SFC Circular 26EC32 (reference SFO/IS/020/2026), issued on 2 June 2026, reminds licensed corporations, SFC-licensed virtual asset trading platforms and their associated entities to review and enhance cybersecurity against AI-enabled cyberattacks, citing the heightened attack risks posed by frontier AI models. It sets expectations in five areas: patching and vulnerability management, access and privilege controls, detection and monitoring, third-party supply chain risk, and incident response and recovery. It makes senior management, including the Manager-in-Charge of Information Technology (MIC-IT), ultimately responsible. It applies to SFC licensed firms rather than banks as such, and a licensed firm should confirm same-day asset inventory prioritisation, faster patching and tested incident response.
OFFICIAL TEXT: apps.sfc.hk ↗ · IN FORCE · HONG KONG SFC
| Document | SFC Circular 26EC32 (AI-enabled cyberattacks) — Circular to licensed corporations, SFC-licensed virtual asset service providers and associated entities - Enhanced cybersecurity measures to address evolving risks arising from artificial intelligence-enabled cyberattacks |
| Issued by | Securities and Futures Commission of Hong Kong |
| Type | Circular |
| Status | In force |
| Published | Jun 2, 2026 |
| Applies to | SFC licensed corporations, SFC-licensed virtual asset trading platform operators (VATPs) and their associated entities (together 'licensed firms'). Banks are supervised by the HKMA and are within it only through SFC-licensed affiliates |
| Official source | apps.sfc.hk ↗ |
| Use cases | Cybersecurity · Generative & agentic AI · Third-party & vendor AI · AI governance (general) |
What are the key points of SFC Circular 26EC32 (AI-enabled cyberattacks)?
- Background: frontier AI models can plan and execute multi-step actions autonomously, find previously undetected vulnerabilities, chain lower-risk vulnerabilities and operate across interconnected systems; the circular cites HKCERT figures of 15,877 cybersecurity incidents in 2025 against 12,536 in 2024.
- Senior management accountability: the MIC-IT must ensure changes to the cybersecurity framework are reviewed and approved and enhancements implemented properly and promptly.
- Asset inventory: keep an accurate, up-to-date inventory of technology assets, identify externally exposed and business-critical components, and keep it current enough for same-day prioritisation and containment decisions.
- (A) Patching: enhance and expedite patching and vulnerability management, with procedures for urgent fixes outside routine cycles and resources for a surge in patching.
- (B) Access and privilege: design on the assumption any user, device, privileged account or network component may be compromised; least privilege including connector and tool permissions, micro network segmentation where feasible, treat external content as potentially adversarial and prevent it from altering system instructions or triggering privileged actions, and maker-checker controls for high-impact actions.
- (C)-(E): strengthen detection of anomalies in client trading and system activity and threat intelligence; assess AI-enabled threats at third-party service providers; and test incident response through tabletop exercises or simulated attacks, plan containment and exploit-interruption strategies, and back up records regularly.
- Licensed firms using AI language models should address related cyber risks (adversarial attacks, data leakage, system prompt override) in their cybersecurity framework, factoring in the core principles of the SFC's November 2024 circular.
- The SFC may issue further guidance, conduct reviews of preparedness or take supervisory action; material cybersecurity incidents must be notified to the SFC as the Code of Conduct (paragraph 12.5(e)) and VATP Guidelines (paragraphs 16.7(b) and (c)) require.
What did SFC Circular 26EC32 (AI-enabled cyberattacks) change for banks?
It extends the SFC's November 2024 generative AI circular from AI model risk to AI as an attacker's tool. It sets supervisory expectations for patching speed, asset inventories, privilege design (including AI tool and connector permissions), supply chain and incident response, and puts accountability on the MIC-IT, within a wave of 2026 frontier-AI cyber advisories from financial regulators including MAS, Japan's FSA and the NYDFS.
What does SFC Circular 26EC32 expect firms to do about AI-enabled cyberattacks?
