2024-09-27
Added · Updated
The Hong Kong Monetary Authority issued this research paper to provide a comprehensive overview of Generative Artificial Intelligence adoption in the financial services sector, outlining strategic principles and practical guidance for responsible integration. The document highlights the rapid evolution of GenA.I., identifies key risks such as hallucination and data privacy, and emphasizes the need for robust governance frameworks to ensure ethical deployment. To support industry innovation, the HKMA details facilitation initiatives including a new GenA.I. Sandbox for risk-controlled testing and various capacity-building programs aimed at developing a future-ready workforce.
Generative Artificial Intelligence in the Financial Services Space September 2024 Supported by
Contents Foreword Introduction
Foreword In recent years, the rapid evolution of technology has redefined the landscape of financial services, presenting new opportunities to enhance efficiency, decision-making, and customer experience. Among these technological advancements, Generative Artificial Intelligence (GenA.I.) stands out for its potential to reshape the way financial institutions operate, innovate, and engage with their customers. However, with this transformative power comes a critical responsibility: ensuring that the adoption of these technologies is both safe and ethical, while continuing to maintain the highest standards of trust and integrity. The evolution of banking technology has been characterised by increasingly shorter innovation cycles. While the widespread adoption of automated teller machines (ATMs) took roughly 15-20 years since its introduction in the 1960s, subsequent banking innovations saw significantly accelerated adoption pace. Phone banking, introduced around the 1980s, took about 10 years to gain widespread acceptance, whereas internet banking, which emerged in the 1990s, achieved a more general level of adoption in approximately 5-8 years. With the unprecedented rapid uptake of GenA.I. applications such as ChatGPT by end-users, it is not surprising if there were an even more compressed innovation cycle for GenA.I.-powered financial services. In response to the rapidly growing interest in Artificial Intelligence (A.I.) adoption from industry participants, the Hong Kong Monetary Authority (HKMA) published a series of whitepapers, including Reshaping Banking with Artificial Intelligence1 (2019), Artificial Intelligence in Banking2 (2020), and Artificial Intelligence and Big Data in the Financial Industry3 (2021), highlighting the importance of A.I. for the financial services sector. These papers have contributed to the foundation of the HKMA’s Fintech 2025 strategy to drive Fintech development in Hong Kong’s financial services industry. Fostering innovation within a well-defined risk management framework is key to the sustainable development of the financial services industry. In 2019, the HKMA issued a circular4 outlining highlevel principles on risk management for the use of A.I. in banking. These principles, focusing on governance, application design and development, and ongoing monitoring and maintenance, remain highly relevant for GenA.I. applications today. While these foundational principles provide a solid and pertinent basis, the evolving nature of GenA.I. may require further practical guidance, which is being addressed through the development of the new Generative A.I. Sandbox rolled out jointly by the HKMA and the Cyberport. This initiative is designed to provide banks with a riskcontrolled environment in which they can experiment, test, and pilot novel use cases of GenA.I., while carefully considering the risk management and ethical implications of these advancements. Through these efforts, the HKMA aims to encourage innovation while promoting risk management, particularly in those areas highlighted in this paper in relation to data privacy, algorithmic bias, and cybersecurity. This aligns with the HKMA’s broader commitment to encourage responsible A.I. adoption, which will enable financial institutions to unlock the full potential of GenA.I. while safeguarding the stability and resilience of the financial system. 1 Hong Kong Monetary Authority. 2019. Reshaping Banking with Artificial Intelligence. (https://www.hkma.gov.hk/media/eng/doc/key-functions/finanical-infrastructure/Whitepaper_on_ AI.pdf). 2 Hong Kong Monetary Authority. 2019. Artificial Intelligence (AI) in Retail Banking. (https://www.hkma.gov.hk/media/eng/doc/key-functions/finanical-infrastructure/Artificial_ Intelligence_(AI)_in_Retail_Banking.pdf). 3 Hong Kong Monetary Authority. 2021. Report on “Artificial Intelligence and Big Data in the Financial Services Industry: A Regional Perspective and Strategies for Talent Development”. (https://www.hkma.gov.hk/eng/news-and-media/press-releases/2021/10/20211028-3/). 4 Hong Kong Monetary Authority. 2019. High-level Principles on Artificial Intelligence. (https://www.hkma.gov.hk/media/eng/doc/key-information/guidelines-andcircular/2019/20191101e1.pdf). Generative A.I. in the Financial Services Space 3
This paper seeks to provide a comprehensive overview of the role GenA.I. can play in the financial sector, as well as the potential use cases and challenges that institutions should consider when integrating these technologies into their operations. It also details diverse approaches to enabling the adoption of GenA.I., focusing on practical guidance, industry collaboration, and capacity building. As we look ahead, the HKMA remains committed to creating an environment where financial institutions can leverage the power of GenA.I. responsibly, while ensuring that Hong Kong continues to be a leader in Fintech innovation. The HKMA believes that by working together, we can unlock the full potential of GenA.I., while upholding the integrity, resilience, and stability of our financial system. Mr Arthur Yuen, Deputy Chief Executive of the HKMA Fostering innovation within a well-defined risk management framework is key to the sustainable development of the financial services industry. We would like to extend our heartfelt thanks to the Insurance Authority (IA), the Mandatory Provident Fund Schemes Authority (MPFA), financial institutions, industry stakeholders, and participants who contributed their insights to this paper. Collaboration is critical as we embark on this journey to shape the future of financial services through GenA.I. 4 Generative A.I. in the Financial Services Space
The financial services sector is entering a new era of transformation, driven by the rapid advancement and integration of emerging technologies. To ensure Hong Kong remains at the forefront of global Fintech innovation, the HKMA has identified five strategic focus areas: Wealthtech, Insurtech, Greentech, A.I., and Distributed Ledger Technology (DLT). These focus areas are pivotal to the HKMA’s Fintech 2025 strategy and its underlying “All banks go Fintech” initiative, aimed to future-proof the financial services industry and ensure Hong Kong remains a global leader in Fintech innovation. In its ongoing mission to promote responsible adoption of technology, the HKMA has recently launched the FiNETech series together with the other local financial regulators. This initiative fosters crosssectoral Fintech collaboration and provides a platform for financial institutions to engage with cutting-edge technologies. The latest edition, FiNETech2, of the series was held in August 2024, focusing on exploring A.I., including GenA.I., for its ability to revolutionise key aspects of banking and financial services. Introduction As financial institutions are entering the next phase of A.I., including the exploration of GenA.I. adoption, the HKMA recognises the importance of an interactive and iterative approach. In response, the GenA.I. Sandbox has been introduced to provide a risk-controlled environment where institutions can develop, test, and pilot innovative GenA.I.- based solutions in real-world banking scenarios. Through the Sandbox, participants will receive early supervisory feedback and guidance from the HKMA, helping them to innovate GenA.I. responsibly. The Sandbox trials will focus on enhancing three priority areas that are expected to benefit most from GenA.I. risk management, anti-fraud measures, and customer experience. With the first cohort of the GenA.I. Sandbox5 now open for applications, the HKMA looks forward to collaborating closely with banks and relevant stakeholders. Leveraging the Sandbox, the ecosystem can jointly explore novel use cases that drive responsible innovation, improve operational efficiency, and enhance the effectiveness of financial systems. The HKMA also reiterates its commitment to supporting such collaborative partnerships between financial institutions and Fintech firms, drawing on the expertise of both sectors to unlock the full potential of GenA.I. technologies. This research paper is another attempt to provide a building block to help banks and other financial institutions to sail through the A.I. journey by sharing insights and practical experiences. It offers an indicative roadmap for integrating GenA.I. solutions into financial operations. The HKMA recognises that the adoption of A.I. technologies demands not only innovation but also a robust governance framework. Accordingly, the HKMA advocates for a comprehensive approach that includes risk management, system integration, and continuous monitoring to ensure the safe and ethical deployment of these technologies. 5 Hong Kong Monetary Authority. 2024. Generative Artificial Intelligence Sandbox. (https://www.hkma.gov.hk/media/eng/doc/key-information/guidelines-and-circular/2024/20240920e1. pdf). FiNETech2 - Into the A.I.verse Generative A.I. in the Financial Services Space 5
Moreover, the HKMA is placing a strong emphasis on capacity building to ensure that the financial services workforce is equipped to navigate the complexities of GenA.I. adoption. Through training initiatives and talent development programmes, the HKMA aims to build a future-ready workforce with the skills necessary to embrace A.I. technologies responsibly and adaptively. As we move forward, the HKMA remains committed to fostering a Fintech ecosystem that balances innovation with supervisory oversight, ensuring that the benefits of GenA.I. can be realised without compromising the stability, security, or ethical standards of the financial system. By working closely with fellow regulators, industry stakeholders, financial institutions, and technology providers, Hong Kong is well-positioned to lead the way in the responsible integration of A.I. and GenA.I. with the global financial systems to achieve effective outcomes. Ms Carmen Chu, Executive Director (Banking Supervision) of the HKMA As financial institutions are entering the next phase of A.I., including the exploration of GenA.I. adoption, the HKMA recognises the importance of an interactive and iterative approach. 6 Generative A.I. in the Financial Services Space
Against this regulatory backdrop, financial institutions are encouraged to establish a robust GenA.I. governance structure that ensures compliance and facilitates the responsible deployment of new solutions. This governance framework should include the development of business cases and proofof-concepts that are complemented by comprehensive strategies for risk management, system integration, and continuous monitoring. A well-designed feedback loop across all phases of adoption is essential to drive ongoing improvements and maximise the value of GenA.I. initiatives while mitigating risks. Recognising the resource intensity required to implement A.I and GenA.I. solutions, Hong Kong has introduced a range of facilitation initiatives to support financial institutions. These include access to high-performance computing resources, financial subsidies, talent development programmes, and promotional events aimed at fostering innovation and building a skilled workforce capable of leveraging GenA.I. technologies. 8 Generative A.I. in the Financial Services Space
2.1. A.I. Supporting Pillars and GenA.I. Implications Before exploring the concept of GenA.I., it is important to recognise that GenA.I. is a subset of A.I., meaning its functionalities are based on the same foundational principles as A.I. technology. Therefore, having a solid understanding of how A.I. operates is key to fully grasping the concept of GenA.I. The functionality of A.I. is built upon and supported by four key pillars that govern the training and operation of its models (see Figure 2).
Training Data & Method Before A.I. solutions can be developed and commercialised, the solution provider begins by training the model using a vast dataset, commonly referred to as corpus data, which serves as the foundational ‘content’ for the model. Over time, the output is further refined through exposure to additional data from end-users, external sources, and ongoing evaluations, providing additional ‘context’ for the model’s output generation. This continuous refinement allows the model to generate outputs that more closely align with desired benchmarks. However, it is important to note that while the model benefits from this influx of new data, the original corpus and the foundational architecture of the model typically remain unchanged. The continuous improvement process of A.I. models is achieved through three primary training methods: (1) supervised learning, (2) unsupervised learning, and (3) reinforcement learning. Each method differs in how it interacts with the training data and adapts to new inputs (see Figure 3). Figure 3: A.I. Training Data & Methods Source: MIT Sloan School of Management, Quinlan & Associates analysis Supervised learning involves the provision of labelled training data to the model, where the correct output is already known, enabling the model to learn the mapping function between inputs and outputs. For instance, in the financial services domain, supervised learning algorithms are extensively used in the detection and prevention of fraudulent activities. The training data would consist of examples of both fraudulent and non-fraudulent wire transfers, each explicitly labelled with its respective category. Subsequently, the model is trained to extrapolate this knowledge to new, unlabelled wire-transfer data, effectively classifying it based on the learnt patterns. The breadth of potential applications for supervised learning is substantial, extending to tasks such as sentiment analysis, wherein textual data is systematically classified according to its emotional tone, thereby providing insights into consumer sentiment. Unsupervised learning operates in the absence of labelled data, allowing the model to autonomously explore and identify latent structures within the dataset without predefined outputs. This method is particularly advantageous for exploratory data analysis, clustering, and anomaly detection. For example, a model trained with unsupervised learning might cluster consumers based on their raw purchasing behaviour data, without prior knowledge or labelling of existing segments. Such clustering can be instrumental in other potential applications such as customer profiling, enabling financial institutions Model Architecture Output Output Benchmark (Structure & Parameters) Evaluation (Input & Output & Performance Score) Reinforcement Data (Input & Output) Generate Compare Train Augment Add Refine Refine SUPERVISED & (UN)SUPERVISED LEARNING REINFORCEMENT LEARNING Data Sources A.I. Model Output Corpus Data (From A.I. Providers) Internal Data (From End-users) External Data (e.g., World Wide Web) Generative A.I. in the Financial Services Space 11
to develop tailored credit scores for distinct consumer segments, and recommendation systems that suggest products based on inferred user behaviour patterns. Reinforcement learning diverges from the aforementioned methods by using feedback from its environment to iteratively refine the model’s behaviour. This approach is particularly effective in controlled settings, such as financial markets, where models are trained to perform specific tasks by learning from the rewards and penalties received by their actions. Potential use cases for reinforcement learning include autonomous trading systems, which navigate the complexities of the financial market by optimising the balance of risk and return. Collectively, these learning methodologies are fundamental to the continuous improvement of A.I. systems, enabling them to assimilate new data and experiences in increasingly sophisticated and nuanced ways. One of the key advancements in A.I. is the introduction of retrieval-augmented generation (RAG). While not directly applicable to model training, this approach enables A.I. models to access data beyond their original training corpus, drawing from both internal sources (e.g., user input) and external sources (e.g., the web). This allows models to generate more accurate, relevant, and up-to-date responses without altering their fundamental structure. RAG enhances a model's ability to meet user needs more effectively, making it adaptable and responsive to real-time information while preserving its core model. A.I. Model Architecture All deep learning models that underpin A.I. are structured around artificial neural networks comprising layers of interconnected nodes. This architecture enables the model to learn complex relationships between data points through numerous iterations, thereby becoming increasingly sophisticated over time. These models can be conceptualised as complex mathematical functions that execute computations on input data to generate an output. At their core, these models consist of nodes and parameters, which are critical in the information processing pipeline. Nodes represent individual computation units within the model, while parameters, specifically weights and biases, determine how input signals are transformed as they propagate through the network. Weights regulate the strength of the connections between nodes, influencing the extent to which one node impacts another. Biases, on the other hand, facilitate adjustments in the output independent of the input, providing the model with additional flexibility. The relationship between input and output is mediated through a feed-forward mechanism. In this process, input data traverses multiple layers of calculations, with each layer applying distinct weights to the inputs. This hierarchical approach allows the model to cultivate a deeper and more nuanced understanding of the data, with hidden layers capturing complex, non-linear patterns and interactions within the input. Some of the modern neural network architectures, however, deviate from the purely feed-forward structure, particularly those with memory or attention mechanisms (e.g., recurrent networks or transformers). These models introduce additional dynamics, such as self-attention, which enhance the model's ability to process and retain information. A critical aspect of training an A.I. model is the backpropagation algorithm. This technique initiates by calculating the error through a comparison of the model’s output to a predefined benchmark or expected result. Upon identifying the error, the model adjusts its parameters with the objective of minimising this discrepancy. The recalibration process is computationally intensive, often involving billions of parameters, each necessitating precise calculations to determine the optimal adjustments. This iterative refinement is indispensable for enhancing the model’s accuracy and overall performance, allowing it to learn more effectively from the data it processes (see Figure 4). 12 Generative A.I. in the Financial Services Space
Figure 4: A.I. Model Architecture Source: Google, Quinlan & Associates analysis Processing Hardware The final crucial element in the building of A.I. systems is computational power, which has experienced rapid and transformative growth over the past decade, Figure 5: Hardware Development A performance metric for A.I. hardware that measures the speed of processing operations (such as arithmetic computations) in neural networks, particularly when using 8-bit integer precision Source: Amazon, Google, Intel, NVIDIA, Quinlan & Associates analysis Ensure an A.I. system’s overall management and control Applied to A.I. training for parallel processing abilities Speed up matrix calculations for A.I. training by design Processing Hardware Comparison 0 500 1,000 1,500 2,000 2,500 3,000 3,500 4,000 4,500 2017 2018 2019 2020 2021 2022 2023 125 4,000 32x V100 Q8000 A100 H100 A.I. Specialised Accelerators Graphic Processing Units Single-Chip Inference Performance Int 8 TOPS for NVIDIA chips, 2017-2023 Specialise in processing tensor operations, which are fundamental to deep learning models Handle highly parallel workloads with many smaller, highly efficient processing cores Execute main instructions and perform general-purpose computations 2015 Tensor Processing Units by Google 1999 Geforce256 by NVIDIA 1971 Intel 4004 by Intel Sequential Processing Simultaneous Processing Central Processing Units Graphic Processing Units Tensor Processing Units Description Introduction • Main system operations • Application processing • Calculation in parallel • Computation-intensive tasks • Large-volume processing • Execution of neural networks Functions • Intel Core i9 (Intel) • Ryzen Threadripper 7980X (AMD) • RX 590 (AMD) • Tesla V1000 GPU (NVIDIA) • Tensor Processing Units (Google) • Tensor Core (NVIDIA) Examples Specialisation driven by significant advancements and specialisation in relevant hardware components (see Figure 5). O1 O2 W2 W1 W3 BACK-PROPAGATION Some input sources can contain biases that require optimisation ‘Back-propagation of Errors’ is conducted for updating model parameters for optimisation ‘Feed-forward of Information’ is conducted to move from input to output layer FEED-FORWARD I 1 I 2 B1 HIDDEN LAYERS H1 H2 W: assigned weight H: hidden layer I: input node O: output node B: biased node IN P U T L AY E R O U T P U T L AY E R Generative A.I. in the Financial Services Space 13
Central processing units (CPUs) have served as the primary computational engines in computers since their inception in 1971. CPUs are responsible for the overall management and coordination of computer systems, executing instructions sequentially and performing a wide range of complex calculations. However, the inherently sequential processing capabilities of traditional CPUs are often inadequate for the compute-intensive tasks required for training and deploying modern A.I. models. While CPUs excel at general-purpose tasks, the demands of A.I. necessitate extensive parallel processing, a domain in which CPUs are not inherently designed to operate efficiently. This limitation has catalysed the development of specialised hardware accelerators, such as graphics processing units (GPUs), which are better suited to the simultaneous processing requirements inherent in A.I. workloads. Introduced by NVIDIA in 1999, GPUs were initially designed to accelerate computer graphics and image processing by leveraging numerous smaller, highly efficient processing cores. It was subsequently discovered that the parallel processing capabilities of GPUs were ideally suited to the computational demands of training A.I. models, which involve processing vast volumes of data concurrently. This realisation significantly accelerated the development and sophistication of modern A.I. systems. Beyond CPUs and GPUs, A.I.-specific accelerators have been developed to optimise the complex computations involved in training A.I. models. A prominent example is Google’s Tensor Processing Units (TPUs), introduced in 2015. TPUs feature a custom hardware architecture specifically designed to accelerate low-level operations on multi-dimensional data, which are often the most computationally intensive and time-consuming parts of A.I. systems. These A.I.-specific accelerators achieve significantly higher performance and energy efficiency for A.I. workloads compared to general-purpose CPUs and GPUs. Since the first transformer model was introduced by Google7 researchers in 2017, the number of parameters, which is essential for capturing intricate patterns in data, has grown exponentially. For example, the average number of parameters has increased from 373 million in 2017 to 139 billion in 2024, representing a 373-fold growth (see Figure 6). Figure 6: Average Number of Parameters in Notable A.I. Systems Source: Epoch, Quinlan & Associates analysis 373 632 3,166 5,462 82,451 70,752 73,080 138,991 0 20,000 40,000 60,000 80,000 100,000 120,000 140,000 160,000 Year 2017 2018 2019 2020 2021 2022 2023 2024 373 632 3,166 5,462 82,451 70,752 73,080 138,991 Average No. of Parameters (# in million) 8.9x 1.7x 5.0x 1.7x 15.1x 0.9x 1.0x 1.7x Growth Multiple (vs. the previous year) Examples • Transformer • GPT-1 • Diffractive Deep Neural Network • GPT-2 • DLRM-2020 • GPT-3 • GBERT-Large • ERNIE 3.0 Titan • GLaM • InstructGPT • PaLM • PaLM-E • BloombergGPT • Nemotron-4 340B • Llama 3.1-405B 373x 7 Google. 2017. Attention Is All You Need. (https://proceedings.neurips.cc/paper/2017/file/3f5ee243547dee91fbd053c1c4a845aa-Paper.pdf). 14 Generative A.I. in the Financial Services Space
As the parameter count rises, so does the model's capacity, along with the computational power required to train and operate it. The introduction of specialised processing units, such as NVIDIA’s H100 series8 , which has demonstrated a 32-fold improvement in inference tasks (i.e., making predictions or decisions based on new data) compared to its predecessor from 2017, has provided the computational power necessary for increasingly sophisticated A.I. models. 2.2. Key Concepts of GenA.I. GenA.I., as the name suggests, is a transformative category of A.I. that excels at ‘generating’ novel outputs through the utilisation of generative models. These models are designed to discern patterns and structures from extensive training data. At its core, GenA.I. leverages advanced algorithms within these generative models to assimilate knowledge from vast datasets. Unlike traditional models, which may produce outputs closely mirroring their input data, generative models have the capability to create entirely new outputs. This enables them to produce more coherent and contextually relevant outputs in response to prompts, effectively mimicking human-like understanding and creativity. LLMs, a type of generative model, can produce contextually relevant language and code outputs, such as summarising long documents or suggesting suitable source code for software development, with detailed contextual reasoning communicated in a human-like manner. These capabilities are widely applicable for enhancing everyday productivity across various industries and departments. Beyond language and code generation through LLMs, there are diffusion models that extend to various creative domains, including images, audio, and video. Within seconds, these generative models can effortlessly create and produce compelling media, such as dynamic characters or avatars, audio snippets, and visually engaging video content. These capabilities are particularly useful for initiatives like press releases and marketing efforts by institutions (see Figure 7). Figure 7: Generative Artificial Intelligence Source: OpenAI, Quinlan & Associates analysis HTML Code HTML Output LANGUAGE CODE IMAGE AUDIO VIDEO GENERATIVE ARTIFICIAL INTELLIGENCE LARGE LANGUAGE MODELS DIFFUSION MODELS CONTENT GENERATION: The Hong Kong Monetary Authority (HKMA) is Hong Kong's central banking institution, responsible for maintaining monetary stability, managing the exchange fund, promoting financial system integrity, and developing financial infrastructure. Established in 1993, it ensures the stability of the Hong Kong dollar and oversees banking regulation and policy implementation. PROMPT: Describe the HKMA in 50 words CONTENT GENERATION: Certainly! Here's a simple HTML code snippet to display 'HKMA’. Feel free to customise the content and styles further based on your specific requirements! PROMPT: Generate HTML code for ‘HKMA' CONTENT GENERATION: Here is the image representing the character of the HKMA. If you need any adjustments, feel free to let me know! PROMPT: Generate a character for the HKMA CONTENT GENERATION: I'll create a classical piece with piano and strings, calm and professional, at 80 bpm for the HKMA. PROMPT: Make music for the HKMA CONTENT GENERATION: Great! Let's create a video for the Hong Kong Monetary Authority. PROMPT: Short video introduction of the HKMA 8 NVIDIA. 2024. Wide Horizons: NVIDIA Keynote Points Way to Further AI Advances. (https://blogs.nvidia.com/blog/hot-chips-dally-research/). Generative A.I. in the Financial Services Space 15
GenA.I. is a collective term that encompasses various types of generative models, such as LLMs and diffusion models, capable of creating outputs ranging from language to video. However, it is important to note that these generative models, which support different domains, are distinct technologies that often complement one another, with LLMs and diffusion models running together to support integrated multimodal GenA.I. systems. Understanding this distinction and relationship is crucial as the financial industry, along with other sectors, explores the diverse use cases of this technology. Large Language Models LLMs have significantly advanced natural language processing by capturing the semantic meaning of words and generating contextually relevant outputs. This advancement is facilitated by the seamless interaction of several key components within LLMs, including word embedding, contextual encoding, and output generation (see Figure 8). Figure 8: Large Language Model Mechanism LLM MECHANISM SIGNIFICANCE Similar to previous models / architectures WORD EMBEDDING 1 Capture a word’s semantic meaning with vectors Factors in the word’s sequence in the prompt to enable simultaneous vector processing for rapid response POSITION ENCODING 2 Encode the words’ positions in the vectors Identify the meaning of each word in the context to deeply comprehend the intent behind the prompt ATTENTION BLOCKS Encode weighted relationships among words 3 * Similar to previous models / architectures VECTOR CALCULATION 4 Calculate vectors representing output elements Similar to previous models / architectures OUTPUT CONVERSION 5 Convert vectors back to a suitable type of output capital & France Goods Worth City Letter Noun W Adjective hat is the capital of France? 1 2 3 4 5 6 7 Paris What? Find the city & LLM allows accurate and seamless communication between humans and computers *The model builds contextual representations of the meaning of a word (represented by tokens) by attending to every single word in the context and maps relationships between tokens within the same sequence (i.e., self-attention) and across tokens from other sequences (i.e., cross-attention) to integrate information from surrounding tokens. Source: Google, Quinlan & Associates analysis 16 Generative A.I. in the Financial Services Space
LLMs initiate the process by mapping words to highdimensional vectors through word embedding. This technique encodes relationships and similarities between words, forming the foundation for semantic understanding. Building on this, LLMs enhance coherence and contextual relevance by encoding the order and relative positions of words and dynamically assigning weights to them. This weighting system allows the model to emphasise or de-emphasise words based on their significance within a given context. At the core of LLM architecture are transformers, a fundamental innovation that has revolutionised language processing. Unlike traditional neural networks, which process data sequentially, transformers utilise a mechanism called “selfattention.” This mechanism enables the model to evaluate the importance of each word in a sentence relative to every other word simultaneously. By processing information in parallel, transformers can capture complex dependencies and relationships within the text, regardless of the distance between words. As such, transformer models have become the leading architecture for LLMs due to their versatility and effectiveness in handling various text-based tasks. Three primary types of transformer models have been developed to cater to different LLMs: (1) encoder-only models, (2) decoder-only models, and (3) encoder-decoder models (see Figure 9). Figure 9: Types of Transformer Models for GenA.I. Solutions Source: Stanford University, Quinlan & Associates analysis Transformer Understandability Text Classification Text Generation Text Summarisation Text Translation Notable Examples
further expanded by supporting multiple languages, known as multilingual models, and by adopting sparse models, which optimise computational costs for efficient large-scale tasks. The Role of LLMs in the overall GenA.I. Landscape The ability to understand and manage long-range dependencies enables transformers to produce coherent, contextually relevant outputs. As a result, transformers are central to the robust performance of modern LLMs, enabling them to excel in a diverse array of natural language processing tasks with remarkable accuracy and fluency. Once semantic understanding is established, LLMs perform complex computations to combine information from various words and contextual cues, ultimately transforming these into meaningful and contextually appropriate outputs, such as in producing summarisation, reports, and appropriate source codes. LLMs also act as the bridge that connects people to fully tap into the capabilities of other generative models, such as diffusion models for image, audio, and video generation. Understanding the intricate interplay between these models allows for a deeper appreciation of the unique contributions of LLMs in unlocking the full potential of GenA.I. Most solutions operate through a mechanism that can be broken down into three core steps: (1) user prompt, (2) input processing, and (3) output generation (see Figure 10). Figure 10: GenA.I. Mechanism Source: Subject matter expert interviews, Quinlan & Associates analysis Text Prompt (i.e., Text and code) Non-Text Prompt (i.e., Image, audio, and video) Multimodal Single Modal Provides the instruction in natural language Continuous Representations (e.g., Feature embeddings) Discrete Representations (e.g., Input tokens) Diffusion Models (e.g., DALL-E 2, Imagen, etc.) Large Language Models (e.g., GPT, Llama, etc.) Generated Output Generates human-digestible output based on the instruction Generates human-digestible output based on the instruction Feeds into LLMs Video Text-to-Video Audio Text-to-Audio Image Text-to-Image Computer Code Text-to-Code Language & Reasoning Text-to-Text STEP 1 USER PROMPT STEP 2 INPUT PROCESSING STEP 3 OUTPUT GENERATION Feeds into diffusion models Converts to numerical representation 18 Generative A.I. in the Financial Services Space
In natural language processing, GenA.I. has surpassed human baselines in English comprehension and is approaching parity with human performance in areas such as mathematical and verbal reasoning. With an increasing ability for moral reasoning, GenA.I. can engage in coherent conversations, perform complex summarisation tasks, and generate original content, demonstrating its growing versatility. Speech recognition, a critical component of speech-to-speech GenA.I. use cases, achieved an impressive accuracy of 99.9% by 20229 . Although comprehensive evaluation frameworks for generated audio content remain underdeveloped, GenA.I. has already demonstrated the capability of producing lifelike speech and original music, signalling its potential for transformative applications in audio generation. While GenA.I. has made significant strides in traditional input and output modalities, its scope continues to expand, pushing the boundaries of what was once considered impossible. For instance, in code generation, a leading GenA.I. model successfully solved 96.3% of HumanEval’s Python-focused programming problems on the first attempt10, showcasing its advanced understanding of programming languages and its potential to revolutionise software development. In the visual domain, various GenA.I. models have emerged that can generate photorealistic images from text prompts, thereby transforming creative workflows with far-reaching implications for product design, visualisation, and the creative arts. Moreover, by integrating image and audio generation, GenA.I. has developed the capability to animate static images, manipulate videos, and create entirely new clips. Performance metrics such as the Fréchet Video Distance score show an almost 95% reduction, reflecting a significant improvement in the similarity between generated videos and benchmark dataset samples, and indicating the increasing realism of these generated videos. The continuous advancements in GenA.I. capabilities are poised to reshape the way we interact with and create digital content, with the potential to transform business operations and customer interactions across a multitude of industries, including financial services. 2.4. Conclusion GenA.I. represents a significant evolution in the capabilities of A.I., extending its reach beyond traditional data processing to include the generation of original outputs. While GenA.I. excels at generating relevant and seemingly novel outputs based on context, the nature of these outputs may be controversial. By design, GenA.I. models predict the likelihood of the next occurrence based on the given context, which includes all previous prompts and generated outputs. As a result, they tend to produce outputs similar to what they were trained on based on the previous data, with intentional randomness introduced to generate more diverse outcomes. Driven by the advancements in LLMs that unlock the potential of other generative models, GenA.I. is redefining how industries engage with and leverage A.I. technologies. The continuous progress in increasingly sophisticated model architectures, training methodologies, and computational power, is laying the groundwork for widespread application across various sectors. In the context of financial services, GenA.I. holds the promise of delivering highly tailored customer experiences through personalised financial advice, automated report generation, and dynamic customer engagement strategies. Moreover, its ability to process and analyse vast datasets with unprecedented speed and accuracy presents significant potential for optimising risk management, enhancing fraud detection, and ensuring compliance with regulatory requirements. 9 Stanford Institute for Human-Centered Artificial Intelligence. 2023. 2023 AI Index Report. (https://aiindex.stanford.edu/wp-content/uploads/2023/04/HAI_AI-Index-Report_2023.pdf). 10 Stanford Institute for Human-Centered Artificial Intelligence. 2024. 2024 AI Index Report. (https://aiindex.stanford.edu/wp-content/uploads/2024/05/HAI_AI-Index-Report-2024.pdf). 20 Generative A.I. in the Financial Services Space
(2) external-facing adoption cases for customer empowerment (see Figure 12).
Figure 13: GenA.I. Adoption Status Information Overload Challenges associated with handling large volumes of information, stemming from both internal and external data sources Time-Consuming / Repetitive Tasks Challenges associated with delivering tasks that demand significant resource commitment and human input, yet contribute limited value Human Errors Challenges related to inconsistent or inaccurate outputs that often stem from human error and the inability to maintain a standard of quality Summarisation & Insights Derivation GenA.I. can process vast amounts of data and condense it into concise snippets, enabling users to quickly grasp and navigate relevant knowledge Workflow Automation GenA.I. can streamline resource-intensive workflows traditionally requiring human effort, such as idea, code, and report creation Quality Assurance GenA.I. ensures that output quality adheres to high and consistent standards based on extensive training and finetuning from a large set of data PLANNED EXTERNAL INTERNAL CURRENT ADOPTION MATURITY COMMON PAIN POINTS GenA.I. APPLICATIONS A D OPTION C ASE 2 47 6 4 Source: Interview findings, Quinlan & Associates analysis The institutions that participated in the interview shared a total of 59 GenA.I. use cases, including both current and planned adoption scenarios. Our findings indicate that most organisations are currently focusing on internal-facing use cases, with 47 of the reported cases aimed at supporting employee empowerment (see Figure 13). This emphasis is largely driven by the perception that the risks associated with internal applications are more manageable and controllable. While some institutions are exploring externalfacing applications, adoption has been limited due to uncertainties regarding both technological and regulatory maturity. Most financial institutions we interviewed expressed concerns about whether GenA.I. is sufficiently advanced to consistently deliver reliable and accurate results directly to customers. One technology provider observed that their financial institution clients expect improved technological maturity before adopting GenA.I. solutions and are placing greater emphasis on the explainability of outputs. We observed that financial institutions are adopting GenA.I. to address three key pain points:
Source: Quinlan & Associates analysis Figure 14: GenA.I. Workflow Applicability 3. Human Errors Inconsistencies or inaccuracies in outputs resulting from human error present a significant challenge to many organisations. GenA.I. tackles this issue by delivering consistent, high-quality outputs through continuous fine-tuning with vast datasets. This reduces the likelihood of errors and helps ensure a standard of quality across all GenA.I.-generated and revised outputs. By leveraging GenA.I. for both augmentation and automation, financial institutions can significantly enhance employee productivity while offering greater personalisation for customers, which is critical in maintaining an edge in today’s highly competitive financial services landscape. Evaluate key objectives, such as organisational goals, regulatory requirements, and customer demands, to pinpoint challenges or opportunities that necessitate actions. Brainstorm and develop potential strategies and approaches to effectively address the identified challenges or opportunities. Gather pertinent data (e.g., market reports, customer information, etc.) from both internal and external sources, to support informed decision-making. Apply analytical tools and techniques to process and interpret collected data, identifying significant patterns, trends, and anomalies. Convert data analysis into actionable insights with direct implications for decision-making. Create outputs based on findings that align with and effectively address the defined challenges or opportunities. Rigorously review outputs for content accuracy, tone consistency with organisational standards, and alignment to industry best practices. Implement decisions (e.g., trade execution, client request handling, etc.) based on the reviewed outputs. Description Human-in-the-Loop MODERATE Augmentation MODERATE Augmentation LOW Automation LOW Automation LOW Automation LOW Automation HIGH GenA.I. Not Applicable HIGH GenA.I. Not Applicable IDENTIFY NEEDS COLLECT DATA DERIVE INSIGHTS TAKE ACTION GENERATE OUTPUT REVIEW OUTPUT GENERATE IDEAS ANALYSE DATA The insurance industry embraces innovations that enhance business operations and customer convenience, bridge protection gaps and deepen financial inclusion. The IA is committed to fostering an environment that is conducive to the development and responsible use of A.I. technologies, including GenA.I., within the insurance market. Mr Clement Lau, Executive Director, Policy and Legislation, IA Generative A.I. in the Financial Services Space 23
Of the 59 cases we examined in our interviews, 8 were general use cases that are both industry- and department-agnostic, such as solutions for taking meeting minutes and code generation. While these agnostic use cases significantly enhance overall workforce productivity, they may not be the most relevant for financial institutions seeking to improve their specific financial operations. As such, this section examines the 51 use cases specifically relevant to the financial services industry, focusing on their adoption in service fulfilment and operations & risk management (see Figure 15). Figure 15: GenA.I. Adoption Areas for the Financial Services Space Source: Interview findings, Quinlan & Associates analysis • Service Fulfilment: Financial institutions seek to help customers fulfil their objectives across a service fulfilment value chain, i.e., (1) customer acquisition, which involves outreach optimisation and content creation, (2) customer monetisation, which involves research and analysis and purchase facilitation, and (3) customer maintenance, which covers customer servicing and ongoing disclosures. Financial institutions are using GenA.I. solutions to deliver a seamless, cohesive, and tailored experience at every stage. Based on the interview findings, they are primarily adopting GenA.I. for customer monetisation and maintenance, with the insurance sector more actively exploring customer acquisition use cases. This trend is further validated by interview findings from technology providers, revealing that the common GenA.I. adoption cases among the financial institutions they support are focused on customer monetisation and maintenance. • Operations & Risk Management: In this domain, GenA.I. is deployed to optimise backend internal processes. While it does not directly impact customer-facing functions, such solutions are crucial for driving efficiency and maintaining regulatory compliance. Additionally, GenA.I. solutions are increasingly being used to validate A.I. models themselves and empower institutions to assess vulnerabilities, thereby bolstering overall security and resilience. RISK PROFILING REGULATORY MONITORING TECHNOLOGY RISK MANAGEMENT • A.I. Model Validation • A.I. Model Compliance Check • Cybersecurity • Customer Due Diligence • Compliance Review Total Company Count: 4 Total Company Count: 2 Total Company Count: 3 OUTREACH OPTIMISATION CONTENT CREATION RESEARCH & ANALYSIS PURCHASE FACILITATION CUSTOMER SERVICING ONGOING DISCLOSURES • Enquiries Management • Customer Reporting • Complaints Analysis • Needs Identification • Pitch Customisation • External Research • Internal Research • Search Engine • Collateral Generation Optimisation CUSTOMER ACQUISITION CUSTOMER MONETISATION CUSTOMER MAINTENANCE SERVICE FULFILMENT 0 Companies 1 - 3 Companies 4 – 6 Companies 7+ Companies (n = 16) Total Company Count: 2 Tech. Providers Banks Securities Firms Insurers Total Company Count: 2 Total Company Count: 10 Total Company Count: 3 Total Company Count: 7 Total Company Count: 1
3 2 1 1 - 1
