AI Regulation Tracker · Canada (federally regulated financial institutions: banks, foreign bank branches, insurers, and trust and loan companies)

How does the OSFI regulate AI in banking?

Last updated Oct 5, 2026 · Updated as rules change

OSFI has no AI-specific rule for Canadian banks: it applies technology-neutral supervisory guidelines to AI. The central one is Guideline E-23 Model Risk Management, published on 11 September 2025 and effective 1 May 2027, whose model definition expressly includes AI/ML methods. Guideline B-10 (third-party risk, effective 1 May 2024) governs AI vendors, and OSFI's technology risk bulletins on frontier AI (April 2026) and generative and agentic AI (July 2026) set out sound practices under B-13, E-21 and B-10. Reports such as the OSFI-FCAC AI risk report (September 2024) and the FIFAI II report (March 2026) describe risks and priorities but are not guidance.

Full nameOffice of the Superintendent of Financial Institutions (Canada) — federal prudential supervisor of banks, insurers, and trust and loan companies; works with the Financial Consumer Agency of Canada (FCAC) on consumer protection
RoleCanada's federal prudential supervisor, regulating AI in banks through technology-neutral guidelines on model risk (E-23), third-party risk (B-10), technology and cyber risk (B-13) and operational risk (E-21)
Force on banksSupervisory guidance
Applies toFederally regulated financial institutions, including banks and foreign bank branches. OSFI guidelines set supervisory expectations rather than statute; E-23 applies proportionally to each institution's size, risk profile and complexity
Key documentGuideline E-23 – Model Risk Management (2027): published 11 September 2025, effective 1 May 2027; names AI/ML in the model definition and sets 3 outcomes and 12 principles
Latest moveIn July 2026 OSFI issued a Technology Risk Bulletin on generative and agentic AI (implications for technology, cyber security and operational resilience), following its April 2026 bulletin on frontier AI and the March 23, 2026 FIFAI II report; Guideline E-23 takes effect 1 May 2027
Documents tracked4 · all documents →

OSFI's position is that AI is a transverse risk handled inside existing frameworks. The OSFI-FCAC report of 24 September 2024 states that OSFI's and FCAC's frameworks on model risk, third-party risk, cybersecurity and operational resilience are technology-neutral and already cover many prudential areas that AI affects. Guideline E-23 then made model risk management explicit for AI/ML from 1 May 2027: all models at all federally regulated institutions are in scope, models with non-negligible risk go into an inventory with a risk rating, and explainability, bias, data quality, self-learning behaviour and drift monitoring receive specific expectations. Third-party and vendor models are governed through Guideline B-10.

OSFI's more recent output is operational. The April 2026 Technology Risk Bulletin on frontier AI and the July 2026 bulletin on generative and agentic AI raise awareness of how AI changes cyber and operational risk, and recommend practices such as AI governance and human oversight, controls on AI agent autonomy and access, AI-specific incident playbooks, and mapping AI dependencies to critical operations; the bulletins describe these as measures institutions can consider, consistent with B-13, E-21 and B-10. The FIFAI forums with the Global Risk Institute produced the EDGE principles (2022) and the AGILE framework (2026), neither of which is guidance.

What has the OSFI actually published on AI?

DateDocumentStatus
Mar 23, 2026OSFI FIFAI II report (AGILE framework) — FIFAI II: AI Risks and Opportunities: Adopting an AGILE Framework in Canadian Financial ServicesFinal
Sep 11, 2025OSFI Guideline E-23 — Guideline E-23 – Model Risk Management (2027)Final · applies from May 1, 2027
Sep 24, 2024OSFI-FCAC AI Risk Report (2024) — OSFI-FCAC Risk Report - AI Uses and Risks at Federally Regulated Financial InstitutionsFinal
Apr 24, 2023OSFI Guideline B-10 — Third-Party Risk Management GuidelineIn force
DateTypeDocument / event
Jul 2026MilestoneTechnology Risk Bulletin on generative and agentic AI. OSFI outlined sound practices on governance, information and decision integrity, controlled software changes, AI agent autonomy and access, AI in cyber operations, and resilience and third-party risk, aligned to B-13, E-21 and B-10 and pointing to E-23 for model risk.
Apr 2026MilestoneTechnology Risk Bulletin on frontier AI. OSFI raised awareness of risks from frontier AI models and highlighted sound practices with references to Guidelines B-13, E-21 and B-10.
Mar 23, 2026ReportOSFI FIFAI II report (AGILE framework) — FIFAI II: AI Risks and Opportunities: Adopting an AGILE Framework in Canadian Financial Services. The second Financial Industry Forum on Artificial Intelligence (FIFAI II) final report, hosted by OSFI and dated 23 March 2026, is the output of four workshops held between May and November 2025 by the Global Risk Institute with OSFI, Finance Canada, FINTRAC, FCAC and the Bank of Canada, involving more than 170 participants. source ↗
Sep 11, 2025GuidanceOSFI Guideline E-23 — Guideline E-23 – Model Risk Management (2027). Guideline E-23 is the Office of the Superintendent of Financial Institutions' (OSFI) final model risk management guideline. source ↗
Sep 24, 2024ReportOSFI-FCAC AI Risk Report (2024) — OSFI-FCAC Risk Report - AI Uses and Risks at Federally Regulated Financial Institutions. The OSFI-FCAC Risk Report on AI uses and risks, published on 24 September 2024 by the Office of the Superintendent of Financial Institutions and the Financial Consumer Agency of Canada, is the regulators' joint survey of how Canadian federally regulated financial institutions use AI and what risks follow. source ↗
Nov 20, 2023MilestoneDraft revised Guideline E-23 published for consultation. OSFI published a draft revised Guideline E-23 on model risk management for public consultation until 22 March 2024, with a proposed twelve-month implementation period that the final guideline extended to 1 May 2027.
Apr 24, 2023GuidanceOSFI Guideline B-10 — Third-Party Risk Management Guideline. Guideline B-10 is OSFI's Third-Party Risk Management Guideline, published on 24 April 2023 with an effective date of 1 May 2024. source ↗
  • May 1, 2027: Guideline E-23 takes effect for all federally regulated financial institutions; OSFI's response letter expects institutions to have started gap assessments and prioritised high-risk models
  • How OSFI supervises the sound practices in its April and July 2026 technology risk bulletins, which it presents as measures institutions can consider under B-13, E-21 and B-10
  • Whether OSFI issues further AI-specific guidance, given the FIFAI II report's observation that AI-specific guidance from Canadian financial regulators has been limited
  • Follow-up work from FIFAI II and the OSFI-FCAC AI risk work on third-party concentration, financial crime and consumer protection

Does OSFI have AI rules for banks?

OSFI has no AI-specific rule. It applies technology-neutral guidelines, principally E-23 on model risk (which names AI/ML in its model definition), B-10 on third-party risk, B-13 on technology and cyber risk and E-21 on operational risk, and has issued technology risk bulletins on frontier and generative and agentic AI. These are supervisory guidelines, not statute.

When does OSFI Guideline E-23 take effect?

OSFI published the final Guideline E-23 on 11 September 2025, and it takes effect for all federally regulated financial institutions on 1 May 2027.

Is the FIFAI II report OSFI guidance?

No. The FIFAI II report, dated 23 March 2026, reflects the views of forum participants and says it should not be interpreted as guidance from OSFI or any other regulator.

Follow every move these regulators make

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning