July 2026 · 7 min read
FSB Releases 12 Sound Practices for AI
The Global Standard for Financial AI Governance Has Arrived
On June 10, 2026, the Financial Stability Board (FSB) released a consultation report: Sound Practices for Responsible Adoption of AI. This is not an ordinary industry guideline. The FSB is the G20's highest-level financial regulatory coordination body. Its framework is the coordinate system for global financial regulation.

Key Definitions
FSB Releases 12 Sound Practices for AI On June 10, 2026, the Financial Stability Board (FSB) released a consultation report: Sound Practices for Responsible Adoption of AI. This is not an ordinary industry guideline. The FSB is the G20's highest-level financial regulatory coordination body. Its framework is the coordinate system for global financial regulation.
The same week, Fed Vice Chair Bowman explicitly endorsed proportional regulation — lighter touch for smaller institutions, stricter oversight for larger ones. Two signals, one direction: financial AI governance is moving from "everyone figures it out alone" to "one global standard."
For any enterprise deploying AI in financial services, this is not a distant policy discussion — it is tomorrow's compliance reality.
Who Is the FSB and Why Does Its Framework Matter?
The Financial Stability Board was established at the 2009 G20 London Summit. Its members include central banks, treasuries, and regulatory authorities from 24 countries and regions, plus the IMF, World Bank, and Bank for International Settlements. Its core mandate: coordinate global financial regulation to prevent the next systemic financial crisis.
After the 2008 financial crisis, the FSB drove global regulatory frameworks for shadow banking, derivatives trading, and systemically important financial institutions. Today, the FSB believes AI's rapid deployment in financial systems carries similar systemic risk characteristics.
The FSB framework matters not because of its legal force — but because it represents global regulatory consensus. FSB frameworks are translated into local regulatory requirements by national authorities (Fed, ECB, PRA, FCA, MAS, JFSA). The FSB's 12 practices are the blueprint for global financial AI regulation over the next 3-5 years.
12 Practices, Three Dimensions, One Framework

The FSB's 12 sound practices span three dimensions:
Dimension 1: Organizational AI Governance (SP1-4)
SP1 Board Oversight: Boards bear ultimate responsibility for AI strategy and risk management.
SP2 Risk Management Framework: AI risk must be embedded in the enterprise-wide risk framework.
SP3 AI Strategy: A clear AI adoption strategy aligned with business objectives.
SP4 Third-Party Risk Management: AI vendors and models must be included in third-party risk management.
Dimension 2: AI Lifecycle Management (SP5-10)
SP5 Use Case Inventory: All AI use cases must be registered, classified, and risk-assessed.
SP6 Risk Assessment: Each AI use case requires independent risk assessment.
SP7 Testing and Validation: AI systems need independent testing before deployment.
SP8 Deployment Monitoring: Continuous performance and risk monitoring during operation.
SP9 Audit Trail: Complete audit trails for all AI decisions.
SP10 Continuous Improvement: Regular evaluation and updates to the AI governance framework.
Dimension 3: Compensating Controls (SP11-12)
SP11 Human Oversight: High-risk AI decisions require effective human oversight.
SP12 Emergency Rollback: AI systems must have emergency shutdown and rollback capabilities.
These 12 practices directly map to enterprise AI governance platform capabilities. SP5 (Use Case Inventory) maps to Agent Registry. SP7 (Testing & Validation) maps to compliance review workflows. SP8 (Deployment Monitoring) maps to runtime governance. SP9 (Audit Trail) maps to the audit layer. SP12 (Emergency Rollback) maps to Kill Switch capabilities.
Proportional Regulation: Bowman's Key Signal
On July 7, Fed Vice Chair Bowman explicitly endorsed proportional AI regulation — lighter touch for smaller institutions, stricter oversight for larger ones. This position is fully aligned with the FSB framework and provides flexibility for financial AI governance implementation.
For smaller and mid-sized financial institutions, this means they don't need to build a complete AI governance system overnight — they can start with low-risk use cases and expand gradually. For large banks and systemically important financial institutions, the FSB framework means building governance capabilities covering all 12 practices.
Proportional regulation is not deregulation — it is precision regulation. Bowman's speech sends a clear signal: the Fed is taking AI governance seriously, but it will not apply a one-size-fits-all approach.
Dual-Track Narrative: Regulatory Vacuum + Best Practices
The FSB framework, combined with SR 26-2 (the Fed's Agentic AI Carveout), creates a powerful dual-track narrative for financial vertical GTM:
Track 1: Regulatory Vacuum (SR 26-2)
The Fed's SR 26-2 carves out Agentic AI from existing regulatory frameworks, leaving financial institutions in a regulatory vacuum — no specific guidance, no compliance standards, no audit requirements for agentic AI.
Track 2: Best Practices (FSB 12 Practices)
The FSB's 12 practices fill this vacuum. While not legally binding, they represent global regulatory consensus. Financial institutions building AI governance around the FSB framework are preparing for future regulatory requirements.
Two tracks, one GTM narrative: regulatory vacuum is the problem, FSB best practices are the solution framework, and an independent governance platform is the implementation tool.
Consultation Deadline: July 22
The FSB consultation period closes on July 22, 2026. The final report will be published in H2 2026 as a G20 deliverable. Between now and year-end, global financial regulators will debate and refine these 12 practices.
For financial institutions, this is not a "wait and see" question. The FSB consultation period is itself a window for participating in rule-making. Submitting feedback, engaging in discussions, preparing early — building governance capability before the final standard is cheaper than scrambling after it arrives.
History tells us: after the 2008 financial crisis, the FSB's regulatory reforms took 5 years for global implementation. AI governance will move faster — not because regulators are more efficient, but because AI deployment speed far exceeds traditional fintech.
From FSB Framework to Action
The FSB's 12 practices provide a clear action framework for financial AI governance:
1. Build an AI use case inventory (SP5). You cannot govern what you cannot see. Agent Registry is step one.
2. Implement independent risk assessment (SP6). Each AI use case needs independent risk assessment — not self-assessment by the development team.
3. Establish continuous monitoring (SP8). AI systems are not "deploy and done" — they need continuous performance and risk monitoring.
4. Maintain human oversight and rollback capability (SP11-12). High-risk AI decisions require human review, and systems must have emergency shutdown capability.
This is not a compliance burden — it is the global standard for financial AI governance. Enterprises that build the framework first will have a structural advantage when regulation lands.
FAQ
Who Is the FSB and Why Does Its Framework Matter?+
The Financial Stability Board was established at the 2009 G20 London Summit. Its members include central banks, treasuries, and regulatory authorities from 24 countries and regions, plus the IMF, World Bank, and Bank for International Settlements. Its core mandate: coordinate global financial regulation to prevent the next systemic financial crisis.
What are the FSB's 12 sound practices and their three dimensions?+
The FSB's 12 sound practices span three dimensions:
What is Bowman's key signal on proportional AI regulation?+
On July 7, Fed Vice Chair Bowman explicitly endorsed proportional AI regulation — lighter touch for smaller institutions, stricter oversight for larger ones. This position is fully aligned with the FSB framework and provides flexibility for financial AI governance implementation.
How do the FSB framework and SR 26-2 create a dual-track narrative?+
The FSB framework, combined with SR 26-2 (the Fed's Agentic AI Carveout), creates a powerful dual-track narrative for financial vertical GTM:
When does the FSB consultation deadline close?+
The FSB consultation period closes on July 22, 2026. The final report will be published in H2 2026 as a G20 deliverable. Between now and year-end, global financial regulators will debate and refine these 12 practices.
相关文章
OpenAI 承认 Astra 思维链更难监控:审计证据必须从模型推理搬到动作边界
OpenAI 在 Astra 系统卡中首次承认:模型对自身思维链的控制力增强,链式思维监控的可信度下降,隐蔽作弊可能无法被发现。三天后首席科学家 Pachocki 撰文称没有任何实验室已解决对齐与监控。当被审计的实体能控制审计所读取的推理,审计就不再是独立证据。
知道坏了,不知道是谁干的:七成企业无法定位肇事 Agent
Kore.ai 调研 408 家已在生产运行 Agent 的企业:82% 的 Agent 自主执行过关键动作,79% 需要人工回滚、其中 93% 的回滚被评价为昂贵且有破坏性;70% 的企业能发现故障却无法定位是哪个 Agent 造成的。可观测性≠可归因,没有身份绑定的动作证据,遏制、回滚与问责都无从谈起。
一个叫「编辑」的权限,其实是代码执行——Google Dialogflow CX Rogue Agent 漏洞深度解析
Google Cloud Dialogflow CX 的 dialogflow.playbooks.update 权限——表面是编辑聊天机器人回复的内容管理权限——实际上是任意代码执行入口。一个拥有该权限的账户可在共享 Cloud Run 环境中覆盖所有 Agent 的代码执行文件。
CRC Clamp:一个在激活层上防止 LLM 说谎的技术——这对 AI 治理意味着什么?
NYU 新论文在 Bayesian-witness 基准上实现了 resist=1.00, update=1.00 的联合结果(Wilson 95% CI [0.99, 1.00])。不是检测说谎,是从架构层面防止说谎。
OOMeta AI Governance Platform
Vendor-independent, cross-platform governance layer. Agent Registry, compliance review, runtime governance, audit trails, Kill Switch — covering all 12 FSB practices. 2-week deployment, model-agnostic, cross-vendor.