Artificial intelligence is moving quickly into almost every part of the economy. Banks use technology to analyse information, businesses are adopting AI agents, and financial firms are increasingly relying on digital systems to make decisions and manage operations.
But as AI becomes more powerful, the risks become harder to ignore.
A sophisticated AI system could potentially be misused to launch cyberattacks against important infrastructure, including financial markets. There are also concerns about financial institutions becoming too dependent on a small number of technology and cloud providers.
These risks raise an important question: how can governments, regulators, banks, and technology companies keep up with AI without slowing down useful innovation?
The answer is unlikely to come from one new rule or one central authority. Regulators are already exploring different approaches, including using AI themselves to monitor financial markets and identify emerging threats.
Why Are AI Financial Risks Becoming a Bigger Concern?
AI can make financial systems faster and more efficient, but the same capabilities can potentially be used in harmful ways.
One concern is cybersecurity. AI could be used by malicious actors to identify weaknesses in systems or support sophisticated attacks on critical infrastructure.
Financial markets are particularly sensitive because they depend on interconnected digital systems. A significant interruption could have an impact on other financial system components in addition to one institution.
There are also concerns about the growing dependence of banks and other financial institutions on major cloud providers. When many businesses rely on the same small group of technology companies, a problem affecting one provider could potentially have wider consequences.
The source highlights this concentration as one of the headaches facing financial regulators.
Why Can’t Regulators Simply Wait for New Laws?
Technology often develops faster than legislation.
By the time governments pass a new law, AI systems may already have changed significantly. International agreements can take even longer, particularly when several countries and regulatory bodies are involved.
That creates a difficult situation for supervisors.
The source describes regulators increasingly looking for ways to work with the powers they already have instead of waiting for entirely new laws or regulatory frameworks.
This does not mean existing rules are enough for every situation. It means regulators are trying to adapt the tools they already have while the wider policy debate continues.
The approach requires regulators to be more flexible and creative than they may traditionally have been.
What Does Agentic AI Mean for Financial Regulation?
Agentic AI refers to systems that can carry out tasks more independently rather than simply responding to individual prompts.
For financial regulators, that could open up new ways of monitoring markets.
Instead of relying entirely on people to review huge amounts of information, AI agents could continuously look for unusual activity, patterns, or potential risks.
The source describes a global “Agentic Regulator” hackathon where regulators explored exactly these kinds of applications.
Nearly 300 teams submitted ideas, and participants included financial and non-financial regulators from different parts of the world.
The experiments showed that regulators are not only discussing AI as something they need to control. Some are also beginning to use it as a practical tool for supervision.
What Can Regulatory AI Actually Monitor?
The types of systems presented at the hackathon covered a wide range of financial risks.
Some AI agents were designed to track capital flows. Others looked at market herding, fraud risks, financial vulnerabilities, and robo-adviser activity.
This matters because financial markets generate enormous amounts of information.
A human team can only review so much data at once. AI systems can potentially process large volumes of information continuously and flag patterns that deserve closer examination.
That does not mean an AI system should automatically make regulatory decisions.
A more practical role is to help supervisors identify possible problems earlier and direct human attention toward areas that need investigation.
Does AI Need to Be Completely Explainable?
Explainability has been an important principle in financial regulation for years.
Regulators generally want to understand how important decisions are being made, particularly when those decisions can affect customers, companies, or markets.
AI makes that much harder.
Some advanced models can be extremely difficult to interpret in simple, step-by-step terms. Requiring complete transparency for every AI system may therefore be difficult to enforce.
The source suggests that regulators are beginning to reconsider what explainability should mean in an AI-driven financial system.
Instead of demanding that every model be perfectly transparent, regulators may increasingly focus on what the model actually does, whether its outcomes create unacceptable risks, and what safeguards exist when something goes wrong.
Could Guardrails Make AI Safer?
Guardrails can provide limits around how an AI system operates.
For example, regulators and financial firms could build controls that restrict certain actions, require human approval, or allow a system to be shut down when serious problems arise.
Safeguards such as kill switches and more precise guidelines on legal liability are particularly mentioned in the source.
This approach recognises a practical reality: completely banning advanced AI systems may not be realistic, particularly as businesses continue adopting the technology.
Instead, the focus can shift toward making sure systems operate within defined boundaries and that someone remains accountable for the consequences.
Why Is Legal Responsibility So Important?
When an AI system causes or contributes to a serious problem, it needs to be clear who is responsible.
Imagine an AI-powered system makes a decision that exposes a financial institution to significant losses, or an automated tool behaves in a way that creates a wider market problem.
Who should answer for that outcome?
The technology provider? The financial institution using the system? A manager who approved its deployment? Someone else?
These questions become increasingly important as AI systems take on more independent tasks.
Clear rules around responsibility can encourage companies to take AI governance seriously instead of treating problems as something that simply happened because “the AI did it.”
Should Regulators Build Their Own AI Tools?
