Insight Details

/

The Emerging AI Governance Landscape

The Emerging AI Governance Landscape

The emerging AI governance landscape is not one body of law. It is developing through several overlapping forms of regulation, supervision, and industry practice, and these do not carry the same legal weight or operate in the same way.

For the purposes of Banking 3.0, it is useful to think of this landscape in three layers.

The first is existing regulation relevant to AI. These are laws and regulatory obligations that were not necessarily written for artificial intelligence but continue to govern the activity in which an agent participates. Privacy law still governs personal information. Fair-lending requirements still govern lending. Operational-resilience requirements still govern critical technology and third-party dependencies. The arrival of an agent does not remove the obligation attached to the underlying activity.

The second is AI-specific regulation. These are requirements created specifically for artificial intelligence and its use. The European Union has moved furthest in this direction through the EU AI Act, while other jurisdictions are developing different combinations of legislation, rules, and sector-specific requirements.

The third is AI standards, guidance, and supervisory expectations. These include frameworks for AI risk management, responsible AI, security, model governance, testing, monitoring, and assurance. They may not have the same legal force as legislation, but they increasingly influence how institutions design governance programs and demonstrate that AI is being used responsibly.

These layers overlap. A single banking agent may therefore be subject to the rules governing the financial activity it performs, the data it processes, the technology on which it depends, and the AI capability itself. The resulting landscape differs considerably across jurisdictions.

Table 1: Global AI and Agent Governance Landscape

Geography

Existing Regulation Relevant to AI

AI-Specific Regulation

AI Standards, Guidance & Supervisory Expectations

European Union

GDPR; DORA; existing financial-services and consumer-protection requirements

EU AI Act

EU AI Act guidance, codes and technical standards; European supervisory guidance

United States

ECOA/Regulation B; FCRA; GLBA; FTC Act; banking, cybersecurity, consumer-protection and third-party requirements

No single comprehensive federal AI statute equivalent to the EU AI Act

NIST AI RMF; NIST Generative AI Profile; federal, state and banking supervisory guidance

United Kingdom

UK GDPR/Data Protection Act; Consumer Duty; existing financial-services requirements

No comprehensive EU-style AI Act

FCA/PRA supervisory expectations and UK AI governance guidance

Singapore

PDPA; applicable MAS technology, operational-risk and financial-services requirements

No comprehensive statutory AI Act

IMDA AI governance frameworks; MAS FEAT/Veritas and related guidance

Canada

Federal and provincial privacy requirements; applicable financial-sector regulation

AI-specific legislative framework continues to evolve

OSFI model-risk expectations and responsible-AI guidance

Australia

Privacy Act; applicable APRA prudential, operational-risk and information-security requirements

AI-specific regulatory approach continues to develop

Responsible-AI guidance and financial-sector supervisory expectations

China

PIPL and applicable data and cybersecurity requirements

Algorithmic Recommendation Provisions; Deep Synthesis Provisions; Interim Measures for Generative AI Services

National AI governance standards and regulatory guidance

Hong Kong

PDPO; applicable HKMA technology and risk requirements

No comprehensive AI Act

HKMA AI and generative-AI supervisory guidance

Japan

APPI and applicable sectoral requirements

Primarily an existing-law and sectoral approach

AI Guidelines for Business and financial-sector guidance

United Arab Emirates

UAE PDPL; DIFC and ADGM data-protection regimes; applicable financial-sector requirements

AI-specific framework continues to develop

Government and financial-sector responsible-AI principles and guidance


The table is illustrative rather than exhaustive. What matters for Banking 3.0 is not simply the number of regimes, but their overlap. The same agent may simultaneously inherit obligations from banking and privacy law, emerging AI-specific regulation, and supervisory or technical standards. AI regulation does not replace the regulatory architecture described in Chapter 8. It lands on top of it.

Some frameworks also travel more easily across borders than national regulation. International standards, cybersecurity frameworks, and industry guidance increasingly provide institutions with common ways to think about AI governance, risk, security, testing, monitoring, and evidence.

Table 2: Standards and Frameworks Relevant to AI and Agent Governance

Standard or Framework

Relevance to Banking 3.0

ISO/IEC 42001

AI management systems, governance, organizational responsibilities, risk processes and continuous improvement

ISO/IEC 23894

AI risk-management principles and processes

NIST AI Risk Management Framework (AI RMF)

Framework for managing AI risk through Govern, Map, Measure and Manage

NIST Generative AI Profile (AI 600-1)

Generative-AI-specific risks and risk-management considerations

OWASP guidance for LLM and agentic systems

Security risks, attack patterns and mitigations relevant to LLM applications and AI agents

MITRE ATLAS

Knowledge base for adversarial threats and techniques affecting AI-enabled systems

ISO/IEC 27001

Information-security management supporting the systems, data and infrastructure on which agents depend

NIST Cybersecurity Framework 2.0

Enterprise cybersecurity governance and risk management

SOC 2

Independent assurance over relevant controls at service organizations supporting third-party technology and AI services


These frameworks are not interchangeable, and they do not all have the same legal or supervisory status. Their importance to architecture lies in the common themes that run through them: governance, accountability, risk assessment, security, testing, monitoring, human oversight, and evidence. They provide increasingly common languages through which broad expectations can be translated into operating practices and controls.

The global picture therefore contains both continuity and change. Existing regulation continues to govern the activity around the agent. AI-specific regulation increasingly governs aspects of the technology and its use. Standards and supervisory frameworks help institutions determine how those requirements should be implemented.

Europe provides perhaps the clearest example of how these layers can converge.

Umar Rafi

Founder and CEO Sayaa Inc.

Actionable tips from top designers & developer

Get that doubles sales for startups and performance SMBs.

Ready to control your AI estate and

govern AI at scale?

One platform designed specifically for runtime assurance — not bolted onto something else.

Align risk, compliance, and AI teams

Real-time compliance visibility

Ready to control your AI estate and

govern AI at scale?

One platform designed specifically for runtime assurance — not bolted onto something else.

Align risk, compliance, and AI teams

Real-time compliance visibility

Ready to control your AI estate and

govern AI at scale?

One platform designed specifically for runtime assurance — not bolted onto something else.

Align risk, compliance, and AI teams

Real-time compliance visibility

Create a free website with Framer, the website builder loved by startups, designers and agencies.