AI Regulation Tracker · Global (G20)

How does the FSB regulate AI in banking?

Last updated Sep 26, 2026 · Updated as rules change

The Financial Stability Board is the G20 body that coordinates how national regulators respond to AI risk in finance. It does not bind banks directly, but its reports set the agenda supervisors follow. Its current workstream matters: an October 2025 report on monitoring AI adoption and vulnerabilities, and a June 2026 consultation proposing 12 sound practices for responsible AI adoption by financial institutions, with the final report due in October 2026.

Full nameFinancial Stability Board
RoleGlobal financial-stability standard-setter
Force on banksNon-binding standards
Applies toNational regulators and, through them, systemically important banks and financial institutions worldwide
Key documentThe Financial Stability Implications of Artificial Intelligence (Nov 2024)
Latest move31 August 2026: FSB Chair's letter to G20 finance ministers and central bank governors warns that frontier AI models' autonomy and threat capabilities make cyber risk the most immediate financial-stability concern; final AI sound-practices report still expected October 2026
Documents tracked9 · all documents →

The FSB has tracked AI in finance since a 2017 report on AI and machine learning, but its work accelerated after generative AI: a November 2024 report assessed the financial-stability implications of AI (third-party concentration, correlated models, cyber, and market herding), and an October 2025 report gave authorities concrete indicators for monitoring AI adoption and flagged the sector's reliance on a small number of critical AI suppliers.

The June 2026 consultation, 'Sound Practices for the Responsible Adoption of AI,' is the closest the FSB has come to firm-level expectations: 12 practices covering governance, risk management, and oversight of AI — including agentic AI, whose capacity to act autonomously and at speed the FSB singles out as a risk that can outpace human oversight. National supervisors typically translate FSB sound practices into examination expectations.

What does the FSB say about AI governance in financial services?

The Financial Stability Board's position on AI governance is set out in its June 10, 2026 consultation 'Sound Practices for Responsible Adoption of Artificial Intelligence', which proposes twelve sound practices for financial institutions and puts governance first: boards and senior management should set the strategic direction for AI and oversee it (Sound Practice 1), accountability for AI outcomes should be clearly assigned (SP2), AI risks should sit inside the enterprise risk-management framework rather than beside it (SP3), and the organisation should build the skills and resourcing to adapt (SP4). The lifecycle practices that follow — materiality-based risk assessment, model selection, data governance, explainability, performance management, human oversight with extra measures for highly autonomous agentic AI, cyber and ICT controls, and third-party AI risk (SP5–SP12) — are the governance programme in operation. The practices are proportionate, apply to traditional, generative and agentic AI, and are deliberately consistent with what the FSB's November 2024 stability report identified as the vulnerabilities to govern: third-party concentration, correlated models, cyber risk, model and data governance gaps, fraud, and misaligned systems. The final report is due in October 2026 as a deliverable to the US G20 presidency, and the FSB Chair's August 31, 2026 letter added frontier-model autonomy and cyber capability to the list of what boards must now oversee.

