated Aug 26, 2026 · Updated as rules change

The Basel Committee has not issued AI-specific standards for banks — it monitors AI under its digitalisation-of-finance workstream and addresses the risks through existing prudential channels. Its May 2024 digitalisation report analyzed AI/ML among the technologies reshaping banking, and its 2025–26 work programme keeps AI under watch, including a June 2026 report on ICT risk-management practices and ongoing attention to AI's implications for bank cybersecurity.

Full nameBasel Committee on Banking Supervision (BCBS)
RoleGlobal banking standard-setter
Force on banksNon-binding standards
Applies toInternationally active banks, via national implementation of Basel standards
Key documentDigitalisation of finance report (May 2024)
Latest moveJune 2026 ICT risk-management report; AI monitoring continues in the 2025–26 work programme
Documents tracked8 · all documents →

The Committee's posture is deliberate patience: rather than write AI rules that member jurisdictions would implement unevenly, it tracks how AI changes the risk profile of banks — operational resilience, third-party dependence, cyber threat, and strategic risk — and lets existing Basel standards (operational risk, outsourcing principles) carry the load.

Two documents anchor the current position: the May 2024 'Digitalisation of finance' report, which assessed AI/ML alongside APIs, DLT, and cloud, warning about new vulnerabilities and system-wide interconnection; and the June 2026 range-of-practices report on ICT risk management, produced under a work programme that explicitly monitors AI developments and their cybersecurity implications. If the FSB's 2026 sound-practices work hardens into expectations, the Basel Committee is the likely channel for turning them into supervisory standards.

What has the Basel Committee actually published on AI?

DateDocumentStatus
Jun 2, 2026BCBS ICT Risk Management Report (June 2026)Information and communication technology risk management: range of practicesFinal
Jan 6, 2026BCBS 239 Implementation Newsletter (Jan 2026)Implementation of the Principles for effective risk data aggregation and risk reporting (BCBS 239 Principles)Final
Dec 10, 2025BCBS Third-Party Risk Principles (Dec 2025)Principles for the sound management of third-party riskIn force
Feb 4, 2025BCBS Work Programme 2025–26Basel Committee work programme and strategic priorities for 2025/26In force
May 16, 2024BCBS Digitalisation of finance report (May 2024)Digitalisation of financeFinal
Mar 16, 2022BCBS AI/ML Newsletter (March 2022)Newsletter on artificial intelligence and machine learningFinal
Mar 31, 2021BCBS Principles for Operational Resilience (2021)Principles for Operational ResilienceIn force
Jan 9, 2013BCBS 239Principles for effective risk data aggregation and risk reportingIn force
DateTypeDocument / event
Jun 2, 2026ReportBCBS ICT Risk Management Report (June 2026) — Information and communication technology risk management: range of practices. The Basel Committee published its 23-page range-of-practices report on ICT risk management on 2 June 2026, produced under the 2025–26 work programme and focused on non-malicious ICT incidents affecting critical bank operations, complementing its 2018 cyber-resilience report. source ↗
May 20, 2026MilestoneCommittee flags frontier AI models as a cyber-risk accelerant. At its 19–20 May 2026 meeting the Basel Committee noted that frontier AI models could help banks and supervisors find cyber vulnerabilities, but that their malicious use 'may materially change the speed and scale of cyber incidents'; it committed to keep monitoring AI developments and exchanging supervisory insights.
Jan 6, 2026GuidanceBCBS 239 Implementation Newsletter (Jan 2026) — Implementation of the Principles for effective risk data aggregation and risk reporting (BCBS 239 Principles). On 6 January 2026 the Basel Committee issued a newsletter on the state of BCBS 239 implementation, more than a decade after the 2013 principles. source ↗
Dec 10, 2025GuidanceBCBS Third-Party Risk Principles (Dec 2025) — Principles for the sound management of third-party risk. On 10 December 2025 the Basel Committee published 12 Principles for the Sound Management of Third-Party Risk, finalising a July 2024 consultation and replacing the 2005 Joint Forum outsourcing paper for banks. source ↗
Feb 4, 2025ReportBCBS Work Programme 2025–26 — Basel Committee work programme and strategic priorities for 2025/26. The Basel Committee's 2025–26 work programme, endorsed by the Group of Governors and Heads of Supervision and published in February 2025, sets four themes: Basel III implementation, risk assessment and safeguarding resilience, digitalisation of finance, and liquidity. source ↗
May 16, 2024ReportBCBS Digitalisation of finance report (May 2024) — Digitalisation of finance. The Basel Committee's 46-page 'Digitalisation of finance' report of 16 May 2024 assesses APIs, AI/ML, distributed ledger technology, and cloud computing, updating its 2018 fintech work, and sets out eight implications for banks and supervisors. source ↗
Mar 16, 2022GuidanceBCBS AI/ML Newsletter (March 2022) — Newsletter on artificial intelligence and machine learning. On 16 March 2022 the Basel Committee published a newsletter summarising its internal discussions on banks' use of artificial intelligence and machine learning. source ↗
Mar 31, 2021GuidanceBCBS Principles for Operational Resilience (2021) — Principles for Operational Resilience. On 31 March 2021 the Basel Committee published seven Principles for Operational Resilience, aimed at banks' ability to withstand events such as pandemics, cyber incidents, technology failures, and natural disasters. source ↗
Jan 9, 2013FrameworkBCBS 239 — Principles for effective risk data aggregation and risk reporting. BCBS 239, published by the Basel Committee on 9 January 2013, sets 14 principles for how banks govern, aggregate, and report risk data, covering governance and IT infrastructure, data accuracy, completeness, timeliness and adaptability, and supervisory review. source ↗

Which of the 100 largest US banks answer to the Basel Committee on AI?

7 of the 100 bank pages on this site name the Basel Committee among the authorities their AI programme answers to. Each page lists the documents that apply and why.

  • Whether FSB sound practices on AI (final report Oct 2026) get translated into Basel supervisory expectations
  • Treatment of AI third-party concentration under Basel outsourcing and operational-resilience principles
  • Any move from monitoring to standard-setting as agentic AI enters core banking processes

Has the Basel Committee issued AI regulations?

No. The Committee monitors AI under its digitalisation workstream and addresses risks through existing standards on operational risk and resilience. Its most relevant publications are the 2022 AI/ML newsletter, the May 2024 digitalisation-of-finance report, and the June 2026 ICT risk-management report.

How does Basel Committee work reach actual banks?

Through national implementation: the Committee's 28 member jurisdictions translate Basel standards and guidance into local regulation. Its AI observations shape how the ECB, PRA, OCC, and other supervisors examine banks even without a dedicated AI standard.

Which Basel Committee standards actually bind a bank's AI program today?

None is AI-specific, but three apply directly through national implementation: BCBS 239 (2013) governs the risk data that feeds AI models, the March 2021 Principles for Operational Resilience cover AI-driven ICT and dependency risk, and the December 2025 Principles for the Sound Management of Third-Party Risk cover vendor AI models, cloud hosting, and nth-party concentration.

Follow every move these regulators make

the daily brief · six sourced stories · in your inbox by 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning