On 10 June 2026 the Financial Stability Board (FSB) published a consultation report setting out twelve sound practices for the responsible adoption of artificial intelligence in financial institutions. Comments closed on 22 July, and the final report is due to reach G20 finance ministers in October. Read closely, the document is less a catalogue of new obligations than an uncomfortable observation: the kind of oversight institutions exercise over their models is not keeping pace with the number of those models, or with how autonomously they now operate.

The FSB treats this as a design problem rather than a warning. Instead of insisting that a human review every decision, the report sets out six distinct forms of human oversight and maps them to different degrees of autonomy. For anyone running governance, that mapping is the real substance of the paper, and it does not sit in the executive summary. It sits in sound practice 10.

At a glance

What: consultation report setting out twelve sound practices for the responsible adoption of AI in financial institutions

Who: Financial Stability Board (FSB), produced by the Workstream on Artificial Intelligence of the Standing Committee on Supervisory and Regulatory Cooperation (SRC)

When: published 10 June 2026, comment deadline 22 July 2026

Status: consultation closed; no extension of the deadline has been confirmed

Next: final report in October 2026 to G20 finance ministers, with the United States holding the 2026 presidency

Legal character: explicitly not an international standard and not a prescribed approach

Twelve practices in three blocks

The twelve sound practices are not a flat list of equally weighted requirements. They fall into three blocks, each addressing a different level of an institution. The report describes the first block this way: “Sound practices 1 to 4 emphasise the importance of organisation-wide AI governance, in informing the financial institution in its decision on whether and how to adopt an AI technology and at what scale.” This is the layer of strategic direction, accountability, how AI risk folds into the existing risk management framework, and the organisation's own adaptability.

The second block moves down to the individual use case: “Sound practices 5 to 10 focus on managing specific AI use cases at or throughout different stages of an AI lifecycle so that use case deployments are supported by proportionate guardrails.” It covers materiality and risk assessment, selection, data governance, explainability and transparency, performance management, and human oversight.

The third block holds two practices that have been largely lost in the public reception of the report: managing AI-related cyber and information and communication technology (ICT) risk, and managing the risk that arises when third parties use AI. Anyone who reads the document as a pure governance paper therefore misses precisely the two practices that connect most directly to existing European law such as the Digital Operational Resilience Act (DORA).

Six forms of oversight, not one

Sound practice 10 is titled human oversight, and it is the most analytically interesting part of the report. Rather than treating human oversight as a single state, the FSB distinguishes six variants: human-in-the-loop, AI-in-the-loop, human-on-the-loop, human-in-command, kill switch and contestability. The order is not a ranking by quality. It sorts the variants by the point at which a person actually intervenes.

Two of them deserve particular attention. The first is AI-in-the-loop, which the report defines as follows: “‘AI-in-the-loop’: integrates AI into human oversight to augment performance monitoring rather than merely using humans to oversee AI. It uses AI as a supportive layer for decision-making and task automation while keeping humans in control (e.g. humans monitor and respond to AI-enabled automated alerts). AI-in-the-loop may become warranted as financial institutions scale the number of AI use cases.” Once the number of use cases grows, this may be the only form that remains workable. That is the reason the report raises it.

The second is human-in-command, aimed squarely at autonomous systems: “‘Human-in-command’: high-level human oversight, including deciding the extent of autonomy, setting guardrails, and managing its overall impact. This form of human oversight is aimed at AI with high levels of autonomy, such as agentic AI.” Here the human no longer inspects individual outputs. The human decides the frame: how much autonomy the system gets, which guardrails apply, and what overall impact is acceptable.

The shift is not that the human disappears. The shift is that the human moves up a level, from checking individual outputs to deciding the frame within which outputs may be produced at all. On the grading of oversight forms in sound practice 10

A soundbite that is not in the report

Coverage of the paper has circulated the idea that the FSB is pointing banks towards AI that monitors AI, because human oversight has reached its limits. That formulation comes from a trade publication's headline, not from the report. The phrase “AI monitoring AI” does not appear anywhere in the document; the only remotely similar hit is a bibliography entry for an earlier FSB publication on monitoring AI adoption.

The distinction matters beyond semantics. AI-in-the-loop explicitly does not mean that an AI takes over oversight. It means that AI strengthens the monitoring capacity of the human, who stays in control. Carry the shortened version into an internal governance debate and you end up arguing against a position the FSB has not taken, with a real risk of delegating more than the report supports.

What the case studies actually show

The report includes case studies from practice, and they are more revealing than the principles. One large internationally active bank has deployed an agentic AI system to detect emerging fraud and scam patterns in real time. Its existing set-up already monitored more than 80 million signals a day. According to the report, the agent has helped develop or update three quarters of the bank's card fraud rules and has contributed to cutting fraud losses by more than 20 per cent in the first half of the 2026 financial year against the same period a year earlier.

That result comes with a condition worth noting: the bank “embeds human-in-the-loop oversight to review and approve all new rules by the bank's fraud analytics team before implementation”. The case with the strongest numbers therefore retains the strictest form of oversight: every new rule passes a human analyst before it goes live. The FSB documents both models side by side rather than claiming that one has replaced the other.

A second case study comes from an insurer that cut underwriting turnaround from two or three days to roughly 45 seconds. The same insurer reports six million lines of code in 2025 at an adoption rate of around 80 per cent among its developers. Figures like these are striking and hard to place at the same time, because the report carries them without stating the baseline they are measured against.

Legal character and the proportionality test

The legal character of the paper is unambiguous, and the report says so twice: “The sound practices are not intended to establish an international standard, to impose a prescriptive approach for responsible AI adoption by financial institutions, nor to influence business decisions in adopting a certain AI technology.” Elsewhere it adds that the practices are not exhaustive and may be refined as the technology develops.

Attached to that is a proportionality principle that matters a great deal for smaller institutions: “More robust practices may be appropriate for financial institutions that are large, complex, and highly connected within their ecosystem and where the AI is used or deployed in the financial institutions’ critical (or material) functions.” Smaller, less complex or less interconnected firms may, on the report's own terms, apply only the relevant practices or adapt them appropriately. Treating all twelve as a checklist misreads the document.

The paper also needs placing against the work of other bodies. The International Organization of Securities Commissions (IOSCO) published its Supervisory Toolkit for AI Use in Capital Markets as a final report on 25 May 2026. The FSB describes its own work as broadly compatible with existing and ongoing work by other standard-setting bodies and lists the IOSCO document as background literature. It nowhere claims a joint initiative between the two, and describing one overstates what the report says.

What this means in practice

Four starting points follow for governance, risk and internal audit functions. None of them requires waiting for the final report, since the structure of the twelve practices is unlikely to change fundamentally before October.

1. Name the oversight form for each use case

Now: For every AI use case in production, record which of the six forms in sound practice 10 is actually being practised. The question is not whether human oversight exists, but where it bites. Firms that document this can show a supervisor or an auditor that the form of oversight matches the degree of autonomy, instead of pointing at a four-eyes process that nobody can sustain any more.

2. Connect practices 11 and 12 to DORA

In planning: Cyber and ICT risk, and third-party risk, are the two practices with the most direct bearing on European law already in force. Firms that maintain a DORA register should check whether AI services are captured in it well enough to satisfy practice 12. That builds on an asset firms already maintain.

3. Argue proportionality rather than assume it

Now: The report expressly allows smaller firms to apply only the relevant practices. That relief holds only where the selection is reasoned and documented. An unexplained partial application is far harder to defend in an examination than a deliberately reasoned one.

4. Treat the October report as a checkpoint, not a starting gun

On the timeline: The consultation has closed and the final report goes to G20 finance ministers in October. Firms that finish mapping use cases to oversight forms before then can use the final report to reconcile their position instead of starting from it. That difference decides whether this lands in the line organisation or in a project.

Timeline: from consultation report to G20 final report
What applies, what has closed and what is still to come
25 May 2026
IOSCO Supervisory Toolkit published as a final report
Supervisory Toolkit for AI Use in Capital Markets; listed by the FSB report as background literature.
10 June 2026
FSB consultation report published
Twelve sound practices in three blocks: governance, use-case lifecycle, cyber and third party.
7 July 2026
FSB virtual outreach event
Michelle W. Bowman points to the final report going to the US G20 presidency later in the year.
22 July 2026
Comment deadline passed
Consultation closed; no extension has been confirmed, although at least one submission asked for one.
October 2026
Final report to G20 finance ministers
Delivered under the US G20 presidency; the structure of the twelve practices is likely to survive largely intact.
Christian Schablitzki

Christian Schablitzki

Strategy & Management Consultant · Agentic AI expert for financial institutions

More than 20 years in investment banking and derivatives trading, followed by over 10 years advising financial institutions. Currently Partner at Infosys Consulting in Germany. Certified in Google AI, Generative AI Leader (Google Cloud) and IBM RAG and Agentic AI.

LinkedIn profile →
newsletter
the agentic banker

Keep reading – every fortnight in your inbox.

Capital markets insights, regulatory updates and AI trends. Concise, well-founded, free of charge.

GDPR-compliant. Unsubscribe at any time.

← Back to overview