Figure 16: Customer Acquisition Adoption Cases 1 Figures may not add up to the total count presented in Figure 15 due to double counting in the sub-categories Source: Interview findings, Quinlan & Associates analysis 3.1. Current Adoption Cases for Service Fulfilment 3.1.1. Customer Acquisition A customer journey begins with customer acquisition, where financial institutions identify and shortlist target customers, and reach out to—and convert— leads. As part of this process, marketing and sales teams have to generate relevant marketing material, identify prospective customers, and shortlist targets. However, financial institutions remain cautious about data management and cybersecurity concerns, with most refraining from feeding in externally sourced and sensitive data to their GenA.I. models. As such, the GenA.I. use cases shared by 2 of the 16 institutions we interviewed focused on applications in search engine optimisation (SEO), and 2 focused on generic product marketing and brand building (see Figure 16). SOLUTION DESCRIPTION ADOPTION BENEFITS PAIN POINTS Errors Time-Consuming, Human Repetitive Tasks Information COMPANY COUNT Overload 1 Outreach Optimisation • Greater online marketing outreach and efficacy • Optimisation of SEO capabilities SEO 2 Content Creation • Faster content generation for marketing workflows • Creation of marketing content Collateral Generation 2 Search Engine Optimisation GenA.I. can be employed for various SEO tasks, including identifying trending topics and high-ranking keywords and phrases, by analysing search engine data and online content. Once these insights are gathered, they can be incorporated by GenA.I. to generate multiple content variations, allowing financial institutions to test and subsequently determine the most effective options. For example, a global bank and a global insurer we spoke to reported similar solutions that amplified their SEO endeavours by tailoring their digital marketing content to align with current search trends and interests of target customer segments. This has helped them to streamline processes that would otherwise demand significant time and effort, as well as maximise content reach to the right target audience. Collateral Generation From our interviews, we also see financial institutions adopting GenA.I. to create basic marketing and brand promotion materials. These solutions produce outreach content that the marketing team can adapt, saving time on creation from scratch. Two of the three insurance companies we interviewed have empowered their marketing teams with GenA.I. solutions to create customer-facing marketing content. This has helped them to streamline existing workflows and provided their marketing teams with a foothold in the ideation process. By leveraging GenA.I. for SEO and general marketing content generation, financial institutions can attract new customers more effectively by optimising campaigns in real-time, tailored to market trends, customer preferences, and search engine algorithms. Generative A.I. in the Financial Services Space 25
3.1.2. Customer Monetisation Once financial institutions acquire a customer base, their focus shifts to enhancing their services—such as offering more personalised solutions—to differentiate themselves, capture cross-selling opportunities, and drive revenue growth. Achieving these goals requires a deep understanding of customer behaviours, preferences, and needs, which can only be accomplished through comprehensive research and analysis. However, with vast amounts of consumer and market data at their disposal, yet lacking optimal methods to process such information into actionable insights that can support customer outreach efforts, institutions are increasingly turning to GenA.I. solutions (see Figure 17). Figure 17: Customer Monetisation Adoption Cases 1 Figures may not add up to the total count presented in Figure 15 due to double counting in the sub-categories Source: Interview findings, Quinlan & Associates analysis SOLUTION DESCRIPTION ADOPTION BENEFITS PAIN POINTS Errors Time-Consuming, Human Repetitive Tasks Information COMPANY COUNT Overload 1 Research & Analysis • Less time employees spent on research and report generation • Provision of relevant and current info 3 • Generation of customised insights External Research • Better frontline staff preparation for client meetings • Greater employee comprehension of internal documents • Creation of simplified product materials 8 • Provision of guideline summaries Internal Research Purchase Facilitation • More efficient work from frontline staff • Greater customisation for product offerings • Extraction of relevant client data 1 • Identification of client preferences Needs Identification • More tailored messages to engage clients with • More staff focus on creativity and outreach strategy • Personalisation of outreach material 2 • Generation of marketing collateral Pitch Customisation External Research Research and analysis are among the most labourintensive tasks for financial institutions, which may include the preparation of timely market updates, portfolio commentary, and research reports. Analysts and employees spend substantial time gathering, processing, and interpreting large volumes of quantitative and qualitative data. This effort is magnified by the sheer volume of customers and accounts managed, resulting in repetitive analysis and reporting that strains resources. To alleviate this strain, 3 out of the 16 financial institutions we interviewed are turning to GenA.I. solutions to synthesise information from various sources, such as financial news outlets and market data feeds, and automate the creation of collateral. According to a GenA.I. technology provider, institutions operating in the capital markets sector, in particular, stand to benefit from GenA.I.'s automation capabilities, which enable large-scale data analysis far beyond the capacity of manual efforts. With this capability, GenA.I. can even continuously monitor data sources and update product reports in realtime, ensuring that information remains both up-todate and relevant. Another global securities firm used GenA.I. to empower its customers to generate keywords to identify suitable stocks for their portfolios. 26 Generative A.I. in the Financial Services Space
Internal Research Financial institutions manage a vast array of financial products and operational procedures, making it challenging for employees to effectively retrieve, understand, and utilise internal documents. GenA.I. solutions tackle this challenge by generating user-friendly summaries and facilitating more efficient document navigation. Our interviews revealed that this application of GenA.I. is the most popular among financial institutions, with 8 out of 16 interviewees having some form of GenA.I. implemented to support internal research. For example, a major banking institution in Hong Kong leverages GenA.I. to distil internal product documents and guidelines into concise summaries, complete with references to the original sources. This approach makes it easier for employees to understand key information and better prepare them for sales engagements. Another major bank in Hong Kong with a similar solution is looking to expand its GenA.I. capabilities to consolidate all internal information, transforming it into a knowledge bot where employees can ask questions. This would allow employees to extract the specific information they require, bypassing the need to sift through lengthy documents. A global bank utilises a similar solution to help its RMs navigate internal research documents and investment policies to better serve their customers. Our interview findings also show that GenA.I. applications in research and analysis are highly versatile, supporting a wide range of functions within financial institutions. One global bank we interviewed is using GenA.I. for multilingual support, which is especially useful for operations across multiple jurisdictions, such as Mainland China and Hong Kong (SAR). The bank leverages GenA.I. to process internal policy documents in simplified Chinese and English to answer queries raised by new employees. By automating and enhancing research and analysis efforts, financial institutions allow employees to focus on higher-value tasks. A global technology provider highlights how this efficiency boost allows employees to be better prepared for critical tasks like loan approvals, supported by insights generated from GenA.I. solutions. Generative A.I. in the Financial Services Space 27
Needs Identification Once equipped with insights from research and analysis, materials are handed over to client-facing roles such as RMs. However, RMs often face the challenge of turning these materials into actionable insights tailored to each customer they manage. Given customers’ diverse risk profiles, including varying preferences, financial goals, and risk tolerances, a one-size-fits-all approach can lead to missed opportunities for hyper-personalised offerings and/or cross-selling opportunities. To facilitate a more nuanced understanding of client needs, one of the leading banking institutions in Hong Kong utilises GenA.I. to extract and analyse information such as annual reports and financial information about their corporate clients. This application produces tailored memos that RMs can use to engage clients more effectively, offering solutions that are better aligned with each client’s specific needs and preferences. The solution also extends to personal banking, allowing RMs to gain insights into their clients' demographics and preferences, enabling them to provide more tailored propositions that were previously challenging to achieve given the sheer scale of personal banking clientele. Pitch Customisation Financial institutions often rely on standardised marketing materials and pitches that demand significant time and effort to develop. Such materials are usually designed to be comprehensive yet general to appeal to a wide audience. However, this comes at the cost of creating content with a degree of specificity that will resonate with different clients. Moreover, as clients evolve and their needs change over time, these materials may need to be regularly revisited and updated, demanding additional time and effort. GenA.I. solutions can provide tailored suggestions for marketing teams and even create customised campaigns and pitches for distinct client segments, with 2 out of 16 financial institutions we interviewed utilising GenA.I. for this purpose. Among them, a global bank uses GenA.I. to translate its marketing materials into different languages and generate conversation prompts for RMs to engage with clients. Another major bank in Hong Kong utilised GenA.I. to generate marketing outreach material for RMs to provide personalised messages to clients. For instance, if a client holds a large deposit balance, the GenA.I. solution may suggest the RM to propose products such as time deposits based on the client’s financial profile. This proactive approach to client engagement can help uncover new revenue streams. By incorporating GenA.I., financial institutions can overcome the challenges of standardisation and lack of differentiation. This ensures that both client interactions and outreach materials are better tailored to meet each client’s unique needs. And this hyperpersonalised approach ultimately drives higher success rates, allowing financial institutions to capture previously untapped or under-tapped monetisation opportunities. 3.1.3. Customer Maintenance Beyond monetisation, financial institutions face two ongoing tasks with their existing customers: (1) maintaining client servicing, and (2) ensuring continuous disclosures. As part of this process, they need to address ongoing client needs, including managing enquiries, handling complaints, and providing client reports. However, financial institutions face a multitude of obstacles in conducting these operations (see Figure 18). 28 Generative A.I. in the Financial Services Space
Figure 18: Customer Maintenance Adoption Cases 1 Figures may not add up to the total count presented in Figure 15 due to double counting in the sub-categories Source: Interview findings, Quinlan & Associates analysis Enquiries Management Financial institutions need robust enquiry systems, given that the public often lacks an understanding of financial products and requires strong aftersales support. However, these systems face several limitations, namely: (1) addressing the sheer volume of enquiries can hinder response capabilities (e.g., delays), (2) ensuring consistency in service delivery can be challenging, and (3) monitoring overall service quality can be problematic. To manage these issues, 7 out of 16 financial institutions we interviewed have enhanced their client servicing using GenA.I., the second most popular use case of GenA.I. we identified. By leveraging GenA.I.’s workflow automation features, query systems can generate rapid personalised responses based on customer data. This not only improves the efficiency of customer engagement but also enhances customer retention through more targeted messaging. For instance, one global securities firm reported a 33% reduction in the time needed to draft replies after implementing this solution. Another leading technology provider noted that its insurance client reduced post-call work (e.g., inputting the customer’s enquiries) by 30%, allowing staff to focus on determining the best next steps without needing to manually input customer information. Additionally, several organisations we spoke to pointed to the ability of their GenA.I. solutions to deliver consistency in frontline messaging. One interviewee noted the difficulty of having their staff consistently produce standardised content in a professional tone. To alleviate this issue, it has adopted GenA.I. solutions to create initial draft replies that its employees can simply review and finalise before sending to address customer queries and complaints. This approach has significantly reduced response variance among employees, ensuring that all communications maintain a professional tone and consistent service quality. Similarly, a global bank we spoke to highlighted that its GenA.I. solution ensures customer complaint responses are consistently delivered in a professional tone and with high-quality service, aligning with its brand image. Another global insurer utilised a similar solution to address customer enquiries, which led to a more than three-fold increase in cases addressed per day. SOLUTION DESCRIPTION ADOPTION BENEFITS PAIN POINTS Human Errors Time-Consuming, Repetitive Tasks Information COMPANY COUNT Overload 1 Customer Servicing • More consistent and faster responses for clients • Greater control over service quality • Generation of personalised responses • Assistance and monitoring of interactions Enquiries Management 7 • Faster complaint analysis times • Greater efficiency in processing • Analysis of customer complaints • Automatic assessment of staff responses Complaint Analysis Customer Reporting 1 1 • Notification of client reporting dates • Generation of draft reports for staff • Less frontline staff workload on reporting • Faster report generation process Ongoing Disclosures Generative A.I. in the Financial Services Space 29
Some of the interviewees we spoke to have also capitalised on GenA.I. to monitor customer servicing, with a focus on ensuring compliance and assessing service quality. In these solutions, GenA.I. automatically identifies service gaps that may be overlooked by human error and highlights areas for improvement in customer maintenance. These solutions enhance operational efficiency by automatically recognising errors and fostering a culture of continuous quality improvement. One global insurer observed that implementing this GenA.I. solution enhanced its ability to identify issues and systematically pinpoint areas for improvement in its call interactions. Complaint Analysis To complement their client servicing capabilities, financial institutions need procedures to handle and escalate complaints. However, this is often easier said than done due to the substantial resources required to understand and investigate complaints. Customer Success staff or related departments must painstakingly—and carefully—listen to and comprehend thousands of complaints while simultaneously conducting their research. To enhance their complaint analysis and handling capabilities, one financial institution we interviewed has begun to leverage GenA.I. workflow automation features: their solution automates the parsing of complaints, enabling them to investigate and take remedial actions in a more structured manner. Similarly, a global securities firm we interviewed stated that its GenA.I. solution has delivered a 50% reduction in the time taken for complaint call analysis. Customer Reporting To effectively manage accounts, whether they are investment, banking, or insurance policy accounts, financial institutions routinely generate and share periodic reports or statements with end-users, detailing historical transactions and activities. While automation has streamlined the generation of these statements to some degree, the process of producing detailed reviews can still be time-consuming and resource-intensive. Often, these reports require the integration of relevant commentary and nuanced analysis that current automation technologies cannot fully address. One global bank that we interviewed has adopted GenA.I. solutions to create detailed, contextually relevant reports for customers by analysing transaction data, identifying key trends, and crafting tailored commentary. This includes streamlining the review process by dynamically adjusting content to reflect the most updated data available. More specifically, their GenA.I. solution helps to draft portfolio reviews that require only modifications by RMs, allowing RMs to focus more on strategic, valueadding tasks. The integration of GenA.I. into financial institutions' customer maintenance processes enhances their ability to meet customer needs in enquiries management, complaint analysis, and customer reporting. These solutions efficiently summarise vast amounts of information, automate repetitive workflows, and accurately identify inaccuracies and errors, enabling institutions to strengthen customer relationships at scale. 3.2. Current Adoption Cases for Operations & Risk Management Operations are the foundation of financial institutions, with risk management serving as a critical mechanism for safeguarding customer trust and ensuring regulatory compliance. In an increasingly complex and dynamic competitive environment, financial institutions are striving to enhance their operational efficiency and resilience by turning to GenA.I. technologies. These solutions offer the ability to automate labour-intensive processes, especially the analysis of large datasets, which is useful for detecting patterns and anomalies that support proactive risk management (see Figure 19). 30 Generative A.I. in the Financial Services Space
