AI Regulation Tracker · Hong Kong SFC · Circular

What does SFC Circular 24EC55 (generative AI language models) say about AI in banking?

Published Nov 12, 2024 · Last reviewed Oct 5, 2026

SFC Circular 24EC55, issued to licensed corporations on 12 November 2024 and effective immediately, sets the Hong Kong Securities and Futures Commission's expectations for the use of generative AI language models (AI LMs). It is organised around four Core Principles: senior management responsibilities, AI model risk management, cybersecurity and data risk management, and third-party provider risk management. It applies to licensed corporations (securities, asset management and similar firms) rather than banks as such, and treats using an AI LM to give investment recommendations, advice or research as a high-risk use case requiring extra safeguards, including a human in the loop. A licensed firm should map its AI LM uses to these four principles and, for high-risk uses, comply with the SFC's notification requirements for significant changes in its business.

OFFICIAL TEXT: apps.sfc.hk ↗ · IN FORCE · HONG KONG SFC

DocumentSFC Circular 24EC55 (generative AI language models) — Circular to licensed corporations - Use of generative AI language models
Issued bySecurities and Futures Commission of Hong Kong
TypeCircular
StatusIn force
PublishedNov 12, 2024
EffectiveNov 12, 2024
Applies toLicensed corporations (LCs) of the Securities and Futures Commission offering services or functionality provided by generative AI language models (AI LMs) or AI LM-based third-party products in relation to their regulated activities, whether the model is developed in-house, by a group company, by an external provider or comes from open source. Banks are supervised by the HKMA; a bank is within this circular only where it or an affiliate is an SFC licensed corporation, since the circular is addressed to LCs
Official sourceapps.sfc.hk ↗
Use casesGenerative & agentic AI · Model risk management · Customer-facing chatbots · Third-party & vendor AI · Cybersecurity · Trading & capital markets

What are the key points of SFC Circular 24EC55 (generative AI language models)?

  • Core Principle 1 (senior management responsibilities): effective policies, procedures and internal controls and suitably qualified oversight across the full AI LM lifecycle, including identifying high-risk use cases and having staff with AI, data science, model risk and domain competence.
  • Core Principle 2 (AI model risk management): segregate model development from validation where practicable; validate before approval and on material change; test end-to-end including retrieval-augmented generation (RAG) and content filtering; monitor ongoing performance.
  • Paragraph 8: using an AI LM for investment recommendations, advice or research is generally a high-risk use case (this excludes after-sales client servicing, per footnote 3).
  • Paragraph 17: where an AI LM is used in the client interface, prominently disclose that the client is interacting with AI and that output may be inaccurate. Paragraphs 18-19 add, for high-risk uses, validation, a human in the loop to review factual accuracy before output reaches the user, output-robustness testing against prompt variations and disclosure at each interaction.
  • Core Principle 3 (cybersecurity and data risk management): cover adversarial attacks on AI LMs and their training data, test adversarially to the extent practicable, encrypt non-public data, control confidential data input and mitigate browser-extension leakage; LCs should have regard to the Privacy Commissioner's Model Personal Data Protection Framework for AI.
  • Core Principle 4 (third-party provider risk management): due diligence and monitoring of providers, assessing the provider's model risk framework where transparency is limited, supply-chain and data leakage assessment of components such as embedding models and vector stores, and contingency plans for disruption.
  • Paragraph 30: LCs intending to adopt AI LMs in high-risk use cases are reminded to comply with the notification requirements under the Securities and Futures (Licensing and Registration) (Information) Rules and are encouraged to discuss plans with the SFC early.
  • The circular takes immediate effect; the SFC says it recognises some LCs need time to update policies and will take a pragmatic approach in assessing compliance, and a risk-based implementation is allowed.

What did SFC Circular 24EC55 (generative AI language models) change for banks?

It was the first SFC statement of expectations on generative AI. It ties AI LM use to existing obligations (the Code of Conduct and the Management, Supervision and Internal Control Guidelines) and introduces the high-risk use case concept for investment recommendations, advice and research, with human-in-the-loop and notification expectations. The SFC's 2 June 2026 circular on AI-enabled cyberattacks builds on its cybersecurity principles.

What does SFC Circular 24EC55 require of firms using generative AI language models?

SFC Circular 24EC55 of 12 November 2024 requires licensed corporations that use generative AI language models in regulated activities to meet four Core Principles: senior management must put effective policies, controls and qualified oversight in place across the AI LM lifecycle; AI model risk management must include segregated development and validation, validation before use and on material change, end-to-end testing and ongoing monitoring; cybersecurity and data risk management must cover adversarial attacks, encryption and confidentiality of client data; and third-party provider risks, including supply chain and concentration, must be assessed with contingency plans. High-risk uses, meaning investment recommendations, advice or research, need extra measures including a human in the loop, prompt-robustness testing and disclosure at each client interaction, and firms must observe notification requirements when adopting them. It applies from 12 November 2024 and is addressed to licensed corporations rather than banks.

RuleAuthorityWhat it requiresApplies
Core Principle 1 — Senior management responsibilitiesHong Kong SFCSenior management ensures effective policies, procedures and internal controls and adequate oversight by qualified staff throughout the AI LM lifecycle, including identification of high-risk use cases.In force since 12 November 2024
Core Principle 2 — AI model risk managementHong Kong SFCSegregate development from validation where practicable, validate before approval and on material change, test end-to-end including RAG and content filtering, and monitor performance on an ongoing basis, documenting results.In force since 12 November 2024
Paragraph 17 — Client-facing disclosureHong Kong SFCProminently disclose in the user interface that clients are interacting with AI and that output may be inaccurate.In force since 12 November 2024
Paragraphs 18-19 — High-risk use casesHong Kong SFCFor investment recommendations, advice or research, add validation focused on factual accuracy, a human in the loop before output reaches the user, output-robustness testing against prompt variations, and disclosure at each interaction.In force since 12 November 2024
Core Principle 3 — Cybersecurity and data risk managementHong Kong SFCManage adversarial attacks on AI LMs and training data with periodic adversarial testing, encrypt non-public data at rest and in transit, ensure training data quality and control confidential data entering AI LMs.In force since 12 November 2024
Core Principle 4 — Third-party provider risk managementHong Kong SFCPerform due diligence and ongoing monitoring of providers, assess supply-chain and data leakage risk at each third-party component, define cybersecurity responsibilities and plan for disruption.In force since 12 November 2024
Paragraph 30 — NotificationHong Kong SFCComply with the notification requirements under the Securities and Futures (Licensing and Registration) (Information) Rules when adopting AI LMs in high-risk use cases, and discuss plans with the SFC early.In force since 12 November 2024

The circular is risk-based: LCs may implement the Core Principles in a manner commensurate with the materiality of impact and the level of risk of each use case. Model Development requirements apply only where an LC develops, customises, refines or enhances an AI LM (for example fine-tuning, RAG, content filtering or integrating prompt-management tools); an off-the-shelf product used with only essential parameters configured remains subject to Model Management but not Model Development requirements.

It anchors each expectation to existing SFC instruments, citing the Code of Conduct and the Management, Supervision and Internal Control Guidelines in its footnotes, and footnote 13 states that the AI model risk framework need not duplicate firms' existing cybersecurity, data and third-party frameworks provided those cover the circular's requirements. Hong Kong's banks fall under the HKMA, whose guidance sits outside this circular.

WHAT THIS MEANS IN PRACTICE

  • Inventory every AI LM use in regulated activities and classify which, if any, are high-risk investment recommendation, advice or research uses.
  • Segregate development and validation functions where practicable and document validation, end-to-end tests and monitoring.
  • Add AI disclosures and, for high-risk uses, human review before output reaches clients.
  • Extend third-party risk management to AI providers, embedding models, vector stores and orchestration tools.
  • Check whether adopting a high-risk use triggers notification under the Information Rules and speak to the SFC early.
  • Review prompt-robustness and adversarial testing practices.

Does SFC Circular 24EC55 apply to banks?

It is addressed to SFC licensed corporations and applies to LCs offering services or functionality provided by AI language models in relation to their regulated activities. Banks in Hong Kong are supervised by the HKMA, so a bank is covered only through an SFC-licensed entity such as a securities or asset management affiliate.

When did SFC Circular 24EC55 take effect?

Immediately on 12 November 2024. The SFC said it recognises that some LCs need time to update policies and procedures and would take a pragmatic approach in assessing compliance.

What is a high-risk use case under the SFC generative AI circular?

Generally, using an AI LM to provide investment recommendations, investment advice or investment research to investors or clients (paragraph 8), because problematic output may lead to unsuitable recommendations or misinformed investors. After-sales client servicing is excluded. High-risk uses call for extra measures, including a human in the loop.

What are the penalties under the SFC generative AI circular?

The circular does not state penalties. It ties its expectations to provisions of the Code of Conduct and the Internal Control Guidelines, which it cites in footnotes, and the SFC says it will take a pragmatic approach when assessing compliance.

How does the SFC circular compare with the EU AI Act?

The EU AI Act is binding legislation with defined risk categories and obligations by role. The SFC circular is supervisory guidance for licensed corporations, risk-based, centred on one defined high-risk category (investment recommendations, advice and research) and four Core Principles.

DateDocumentStatus
Jun 2, 2026SFC Circular 26EC32 (AI-enabled cyberattacks) — Circular to licensed corporations, SFC-licensed virtual asset service providers and associated entities - Enhanced cybersecurity measures to address evolving risks arising from artificial intelligence-enabled cyberattacksIn force
Sep 30, 2026Bailey: Frontier AI and the Question of Governance (Sep 2026) — Frontier AI and the Question of Governance — Governor Andrew BaileyFinal
Sep 10, 2026Atkins remarks at Investor Advisory Committee (Sep 2026) — Remarks at the SEC Investor Advisory Committee Meeting on AI Technologies and the Public Markets Information EcosystemFinal
Sep 3, 2026FIN-2026-Alert005 (Digital Asset Investment Scam Centers) — FinCEN Alert on Money Laundering Activity Associated with Digital Asset Investment Scam CentersIn force
Sep 2, 2026FCA multi-firm review: Frontier AI and cyber resilience (Sep 2026) — Frontier AI and Cyber ResilienceIn force
Aug 31, 2026FSB Chair's letter to G20 (Aug 2026) — FSB Chair's letter to G20 Finance Ministers and Central Bank Governors: August 2026 — risks arising from frontier artificial intelligence modelsFinal

Follow every document these regulators publish

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning