
The emerging AI governance landscape is not one body of law. It is developing through several overlapping forms of regulation, supervision, and industry practice, and these do not carry the same legal weight or operate in the same way.
For the purposes of Banking 3.0, it is useful to think of this landscape in three layers.
The first is existing regulation relevant to AI. These are laws and regulatory obligations that were not necessarily written for artificial intelligence but continue to govern the activity in which an agent participates. Privacy law still governs personal information. Fair-lending requirements still govern lending. Operational-resilience requirements still govern critical technology and third-party dependencies. The arrival of an agent does not remove the obligation attached to the underlying activity.
The second is AI-specific regulation. These are requirements created specifically for artificial intelligence and its use. The European Union has moved furthest in this direction through the EU AI Act, while other jurisdictions are developing different combinations of legislation, rules, and sector-specific requirements.
The third is AI standards, guidance, and supervisory expectations. These include frameworks for AI risk management, responsible AI, security, model governance, testing, monitoring, and assurance. They may not have the same legal force as legislation, but they increasingly influence how institutions design governance programs and demonstrate that AI is being used responsibly.
These layers overlap. A single banking agent may therefore be subject to the rules governing the financial activity it performs, the data it processes, the technology on which it depends, and the AI capability itself. The resulting landscape differs considerably across jurisdictions.
Table 1: Global AI and Agent Governance Landscape
Geography | Existing Regulation Relevant to AI | AI-Specific Regulation | AI Standards, Guidance & Supervisory Expectations |
European Union | GDPR; DORA; existing financial-services and consumer-protection requirements | EU AI Act | EU AI Act guidance, codes and technical standards; European supervisory guidance |
United States | ECOA/Regulation B; FCRA; GLBA; FTC Act; banking, cybersecurity, consumer-protection and third-party requirements | No single comprehensive federal AI statute equivalent to the EU AI Act | NIST AI RMF; NIST Generative AI Profile; federal, state and banking supervisory guidance |
United Kingdom | UK GDPR/Data Protection Act; Consumer Duty; existing financial-services requirements | No comprehensive EU-style AI Act | FCA/PRA supervisory expectations and UK AI governance guidance |
Singapore | PDPA; applicable MAS technology, operational-risk and financial-services requirements | No comprehensive statutory AI Act | IMDA AI governance frameworks; MAS FEAT/Veritas and related guidance |
Canada | Federal and provincial privacy requirements; applicable financial-sector regulation | AI-specific legislative framework continues to evolve | OSFI model-risk expectations and responsible-AI guidance |
Australia | Privacy Act; applicable APRA prudential, operational-risk and information-security requirements | AI-specific regulatory approach continues to develop | Responsible-AI guidance and financial-sector supervisory expectations |
China | PIPL and applicable data and cybersecurity requirements | Algorithmic Recommendation Provisions; Deep Synthesis Provisions; Interim Measures for Generative AI Services | National AI governance standards and regulatory guidance |
Hong Kong | PDPO; applicable HKMA technology and risk requirements | No comprehensive AI Act | HKMA AI and generative-AI supervisory guidance |
Japan | APPI and applicable sectoral requirements | Primarily an existing-law and sectoral approach | AI Guidelines for Business and financial-sector guidance |
United Arab Emirates | UAE PDPL; DIFC and ADGM data-protection regimes; applicable financial-sector requirements | AI-specific framework continues to develop | Government and financial-sector responsible-AI principles and guidance |
The table is illustrative rather than exhaustive. What matters for Banking 3.0 is not simply the number of regimes, but their overlap. The same agent may simultaneously inherit obligations from banking and privacy law, emerging AI-specific regulation, and supervisory or technical standards. AI regulation does not replace the regulatory architecture described in Chapter 8. It lands on top of it.
Some frameworks also travel more easily across borders than national regulation. International standards, cybersecurity frameworks, and industry guidance increasingly provide institutions with common ways to think about AI governance, risk, security, testing, monitoring, and evidence.
Table 2: Standards and Frameworks Relevant to AI and Agent Governance
Standard or Framework | Relevance to Banking 3.0 |
ISO/IEC 42001 | AI management systems, governance, organizational responsibilities, risk processes and continuous improvement |
ISO/IEC 23894 | AI risk-management principles and processes |
NIST AI Risk Management Framework (AI RMF) | Framework for managing AI risk through Govern, Map, Measure and Manage |
NIST Generative AI Profile (AI 600-1) | Generative-AI-specific risks and risk-management considerations |
OWASP guidance for LLM and agentic systems | Security risks, attack patterns and mitigations relevant to LLM applications and AI agents |
MITRE ATLAS | Knowledge base for adversarial threats and techniques affecting AI-enabled systems |
ISO/IEC 27001 | Information-security management supporting the systems, data and infrastructure on which agents depend |
NIST Cybersecurity Framework 2.0 | Enterprise cybersecurity governance and risk management |
SOC 2 | Independent assurance over relevant controls at service organizations supporting third-party technology and AI services |
These frameworks are not interchangeable, and they do not all have the same legal or supervisory status. Their importance to architecture lies in the common themes that run through them: governance, accountability, risk assessment, security, testing, monitoring, human oversight, and evidence. They provide increasingly common languages through which broad expectations can be translated into operating practices and controls.
The global picture therefore contains both continuity and change. Existing regulation continues to govern the activity around the agent. AI-specific regulation increasingly governs aspects of the technology and its use. Standards and supervisory frameworks help institutions determine how those requirements should be implemented.
Europe provides perhaps the clearest example of how these layers can converge.
Actionable tips from top designers & developer
Get that doubles sales for startups and performance SMBs.
More Blogs