SFC Circular 26EC32 of 2 June 2026 expects licensed corporations, SFC-licensed virtual asset trading platforms and associated entities to assess their preparedness for AI-enabled cyberattacks and enhance their cybersecurity frameworks in five areas: patching and vulnerability management; access and privilege controls (assume compromise, least privilege, segmentation, treating external content as adversarial, maker-checker); detection and monitoring; third-party supply chain risk; and incident response and recovery. Firms should keep technology asset inventories current enough for same-day prioritisation, and senior management including the MIC-IT is ultimately responsible. It also reminds firms using AI language models to address their cyber risks under the SFC's November 2024 circular. It is addressed to SFC licensed firms, not banks as such.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| Senior management / MIC-IT accountability | Hong Kong SFC | Senior management, including the MIC-IT, is ultimately responsible; changes to the cybersecurity framework must be reviewed and approved and enhancements implemented properly and promptly. | From 2 June 2026 |
| Asset inventory | Hong Kong SFC | Maintain an up-to-date inventory of hardware, software, network, database and cloud assets, flagging externally exposed, business-critical and third-party-dependent components for same-day prioritisation. | From 2 June 2026 |
| Section (A) — Patching and vulnerability management | Hong Kong SFC | Enhance and expedite patching, address known vulnerabilities promptly, have urgent-fix procedures and resources for surges. | From 2 June 2026 |
| Section (B) — Access and privilege controls | Hong Kong SFC | Assume any user, device or account may be compromised; enforce least privilege (including connectors and tool permissions), micro-segmentation, treat untrusted inputs as adversarial and apply maker-checker to high-impact actions. | From 2 June 2026 |
| Section (C) — Detection and monitoring | Hong Kong SFC | Strengthen detection of anomalies in client trading and system activity and improve threat intelligence gathering. | From 2 June 2026 |
| Section (D) — Third-party supply chain | Hong Kong SFC | Strengthen third-party supply chain governance and assessments to factor in AI-enabled threats against providers supporting critical operations. | From 2 June 2026 |
| Section (E) — Incident response and recovery | Hong Kong SFC | Update incident handling and contingency plans for faster AI-enabled attacks, plan containment strategies, test them regularly, back up records and notify material incidents to the SFC. | From 2 June 2026 |
The circular is a supervisory reminder grounded in the SFC's engagement with licensed firms and key internet trading platform providers on preparedness. It cites a rise of about 27% in Hong Kong cybersecurity incidents (from 12,536 in 2024 to 15,877 in 2025, according to HKCERT) as context, and explains that the shrinking interval between vulnerability disclosure and exploitation shortens the window for patching.
It sits beside the SFC's November 2024 circular on generative AI language models: that circular deals with the risks of the firm's own AI use, and this one with AI as an attacker's capability, while reminding firms that AI language model use introduces additional exploitable risks such as adversarial attacks, data leakage and system prompt override. The SFC may follow with further guidance or reviews.
WHAT THIS MEANS IN PRACTICE
- Confirm the asset inventory identifies externally exposed and business-critical components and can support same-day decisions.
- Review patch SLAs and emergency change procedures, and budget for a surge in patching.
- Review agent, connector and tool permissions for any AI tools with access to systems, and apply least privilege.
- Check third-party providers' readiness for AI-enabled threats in contracts and assessments.
- Run a tabletop or simulated attack and record the result for the MIC-IT.
Does SFC Circular 26EC32 apply to banks?
It is addressed to SFC licensed corporations, SFC-licensed virtual asset service providers and associated entities. Hong Kong's authorized institutions are supervised by the HKMA, so a bank is covered only through an SFC-licensed affiliate.
When does SFC Circular 26EC32 take effect?
It is dated 2 June 2026 and takes the form of a reminder to licensed firms to review and enhance their cybersecurity measures now; it sets no separate phase-in date. The SFC says it may issue further guidance, conduct reviews or take supervisory action.
Is SFC Circular 26EC32 binding?
It is a supervisory circular that states expectations rather than new rules; it reminds firms of existing obligations such as the Code of Conduct and notification of material cybersecurity incidents, and says senior management, including the MIC-IT, is ultimately responsible.
What does the SFC expect on patching under the circular?
Licensed firms should enhance and expedite patching and vulnerability management, take prompt action on known vulnerabilities, have procedures for urgent fixes outside routine cycles, and allocate resources for a surge in patching demand.
| Date | Document | Status |
|---|---|---|
| Nov 12, 2024 | SFC Circular 24EC55 (generative AI language models) — Circular to licensed corporations - Use of generative AI language models | In force |
| Sep 30, 2026 | Bailey: Frontier AI and the Question of Governance (Sep 2026) — Frontier AI and the Question of Governance — Governor Andrew Bailey | Final |
| Sep 2, 2026 | FCA multi-firm review: Frontier AI and cyber resilience (Sep 2026) — Frontier AI and Cyber Resilience | In force |
| Aug 31, 2026 | FSB Chair's letter to G20 (Aug 2026) — FSB Chair's letter to G20 Finance Ministers and Central Bank Governors: August 2026 — risks arising from frontier artificial intelligence models | Final |
| Jul 31, 2026 | ESA Statement on ICT risks from frontier AI models (JC 2026 25) — ESA Statement: Toward a consistent and risk-based approach for ICT risks from frontier AI models | In force |
| Jul 7, 2026 | ECB 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301) — Addressing AI-enabled cybersecurity threats — letter from the Chair of the Supervisory Board to CEOs of significant institutions | In force |
Follow every document these regulators publish
when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning