
Sound Practices for Responsible Adoption of Artificial Intelligence (AI)
FSB
The Financial Stability Board has released its long-awaited AI governance framework ‘Sound Practices for Responsible Adoption of Artificial Intelligence (AI)’ for financial services. It is a serious piece of work — and it has a serious blind spot.
Somewhere between the credit algorithm that approved your last loan and the fraud-detection model that flagged your vacation spending, financial services quietly became an AI industry. Banks, insurers, asset managers, and payment providers are now embedding artificial intelligence into decisions that touch millions of lives — and until recently, they were doing so with little regulatory direction. The Financial Stability Board’s new consultation report, Sound Practices for Responsible Adoption of Artificial Intelligence, is the most substantial attempt yet to change that. It deserves serious attention, and serious criticism.
What the FSB Got Right
The framework organizes twelve sound practices across two pillars: governance (practices 1–4) and AI lifecycle management (practices 5–12). Boards and senior management are placed squarely in charge, responsible for aligning AI adoption with risk appetite and building the culture and skills required to sustain it. The lifecycle pillar then operationalizes governance through requirements covering model selection, data quality, explainability, performance monitoring, human oversight, cybersecurity, and third-party risk.
Three features stand out. First, the FSB wisely avoided prescribing rules for specific AI architectures. By focusing on governance outcomes rather than today’s models, the framework should remain relevant as generative AI gives way to whatever comes next — harder to achieve than it sounds, given how quickly early AI regulations have dated.
Second, the report grapples seriously with agentic AI — autonomous systems capable of planning, reasoning, and executing multi-step tasks without continuous human direction. The FSB correctly identifies that agentic AI introduces qualitatively different risks: goal misalignment, emergent behaviors from agent-to-agent interaction, and the near-impossibility of real-time human monitoring at scale. Most regulators are still catching up with large language models; the FSB has looked a step further.
Third, the framework takes vendor concentration risk seriously. Heavy dependence on a small number of cloud providers and foundation model developers creates single points of failure that traditional risk management frameworks were never designed to handle.
Where It Falls Short
The framework is comprehensive in scope but frequently too vague to be actionable. It correctly identifies what institutions should govern — lifecycle stages, data quality, explainability, human oversight — but repeatedly stops at “have effective controls” without specifying minimum testing standards, validation frequencies, escalation thresholds, or required documentation. Practitioners implementing these practices against supervisor expectations will face significant interpretive uncertainty. That uncertainty will resolve differently across jurisdictions, undermining the global consistency the FSB exists to promote.
Generative AI also deserves its own dedicated section. Prompt management, hallucination testing, retrieval-augmented generation, and human review requirements for generative outputs are substantively different from traditional model validation. Folding them into generic lifecycle guidance undersells both the challenge and the risk.
The case studies, meanwhile, skew heavily toward large internationally active banks. Nonbank lenders, private credit firms, insurers, and fintechs — all fast-growing users of AI with distinct regulatory environments — get thin coverage. And the cases that do appear stop well short of operational detail: what controls were deployed, what failed, how failures were caught, and what was learned. Without that texture, case studies risk becoming promotional material rather than implementation guides.
The Risk No One Is Talking About Loudly Enough
The most important gap in the FSB’s framework is not a missing definition or a thin case study. It is a missing chapter on systemic risk from correlated AI adoption — and this omission matters more than all the others combined.
When dozens of banks rely on the same foundation models, trained on the same datasets, optimized with the same techniques, their decisions can become correlated in dangerous ways. Simultaneous credit contractions, synchronized asset sales, similar risk-off moves — none of these would be visible in any individual institution’s risk reporting, but together they could amplify market stress in ways that dwarf traditional contagion. Call it model monoculture: the financial equivalent of an entire region planting the same crop.
The FSB’s report acknowledges herding risk as a concern. It does not treat it as the central financial stability threat that it is. A framework built to protect the global financial system should have that analysis at its core, not in a footnote.
The Verdict
The FSB’s AI sound practices earn a solid B+ as a foundation. The technology-neutral architecture, the governance emphasis, the lifecycle coverage, and the explicit attention to agentic AI are genuine achievements that took real intellectual work to produce. The shortcomings — insufficient specificity, thin systemic risk analysis, bank-centric case studies — are significant but correctable.
The consultation closes July 22. That is a tight window for an industry processing a lot of regulatory change at once, but the stakes justify the effort. Financial institutions, their supervisors, and the broader financial system will be better served if the FSB uses the feedback period to sharpen, rather than merely ratify, what it has produced.
AI is no longer a future concern for financial services. The decisions are being made now, at scale, often in ways that neither institutions nor regulators fully understand. A governance framework that tells firms to “have effective controls” without specifying what effective looks like is better than nothing — but only barely.
The FSB can do more, and the financial industry should work with the FSB to improve these proposed AI practices.