RuleAuthorityWhat it requiresApplies
FSB Sound Practices 1–4 (organisation-wide governance)FSBStrategic direction and oversight by board and senior management; clear governance and accountability for AI; AI risks incorporated into the risk-management framework; organisational adaptability in skills and resourcing.Consultation Jun 10, 2026; final report due Oct 2026
FSB Sound Practices 5–12 (AI lifecycle)FSBMateriality and risk assessment, selection of models fit for the use case, data governance, explainability and transparency, performance management and monitoring, human oversight (heightened for highly autonomous agentic AI), cyber and ICT risk, and third-party AI risk management.Final report due Oct 2026
FSB, The Financial Stability Implications of AIFSBNames the six vulnerabilities governance has to address — third-party dependencies and provider concentration, market correlations, cyber risk, model risk and data governance, AI-enabled fraud and disinformation, misaligned AI — and asks authorities to assess whether existing frameworks are adequate.Nov 14, 2024
FSB monitoring report and next steps for authoritiesFSBIndicators for tracking AI adoption and each vulnerability; finds generative AI depends on a small number of hardware, cloud and model suppliers and that authorities' monitoring is at an early stage.Oct 10, 2025
FSB third-party risk toolkitFSBThe lifecycle framework — identifying critical services, due diligence, contracting, monitoring, continuity, exit and nth-party supply-chain risk — that Sound Practice 12 applies to AI model, cloud and data vendors.Dec 4, 2023
Vice Chair Bowman's opening remarks on the sound practicesFSBThe practices are proportionate to size and complexity, lower-risk uses warrant a lighter touch, and institutions should first decide whether an AI use is material to operations or to legal and regulatory obligations.Jul 7, 2026
FSB Chair's letter to the G20 on frontier AI modelsFSBFrontier models' 'increasingly sophisticated autonomy' and threat capabilities make cyber risk the most immediate stability channel; firms should ensure robust response and recovery capabilities and resilience among critical third-party providers.Aug 31, 2026
Public responses to the consultationFSB124 published responses, including JPMorgan Chase, UBS, the ABA, BPI/IIB and GFMA, published ahead of the final report; the practices' proportionality and prescriptiveness were the main points of contention.Aug 6, 2026
Interagency model risk guidance (SR 26-2 / OCC 2026-13 / FIL-15-2026)Federal ReserveThe US expression of the same governance stack for quantitative models — board ownership, independent validation, effective challenge — with generative and agentic AI left to broader governance, which is where the FSB practices fill in.In force from Apr 17, 2026
ECB: 'Technology is neutral, governance is not'ECBEuropean supervisors' three governance expectations — clear accountability, senior-management oversight, effective challenge — track FSB Sound Practices 1–3 almost line for line.Feb 2026
NIST AI RMF 1.0, Govern functionNISTThe voluntary Govern–Map–Measure–Manage cycle the FSB practices, Treasury's FS AI RMF and US agencies use as common vocabulary for AI governance.Since Jan 2023

The FSB's AI governance work is nine years old, but the operative document is the June 2026 consultation. The 2017 report on AI and machine learning in financial services had already flagged opaque models, shared data sources that could correlate firms' behaviour and third-party providers that might become systemically important outside the regulatory perimeter. The November 2024 report re-ran that analysis for generative AI and settled on six vulnerabilities; the October 2025 monitoring report gave authorities indicators for each and found that generative AI runs on a handful of chip, cloud and model suppliers. The sound practices are the FSB's answer to the question those reports left open — what should each institution actually do — and they are written for boards, not data scientists.

Read together, the twelve practices describe one governance loop. The board sets direction and appetite (SP1) and assigns accountability (SP2); AI risk is measured inside the existing enterprise framework, not in a parallel AI committee (SP3); the institution invests in the skills to run it (SP4). Each use case is then assessed for materiality (SP5), given a model chosen for the job (SP6), fed governed data (SP7), made explainable to the degree the decision requires (SP8), monitored in production (SP9), and kept under human oversight that tightens rather than loosens as autonomy grows (SP10), with cyber (SP11) and vendor (SP12) controls wrapped around it. Vice Chair Bowman, who chairs the FSB committee that wrote them, framed the first question for any bank as whether an AI use is material to its operations or its legal obligations — proportionality is built in.

What changes after October 2026 is mostly emphasis, not obligation. The FSB cannot bind banks; national supervisors adopt its practices through their own guidance and examinations, and the US, EU and UK frameworks already say much the same in their own vocabulary. The direction of travel is toward agentic systems: the consultation pays 'specific attention to generative and agentic AI', Sound Practice 10 asks for extra human-oversight measures for highly autonomous agents, and the Chair's August 2026 letter to the G20 treats frontier models' autonomy and cyber capability as a stability concern in their own right. A bank that can map its AI programme to the twelve practices today will find the final report, and the supervisory questions that follow it, familiar.

WHAT THIS MEANS IN PRACTICE

  • Map the bank's existing AI policy to the twelve practices by number and record the gaps; supervisors in several jurisdictions are expected to use the FSB list as an examination frame once the final report lands in October 2026.
  • Put AI risk inside the enterprise risk framework and the board's risk appetite (SP1–SP3) rather than in a standalone AI committee that reports nowhere.
  • Classify every AI use by materiality first (SP5, and Bowman's opening question); the control set follows from that, and lower-risk uses are allowed a lighter touch.
  • Treat human oversight as scaling up with autonomy (SP10): define who can override an agent, at what threshold automation stops, and what the record shows afterwards.
  • Apply the 2023 third-party toolkit to model, cloud and data vendors (SP12) — concentration among a few providers is the vulnerability the FSB has named most consistently since 2017.
  • Read the Chair's August 2026 letter as a board-level cyber instruction: response and recovery capabilities and critical-provider resilience are what the FSB now expects to see tested.

What has the FSB actually published on AI?

DateDocumentStatus
Aug 31, 2026FSB Chair's letter to G20 (Aug 2026) — FSB Chair's letter to G20 Finance Ministers and Central Bank Governors: August 2026 — risks arising from frontier artificial intelligence modelsFinal
Aug 6, 2026Responses to FSB AI sound practices consultation (Aug 2026) — Public responses to consultation on Sound Practices for Responsible Adoption of Artificial Intelligence (AI)Final
Jul 7, 2026Bowman remarks at FSB AI outreach (July 2026) — Opening remarks on sound practices for artificial intelligence (FSB virtual outreach event)Final
Jun 10, 2026FSB AI sound practices consultation (June 2026) — Sound Practices for Responsible Adoption of Artificial Intelligence (AI): Consultation reportProposed · comment period closed
Oct 10, 2025FSB AI monitoring report (Oct 2025) — Monitoring Adoption of Artificial Intelligence and Related Vulnerabilities in the Financial SectorFinal
Oct 10, 2025FSB next steps on AI monitoring (Oct 2025) — FSB outlines next steps for authorities on AI monitoringFinal
Nov 14, 2024FSB AI financial stability report (Nov 2024) — The Financial Stability Implications of Artificial IntelligenceFinal
Dec 4, 2023FSB third-party risk toolkit (2023) — Final Report on Enhancing Third-party Risk Management and Oversight: A toolkit for financial institutions and financial authoritiesFinal
Nov 1, 2017FSB 2017 AI/ML report — Artificial intelligence and machine learning in financial services: Market developments and financial stability implicationsFinal
DateTypeDocument / event
Aug 31, 2026LetterFSB Chair's letter to G20 (Aug 2026) — FSB Chair's letter to G20 Finance Ministers and Central Bank Governors: August 2026 — risks arising from frontier artificial intelligence models. On 31 August 2026, ahead of the G20 Finance Ministers and Central Bank Governors meeting, FSB Chair Andrew Bailey wrote that frontier AI models now show 'increasingly sophisticated autonomy and problem-solving abilities, as well as threat capabilities', and that their most immediate financial-stability impact is on cyber risk. source ↗
Aug 6, 2026ReportResponses to FSB AI sound practices consultation (Aug 2026) — Public responses to consultation on Sound Practices for Responsible Adoption of Artificial Intelligence (AI). On 6 August 2026 the FSB published 124 public responses received by the 22 July 2026 deadline on its AI sound practices consultation. source ↗
Jul 22, 2026MilestoneComment deadline passes on FSB AI sound-practices consultation. Responses to the June 2026 consultation on Sound Practices for Responsible Adoption of AI were due via the FSB's online form by 22 July 2026; the FSB published 124 responses on 6 August 2026.
Jul 7, 2026SpeechBowman remarks at FSB AI outreach (July 2026) — Opening remarks on sound practices for artificial intelligence (FSB virtual outreach event). On 7 July 2026 Federal Reserve Vice Chair for Supervision Michelle Bowman, who chairs the FSB Standing Committee on Supervisory and Regulatory Cooperation that led the work, opened the FSB's outreach on the AI sound practices. source ↗
Jun 10, 2026ConsultationFSB AI sound practices consultation (June 2026) — Sound Practices for Responsible Adoption of Artificial Intelligence (AI): Consultation report. On 10 June 2026 the FSB published a consultation proposing 12 sound practices for responsible AI adoption by financial institutions, with comments due 22 July 2026. source ↗
Oct 10, 2025ReportFSB AI monitoring report (Oct 2025) — Monitoring Adoption of Artificial Intelligence and Related Vulnerabilities in the Financial Sector. Published 10 October 2025, this report gives national authorities key considerations and candidate indicators for tracking AI adoption and the vulnerabilities identified in November 2024 — third-party dependencies, market correlations, cyber risk, and model-risk and governance gaps. source ↗
Oct 10, 2025GuidanceFSB next steps on AI monitoring (Oct 2025) — FSB outlines next steps for authorities on AI monitoring. The FSB's 10 October 2025 statement accompanying its AI monitoring report says authorities' AI monitoring is still at an early stage, that generative AI depends on a small number of key suppliers for hardware, cloud and models, and that national authorities should strengthen monitoring using the report's indicators while the FSB coordinates on taxonomies and data standards. source ↗
Nov 14, 2024ReportFSB AI financial stability report (Nov 2024) — The Financial Stability Implications of Artificial Intelligence. On 14 November 2024 the FSB published its post-generative-AI assessment of AI's financial-stability implications. source ↗
Dec 4, 2023FrameworkFSB third-party risk toolkit (2023) — Final Report on Enhancing Third-party Risk Management and Oversight: A toolkit for financial institutions and financial authorities. Published 4 December 2023, the FSB's third-party risk toolkit is the international framework for how banks and supervisors manage reliance on critical service providers, including cloud and AI vendors. source ↗
Nov 1, 2017ReportFSB 2017 AI/ML report — Artificial intelligence and machine learning in financial services: Market developments and financial stability implications. The FSB's 1 November 2017 report was the first systematic international survey of AI and machine learning in finance. source ↗