Figure 19: Operations & Risk Management Adoption Cases 1 Figures may not add up to the total count presented in Figure 15 due to double counting in the sub-categories Source: Interview findings, Quinlan & Associates analysis Customer Due Diligence Financial institutions must evaluate the financial health and risk profile of new customers to ensure compliance with KYC and AML regulations. However, the customer due diligence process involves analysing vast amounts of data within submitted documents, taking up a significant amount of time and effort. To streamline this essential operation, 4 of the 16 organisations interviewed have implemented GenA.I. solutions to enhance risk assessments, enabling employees to profile client risks more efficiently and with greater accuracy. This includes rapidly summarising customer information to quickly grasp their situation and locate relevant details for further investigation. By automating the document review process, three interviewees highlighted their ability to arrive at faster and more accurate due diligence decisions, with a global credit rating agency citing a 27% reduction in time needed for credit analysis tasks. One regional bank echoed this sentiment, stating that GenA.I.’s summarisation capabilities and automated checking processes allowed its employees to focus on more complex tasks. Two global banks also reported improved decision-making efficiency and enhanced customer understanding with the support of GenA.I. solutions. While other interviewed organisations have yet to adopt such solutions, there is substantial potential for securities firms to leverage GenA.I. solutions to identify unusual trading activities while examining new customer profiles during KYC checks. Insurance firms may also benefit from producing preliminary reports, based on a customer’s previous claims history, to detect potential fraudulent claims more rapidly. More broadly, leveraging GenA.I. solutions not only enables financial institutions to expedite the onboarding process for consumers but also facilitates the creation of more accurate customer profiles, allowing for the delivery of personalised products and services. SOLUTION DESCRIPTION ADOPTION BENEFITS PAIN POINTS Human Errors Time-Consuming, Repetitive Tasks Information Overload Risk Profiling • Quicker method to locate relevant information • Greater overall efficiency • Automation of due diligence checks 4 • Summarisation of client documentation Customer Due Diligence Regulatory Monitoring • Greater employee understanding of policy documents • Greater risk mitigation for external compliance • Summarisation of policy documentation • Identification of policy compliance gaps Compliance Review 2 Technology Risk Management • Faster A.I. model assessment • More efficient operations that are compliant • Summarisation of A.I. model assessment • Analysis of A.I. capabilities and suitability A.I. Model Validation 2 • More efficient and compliant operations with GenA.I. • Greater confidence in adhering to standards • Assurance of compliant model behaviour • Generation of compliant responses 2 2 A.I. Model Compliance Check Cybersecurity • Automation of cybersecurity alert processing • More efficient prioritisation of alerts by staff • Faster cybersecurity reporting process COMPANY COUNT1 Generative A.I. in the Financial Services Space 31
Compliance Review As the regulatory landscape evolves, with updates to regulations, circulars, and guidelines, financial institutions must maintain continuous compliance monitoring. This practice can be time-consuming, requiring compliance personnel to regularly sift through lengthy regulatory documents and extensive internal policy manuals. When addressing new regulatory requirements or conducting general reviews, the sheer volume of documentation creates challenges in pinpointing and reconciling information. To support the compliance review process, two financial institutions are using GenA.I. to enhance staff capabilities in responding to new policies. Their solutions provide clear, concise breakdowns of policy documents, allowing employees to swiftly understand key regulatory changes. For example, a global bank utilises GenA.I. to allow employees to search through documents and quickly locate the most relevant regulations, policies, and procedures that need to be followed. Another regional bank leverages similar technology to identify gaps between current operational policies and new or updated regulations, facilitating faster responses and reducing manual errors. As they noted, adopting GenA.I. in this capacity has made the bank more efficient at identifying compliance gaps and taking swift action. While adoption has thus far been observed primarily in banking institutions, securities and insurance firms can similarly benefit from similar applications for regulatory compliance. Overall, incorporating GenA.I. into compliance reviews enables institutions to swiftly adapt to regulatory changes and address potential compliance shortfalls. A.I. Model Validation With the growing exploration of A.I. and GenA.I., financial institutions must properly assess, validate, and verify the A.I. models' output to ensure they effectively fulfil their intended purposes. The model validation process is resource-intensive, requiring the analysis of large datasets and the evaluation of various models. Once validation is complete, institutions must compile comprehensive reports documenting their findings, a process can take several months for a single use case, as cited by a banking institution we interviewed. To support their model validation endeavours, a regional insurer has adopted GenA.I. to assess different A.I. models, helping users to efficiently choose the model best suited to their specific needs. Additionally, a global bank utilises GenA.I. to automate the drafting of validation reports, summarising key insights and findings. This has not only reduced the workload associated with report preparation but also improved employees’ ability to interpret insights more effectively due to the synthesised nature of the output. By leveraging GenA.I. solutions, financial institutions can significantly reduce the time and effort required for model validation, accelerating the deployment timelines of models in practical application. A.I. Model Compliance Check After validating the model functionalities, financial institutions must ensure that these models comply with relevant regulations. Off-the-shelf solutions, however, often present challenges as they may not fully align with financial industry standards, particularly in data privacy and intellectual property compliance. To address these challenges, two of the institutions interviewed have developed tailored GenA.I. solutions, enabling them to maintain compliance when using code generated by their GenA.I. systems. A global bank utilises its GenA.I. solution to reference its proprietary approved code repository, which contains millions of lines of tested code, allowing developers to generate and review code while ensuring compliance. Similarly, a securities firm has implemented a customised version of ChatGPT, incorporating additional features to enhance interaction with content, allowing its employees to use ChatGPT in a secure and compliant manner. 32 Generative A.I. in the Financial Services Space
These tailored GenA.I. solutions allow financial institutions to innovate while maintaining the compliance standards essential to their operations. By doing so, institutions can harness the productivity gains of GenA.I. without compromising their regulatory obligations. Cybersecurity In today's digital landscape, financial institutions are often inundated with an overwhelming volume of cybersecurity alerts, potentially numbering in the thousands each day. This influx of notifications presents a significant operational challenge, particularly for institutions with limited resources or insufficient cybersecurity expertise. The sheer volume of alerts increases the likelihood that critical vulnerabilities may be overlooked, thereby heightening the risk of security breaches and prolonging response times. To mitigate these challenges, two financial institutions interviewed have adopted GenA.I. technologies to optimise the analysis of cybersecurity notifications and reports. By automating the extraction of core insights from the alerts, these financial institutions have streamlined their cybersecurity operation, significantly reducing the time spent on manual investigations and enabling more efficient prioritisation of issues. For instance, a multinational securities firm utilises GenA.I. copilots to filter alerts based on priority so that employees can focus their attention on the most important cybersecurity issues, accelerating their internal cybersecurity processes. In addition, the GenA.I. solution can supplement internal analytics by leveraging external datasets to tackle cybersecurity issues. A notable application was observed in an insurance firm, which utilises GenA.I. solutions to generate reports for external attack service management and vulnerability assessments. Users can interact with reports dynamically, asking specific questions about vulnerabilities and quickly accessing essential information. Generative A.I. in the Financial Services Space 33
By harnessing targeted cybersecurity analysis powered by GenA.I., financial institutions can significantly enhance their decision-making processes and expedite their responses to potential threats, cultivating a proactive approach to risk management. This helps to strengthen the overall security posture and foster a culture of vigilance and resilience within financial institutions, better preparing them to navigate an increasingly complex digital landscape. 3.3. Planned Adoption Cases As GenA.I. is still in the early stages of exploration for many financial institutions, and its advancements often outpace deployment timelines, several use cases are still being examined by the organisations we interviewed. Two prominent themes of planned adoption cases emerged from the interviews, including (1) externalfacing applications, such as customer-facing chatbots and (2) non-text processing applications in more creative domains, like avatar generation. While such use cases are promising, all interview participants recognise that their implementation will depend on greater technological reliability and regulatory maturity. Consequently, they were viewed more as long-term aspirational goals. 3.3.1. External-Facing Applications The majority of current GenA.I. use cases are internalfacing, primarily focused on employee empowerment, as the presence of a human in the loop helps manage risks. While external-facing applications remain limited, financial institutions are showing significant interest in adopting GenA.I. for these purposes. As a result, many institutions are tentatively exploring these solutions while awaiting clearer regulations. Customer-facing Chatbots One notable solution is customer-facing chatbots, which enhance self-service capabilities by providing tailored, context-aware responses. Currently, many internal-facing use cases are a form of query-based interaction that retrieves and summarises data from knowledge bases. Given the success of these solutions, it is only natural that financial institutions are thinking about extending these functionalities to a broader user base, such as consumers, once regulations mature. These capabilities streamline client interactions, offering faster and more timely service. For example, customers can directly file claims, inquire about policy coverage, and check claims processing times online at any time, all without needing to contact a call centre. The ability to access high-quality service at any time, unrestricted by traditional working hours, significantly boosts client satisfaction and overall experience. Embedded Tools In addition to customer-facing chatbots, financial institutions also see the potential of GenA.I. applications serving as embedded tools to deepen client engagement. These solutions can offer advanced analysis, summarisation, and predictive functionalities directly to clients, facilitating better financial decisions. For instance, they can provide securities clients with valuable investment insights, assist banking clients in making informed product choices, and help insurance customers select the most suitable coverage options. By discreetly integrating client information within prompts, these GenA.I. solutions can automatically recommend more appropriate products and services. For example, a securities brokerage firm could use GenA.I. to recommend portfolio adjustments based on news from user-preferred sources that were shortlisted by the users and individual risk tolerances. Once the GenA.I. tool detects relevant market updates, the embedded tool could immediately notify the user of corresponding trading opportunities. While many of these applications are technically feasible, most financial institutions have yet to implement these solutions due to the lack of regulatory maturity. In particular, certain systemgenerated suggestions may be classified as regulated activities, such as investment advice. Additionally, the outputs of these systems are often challenging to control, making it crucial to establish a clear liability framework. The interviewed institutions recognise that these applications promise to exponentially enhance user experience and improve operational efficiency. We anticipate that these institutions are poised to adopt more external-facing solutions once regulations further mature. 34 Generative A.I. in the Financial Services Space
