Back to perspectives

Financial Technology and Governance

Financial institutions adopt AI: the real risk extends beyond a wrong answer

An illustrative server room seen through a glass partition, with access controls and a person in the background.
Concept illustration; not a documentary photograph of a real factory, financial facility or news event.

Four Hong Kong financial regulators selected 36 use cases for the first GenA.I. Sandbox++ cohort. AI can now read data, call tools and carry out work as well as answer questions. Greater capability calls for clearly defined permissions and accountability.

Controlled testing

Greater capability requires clearer permissions, records and accountability

36

First-cohort use cases

30

Financial institutions

27

Technology partners

01

What makes this trial different

On 27 August 2026, the HKMA, SFC, Insurance Authority and MPFA, together with Cyberport, announced the first GenA.I. Sandbox++ cohort. They selected 36 use cases from nearly 100 proposals, involving 30 financial institutions and 27 technology partners.

The focus is agentic AI. A conventional chatbot answers a question; agentic AI can divide a task into steps, consult data, use system tools and advance a workflow.

The first use cases cover customer onboarding, payments, insurance claims and customer interactions, as well as one AI system overseeing another. Technical trials were expected to begin later in 2026.

Scale of the first GenA.I. Sandbox++ cohort Open full-size image ↗
Scale of the first GenA.I. Sandbox++ cohort
02

Why financial AI needs particular limits

When AI only prepares meeting notes, errors can usually be corrected before distribution. The consequences change when it can amend customer records, initiate payments or process claims.

The problem may involve more than a wrong answer: a system may use outdated information, access customer data without authorisation, bypass approval or send an incorrect result into another system. A technical error can become a privacy, compliance, operational and customer liability issue at the same time.

Six controls before financial AI deployment Open full-size image ↗
Six controls before financial AI deployment
03

Six questions to settle before deployment

A financial AI system needs clear answers to at least these questions: who authorises its use, which data it may read, which actions require human confirmation, who samples its output, whether the complete process can be reconstructed after an incident, and whether it can be stopped immediately and switched to manual handling.

HKMA principles hold bank boards and senior management accountable for AI outcomes and address data quality, model validation, explainability, audit trails, vendor management and contingency arrangements. The SFC also identifies investment recommendations, investment advice and investment research as high-risk uses of generative AI, because erroneous content may mislead clients.

Using an external AI provider does not outsource responsibility. Financial institutions still need to understand where data is sent, when models change, how service interruptions are handled and whether a vendor technology change requires retesting.

04

A sandbox is not regulatory approval

Sandbox++ is a controlled testing environment, not a licence or approval for participating firms to launch products at full scale. Its purpose is to identify gaps in data, permissions, monitoring and responsibility before exposure to large numbers of clients or important transactions.

Trial success therefore cannot be measured only by time saved. More important questions are whether errors can be detected promptly, their effects contained, and staff know when they must stop using AI.

05

Questions G70 would examine further

If AI supports family data, cross-border documents, insurance claims or payments, which error would be hardest to remedy? Are complete human review and operational records retained? Who revalidates the system after a provider changes its model?

Future differences among financial institutions will depend not only on model selection but also on clearly limiting what AI may see and do, and identifying who bears ultimate responsibility.

06

Important information

This article is for general information and educational purposes only and does not constitute legal, regulatory, investment or information security advice. The applicability of regulatory requirements depends on the institution’s licence, activities and specific use case.

G70

G70 governance perspective

Define what AI may access and do

A sandbox is a testing environment, not regulatory approval; governance and responsibility must still be designed before deployment.

  1. Which actions require human confirmation?
  2. Can the complete process be reconstructed after an error?
  3. Who revalidates a model after vendor updates?
Sources