Technology & Cyber regulatory updates from International.
We track 18 Technology & Cyber updates from International regulators, published by BIS and FSB. The archive covers 10 news items, 5 speeches and 3 consultations. Most recent update: September 2026. Coverage runs from 2025 to 2026.
CPMI-IOSCO are seeking input from stakeholders on a cyber resilience toolkit for financial market infrastructures (FMIs) and on risks to FMIs from third-party service providers. The Cyber resilience toolkit: practical considerations for FMIs supports FMIs in strengthening their cyber resilience frameworks. The…
Why this matters
This is a formal consultation by CPMI-IOSCO seeking stakeholder input on two interconnected deliverables: a cyber resilience toolkit for FMIs and a discussion paper on third-party service provider risks. The toolkit complements existing PFMI principles and provides practical guidance on operational resilience.
The potential impact of frontier AI on cyber risk is the most immediate concern to the financial system, says FSB Chair, Andrew Bailey.
Why this matters
This is a policy statement from the FSB Chair to G20 authorities identifying frontier AI and cyber risk as priority concerns requiring jurisdictional and institutional response. The letter calls for concrete steps on safe AI deployment and third-party resilience, indicating regulatory intent to develop standards.
In his letter to G20 Finance Ministers and Central Bank Governors, Andrew Bailey, warns that markets remain vulnerable to a potential disorderly correction and cautions on the risks posed by frontier AI models.
Why this matters
This is a speech/letter from the FSB Chair to G20 policymakers flagging frontier AI as an emerging systemic risk to financial stability, particularly through cyber vulnerabilities and market confidence impacts.
Consultation responses to ‘Sound Practices for Responsible Adoption of Artificial Intelligence (AI): Consultation report‘.
AI Analysis
The FSB has published public responses to its consultation on sound practices for responsible AI adoption, following the 10 June 2026 consultation report and the 22 July 2026 comment deadline. This is a consultation-stage update, so it does not create binding obligations, but it signals the direction of emerging global expectations for AI governance in financial institutions.
Key dates
2026-06-10
FSB published the consultation report on Sound Practices for Responsible Adoption of Artificial Intelligence (AI)
2026-07-22 Deadline
Deadline for written comments on the consultation report
2026-08-06
FSB published the public responses to the consultation
Suggested considerations
Compliance teams may wish to review the consultation responses to identify supervisory themes and likely refinements to the final FSB report.
Firms considering or already using AI may wish to map their current governance, risk, and lifecycle controls against the FSB’s 12 proposed sound practices.
Risk and model governance teams may wish to assess whether their controls address generative AI, agentic AI, and third-party or technology dependencies in a way that aligns with the consultation’s focus.
Public policy and regulatory affairs functions may wish to track the final report once published, as it may influence national supervisory expectations even if it remains non-binding soft law.
What changed
The publication makes available the written public comments received on the FSB’s consultation report on Sound Practices for Responsible Adoption of Artificial Intelligence (AI). The underlying consultation proposed a menu of 12 sound practices for financial institutions to apply across organisation-wide AI governance and the full AI lifecycle, including emerging forms such as generative AI and agentic AI.
Compliance impact
The immediate compliance impact is limited because this is a consultation-response publication and the underlying document is non-binding guidance. The practical consequence is that firms may see the direction of future international supervisory expectations on AI governance, lifecycle controls, and related technology and third-party risks.
In this speech, John Schindler, FSB Secretary General, addresses the importance of international organisations in a shifting geopolitical landscape.
Why this matters
This is a speech by the FSB Secretary General addressing the state of multilateralism in financial regulation. While not a binding rule or consultation, it provides noteworthy regulatory signals about FSB priorities and approach.
At the virtual event, hosted by OMFIF, FSB Deputy Secretary General calls for a debate on the next steps for cross-border payments beyond 2027.
Why this matters
This is an opening remarks speech at a virtual event, not a binding obligation or final rule. However, it carries concrete regulatory signals about the FSB's thinking on cross-border payments policy beyond 2027, including questions about standardization (ISO 20022), stablecoins, regional coordination, and...
In her remarks, Michelle W. Bowman, Chair of the FSB Standing Committee on Supervisory and Regulatory Cooperation (SRC), discusses the FSB’s Consultation Report on the Sound Practices for Responsible Adoption of Artificial Intelligence.
AI Analysis
The FSB used this speech to signal that its consultation report on sound practices for responsible AI adoption is meant to guide, not hard-code, how financial institutions govern AI use. For compliance teams, the key message is that the draft framework is risk-based and proportional, with lighter-touch expectations for lower-risk uses and greater scrutiny where AI is material to business operations or legal and regulatory obligations.
Key dates
2026-06-10
FSB published the consultation report on Sound Practices for Responsible Adoption of Artificial Intelligence
2026-07-07
FSB virtual outreach event and Michelle W. Bowman opening remarks on the consultation
2026-07-22 Deadline
Deadline for public comments on the consultation report
Suggested considerations
Compliance teams may wish to map all AI use cases and classify which deployments are material to business operations, legal obligations, or regulatory obligations.
Firms should consider whether existing governance, model risk, and operational risk controls already cover AI lifecycle risks, including selection, data governance, monitoring, human oversight, and cyber/ICT exposures.
Institutions may wish to test whether AI governance is proportionate by business size and complexity, especially where lower-risk use cases could justify lighter controls.
Board and senior management teams should consider whether roles, responsibilities, and escalation paths for AI are clearly defined and documented.
Firms may wish to maintain a current inventory of AI systems and vendors so they can evidence oversight, dependency management, and remediation decisions if the final report adopts similar sound practices.
Compliance teams should monitor the final FSB report later in 2026 and compare any finalized practices against current internal policies, third-party controls, and incident response arrangements.
What changed
This publication does not impose new binding rules; it is an opening remark supporting the FSB’s June 2026 consultation report on Sound Practices for Responsible Adoption of Artificial Intelligence. The speaker says the report is intended to be finalized later in 2026 as a U.S. G20 deliverable, and that feedback from the public comment process will shape the final text.
Compliance impact
The current publication is consultative and non-binding, so immediate legal impact is limited. The practical consequence is preparatory pressure: firms that use AI should expect a future FSB final report to reinforce risk-based governance, proportionality, and stronger controls for materially important AI deployments.
The FSB hosted a virtual outreach event on 7 July 2026.
Why this matters
This is an announcement of a virtual outreach event supporting an FSB consultation on responsible AI adoption. The underlying consultation report (published 10 June 2026) is substantive policy guidance on AI governance and risk management for financial institutions.
Digital innovation is transforming finance, potentially enabling greater competition and efficiency in payment systems and financial intermediation. However, it also poses new macro-financial challenges and raises the broader question of how to preserve trust in money in the digital age.
Why this matters
This is a BIS media release accompanying a special chapter of the Annual Economic Report 2026. It articulates high-level policy direction on stablecoins and tokenisation, identifies structural weaknesses in current stablecoin designs, and calls for coordinated global regulatory efforts on two fronts: near-term...
The Basel Committee on Banking Supervision today published a range of practices report on information and communication technology (ICT) risk management. ICT is a key component of operational risk management, playing a vital role in supporting the broader goal of achieving operational resilience.
Why this matters
This is a Basel Committee publication of a range of practices report (not binding rules, but authoritative guidance) addressing ICT risk management as a component of operational resilience. The content is informational/guidance-focused rather than a consultation or final rule, and targets banks specifically.
Basel Committee publishes report on information and communication technology risk management.
Why this matters
This is a published report from the Basel Committee on Banking Supervision (BCBS) analyzing ICT risk management practices across jurisdictions. The content explicitly addresses operational resilience and ICT/cyber risk in banking.
The Basel Committee has published a report describing a range of observed information and communication technology (ICT) risk management practices across jurisdictions to address non-malicious ICT incidents.
Why this matters
This is a media release announcing publication of a Basel Committee range of practices report on ICT risk management. The report documents observed practices across jurisdictions and is intended as a reference for banks and supervisory authorities.
The Project Agorá prototype demonstrates how tokenisation and programmable technologies can address long-standing inefficiencies in wholesale cross-border payments at scale, while preserving the safety and integrity of settlement in central bank reserves.
Why this matters
This is a press release and research report from the BIS announcing Project Agorá findings on tokenisation for wholesale payments. It is informational and exploratory in nature (explicitly noted as experimental), not a binding obligation or final rule.
The Project Agorá prototype demonstrates how tokenisation and programmable technologies can address long-standing inefficiencies in wholesale cross-border payments at scale, while preserving the safety and integrity of settlement in central bank reserves.
Why this matters
The content is a media release and research report from the BIS Innovation Hub detailing Project Agorá's exploratory findings on tokenised wholesale cross-border payments.
Agrees to publish range of practices report on information and communication technology risk management. Progresses its targeted review of the prudential standard for banks' cryptoasset exposures. Considers targeted updates of its principles on liquidity risk.
Why this matters
This is a Basel Committee press release documenting meeting outcomes and regulatory work in progress. The Committee approved publication of an ICT risk management practices report (addressing operational resilience), is progressing a targeted review of cryptoasset prudential standards, and is considering updates to...
Agrees to publish range of practices report on information and communication technology risk management. Progresses its targeted review of the prudential standard for banks' cryptoasset exposures. Considers targeted updates of its principles on liquidity risk.
Why this matters
This is a media release documenting Basel Committee meeting outcomes. The content supports three primary regulatory initiatives: (1) publication of ICT risk management practices report addressing operational resilience, (2) ongoing targeted review of cryptoasset prudential standards with updates promised later in...
As part of its 2025-2026 work programme, the Basel Committee is advancing various supervisory initiatives related to the digitalisation of finance.
AI Analysis
The Basel Committee has published its Principles for the sound management of third-party risk, setting a common baseline for banks and supervisors as firms become more dependent on third-party service providers. The publication matters because it broadens the supervisory lens beyond traditional outsourcing to a wider range of third-party arrangements, with implications for governance, due diligence, contracts, monitoring, and exit planning.
Key dates
2025-12-10
Basel Committee publication date for the Principles for the sound management of third-party risk
Suggested considerations
Compliance teams may wish to map all third-party arrangements against the new lifecycle expectations, including non-traditional outsourcing and intra-group or technology-enabled arrangements.
Firms should consider whether board-approved third-party risk appetite, tolerance for disruption, and reporting lines are documented clearly and align with current governance arrangements.
Banks may wish to review due diligence, contracting, onboarding, monitoring, continuity, and exit procedures to confirm they address the principle-based expectations across the full relationship lifecycle.
Supervisory liaison teams may wish to assess whether concentration risk, critical provider dependencies, and cross-border coordination issues are adequately captured in existing risk registers and escalation frameworks.
What changed
The document sets out 12 principles covering the full third-party service provider lifecycle, divided between bank-facing expectations and supervisor-facing expectations. For banks, the principles cover governance and strategy, board and senior management oversight, risk assessment, due diligence, legally binding contracts, onboarding, ongoing monitoring, business continuity, and termination/exit management.
Compliance impact
The publication is a material supervisory signal rather than a binding rule, but it raises the expected standard for how banks identify, manage, and oversee third-party dependencies. Institutions that rely heavily on external providers may face closer supervisory scrutiny of governance, resilience, and concentration risk, especially where critical services are involved.
The Basel Committee on Banking Supervision has issued a consultation on Machine-readable Pillar 3 disclosure. The consultation proposes to make the data disclosed by banks (so-called Pillar 3 disclosures) available in a machine-readable format.
AI Analysis
The Basel Committee issued a consultation proposing a standard for machine-readable Pillar 3 disclosures, aimed at making banks’ quantitative prudential disclosures easier to aggregate, process, and compare across jurisdictions. The proposal matters because it adds technical format requirements without changing the underlying disclosure content, signaling a move toward standardized supervisory data infrastructure.
Key dates
2025-12-05
Basel Committee publishes the consultation on machine-readable Pillar 3 disclosure
2026-03-05 Deadline
Deadline for comments on the consultative document
Suggested considerations
Compliance teams may wish to review current Pillar 3 disclosure production processes and determine whether quantitative disclosures can be generated in a machine-readable format.
Banks may wish to map any existing PDF-based Pillar 3 outputs against likely technical data structure requirements, including whether disclosures could be published on a website or via a central repository.
Supervisors and policy teams may wish to assess how local disclosure arrangements align with the proposed global standard and whether current formats already satisfy the envisaged approach.
Firms subject to overlapping regional disclosure regimes may wish to compare current machine-readable standards with the Basel Committee proposal to identify expected implementation gaps.
What changed
The consultation proposes a new standard for machine-readable quantitative Pillar 3 disclosures across Basel Committee member jurisdictions. It would introduce both a requirement and technical specifications for producing disclosures in a machine-readable format, while leaving the substantive disclosure obligations unchanged. The consultation also contemplates that national supervisors would choose whether disclosures are posted on banks’ own websites or in a central repository.
Compliance impact
The Basel Committee describes the issue as a practical transparency and data-usability problem, because many banks currently publish Pillar 3 information only in PDF format, making cross-bank comparison difficult. The proposal is not a new prudential capital requirement, but it could materially affect disclosure production, data governance, and supervisory reporting processes for affected banks.