Which of the 120 largest US banks answer to the FSB on AI?

13 of the 120 bank pages on this site name the FSB among the authorities their AI programme answers to. Each page lists the documents that apply and why.

  • Final 'Sound Practices for Responsible Adoption of AI' report, expected October 2026 as a deliverable to the US G20 presidency — likely to become the global reference for bank AI governance
  • What 'steps within its mandate' the FSB takes on frontier-AI cyber risk after the Chair's 31 August 2026 letter to the G20 — a possible work stream on model release, AI/cloud provider concentration and response-and-recovery expectations
  • How the FSB resolves industry pushback in the 124 published consultation responses (proportionality, overlap with existing model-risk and third-party rules, treatment of agentic AI)
  • Whether the FSB moves from monitoring to recommending policy action on AI third-party concentration
  • National supervisors (ECB, PRA, OCC, Federal Reserve) importing the 12 sound practices into examination programs

Is FSB AI guidance binding on banks?

No. The FSB sets standards and sound practices for its member jurisdictions; national regulators decide how to implement them. In practice, FSB sound practices strongly shape supervisory expectations at the ECB, Bank of England, and US federal banking agencies.

What are the FSB's 12 sound practices for AI?

They are proposals in the FSB's June 2026 consultation on responsible AI adoption, covering governance, risk management, and oversight of AI use by financial institutions — including risks from agentic AI that can act autonomously at speed. The final version is due in October 2026.

What does the FSB consider the biggest AI risk to financial stability?

Its 2024 and 2025 reports emphasize concentration: many institutions depending on the same few AI model and infrastructure providers, plus correlated behavior when firms use similar models — alongside AI-enabled cyber threats and gaps in the data regulators need to monitor adoption.

Who responded to the FSB's AI sound-practices consultation?

The FSB published 124 responses on 6 August 2026. Respondents included JPMorgan Chase, UBS, Credit Agricole, Mastercard, Visa, the American Bankers Association, the Bank Policy Institute with the Institute of International Bankers, GFMA, UK Finance, the Japanese Bankers Association, and consumer groups such as Better Markets and Finance Watch.

Follow every move these regulators make

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning