AI Regulation Tracker · Hong Kong SAR (all Authorized Institutions: licensed banks, restricted licence banks and deposit-taking companies)

How does the HKMA regulate AI in banking?

Last updated Oct 5, 2026 · Updated as rules change

The Hong Kong Monetary Authority regulates AI in banks through principles-based circulars rather than a statute: the 1 November 2019 "High-level Principles on Artificial Intelligence" (12 principles on governance, design and development, and ongoing monitoring), the 5 November 2019 consumer-protection principles for big data analytics and AI (BDAI), and the 19 August 2024 circular extending those principles to generative AI in customer-facing uses. It pairs them with an enabling programme: the GenA.I. Sandbox (launched 13 August 2024, expanded to the cross-sector GenA.I. Sandbox++ on 5 March 2026) and a push for AI in anti-money-laundering monitoring, where the HKMA asked AIs with significant Hong Kong operations to submit a board-approved AI feasibility study and implementation plan by the end of March 2025. These are supervisory expectations, not rules with stated penalties; AIs are expected to apply them proportionately to the risk of each AI application.

Full nameHong Kong Monetary Authority — Hong Kong's banking regulator and de facto central bank (circulars to Authorized Institutions under the Banking Ordinance, Cap. 155)
RolePrinciples-based supervisor that regulates AI in banks through circulars, plus the GenA.I. Sandbox for supervised pilots
Force on banksSupervisory guidance
Applies toAuthorized Institutions (AIs) in Hong Kong. The HKMA's AI circulars are addressed to the chief executive of every AI; the AML circular of 9 September 2024 targets AIs with significant operations in Hong Kong, and the GenA.I. Sandbox++ joint circular of 5 March 2026 also reaches securities, insurance, MPF and stored value facility firms through the SFC, IA, MPFA and the HKMA.
Key documentCircular "High-level Principles on Artificial Intelligence" (1 November 2019), extended to generative AI by the circular "Consumer Protection in respect of Use of Generative Artificial Intelligence" (19 August 2024)
Latest moveOn 27 August 2026 the HKMA, SFC, Insurance Authority and MPFA announced the first cohort of the GenA.I. Sandbox++: 36 use cases from nearly 100 proposals, 30 financial institutions and 27 technology partners, focused on agentic AI; on 22 June 2026 the HKMA circulated a report on AI in fighting financial crime, and on 2 June 2026 a circular on cyber resilience against AI-empowered threats
Documents tracked6 · all documents →

The HKMA's framework has two layers. The 2019 letters set the baseline: the "High-level Principles on Artificial Intelligence" (issued by the Executive Director (Banking Supervision)) make the board and senior management accountable for AI-driven decisions and cover explainability, data quality, model validation, auditability, third-party vendors, bias, ongoing monitoring, data protection, cybersecurity and contingency plans, while the companion consumer-protection circular (issued by the Executive Director (Banking Conduct)) sets four principles: governance and accountability, fairness, transparency and disclosure, and data privacy and protection. The 19 August 2024 circular on generative AI adds extra expectations for customer-facing GenAI: a defined scope, human-in-the-loop in the early stage of deployment, an opt-out or review channel, and disclosure of both use and limitations.

The second layer is promotion and supervision by engagement. The GenA.I. Sandbox, run with Cyberport, gives AIs GPU compute and targeted supervisory feedback; the first cohort (15 use cases, announced 19 December 2024) and second cohort (27 use cases, announced 15 October 2025) have been followed by the GenA.I. Sandbox++ with the SFC, the Insurance Authority and the MPFA, whose first cohort of 36 agentic-AI use cases was announced on 27 August 2026. In financial crime the HKMA has moved from encouragement to a request: its 9 September 2024 circular asked AIs with significant Hong Kong operations to study adopting AI in ML/TF monitoring, and follow-up circulars on 19 November 2025 and 22 June 2026 reported adoption and announced workshops, including one on agentic AI. On 2 June 2026 it also reminded AIs to strengthen cyber resilience against cyber-attacks empowered by frontier AI models.

What has the HKMA actually published on AI?

DateDocumentStatus
Mar 5, 2026HKMA GenA.I. Sandbox++ joint circular — Joint Circular on the Expansion of Generative Artificial Intelligence Sandbox (HKMA, SFC, Insurance Authority and MPFA, 5 March 2026)In force
Sep 20, 2024HKMA GenA.I. Sandbox circular — Generative Artificial Intelligence Sandbox (HKMA circular inviting applications to the GenA.I. Sandbox, 20 September 2024)In force
Sep 9, 2024HKMA circular on AI for monitoring of suspicious activities — Use of Artificial Intelligence for Monitoring of Suspicious Activities (HKMA circular, 9 September 2024)In force
Aug 19, 2024HKMA GenAI consumer protection circular — Consumer Protection in respect of Use of Generative Artificial Intelligence (HKMA circular, 19 August 2024)In force
Nov 5, 2019HKMA BDAI consumer protection principles — Consumer Protection in respect of Use of Big Data Analytics and Artificial Intelligence by Authorized Institutions (HKMA circular, 5 November 2019)In force
Nov 1, 2019HKMA High-level Principles on Artificial Intelligence — High-level Principles on Artificial Intelligence (HKMA circular to all Authorized Institutions, 1 November 2019)In force
DateTypeDocument / event
Aug 27, 2026MilestoneFirst GenA.I. Sandbox++ cohort announced. The HKMA, SFC, IA and MPFA selected 36 use cases from nearly 100 proposals, involving 30 financial institutions and 27 technology partners. The cohort focuses on agentic AI applications such as onboarding, payments, insurance claims and customer interactions, and on AI providing dynamic oversight of other AI.
Jun 22, 2026MilestoneReport "Supporting Adoption of Artificial Intelligence in Fighting Financial Crime". The HKMA circulated a report on how AIs of different sizes are deploying AI in AML/CFT monitoring, covering dynamic risk assessment, facial watch lists and corporate mule detection, and announced a second workshop on agentic AI use cases on 23 June 2026. AIs were reminded that their implementation plans should be kept under review.
Jun 2, 2026MilestoneCircular on cyber resilience amid AI-empowered cyber threats. AIs were told to assess whether their cyber defences remain fit for purpose against attacks empowered by frontier AI models, uplift incident response and recovery, and enhance data resilience. The HKMA announced a Task Force on A.I.-Driven Cyber Risks and a Cyber Resilience Testing Framework with an initial test run targeted for late 2026.
Mar 5, 2026CircularHKMA GenA.I. Sandbox++ joint circular — Joint Circular on the Expansion of Generative Artificial Intelligence Sandbox (HKMA, SFC, Insurance Authority and MPFA, 5 March 2026). The joint circular of 5 March 2026 from the HKMA, the Securities and Futures Commission, the Insurance Authority and the MPFA expands the HKMA's GenA.I. source ↗
Nov 19, 2025MilestoneHKMA reports on AI adoption in AML/CFT monitoring. Following its 9 September 2024 letter, the HKMA reported that 48 AIs had assessed the feasibility of AI for transaction monitoring, that more than 30% had already adopted AI in their monitoring systems, and that most others had timelines that would lift adoption above 80% over the following 12 to 24 months. It announced a series of workshops, the first held that day.
Oct 31, 2025MilestoneGenA.I. Sandbox Practical Insights Report circulated. A circular of 31 October 2025 announced the report "Responsible Innovation with GenA.I. in the Banking Industry - Practical Insights from the GenA.I. Sandbox", drawn from the first cohort's technical trials and covering data preparation, model fine-tuning, output evaluation and ongoing monitoring. The first cohort officially concluded at the GenA.I. Symposium that day.
Oct 15, 2025MilestoneSecond GenA.I. Sandbox cohort selected. Twenty-seven use cases from 20 banks and 14 technology partners were selected from over 60 proposals; trials were to start in early 2026. Themes included AI quality checks on AI outputs and adversarial simulations against deepfake-related fraud.
Apr 28, 2025MilestoneSecond GenA.I. Sandbox cohort opens, with the Collaboratory. The second cohort introduced the GenA.I. Sandbox Collaboratory, a series of workshops pairing banks with technology providers, and an "A.I. versus A.I." theme of using AI in the second and third lines of defence. The accompanying circular set a 31 August 2025 application deadline and expected every use case to include A.I. safety validation.
Dec 19, 2024MilestoneFirst GenA.I. Sandbox cohort announced. Fifteen use cases from 10 banks and four technology partners were selected from over 40 proposals, centred on risk management, anti-fraud measures and customer experience. Trials were expected to run from early 2025 to mid-2025 on Cyberport's Artificial Intelligence Supercomputing Centre.
Sep 20, 2024CircularHKMA GenA.I. Sandbox circular — Generative Artificial Intelligence Sandbox (HKMA circular inviting applications to the GenA.I. Sandbox, 20 September 2024). The HKMA's circular of 20 September 2024 invited Authorized Institutions to apply to the Generative AI (GenA.I.) Sandbox that the HKMA and Cyberport announced on 13 August 2024. source ↗
Sep 9, 2024CircularHKMA circular on AI for monitoring of suspicious activities — Use of Artificial Intelligence for Monitoring of Suspicious Activities (HKMA circular, 9 September 2024). The HKMA's circular of 9 September 2024, signed by the Executive Director (Enforcement and AML), asks banks to consider using artificial intelligence in monitoring money laundering and terrorist financing (ML/TF) risks. source ↗
Aug 19, 2024CircularHKMA GenAI consumer protection circular — Consumer Protection in respect of Use of Generative Artificial Intelligence (HKMA circular, 19 August 2024). The HKMA's circular of 19 August 2024 tells Authorized Institutions to apply and extend the 2019 BDAI consumer-protection principles to generative AI in customer-facing applications and adds extra safeguards under each of the four principle areas. source ↗
Aug 13, 2024MilestoneHKMA and Cyberport launch the GenA.I. Sandbox. Announced at FiNETech2 as a risk-managed environment for banks to pilot GenAI use cases with technical assistance and targeted supervisory feedback, focused on risk management, anti-fraud and customer experience. The HKMA said it would draw insights from the Sandbox and share good practices. The invitation to apply followed in a circular of 20 September 2024.
Nov 5, 2019CircularHKMA BDAI consumer protection principles — Consumer Protection in respect of Use of Big Data Analytics and Artificial Intelligence by Authorized Institutions (HKMA circular, 5 November 2019). The HKMA's circular of 5 November 2019 gives Authorized Institutions four guiding principles on consumer protection in the use of big data analytics and artificial intelligence (BDAI): governance and accountability, fairness, transparency and disclosure, and data privacy and protection. source ↗
Nov 1, 2019CircularHKMA High-level Principles on Artificial Intelligence — High-level Principles on Artificial Intelligence (HKMA circular to all Authorized Institutions, 1 November 2019). The HKMA's "High-level Principles on Artificial Intelligence", issued to all Authorized Institutions on 1 November 2019, are the foundation of Hong Kong's supervisory approach to AI in banking. source ↗
  • Whether the HKMA updates its 1 November 2019 "High-level Principles on Artificial Intelligence", which the 19 August 2024 circular said would be updated from time to time, or issues new supervisory guidance drawing on the GenA.I. Sandbox and Sandbox++ trials, including for agentic AI
  • The GenA.I. Sandbox++ trials of the first cohort announced on 27 August 2026, and any good-practice report the four financial regulators publish from them
  • Follow-up to the 2 June 2026 cyber circular: the Task Force on A.I.-Driven Cyber Risks and the Cyber Resilience Testing Framework, whose initial test run with selected institutions is targeted for late 2026
  • Further HKMA workshops and publications on AI in AML/CFT monitoring, including agentic AI, and any request that AIs report progress against the implementation plans submitted in 2025

How does the HKMA regulate AI in banking?

Through circulars to Authorized Institutions rather than legislation: the 2019 High-level Principles on Artificial Intelligence, the 2019 consumer-protection principles for big data analytics and AI, and the 19 August 2024 extension to generative AI. These are principles-based supervisory expectations to be applied proportionately, supported by the GenA.I. Sandbox and Sandbox++ for supervised pilots.

Are the HKMA's AI circulars binding on banks?

They are supervisory guidance, not legislation. The 2019 letter says banks are expected to take the principles into account and may apply them proportionately; the generative AI circular says the HKMA expects all authorized institutions to apply and extend the 2019 guiding principles. None of the circulars states a specific penalty, and the 9 September 2024 AML circular's feasibility study and implementation plan were requested from AIs with significant operations in Hong Kong.

Does the HKMA have an AI sandbox for banks?

Yes. The GenA.I. Sandbox, run with Cyberport, was launched on 13 August 2024 and has had two bank cohorts. On 5 March 2026 the HKMA, SFC, Insurance Authority and MPFA expanded it into the GenA.I. Sandbox++ across banking, securities, insurance, MPF and stored value facilities; its first cohort was announced on 27 August 2026.

Follow every move these regulators make

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning