The Financial Stability Board (FSB) has unveiled its long-anticipated governance framework, titled “Sound Practices for Responsible Adoption of Artificial Intelligence (AI)” aimed at the financial services sector. While this framework represents a significant step forward, it also has notable shortcomings.
In recent years, financial institutions have increasingly integrated AI into their operations—whether it's a credit algorithm facilitating your loan approval or a fraud detection system monitoring your spending habits. This covert evolution into an AI-centric industry has taken place with minimal regulatory oversight, prompting the release of the FSB's latest consultation report, which seeks to establish critical guidelines.
The FSB framework is organized into two key areas, encompassing twelve sound practices. The first pillar focuses on governance (practices 1–4), emphasizing the crucial role of boards and senior management in ensuring AI implementations align with risk appetites while fostering a supportive organizational culture. The second pillar addresses the AI lifecycle management (practices 5–12), detailing guidelines for model selection, data integrity, explainability, performance assessment, human oversight, cybersecurity, and third-party risk management.
Three aspects of the framework are particularly commendable. Firstly, the FSB smartly refrains from prescribing specific AI architectures, instead prioritizing governance outcomes. This strategic focus could enhance the framework’s longevity, as it’s adaptable to whatever technological advancements may arise, including innovations beyond generative AI. Secondly, the report effectively encompasses the challenges posed by agentic AI—autonomous systems capable of self-directed planning and execution. The FSB accurately points out that such technologies can produce novel risks, including goal misalignment and emergent behavior, areas where many regulators are still catching up. Thirdly, the framework pays careful attention to vendor concentration risks, noting that reliance on a limited number of cloud providers could create vulnerabilities not accounted for by traditional risk management strategies.
Despite its comprehensive nature, the framework often falls short in providing actionable details. While it identifies the governance areas that institutions should focus on—like lifecycle management and data quality—it frequently lacks the specificity needed for practical implementation, such as minimum testing standards or documentation requirements. This vagueness could lead to significant interpretative variations across jurisdictions, which undermines the consistency that the FSB aims to achieve. Additionally, the framework does not dedicate sufficient attention to the nuances of generative AI, which has distinct challenges that should be addressed separately. The case studies included mainly highlight larger, globally active banks, leaving a gap for nonbank lenders, fintech companies, and other fast-growing AI users who operate under different regulatory conditions.
Perhaps the most critical shortcoming of the FSB's framework is its failure to address the systemic risk associated with widespread, correlated AI adoption. When multiple institutions rely on the same foundational models and data sets, their decisions may become dangerously synchronized, leading to simultaneous credit contractions or coordinated asset sell-offs that are not discernible from individual reports but could amplify market stresses significantly. This phenomenon, akin to agricultural monoculture, poses a substantial threat to financial stability. Although the report acknowledges the presence of herding risk, it does not adequately position this concern as a primary issue affecting financial stability. A robust framework for safeguarding the global financial system should incorporate this critical analysis at its core rather than relegating it to a mere footnote.