The source argues that regulators need to get more directly involved with the technology rather than simply trying to regulate it from a distance.
There is a practical reason for this.
It is difficult to supervise technology effectively if you do not understand how it works in real-world settings.
Building and testing their own AI tools could give regulators firsthand experience with the strengths and weaknesses of agentic systems. It could also help them improve their ability to monitor markets.
The global hackathon described in the source is an example of this approach. Regulators were experimenting with AI agents for tasks that could support financial supervision.
In that sense, regulators are not only creating rules for AI. They are also learning by using it.
Why Is International Cooperation Important?
AI does not respect national borders.
A cyberattack can originate in one country and target infrastructure in another. Financial institutions operate internationally, while technology companies can provide services across multiple jurisdictions.
That makes cooperation especially important.
The source points to discussions between the United States and China about a possible AI-risk hotline as one example of efforts to create communication channels around serious AI-related threats.
It also points to work involving organisations such as the Bank for International Settlements and the Bank of England.
No single regulator is likely to have a complete view of the global AI risk landscape. Sharing information and reducing regulatory gaps could therefore become increasingly important.
Why Should Regulators Break Out of Their Silos?
Financial risks do not always fit neatly into one regulator’s area of responsibility.
A bank might depend heavily on a cloud provider. That cloud provider may not traditionally be regulated in the same way as a bank.
This creates a potential gap.
The source highlights the Bank of England’s decision to supervise cloud companies as “critical third parties” as an example of regulators paying closer attention to technology providers that support the financial system.
The broader lesson is that financial stability increasingly depends on companies that may sit outside traditional banking regulation.
If regulators focus only on banks while ignoring the technology infrastructure those banks depend on, important risks could remain outside the regulatory perimeter.
What Can Banks and Financial Firms Do?
Regulators are only part of the solution.
Banks and financial institutions also need to understand where they are using AI, what information their systems depend on, and what could happen if those systems fail.
That means businesses need to think beyond whether an AI system works correctly under normal conditions.
They also need to ask what happens when the system makes an unexpected decision, produces unreliable information, becomes unavailable, or is deliberately targeted by an attacker.
AI governance therefore needs to be part of broader operational and risk-management planning rather than treated as a separate technology project.
What Role Should Technology Companies Play?
Technology companies building advanced AI systems have a major role in managing the associated risks.
That can include investing in monitoring systems, developing safeguards, improving security, and working with regulators to understand how their technology could affect critical industries.
The source argues that technology companies should support regulatory experimentation rather than leaving AI supervision entirely to governments.
That cooperation could be particularly useful as regulators build their own technical expertise.
What Can We Learn From Global Regulatory Experiments?
One interesting point in the source is that many of the creative ideas at the regulatory hackathon came from countries and regions outside the traditional centres of the technology industry.
Participants and ideas came from places including India, Pakistan, Rwanda, Kenya, and the United Arab Emirates.
That is a useful reminder that AI regulation and innovation are not limited to Silicon Valley, Shenzhen, or other major technology hubs.
Governments and regulators in different parts of the world are experimenting with practical ways to use AI for supervision, and those experiments could provide lessons for others.
Can AI Help Regulators Manage AI Risks?
There is a certain irony in using AI to monitor the risks created by AI, but there is also a practical reason for doing so.
Modern financial markets generate huge quantities of information, and potential risks can develop quickly. AI systems may be able to monitor activity continuously and help identify unusual patterns faster than traditional manual processes.
But that does not remove the need for human oversight.
AI-generated alerts still need to be interpreted. Systems can produce false positives, miss important signals, or behave unpredictably.
The most useful role for regulatory AI may therefore be to support human supervisors rather than replace them.
What Should the Future of AI Financial Regulation Look Like?
There probably won’t be one universal solution.
A sensible regulatory framework may need several layers: monitoring systems, technical safeguards, clear responsibilities, cooperation between regulators, stronger oversight of critical technology providers, and practical testing of AI systems.
Regulators will also need to keep learning.
AI changes quickly, so regulation cannot simply be written once and left untouched for years. Supervisors need enough technical knowledge to understand new systems as they emerge.
At the same time, financial institutions need clear rules so they know what is expected of them.
The challenge is finding a balance between encouraging useful innovation and preventing avoidable risks.
Conclusion
AI is creating opportunities across finance, but it is also introducing the risks that regulators cannot afford to ignore.
Cybersecurity threats, dependence on major cloud providers, automated decision-making, and the growing use of agentic AI all raise difficult questions about how financial systems should be supervised.
Waiting for perfect laws may not be realistic when the technology is moving so quickly. That is why regulators are experimenting with the tools they already have while also building AI systems of their own.
International cooperation will matter too. Financial markets are interconnected, and AI-related risks can cross borders just as quickly as the technology itself.
The goal is not to stop AI from developing. It is to make sure that financial innovation does not move faster than the ability to understand, monitor, and manage the risks that come with









