On 10 June 2026 the Financial Stability Board (FSB) published a consultation report setting out twelve sound practices for the responsible adoption of artificial intelligence in financial institutions. Comments closed on 22 July, and the final report is due to reach G20 finance ministers in October. Read closely, the document is less a catalogue of new obligations than an uncomfortable observation: the kind of oversight institutions exercise over their models is not keeping pace with the number of those models, or with how autonomously they now operate.
The FSB treats this as a design problem rather than a warning. Instead of insisting that a human review every decision, the report sets out six distinct forms of human oversight and maps them to different degrees of autonomy. For anyone running governance, that mapping is the real substance of the paper, and it does not sit in the executive summary. It sits in sound practice 10.
What: consultation report setting out twelve sound practices for the responsible adoption of AI in financial institutions
Who: Financial Stability Board (FSB), produced by the Workstream on Artificial Intelligence of the Standing Committee on Supervisory and Regulatory Cooperation (SRC)
When: published 10 June 2026, comment deadline 22 July 2026
Status: consultation closed; no extension of the deadline has been confirmed
Next: final report in October 2026 to G20 finance ministers, with the United States holding the 2026 presidency
Legal character: explicitly not an international standard and not a prescribed approach
Twelve practices in three blocks
The twelve sound practices are not a flat list of equally weighted requirements. They fall into three blocks, each addressing a different level of an institution. The report describes the first block this way: “Sound practices 1 to 4 emphasise the importance of organisation-wide AI governance, in informing the financial institution in its decision on whether and how to adopt an AI technology and at what scale.” This is the layer of strategic direction, accountability, how AI risk folds into the existing risk management framework, and the organisation's own adaptability.
The second block moves down to the individual use case: “Sound practices 5 to 10 focus on managing specific AI use cases at or throughout different stages of an AI lifecycle so that use case deployments are supported by proportionate guardrails.” It covers materiality and risk assessment, selection, data governance, explainability and transparency, performance management, and human oversight.
The third block holds two practices that have been largely lost in the public reception of the report: managing AI-related cyber and information and communication technology (ICT) risk, and managing the risk that arises when third parties use AI. Anyone who reads the document as a pure governance paper therefore misses precisely the two practices that connect most directly to existing European law such as the Digital Operational Resilience Act (DORA).
Six forms of oversight, not one
Sound practice 10 is titled human oversight, and it is the most analytically interesting part of the report. Rather than treating human oversight as a single state, the FSB distinguishes six variants: human-in-the-loop, AI-in-the-loop, human-on-the-loop, human-in-command, kill switch and contestability. The order is not a ranking by quality. It sorts the variants by the point at which a person actually intervenes.
Two of them deserve particular attention. The first is AI-in-the-loop, which the report defines as follows: “‘AI-in-the-loop’: integrates AI into human oversight to augment performance monitoring rather than merely using humans to oversee AI. It uses AI as a supportive layer for decision-making and task automation while keeping humans in control (e.g. humans monitor and respond to AI-enabled automated alerts). AI-in-the-loop may become warranted as financial institutions scale the number of AI use cases.” Once the number of use cases grows, this may be the only form that remains workable. That is the reason the report raises it.
The second is human-in-command, aimed squarely at autonomous systems: “‘Human-in-command’: high-level human oversight, including deciding the extent of autonomy, setting guardrails, and managing its overall impact. This form of human oversight is aimed at AI with high levels of autonomy, such as agentic AI.” Here the human no longer inspects individual outputs. The human decides the frame: how much autonomy the system gets, which guardrails apply, and what overall impact is acceptable.
A soundbite that is not in the report
Coverage of the paper has circulated the idea that the FSB is pointing banks towards AI that monitors AI, because human oversight has reached its limits. That formulation comes from a trade publication's headline, not from the report. The phrase “AI monitoring AI” does not appear anywhere in the document; the only remotely similar hit is a bibliography entry for an earlier FSB publication on monitoring AI adoption.
The distinction matters beyond semantics. AI-in-the-loop explicitly does not mean that an AI takes over oversight. It means that AI strengthens the monitoring capacity of the human, who stays in control. Carry the shortened version into an internal governance debate and you end up arguing against a position the FSB has not taken, with a real risk of delegating more than the report supports.
What the case studies actually show
The report includes case studies from practice, and they are more revealing than the principles. One large internationally active bank has deployed an agentic AI system to detect emerging fraud and scam patterns in real time. Its existing set-up already monitored more than 80 million signals a day. According to the report, the agent has helped develop or update three quarters of the bank's card fraud rules and has contributed to cutting fraud losses by more than 20 per cent in the first half of the 2026 financial year against the same period a year earlier.
That result comes with a condition worth noting: the bank “embeds human-in-the-loop oversight to review and approve all new rules by the bank's fraud analytics team before implementation”. The case with the strongest numbers therefore retains the strictest form of oversight: every new rule passes a human analyst before it goes live. The FSB documents both models side by side rather than claiming that one has replaced the other.
A second case study comes from an insurer that cut underwriting turnaround from two or three days to roughly 45 seconds. The same insurer reports six million lines of code in 2025 at an adoption rate of around 80 per cent among its developers. Figures like these are striking and hard to place at the same time, because the report carries them without stating the baseline they are measured against.
Legal character and the proportionality test
The legal character of the paper is unambiguous, and the report says so twice: “The sound practices are not intended to establish an international standard, to impose a prescriptive approach for responsible AI adoption by financial institutions, nor to influence business decisions in adopting a certain AI technology.” Elsewhere it adds that the practices are not exhaustive and may be refined as the technology develops.
Attached to that is a proportionality principle that matters a great deal for smaller institutions: “More robust practices may be appropriate for financial institutions that are large, complex, and highly connected within their ecosystem and where the AI is used or deployed in the financial institutions’ critical (or material) functions.” Smaller, less complex or less interconnected firms may, on the report's own terms, apply only the relevant practices or adapt them appropriately. Treating all twelve as a checklist misreads the document.
The paper also needs placing against the work of other bodies. The International Organization of Securities Commissions (IOSCO) published its Supervisory Toolkit for AI Use in Capital Markets as a final report on 25 May 2026. The FSB describes its own work as broadly compatible with existing and ongoing work by other standard-setting bodies and lists the IOSCO document as background literature. It nowhere claims a joint initiative between the two, and describing one overstates what the report says.
What this means in practice
Four starting points follow for governance, risk and internal audit functions. None of them requires waiting for the final report, since the structure of the twelve practices is unlikely to change fundamentally before October.
Now: For every AI use case in production, record which of the six forms in sound practice 10 is actually being practised. The question is not whether human oversight exists, but where it bites. Firms that document this can show a supervisor or an auditor that the form of oversight matches the degree of autonomy, instead of pointing at a four-eyes process that nobody can sustain any more.
In planning: Cyber and ICT risk, and third-party risk, are the two practices with the most direct bearing on European law already in force. Firms that maintain a DORA register should check whether AI services are captured in it well enough to satisfy practice 12. That builds on an asset firms already maintain.
Now: The report expressly allows smaller firms to apply only the relevant practices. That relief holds only where the selection is reasoned and documented. An unexplained partial application is far harder to defend in an examination than a deliberately reasoned one.
On the timeline: The consultation has closed and the final report goes to G20 finance ministers in October. Firms that finish mapping use cases to oversight forms before then can use the final report to reconcile their position instead of starting from it. That difference decides whether this lands in the line organisation or in a project.
Keep reading – every fortnight in your inbox.
Capital markets insights, regulatory updates and AI trends. Concise, well-founded, free of charge.
GDPR-compliant. Unsubscribe at any time.