AI Regulation Tracker · Japan FSA · Report

What does Japan FSA AI Discussion Paper v1.1 say about AI in banking?

Published Mar 3, 2026 · Last reviewed Oct 5, 2026

The Japan Financial Services Agency released Version 1.1 of its AI Discussion Paper on 3 March 2026, updating the March 2025 Version 1.0 with insights from the FSA AI Public-Private Forum held from June to December 2025. It adds material on customer-facing AI services and AI agents, groups risk-mitigation measures for customer-facing services into design and pre-testing, customer guidance and risk warnings, review and monitoring, and governance, and sets out the FSA's view on securities-sector regulatory questions. It remains a non-binding discussion paper, with existing laws applying technology-neutrally. A bank should read it for the FSA's current framing of customer-facing generative AI.

OFFICIAL TEXT: fsa.go.jp ↗ · FINAL · JAPAN FSA

DocumentJapan FSA AI Discussion Paper v1.1 — AI Discussion Paper (Version 1.1): Preliminary Discussion Points for Promoting the Sound Utilization of AI in the Financial Sector
Issued byFinancial Services Agency of Japan (with the Bank of Japan on frontier AI cyber measures)
TypeReport
StatusFinal
PublishedMar 3, 2026
Applies toFinancial institutions in Japan, including banks. It remains a discussion paper: it describes itself as an initial analysis for dialogue with stakeholders, not a rule. The English page publishes the summary; the full text is published in Japanese
SupersedesJapan FSA AI Discussion Paper v1.0
Official sourcefsa.go.jp ↗
Use casesCustomer-facing chatbots · Generative & agentic AI · AI governance (general) · Model risk management · Third-party & vendor AI · Data & privacy

What are the key points of Japan FSA AI Discussion Paper v1.1?

  • Section II.2 explains the revision: the FSA AI Public-Private Forum (June to December 2025) found AI use advancing quickly, with customer-facing use, nearly absent at the November 2024 survey, reaching limited-scope service provision or consideration, and risk-management practice beginning to form through trial and error.
  • Section III.3 is new: expansion of AI utilisation into customer-facing services and AI agents (2025 described as the first year of AI agents), including interest in agentic AI to automate financial processes.
  • Customer-facing risk-mitigation measures are grouped into Design and Pre-testing (for example RAG-based restriction of response scope, output filtering, a choice between AI and human service), Appropriate customer guidance and risk warnings (disclosing AI-generated responses may contain errors, customer-understanding checkpoints, the ability to switch to a human), Review and Monitoring (retention of conversation logs, response monitoring) and Governance.
  • Section IV.1.②.v (regulatory compliance): for securities firms outsourcing AI system development to a system subsidiary, the paper's view is that non-public information need not necessarily be stripped from customer conversation data beforehand, because the exception for maintaining and managing information-processing systems (Cabinet Office Ordinance on Financial Instruments Business Etc., Article 153(1)(7), item (ト)) has been interpreted to include system development.
  • The paper also discusses access by data scientists to conversation data that may include corporate-related information, and whether a generative-AI recommendation constitutes 'solicitation' under the Financial Instruments and Exchange Act, which it says depends on the specific facts.
  • Section IV.2 sets out the FSA's response direction and adds industry-level knowledge sharing among expectations of business operators; the structure also covers enterprise-level issues (data management, governance, internal rules, talent, ROI, model and risk management, third-party selection, cybersecurity, financial crime) and system-level issues (explainability, fairness and bias, hallucination, personal information, regulatory compliance).
  • It keeps the Version 1.0 position that the FSA's basic stance is technology-neutral and that existing laws apply regardless of whether AI is used, and invites comments by email to the Fintech and Innovation Office.

What did Japan FSA AI Discussion Paper v1.1 change for banks?

Version 1.1 shifts the FSA's discussion from whether firms should adopt AI to how to deploy it safely in customer-facing and agentic settings, drawing on a six-month public-private forum. It gives banks and securities firms concrete reference points for risk mitigation and flags regulatory interpretations the FSA considers workable, while still imposing no new obligations.

What does the Japan FSA's AI Discussion Paper Version 1.1 say about AI in banks?

Version 1.1 of the Japan FSA's AI Discussion Paper (3 March 2026) is a non-binding update of the March 2025 paper, based on the FSA AI Public-Private Forum of June to December 2025. It records that customer-facing AI is reaching limited, carefully scoped deployment, groups risk-mitigation measures for customer-facing services into four perspectives (design and pre-testing, customer guidance and risk warnings, review and monitoring, and governance), discusses AI agents, and offers views on securities-sector regulatory questions on outsourcing data, access to corporate-related information and solicitation. It keeps the FSA's technology-neutral stance: existing laws apply regardless of whether AI is used, and the FSA will first consider revising principles and guidelines. It adds no new obligations, and it is the current FSA reference for how Japanese banks should think about generative AI governance.

RuleAuthorityWhat it requiresApplies
Section II.2 — Purpose of revisionJapan FSAReflect the forum's findings that customer-facing AI use and risk-management practice have progressed since the November 2024 survey.Discussion paper, 3 March 2026
Summary point 1 — Design and pre-testingJapan FSAFor customer-facing services, use measures such as RAG-based restriction of response scope, higher-capability models, fine-tuning, output filtering, human-or-AI choice and phased rollout.Discussion paper, 3 March 2026
Summary point 1 — Customer guidance and risk warningsJapan FSADisclose that responses are AI-generated and may contain errors, gate progress on confirmed understanding where needed, disclose rationale and sources, and let customers switch to a human.Discussion paper, 3 March 2026
Summary point 1 — Review, monitoring and governanceJapan FSARetain conversation logs, monitor responses, verify biased solicitation with objective metrics, document recommendation logic, and involve executives with a risk-based, agile governance approach.Discussion paper, 3 March 2026
Section IV.1.②.v — Regulatory complianceJapan FSAIdentify the purpose and manner of AI and data use concretely; whether AI-based recommendations amount to 'solicitation' under the Financial Instruments and Exchange Act depends on the specific facts.Discussion paper, 3 March 2026
Section IV.2 — Industry-level knowledge sharingJapan FSAShare practice and understanding across the industry, and engage openly with authorities and industry associations to build regulatory clarity.Discussion paper, 3 March 2026

The FSA says on its page that it has updated Version 1.0 and revised it as Version 1.1 based on insights gained through the FSA AI Public-Private Forum. The new content reflects a phase in which institutions are moving from experiments to concrete, executive-led initiatives, and the paper's regulatory-compliance discussion shows the FSA offering interpretations for specific securities-sector scenarios while saying that appropriateness is a case-by-case, substantive judgment.

As with Version 1.0, it should be read together with existing rules such as the FSA's cybersecurity guidelines for the financial sector. In May 2026 the FSA and Bank of Japan separately issued a short-term request on frontier-AI cyber threats, which is not part of this paper.

WHAT THIS MEANS IN PRACTICE

  • Compare customer-facing AI controls with the four groups of mitigation measures in the summary.
  • Record AI and data use purposes and manner clearly before asking the FSA for interpretation, as the paper suggests.
  • Keep conversation logs and monitoring for customer-facing AI.
  • Watch for FSA guideline revisions, which the FSA says it will consider before any legal response.

Does Version 1.1 of the Japan FSA AI Discussion Paper apply to banks?

It addresses financial institutions including banks, but is a discussion paper that sets out initial points for dialogue and does not impose new obligations. Existing laws and regulations continue to apply regardless of whether AI is used.

What is new in Version 1.1 compared with Version 1.0?

It adds findings from the June to December 2025 FSA AI Public-Private Forum: a section on customer-facing AI and AI agents, grouped risk-mitigation examples for customer-facing services, the FSA's view on securities-sector regulatory questions, and industry-level knowledge sharing.

When was Version 1.1 published?

3 March 2026, replacing Version 1.0 of March 2025. The FSA's English page provides the summary; the full text and a marked-up revised version are on the Japanese page.

Is Version 1.1 binding?

No. It is described as an initial analysis to support dialogue and the FSA says technological change may alter the identified challenges.

DateDocumentStatus
Mar 4, 2025Japan FSA AI Discussion Paper v1.0 — AI Discussion Paper (Version 1.0): Preliminary Discussion Points for Promoting the Sound Utilization of AI in the Financial SectorSuperseded
May 22, 2026Japan FSA/BOJ frontier AI request — Request regarding 'Short-term Responses by Financial Institutions in Light of Threat Changes from Frontier AI' (「フロンティアAIによる脅威変化を踏まえた金融機関等の短期的な対応」に係る要請について)In force
Sep 28, 2026AB 1609 — Customer Service Chatbots (Right to Human Customer Service Act)Final
Aug 11, 2026Colorado AG proposed ADMT rules — Proposed Automated Decision-Making Technology and Conversational AI Service Rules (Notice of Rulemaking Hearing)Comment period open
Jul 24, 2026Regulation (EU) 2026/1744 (Digital Omnibus on AI) — Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)In force
Jul 20, 2026Commission guidelines on AI Act Article 50 transparency — Commission Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of Regulation (EU) 2024/1689 (AI Act)In force

Follow every document these regulators publish

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning