Is the FSB's 'Sound Practices' AI Framework a Soft-Law Strategy to Preempt Hard Global Regulation of Financial AI?
The Financial Stability Board has released a 12-point framework for AI in banking, but its non-binding nature suggests a strategic effort to keep tech regulators out of financial oversight.
- Financial Supervisors
- Principles-based oversight is the only way to govern rapidly evolving technology without stifling innovation.
- Tech Policy Advocates
- Soft law is insufficient to prevent systemic risks and financial AI needs hard, enforceable rules.
- Banking Industry
- Overlapping tech and financial regulations will create compliance paralysis.
The short answer
- The FSB has proposed 12 'sound practices' for AI governance in financial institutions.
- The framework is explicitly non-binding, acting as 'soft law' rather than a prescriptive mandate.
- It addresses emerging threats like agentic AI and third-party vendor concentration.
- The approach contrasts sharply with the EU AI Act's hard, rules-based regulation.
- Financial regulators are using the framework to maintain jurisdictional control over banking algorithms.
The Financial Stability Board's new 12-point "Sound Practices" framework for artificial intelligence looks, at first glance, like a basic governance checklist. In reality, it is a strategic maneuver. By issuing "soft law" guidelines that focus on outcomes rather than specific architectures, global financial regulators are attempting to preempt hard, prescriptive tech regulation from dictating how banks use artificial intelligence.[2]
Financial services quietly became an AI industry years ago. From the credit algorithm that approves a mortgage to the fraud-detection model flagging a transaction, banks are embedding AI into decisions that touch millions of lives. Yet, until recently, they did so with little regulatory direction, relying on existing model risk management frameworks that were not designed for generative or agentic systems.[1]
The regulatory vacuum is increasingly being filled by cross-sector tech regulators. The European Union's AI Act, for example, classifies AI used for credit scoring as "high-risk," imposing mandatory conformity assessments and strict data governance rules. For central bankers and financial supervisors, this represents a loss of jurisdictional control. They do not want tech regulators auditing bank capital allocation or risk models.[3]
Enter the Financial Stability Board, the international body that coordinates global financial rules. On June 10, 2026, the FSB published its consultation report on "Sound Practices for Responsible Adoption of Artificial Intelligence." It is the most substantial attempt yet by the financial establishment to set the terms of AI governance, providing a blueprint for national regulators.[4]
The framework organizes 12 sound practices across two pillars: organization-wide governance and AI lifecycle management. It places boards and senior management squarely in charge, making them responsible for aligning AI adoption with the institution's risk appetite and ensuring continuous human oversight.[1]
Crucially, the FSB explicitly states that the practices are "not intended to establish an international standard or impose a prescriptive approach." This is the definition of soft law. It provides a menu of practices rather than a mandate, seeking to foster coordination without legally binding the institutions it oversees.
It provides a menu of practices rather than a mandate, seeking to foster coordination without legally binding the institutions it oversees.
The argument for this approach is adaptability. The FSB wisely avoided prescribing rules for specific AI architectures. By focusing on governance outcomes rather than today's models, the framework remains relevant as generative AI gives way to whatever comes next. Hard regulation, by contrast, is often obsolete by the time it is enacted.[1]
The FSB is not ignoring the dangers. The framework grapples seriously with agentic AI—autonomous systems capable of planning, reasoning, and executing multi-step tasks without continuous human direction. The FSB correctly identifies that agentic AI introduces qualitatively different risks: goal misalignment, emergent behaviors from agent-to-agent interaction, and the near-impossibility of real-time human monitoring at scale.[1]
The framework also highlights the vulnerability of third-party dependencies. If every major global bank relies on the same three cloud providers and the same foundational models, a single failure could trigger a systemic crisis. The FSB's earlier reports previously identified this as one of four key vulnerabilities, alongside market correlations, cyber risks, and data quality.
But identifying risks is different from mandating solutions. By publishing these sound practices, the FSB gives national financial supervisors a tool to say the sector is already governed. It allows banks to point to an internationally recognized framework to demonstrate compliance, effectively shielding their core algorithms from the mandatory external audits required by cross-sector tech regulators.[2][3]
Critics argue this is insufficient. A solid foundation, as some analysts have called it, does not prevent a flash crash caused by interacting agentic trading algorithms. Soft law relies on the goodwill and competence of bank boards—a reliance that has historically preceded financial crises when profit incentives override risk management.[1]
The tension between the FSB's principles-based approach and the EU's rules-based approach will define the next decade of financial technology. Banks are caught in the middle, preferring the FSB's flexibility but legally bound by the EU's rigidity if they operate in Europe.[3]
The consultation period for the FSB's framework closes on July 22, 2026, with a final report expected in October. While the industry is processing a massive amount of regulatory change, the stakes justify the effort.[1]
The FSB's framework is not just a set of best practices; it is a declaration of regulatory independence. It asserts that financial supervisors, not tech regulators, are best equipped to manage the risks of AI in finance. Whether soft law is strong enough to contain the systemic risks of agentic AI remains the trillion-dollar question.[2]
Jargon, explained
- Soft Law
- Non-binding guidelines or principles that influence behavior without having the force of legally enforceable statutes.
- Agentic AI
- Autonomous artificial intelligence systems capable of planning, reasoning, and executing multi-step tasks without continuous human direction.
- Model Risk
- The potential for adverse consequences from decisions based on incorrect or misused model outputs.
- Third-Party Concentration Risk
- The systemic vulnerability created when many financial institutions rely on the same few external vendors, such as cloud providers or AI model developers.
Sources
[1]Regulation TomorrowBanking IndustryFinancial Stability Board publishes consultation on sound practices for responsible adoption of AI
Read on Regulation Tomorrow →
[2]Factlen Editorial TeamTech Policy AdvocatesSynthesis by Factlen editorial team
Read on Factlen Editorial Team →
[3]European CommissionTech Policy AdvocatesEU Artificial Intelligence Act
Read on European Commission →
[4]WikipediaBanking IndustryFinancial Stability Board
Read on Wikipedia →
Comments
Every angle. Every day.
Get opinion stories with full source coverage and perspective breakdowns delivered to your inbox.