3.3.2. Non-text Processing Applications While current GenA.I. use cases primarily focus on text processing, the technology's capabilities extend to a wide range of formats, including images, audio, and video. By harnessing these capabilities, the potential applications of GenA.I. can broaden significantly, transforming essential processes such as client support and customer engagement. Non-text Analysis Traditional client interactions can be suboptimal, as RMs and customer support teams often miss critical information and cues conveyed by consumers. GenA.I.’s ability to process various input formats allows for the examination of non-verbal cues, including body language, facial expressions, and tone of voice. These subtle aspects of communication that are often overlooked in conventional interactions can serve as powerful tools to enhance the understanding of client sentiments and reactions. The capability of GenA.I. can manifest in digital avatars, which interpret a customer’s emotional state and identify signs of confusion, frustration, or satisfaction in real-time. This technology ensures that no information is overlooked, capturing even the smallest cues. Consequently, support teams are empowered to tailor their responses more effectively based on the context of each interaction. For example, the GenA.I.-powered digital avatar may detect anxiousness in the consumer and prompt an RM to provide additional information in a reassuring tone to address their concerns. The purpose of such solutions is not to replace human interactions with a fully digital, automated proposition, as many consumers still value a human touch. Rather, GenA.I. can empower the agents who are interacting with consumers. Ultimately, the integration of GenA.I. holds the potential to transform the landscape of consumer engagement, enabling financial institutions to move beyond transactional relationships to cultivate more meaningful connections with consumers. Non-text Generation As their internal operations are not limited to textbased interactions, financial institutions are also exploring the adoption of GenA.I. in the realm of nontext generation. By utilising different GenA.I. models, like diffusion models, financial institutions can harness the technology’s image, audio, and video generation abilities, which can be utilised to automate workflow and enhance customer engagement. With GenA.I.’s image and video creation capabilities, financial institutions can enhance their marketing campaigns with customised posters and other media. Automating the design process allows marketing departments to produce high-quality content efficiently, enabling rapid responses to trends and promotional opportunities, saving time and reducing associated costs. Financial institutions also seek to use similar capabilities to visualise complex financial information for client-facing educational materials. Clients can interact with GenA.I. solutions to create infographics from key financial data to better understand their financial situation, supporting more informed decision-making. Financial institutions also show interest in leveraging GenA.I.’s audio generation capabilities for automated client servicing. One bank aims to use GenA.I. for automated calls to check in with clients, remind them of debt repayments, and understand delays. This would free employees to focus on complex tasks while ensuring clients receive timely notifications, improving the efficiency of debt collection. Another potential application is using GenA.I. solutions to handle simple enquiries through hotlines, generating appropriate responses, to address issues around the clock. Together, these capabilities significantly enhance customer engagement. By providing relevant and easily digestible information and 24/7 support, financial institutions can foster stronger relationships with clients. This improved communication leads to higher levels of satisfaction and loyalty, ultimately driving business growth. Overall, financial institutions are considering several exciting applications, especially for external-facing applications and non-text data. The institutions we interviewed have expressed enthusiasm about adopting these solutions, provided they have adequate resources, robust technological knowledge, and regulatory certainty. Generative A.I. in the Financial Services Space 35
Figure 20: Key Adoption Hurdles Source: HKMA Fintech Adoption Study (2023), Quinlan & Associates analysis
which is essential for broader adoption. A banking institution expressed that it would be helpful for regulators to provide training on the adoption of GenA.I. in the banking sector. Similarly, a global securities firm noted the importance of educational programmes to nurture a skilled workforce. Aside from educational or training programmes, use case sharing from other banks was noted by a banking institution as a valuable way to gain insights into navigating the regulatory requirements for GenA.I. adoption. 3. E x t e n s i v e R e s o u r c e R e q u i r e m e n t s : Implementing GenA.I. solutions requires considerable resource commitment. Financial institutions must be prepared for substantial upfront costs to ensure that the solutions are customised to their specific needs and can deliver a sufficient return on investment over time. Additionally, the development process involves extensive research, data collection, processing, model training, testing, validation, and fine-tuning. As a result, financial institutions need to allocate ample time and resources to GenA.I. adoption projects before they can be effectively deployed in real-world scenarios. 3 Given these challenges, financial institutions are adopting a cautious approach to GenA.I., which may result in slower implementation timelines than initially anticipated. To facilitate the adoption process, the subsequent sections of this report aim to address these concerns: (1) Section 4 on regulatory principles provides further clarity on compliance and risk management, (2) Section 5 on adoption considerations offers practical guidance across the pre-deployment, deployment, and post-deployment phases of GenA.I., and (3) Section 6 on facilitation initiatives explores how various support schemes can alleviate business-specific deployment concerns. The MPFA recognises the potential of A.I. or GenA.I. to enhance the management of retirement benefits and improve service delivery in the MPF industry. The MPFA will continue to collaborate with other financial regulators and the MPF industry to foster the healthy development of A.I. technologies within the financial services sector. Mr Kenneth Chan, Executive Director (Members and Supervision), MPFA Generative A.I. in the Financial Services Space 37
Common Principles These foundational principles are frequently discussed, updated, and incorporated into the A.I. regulatory and/or supervisory frameworks of many jurisdictions. They form the bedrock of responsible A.I. usage and are essential for maintaining public trust and safeguarding end-users' rights. The common principles include:
Having outlined the key regulatory principles, we will now examine in greater detail how the four common principles are being addressed across six jurisdictions, including (1) the EU, (2) Hong Kong (SAR), (3) Mainland China, (4) Singapore, (5) the U.K., and (6) the US. Each jurisdiction has taken unique approaches to embedding these principles into their regulatory frameworks, reflecting their respective priorities, legal environments, and strategic goals for A.I. innovation and adoption. For the Governance & Accountability, Fairness, and Data Privacy & Protection principles, we will explore the regulatory updates at the jurisdiction level, as these principles are well-defined and applicable across industries adopting the technology. For the Transparency & Disclosure principle, we will investigate the updates at the industry level, as this principle is often tailored to meet the specific needs of financial market operations. In the case of the US, however, much of the regulatory developments surrounding A.I. take place at the state level. As such, overarching guidance across these principles is provided by the National Institute of Standards and Technology (NIST)11. NIST’s recent framework, titled ‘Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile’ 12, developed in alignment with President Biden’s 2023 ‘Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence’ 13, offers a comprehensive set of standards and guidelines. Although compliance with the framework is voluntary, it plays a crucial role in helping organisations, individuals, and society at large to manage the risks associated with A.I. deployment more effectively. 4.1. Governance & Accountability GenA.I. is a transformative tool that can streamline a broad range of tasks, from back-end employee support to front-end customer engagement. However, despite its powerful capabilities, it is not immune to errors or unintended consequences. The responsibility for any issues that arise from the use of GenA.I. ultimately rests not with the technology itself but with the humans (i.e., internal staff) who develop, implement, and oversee these systems. An important component of accountability is to understand the rationale behind GenA.I.-assisted decisions and how the solutions arrive at their outputs. To address these challenges, regulators across the globe are issuing guidelines that define the roles and responsibilities related to GenA.I. solution providers and setting expectations for interpreting GenA.I. solutions’ mechanisms and outputs. Such measures are essential for maintaining accountability and explainability, ensuring public trust, and safeguarding the rights of end-users (see Figure 22). 11 The NIST is a non-regulatory government agency of the US Department of Commerce to promote US innovation and industrial competitiveness. 12 NIST. 2024. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile. (https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf). 13 The White House. 2023. Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence. (https://www.whitehouse.gov/briefing-room/ presidential-actions/2023/10/30/executive-order-on-the-safe-secure-and-trustworthy-development-and-use-of-artificial-intelligence/). 40 Generative A.I. in the Financial Services Space
Figure 22: Governance & Accountability 1 Rules entered into force in August 2024, and provisions will apply 12-24 months after Source: Regulatory disclosures, Quinlan & Associates analysis OBJECTIVE Allocate the responsibility clearly to stakeholders and maintain a level of explainability for the A.I. solutions JURISDICTION RELEVANT EXCERPTS • Providers of high-risk AI systems shall put a quality management system in place that … shall include at least … an accountability framework setting out the responsibilities of the management and other staff with regard to all the aspects listed in this paragraph. • High-risk AI systems shall be designed and developed in such a way as to ensure that their operation is sufficiently transparent to enable deployers to interpret a system’s output and use it appropriately. European Union European Parliament and the Council of the European Union • Artificial Intelligence Act (20241) • The three lines of defence is a well-established governance concept in many organisations. • Organisations are responsible for the moral implications of their use and misuse of AI applications. There should also be a clearly identifiable accountable party, be it an individual or an organisational entity (e.g., the AI solution provider). • Two approaches can be taken to generate human-readable explanations… built-in interpretation… (and) post-hoc interpretation. Hong Kong (SAR) Digital Policy Office of the Hong Kong Government • Ethical Artificial Intelligence Framework (2024) • … improve… explainability, comprehensibility… to gradually achieve verifiability and auditability. • … humans are the ultimate responsible parties. Clarify the responsibilities of stakeholders … establish an artificial intelligence accountability mechanism… • Clarify the responsibilities and power boundaries of Artificial Intelligence-related management activities. Mainland China National New Generation Artificial Intelligence Governance Specialist Committee • Ethical Norms for New Generation Artificial Intelligence (2021) • Organisations using AI in decision-making should ensure that the decision-making process is explainable… (and) that their use or application of AI is undertaken in a manner that reflects the objectives of these principles as far as possible. • Personnel and/or departments having internal AI governance functions should be fully aware of their roles and responsibilities, be properly trained, and be provided with the resources and guidance needed for them to discharge their duties. Singapore Infocomm Media Development Authority and Personal Data Protection Commission • Model Artificial Intelligence Governance Framework Second Edition (2020) • Actively consider and make justified choices about how to design and deploy AI models that are appropriately explainable to individuals. Take steps to prove … that they are present in the design and deployment of the models themselves. Show that you provided explanations to individuals. • Foundational model developers and deployers are accountable for FM outputs… (and) take responsibility for what they control in the value chain and take positive action necessary to ensure consumers are adequately protected. United Kingdom Information Commissioner’s Office and The Alan Turing Institute • Explaining Decisions made with AI (2022) Competition & Markets Authority • CMA (Competition & Markets Authority) AI Strategic Update (2024) • Accordingly, GAI (GenA.I.) may call for different levels of oversight from AI Actors or different human-AI configurations in order to manage their risks effectively. • Governance tools and protocols that are applied to other types of AI systems can be applied to GAI systems. • Implement interpretability and explainability methods to evaluate GAI system decisions and verify alignment with intended purpose. United States National Institute of Standards and Technology • Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (2024) Generative A.I. in the Financial Services Space 41
• EU: Recognising the rapid development of A.I. solutions, the ‘Artificial Intelligence Act’ 14 was established as the world’s first comprehensive regulatory framework for this technology. To ensure appropriate interpretation and deployment, Article 17 of the Act requires an accountability framework that defines the responsibilities of management and staff concerning various aspects of high-risk A.I. systems, including technical specifications, data management, and post-market monitoring. Article 13 also mandates that instructions for use provide clear information about the system's technical capabilities and characteristics, as well as guidance for interpreting and appropriately using the A.I. system’s outputs. • Hong Kong (SAR): To guide the applications of A.I., the Digital Policy Office of the Hong Kong Government introduced ‘Ethical Artificial Intelligence Framework’ 15. The framework’s accountability principle states that organisations are responsible for the moral implications of using and misusing A.I. applications and proposed three lines of defence in A.I. governance that institutions can look to set up. It also suggested two approaches to achieve explainability: built-in interpretation and post-hoc interpretation. Built-in interpretation provides transparency by showing the exact steps to arrive at a decision, making it clear to endusers, while post-hoc interpretation may require the use of visual tools or examples to explain a model’s behaviour after decisions are made. The Framework encourages other organisations to adopt its principles as a reference for their own A.I. initiatives. • Mainland China: In 2021, China introduced ‘Ethical Norms for New Generation Artificial Intelligence’ 16, marking a significant step towards ethical A.I. solutions. It expects A.I. systems to be more comprehensible and explainable, gradually achieving verifiability and auditability. Moreover, it underscores that 14 European Parliament and the Council of the European Union. 2024. Artificial Intelligence Act. (https://ai-act-law.eu/). 15 Digital Policy Office of the Hong Kong Government. 2024. Ethical Artificial Intelligence Framework. (https://www.digitalpolicy.gov.hk/en/our_work/data_governance/policies_standards/ ethical_ai_framework/). 16 National New Generation Artificial Intelligence Governance Specialist Committee. 2021. Ethical Norms for New Generation Artificial Intelligence. (https://www.most.gov.cn/ kjbgz/202109/t20210926_177063.html/). 42 Generative A.I. in the Financial Services Space
humans are the ultimate responsible parties. Stakeholders’ responsibilities and powers should be clearly delineated to standardise the conditions and procedures for the execution of rights to use, manage, and conduct other activities. In particular, the responsibilities of A.I.-related management activities should be clarified. • Singapore: Addressing public concerns about A.I. solutions, Singapore’s Infocomm Media Development Authority (IMDA) and Personal Data Protection Commission developed the ‘Model Artificial Intelligence Governance Framework Second Edition’ 17 to take a structured A.I. governance approach, i n c o r p o r a t i n g f e e d b a c k f r o m v a r i o u s s t a k e h o l d e r s a n d e x p e r i e n c e s f r o m organisations in the second edition. One overarching principle’s key component is explainability, requiring organisations to ensure the process is explainable and align their A.I. applications with established principles if they use A.I. in the decision-making process. Personnel or departments responsible for internal A.I. governance should clearly understand their roles and responsibilities, and they must be equipped with the necessary resources and guidance to fulfil their duties effectively. • U.K.: As organisations employ A.I. to support or make decisions about individuals, the Information Commissioner’s Office and The Alan Turing Institute issued a co-badged guidance ‘Explaining Decisions made with AI’ 18 to give organisations practical advice on explaining the processes, services, and decisions delivered or assisted by A.I. to the individuals affected by them. The guidance listed six tasks for organisations to consider, ensuring these elements are incorporated into the A.I. solution’s design and deployment. To ensure that consumers, businesses, and the wider economy reap the benefits of developments in A.I. while harms are mitigated, the Competition & Markets Authority issued in 2024 the ‘CMA AI Strategic Update’ 19, mandating developers and deployers to take responsibility for their parts of the value chain. • US: The NIST’s ‘Artificial Intelligence Risk M a n a g e m e n t F r a m e w o r k : G e n e r a t i v e Artificial Intelligence Profile’ suggests that governance tools and protocols for other A.I. systems can also be utilised for GenA.I., including accessibility measures, A.I. actor qualifications, auditing, change management, incident response, risk controls, and monitoring. Furthermore, organisations should adopt explainability methods to assess GenA.I. solutions’ outputs and ensure alignment with their intended purposes. Governance and accountability are critical components of any regulatory framework for GenA.I. systems. By delineating responsibility and offering explainability considerations, jurisdictions are working to promote governance and accountability to mitigate risks associated with A.I. technologies. These measures not only enhance the reliability and safety of A.I. systems but also foster public trust and confidence in the responsible use of A.I., facilitating more informed decision-making in A.I. deployment. 4.2. Fairness While A.I. has the potential to address specific problems, it does not possess an inherent understanding of morality, a distinctly human attribute. Without careful oversight from developers and service providers, particularly in filtering training data and establishing clear guidelines for prompts and outputs, A.I. systems may produce biased or discriminatory content. Such outcomes can negatively impact users and potentially undermine public trust in the technology. 17 Infocomm Media Development Authority and Personal Data Protection Commission. 2020. Model Artificial Intelligence Governance Framework Second Edition. (https://www.pdpc. gov.sg/-/media/files/pdpc/pdf-files/resource-for-organisation/ai/sgmodelaigovframework2.pdf). 18 Information Commissioner’s Office and The Alan Turing Institute. 2022. Explaining Decisions Made with AI. (https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/ artificial-intelligence/explaining-decisions-made-with-artificial-intelligence/). 19 Competition & Markets Authority. 2024. CMA AI Strategic Update. (https://www.gov.uk/government/publications/cma-ai-strategic-update/cma-ai-strategic-update). Generative A.I. in the Financial Services Space 43
Figure 23: Fairness Source: Regulatory disclosures, Quinlan & Associates analysis To address these concerns, guidelines and frameworks have been issued to ensure the fairness of A.I.-generated outputs. These documents emphasise the need for solution providers to treat all users equally and inclusively and avoid discrimination or bias (see Figure 23). OBJECTIVE Ensure equal and inclusive treatment of all users, prevent bias, and avoid discrimination against any certain group JURISDICTION RELEVANT EXCERPTS • Identifiable and discriminatory bias should be removed in the collection phase where possible. The way in which AI systems are developed … may also suffer from unfair bias. This could be counteracted by putting in place oversight processes to analyse and address the system’s purpose, constraints, requirements and decisions in a clear and transparent manner. • Particularly in business-to-consumer domains, systems should be user-centric and designed in a way that allows all people to use AI products or services… European Union High-Level Expert Group on Artificial Intelligence • Ethics guidelines for trustworthy AI (2019) • The recommendation/result from the AI applications should treat individuals within similar groups in a fair manner, without favouritism or discrimination and without causing or resulting in harm. • Organisations can mitigate inherent bias using bias detection methods to evaluate whether the model discriminates against various groups or individuals, given a testdataset. Hong Kong (SAR) Digital Policy Office of the Hong Kong Government • Ethical Artificial Intelligence Framework (2024) • Discriminatory contents are a major security risk for data and generated contents, including those by ethnicity, belief, country, region, gender, age, profession, health condition, and other aspects. • In terms of corpus content filtering: keywords, classification models, manual sampling and other methods should be adopted to fully filter out illegal and harmful information in all corpora. Mainland China National Technical Committee 260 on Cybersecurity • Basic Security Requirements for Generative Artificial Intelligence Service (2024) • While identifying and addressing inherent bias in datasets may not be easy, organisations can mitigate the risk of inherent bias by having a heterogeneous dataset (i.e., collecting data from a variety of reliable sources). • Where applicable, the model could also be checked for systematic bias by testing it on different demographic groups to observe whether any groups are being systematically advantaged or disadvantaged. Singapore Infocomm Media Development Authority and Personal Data Protection Commission • Model Artificial Intelligence Governance Framework Second Edition (2020) • AI systems should not undermine the legal rights of individuals or organisations, discriminate unfairly against individuals or create unfair market outcomes. Actors involved in all stages of the AI life cycle should consider definitions of fairness that are appropriate to a system’s use, outcomes and the application of relevant law. United Kingdom Office for Artificial Intelligence and Department for Science, Innovation & Technology • A Pro-innovation Approach to AI Regulation (2023) • Conduct fairness assessments to measure systemic bias. Measure GAI (GenA.I.) system performance across demographic groups and subgroups, addressing both quality of service and any allocation of services and resources. • Quantify harms using: field testing with sub-group populations to determine likelihood of exposure to generated content exhibiting harmful bias, AI redteaming with counterfactual and low-context (e.g., “leader,” “bad guys”) prompts. United States National Institute of Standards and Technology • Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (2024) 44 Generative A.I. in the Financial Services Space
• EU: The High-Level Expert Group on Artificial Intelligence20 presented the 'Ethics guidelines for trustworthy AI' 21, which outlines seven key requirements that A.I. systems must meet to be considered trustworthy. One of these requirements emphasises the need to eliminate identifiable and discriminatory biases as much as possible during the data collection phase. Additionally, the development of A.I. systems, including the programming of algorithms, can introduce unfair biases, which necessitates the implementation of robust governance and oversight practices. Specifically, in businessto-consumer contexts, A.I. systems should be user-centric and designed to be accessible to all individuals, regardless of age, gender, abilities, or other characteristics. • Hong Kong (SAR): The ‘Ethical Artificial Intelligence Framework’, issued by the Digital Policy Office of the Hong Kong Government, provides guiding principles, practices, and an assessment template for the government and other organisations. The framework states that A.I. recommendations and results should treat individuals within similar groups fairly, without favouritism or discrimination, and without causing harm. Practically, it advises organisations to use bias detection methods to evaluate whether A.I. models discriminate against specific groups or individuals using a test dataset. • Mainland China: The National Technical C o m m i t t e e 2 6 0 o n C y b e r s e c u r i t y h a s outlined the ‘Basic Security Requirements for Generative Artificial Intelligence Service’ 22, which provides a wide range of examples of potential discrimination and misuse. These examples, including content that discriminates based on ethnicity, beliefs, or gender, help service providers clearly understand the scope of discriminatory content. To prevent such undesirable outcomes, proactive measures should be implemented from the outset. This includes using keywords, classification models, and manual sampling to thoroughly filter illegal and undesirable information throughout the entire training dataset. 20 The European Commission appointed a group of experts to form the High-level Expert Group on Artificial Intelligence to provide advice on its A.I. strategy. The concept of trustworthiness and the 7 key requirements, introduced by the ‘Ethics guidelines for trustworthy AI’, are guiding the upcoming legislative steps in A.I. for the European Commission. 21 High-Level Expert Group on Artificial Intelligence. 2019. Ethics guidelines for trustworthy AI. (https://digital-strategy.ec.europa.eu/en/library/ethics-guidelines-trustworthy-ai). 22 National Technical Committee 260 on Cybersecurity. 2024. Basic Security Requirements for Generative Artificial Intelligence Service. (Chinese - https://www.tc260.org.cn/ upload/2024-03-01/1709282398070082466.pdf). Generative A.I. in the Financial Services Space 45
• Singapore: Singapore’s ‘Model Artificial Intelligence Governance Framework Second Edition’ provides comprehensive and actionable guidance for private sector organisations to navigate the ethical and governance challenges associated with deploying A.I. solutions. One of the critical challenges addressed by the framework is the identification and mitigation of inherent bias in datasets. Although detecting such biases can be complex, organisations can reduce this risk by ensuring their datasets are diverse and incorporating data from a broad range of reliable sources. In addition, whenever relevant, A.I. models should be systematically evaluated for potential bias by testing their performance across different demographic groups. This allows organisations to identify whether certain groups are being consistently advantaged or disadvantaged, enabling them to take corrective measures to improve fairness and inclusivity. • U.K.: The command paper ‘A Pro-innovation Approach to AI Regulation’ 23, issued by the Office for Artificial Intelligence and Department for Science, Innovation and Technology, emphasises that A.I. systems should not infringe on the legal rights of individuals or organisations, engage in unfair discrimination, or create unjust market outcomes. It advises all stakeholders involved in the A.I. lifecycle to consider definitions of fairness that align with the system's intended use, outcomes, and applicable laws. • US: The ‘Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile’ issued by the NIST recommends conducting fairness assessments to identify systemic bias in A.I. systems. It advises measuring the performance of GenA.I. systems across various demographic groups and subgroups, considering both the quality of service and the distribution of services and resources. The framework also suggests quantifying potential harms through field testing with subgroup populations to assess exposure to biased content and employing A.I. red-teaming techniques using counterfactual and low-context prompts (such as “leader” or “bad guys”). Fairness is a critical principle in the development and deployment of GenA.I., ensuring that these technologies do not perpetuate bias or discrimination and are used responsibly. By issuing clear guidelines on the ethical use of A.I., regulators across different jurisdictions are working to mitigate risks associated with bias and discrimination. These measures are essential not only for protecting users but also for maintaining public trust in A.I. technologies. 4.3. Data Privacy & Protection The increasing sophistication in GenA.I. systems has escalated the demand for vast volumes of highquality data to train these algorithms. This surge in data usage raised critical concerns related to privacy, security, and the responsible stewardship of sensitive information. Striking the right balance between the benefits of data-driven innovation and the imperative to protect data security, individual privacy, and copyright remains a pressing challenge. R e l e v a n t a u t h o r i t i e s h a v e m a n d a t e d t h e establishment of protections for the legitimate collection and handling of data in A.I. and emphasised the importance of adopting cybersecurity measures and adhering to current regulations. Ensuring data privacy and protection builds trust with users, safeguards personal information from unauthorised access, and enhances the ethical use of A.I., contributing to responsible innovation (see Figure 24). 23 Office for Artificial Intelligence and Department for Science, Innovation & Technology. 2023. A Pro-innovation Approach to AI Regulation. (https://www.gov.uk/government/publications/ ai-regulation-a-pro-innovation-approach/white-paper#correction-slip). 46 Generative A.I. in the Financial Services Space
Figure 24: Data Privacy & Protection 1 The six ministries are: National Development and Reform Commission, Ministry of Education, Ministry of Science and Technology, Ministry of Industry and Information Technology, Ministry of Public Security, and National Radio and Television Administration. Source: Regulatory disclosures, Quinlan & Associates analysis OBJECTIVE Implement safety and cybersecurity measures for lawful data collection to ensure data privacy and security JURISDICTION RELEVANT EXCERPTS • The main recommendation is to treat the cybersecurity of AI systems as an additional effort to existing practices, … with AI-specific practices. • … defining precise collection criteria and ensuring that certain data categories are not collected or that certain sources are excluded from data collection … delete or anonymise personal data … before the training stage… Data subjects should … be clearly and demonstrably informed that such “Content” may be used for training purposes. European Union European Union Agency for Cybersecurity • Multilayer Framework for Good Cybersecurity Practices for AI (2023) European Data Protection Board ChatGPT Taskforce • Report of the Work Undertaken by the ChatGPT Taskforce (2024) • Personal data involved in the development and use of AI should be processed and protected in accordance with the PDPO (Personal Data (Privacy) Ordinance)… and cover the entire life cycle of the handling of personal data… • AI systems should be monitored and reviewed continuously because the risk factors related to their use may change over time… High-risk AI necessitate more frequent and stringent monitoring and review… Organisations should consider incorporating the following review mechanisms… Hong Kong (SAR) Office of the Privacy Commissioner for Personal Data • Guidance on the Ethical Development and Use of Artificial Intelligence (2021) • Artificial Intelligence: Model Personal Data Protection Framework (2024) • The consent of the individual shall be obtained if personal information is involved. The provider shall fulfill its obligation to protect the user's input information and usage records lawfully, …, shall not illegally retain the input information and usage records that can identify the user's identity, and shall not illegally provide the user's input information and usage records to others. • Regular security audits should be conducted on the development frameworks and codes used … Potential security holes should be identified and repaired. Mainland China Cyberspace Administration of China & 6 other Ministries1 • Interim Measures for the Administration of Generative Artificial Intelligence Services (2023) National Technical Committee 260 on Cybersecurity • Basic Security Requirements for Generative Artificial Intelligence Service (2024) • … appropriate technical, process and / or legal controls for data protection should be included. Where possible, organisations are encouraged to pseudonymise or de-identify the personal data used as a basic control. • As required under their Protection Obligation, Service Providers should guard against unauthorised modification of the personal data they are processing. • Security-by-design is a fundamental security concept… New tools have to be developed … to help enhance the ability to identify and extract malicious codes… Singapore Personal Data Protection Commission • Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems (2024) Infocomm Media Development Authority • Model AI Governance Framework for Generative AI: Fostering a Trusted Ecosystem (2024) • Organisations developing or using generative AI should be considering their data protection obligations from the outset, taking a data protection by design and by default approach… Data protection law still applies when the personal information that you’re processing comes from publicly accessible sources. • Security must be a core requirement, not just in the development phase, but throughout the life cycle of the system. United Kingdom Information Commissioner’s Office • Generative AI: Eight Questions that Developers and Users Need to Ask (2023) National Cyber Security Centre • Guidelines for Secure AI System Development (2023) • Conduct periodic monitoring of AI-generated content for privacy risks; address any possible instances of PII or sensitive data exposure… Leverage approaches to detect the presence of PII or sensitive data in generated output text, image, video, or audio. • Establish policies to evaluate risk-relevant capabilities of GAI and robustness of safety measures, both prior to deployment and on an ongoing basis, through internal and external evaluations. United States National Institute of Standards and Technology • Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (2024) Generative A.I. in the Financial Services Space 47
• EU: T h e E u r o p e a n U n i o n A g e n c y f o r Cybersecurity has developed a ‘Multilayer Framework for Good Cybersecurity Practices for AI’ 24, which recommends stakeholders enhance existing protocols by integrating dynamic risk assessments throughout the A.I. lifecycle. In response to the rise of generative A.I., the European Data Protection Board formed a ChatGPT Taskforce, which issued ‘Report of the Work Undertaken by the ChatGPT Taskforce’ 25 in May 2024. The report highlighted that data controllers for personal data related to large language models must comply with regulations, establish data collection criteria, anonymise data from web scraping, and inform users about the potential use of their input for training. • Hong Kong (SAR): In response to the rapid development and adoption of A.I. solutions, the Office of the Privacy Commissioner for Personal Data issued the ‘Guidance on the Ethical Development and Use of Artificial Intelligence’ 26 , which aims to provide organisations with recommendations to embrace key data stewardship and ethical values. It stated privacy is a fundamental human right and requires compliant and effective data governance to protect individuals’ privacy. The Guidance also reminded A.I. suppliers of the need to fulfil user requests regarding data access and correction. Building upon the 2021 Guidance, the 2024 ‘Artificial Intelligence: Model Personal Data Protection Framework’ 27 was published to provide practical recommendations with a risk-based approach to ensure compliance. It also highlights the need to pay special attention to high-risk A.I. systems and suggests review mechanisms such as documentation, monitoring, re-assessments, and periodic reviews. • Mainland China: To ensure the healthy d e v e l o p m e n t a n d r e g u l a t e d u s e o f GenA.I., 7 Chinese ministries issued the ‘Interim Measures for the Administration of Generative Artificial Intelligence Services’ 28 in accordance with relevant laws, protecting national security, public interests, and the rights of individuals and organisations. Consent from individuals is required for handling personal information. The provider must legally protect user input and usage records, refrain from unlawfully retaining identifiable information, and must not share this information with unauthorised parties. In addition, the ‘Basic Security Requirements for Generative Artificial Intelligence Service’ listed the need for regular security audits, focusing on open-source frameworks’ vulnerabilities and identifying potential security holes. • Singapore: Following a public consultation, Singapore’s Personal Data Protection Commission issued the ‘Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems’ 29, which suggested that organisations should include appropriate technical, process and/or legal controls for data protection when designing, training, testing, or monitoring A.I. systems using personal data. Organisations are encouraged to pseudonymise or de-identify personal data as a fundamental measure. Service providers must also protect against unauthorised modifications of the personal data they process, in line with their protection obligations. Moreover, the IMDA’s ‘Model AI Governance Framework for Generative AI: Fostering a Trusted Ecosystem’ 30 also highlighted the need for new tools to help enhance cybersecurity, including input filters and digital forensics tools. 24 European Union Agency for Cybersecurity. 2023. Multilayer Framework for Good Cybersecurity Practices for AI. (https://www.cybersecitalia.it/wp-content/uploads/2023/06/MultilayerFramework-for-Good-Cybersecurity-Practices-for-AI.pdf). 25 European Data Protection Board ChatGPT Taskforce. 2024. Report of the Work Undertaken by the ChatGPT Taskforce. (https://www.edpb.europa.eu/system/files/2024-05/ edpb_20240523_report_chatgpt_taskforce_en.pdf). 26 Office of the Privacy Commissioner for Personal Data. 2021. Guidance on the Ethical Development and Use of Artificial Intelligence. (https://www.pcpd.org.hk/english/resources_ centre/publications/files/guidance_ethical_e.pdf). 27 Office of the Privacy Commissioner for Personal Data. 2024. Artificial Intelligence: Model Personal Data Protection Framework. (https://www.pcpd.org.hk/english/resources_centre/ publications/files/ai_protection_framework.pdf). 28 Cyberspace Administration of China, the National Development and Reform Commission, the Ministry of Education, the Ministry of Science and Technology, the Ministry of Industry and Information Technology, the Ministry of Public Security, and the National Radio and Television Administration. 2023. Interim Measures for the Administration of Generative Artificial Intelligence Services. (https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm). 29 Personal Data Protection Commission. 2024. Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems. (https://www.pdpc.gov.sg/-/media/files/ pdpc/pdf-files/advisory-guidelines/advisory-guidelines-on-the-use-of-personal-data-in-ai-recommendation-and-decision-systems.pdf). 30 Infocomm Media Development Authority. 2024. Model AI Governance Framework for Generative AI: Fostering a Trusted Ecosystem. (https://aiverifyfoundation.sg/wp-content/ uploads/2024/05/Model-AI-Governance-Framework-for-Generative-AI-May-2024-1-1.pdf). 48 Generative A.I. in the Financial Services Space
31 Information Commissioner’s Office. 2023. Generative AI: Eight Questions that Developers and Users Need to Ask. (https://ico.org.uk/about-the-ico/media-centre/blog-generative-aieight-questions-that-developers-and-users-need-to-ask/). 32 National Cyber Security Centre. 2023. Guidelines for Secure AI System Development. (https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development). • U.K.: The Information Commissioner’s Office has published ‘Generative AI: eight questions that developers and users need to ask’ 31 to help developers and users navigate relevant supervisory requirements. Stakeholders must prioritise data privacy by adopting a “data protection by design and by default” approach to consider obligations from the very beginning of their projects. Importantly, data protection laws still apply even when personal information is obtained from publicly accessible sources. In addition, the National Cyber Security Centre has issued the ‘Guidelines for Secure AI System Development’ 32 for all stakeholders to make informed decisions about the design, development, deployment, and operation of their A.I. systems. The guidelines emphasise a “secure by default” approach, prioritising customer security and leadership commitment to security throughout the lifecycle. • US: Developed in response to legislative mandates, the ‘Artificial Intelligence Risk M a n a g e m e n t F r a m e w o r k : G e n e r a t i v e Artificial Intelligence Profile’ establishes a comprehensive, structured approach to identifying and mitigating risks associated with A.I. technologies. The Profile highlighted the need for periodic monitoring of privacy risks and methods to identify personally identifiable information in generated outputs. The framework also suggests risk evaluation prior to deployment and on an ongoing basis to ensure cybersecurity. As the deployment of GenA.I. continues to expand, data privacy and protection are becoming increasingly critical. Responsible and secure data handling is essential for building trust, maintaining regulatory compliance, and safeguarding the integrity of the financial services industry as it integrates GenA.I. systems into its operations. One of the key findings from our interviews is that financial institutions are actively seeking greater clarity on the responsible use of sensitive data in refining the outputs generated by GenA.I. solutions. During the interviews, several financial institutions indicated that clear regulatory guidance on the use of sensitive data, including data classification standards and the extent to which they can be leveraged to refine GenA.I. outputs, would greatly enhance the utilisation of GenA.I. capabilities. These institutions are particularly concerned with ensuring that these outputs remain both relevant and up-to-date, enabling improved service delivery to customers, while maintaining strict adherence to regulatory compliance. Generative A.I. in the Financial Services Space 49
Figure 25: Transparency & Disclosure 4.4. Transparency & Disclosure With the increasing use of A.I. in the financial services industry, customers may not always be fully aware of the extent to which A.I. systems are involved in service delivery. This lack of transparency can affect customer decision-making, where trust and informed consent are essential. Financial regulators are recognising the need for institutions to disclose their use of A.I. more explicitly, ensuring customers understand how A.I. is integrated into services to maintain trust and safeguard consumer rights (see Figure 25). Source: Regulatory disclosures, Quinlan & Associates analysis OBJECTIVE Provide users with clear and sufficient disclosures about A.I. usage in the services to protect user rights JURISDICTION RELEVANT EXCERPTS • Furthermore, investment firms should be transparent on the role of AI in investment decision-making processes related to the provision of investment services. • In general, the ESMA expects that when firms provide clients with information on how the firms use AI tools for the provision of investment services, they ensure that such information is presented in a clear, fair and not misleading manner. European Union European Securities and Markets Authority • Public Statement on the Use of Artificial Intelligence in the Provision of Retail Investment Services (2024) • To provide transparency and thereby increase consumers’ confidence in A.I.- powered services, banks should make clear to the consumer, prior to service provision, that the relevant service is powered by A.I. technology and the risks involved. • Accordingly, they (i.e., banks) should disclose the use of GenA.I. to customers, and, among others, communicate with customers on the use and purpose of adoption of the GenA.I. models as well as the limitations of such models, in order to enhance customers’ understanding of the model-generated outputs. • Clear disclosure would need to be made as to the Chatbot’s limitations, how it should be used, the data set it is trained on and how that data is stored, used and how long it is kept. Hong Kong (SAR) Hong Kong Monetary Authority • High-level Principles on Artificial Intelligence (2019) • Consumer Protection in Respect of Use of Generative Artificial Intelligence (2024) Insurance Authority • Conduct in Focus - Chatting about Chatbots and AI (2023) • Artificial intelligence algorithm financial application disclosure content is divided into seven aspects: algorithm combination disclosure, algorithm logic disclosure, algorithm application disclosure, algorithm data disclosure, algorithm subject disclosure, algorithm change disclosure, and algorithm audit disclosure. Mainland China People's Bank of China • Guidance on Information Disclosure for Financial Applications Based on Artificial Intelligence Algorithms (2023) • Transparency principles require disclosing the use of Artificial Intelligence and Data Analytics, explaining outcomes, and understanding what data is used to drive the outcome. • Data subjects are provided, upon request, clear explanations of the on sequences that AIDA (Artificial Intelligence and Data Analytics)-driven decisions may have on them. Singapore Monetary Authority of Singapore • Emerging Risks and Opportunities of Generative AI for Banks A Singapore Perspective (2023) • Whilst our regulatory framework does not specifically address the transparency or explainability of AI systems, there are a number of high-level requirements and principles under our approach to consumer protection. • Related rules under the Consumer Duty on consumer understanding refer to meeting the information needs of retail customers and equipping them to make decisions that are effective, timely and properly informed. United Kingdom Financial Conduct Authority • AI Update (2024) • Consider disclosing use of GAI (i.e., GenA.I.) to end users in relevant contexts, while considering the objective of disclosure, the context of use, the likelihood and magnitude of the risk posed, the audience of the disclosure, as well as the frequency of the disclosures. United States National Institute of Standards and Technology • Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (2024) 50 Generative A.I. in the Financial Services Space
• EU: In its ‘Public Statement on the Use of Artificial Intelligence in the Provision of Retail Investment Services’ 33, the European Securities and Markets Authority (ESMA) highlights both the opportunities and risks associated with A.I. in the delivery of investment services. A key directive from ESMA is that investment firms should be transparent about the role A.I. plays in their decision-making processes. Firms are expected to communicate their use of A.I. tools in a manner that is clear, fair, and not misleading, ensuring that clients are fully informed and can make well-founded decisions regarding their investments. • Hong Kong (SAR): In 2019, the HKMA issued a circular, titled ‘High-level Principles on Artificial Intelligence’ 34, to provide guidance on the use of A.I. in banking sector. The circular underscores the need for transparency and disclosure, stating that customers must be clearly informed when relevant services utilise A.I. technology and any associated risks. Recently, the HKMA issued another circular, ‘The Consumer Protection in respect of Use of Generative Artificial Intelligence’ 35, providing guidance on using GenA.I. in customerfacing applications. The circular reinforces the importance of transparency, requiring authorised institutions to provide clear, accurate, and easily understandable disclosures about their use of GenA.I. solutions. This includes informing customers about the purpose and limitations of the A.I. models, helping them better understand the generated outputs. For the insurance sector, the IA's Circular on ‘Conduct in Focus – Chatting about Chatbots and AI’ 36 discusses key considerations and perspectives on A.I.-powered Chatbots under the insurance regulated activities regime. The paper highlights the importance of clear disclosure to ensure customers are not only aware of the Chatbot’s limitations and data management processes, but also able to make fully informed decisions in their best interests. • Mainland China: The ‘Guidance on Information Disclosure for Financial Applications Based on Artificial Intelligence Algorithms’ 37, issued by the People's Bank of China, outlines key principles, formats, and content for disclosing the use of A.I. algorithms in the financial sector. The document aims to better protect the legitimate rights and interests of financial consumers by ensuring transparency in A.I.-driven financial services. It identifies seven critical areas for disclosure: algorithm combination, algorithm logic, algorithm application, algorithm data, algorithm subject, algorithm changes, and algorithm auditing, specifying the items to be disclosed under each area. Additionally, the guidance includes a template that financial institutions can reference to ensure proper disclosure of A.I. algorithmrelated information. • Singapore: The Monetary Authority of Singapore has released a whitepaper titled ‘Emerging Risks and Opportunities of Generative AI for Banks, A Singapore Perspective’ 38 as part of Project MindForge. In the first phase of the project, a comprehensive framework for managing GenA.I. risks was developed. The whitepaper emphasises that transparency principles require disclosing the use of Artificial Intelligence and Data Analytics (AIDA), explaining the outcomes produced, and clarifying the data driving these outcomes. Additionally, data subjects must be provided with clear explanations, upon request, about the potential impacts of AIDA-driven decisions on them. • U.K.: Following the Government’s publication of its pro-innovation strategy on A.I., the Financial Conduct Authority (FCA) outlined its approach to A.I. in its ‘AI Update’ 39. While the FCA acknowledges that its regulatory framework does not specifically address the transparency or explainability of A.I. systems, it upholds several high-level requirements and principles under its consumer protection approach that are pertinent 33 European Securities and Markets Authority. 2024. Public Statement on the Use of Artificial Intelligence in the Provision of Retail Investment Services. (https://www.esma.europa.eu/ sites/default/files/2024-05/ESMA35-335435667-5924__Public_Statement_on_AI_and_investment_services.pdf). 34 Hong Kong Monetary Authority. 2024. High-level Principles on Artificial Intelligence. (https://www.hkma.gov.hk/media/eng/doc/key-information/guidelines-andcircular/2019/20191101e1.pdf). 35 Hong Kong Monetary Authority. 2024. Consumer Protection in Respect of Use of Generative Artificial Intelligence. (https://www.hkma.gov.hk/media/eng/doc/key-information/ guidelines-and-circular/2024/20240819e1.pdf). 36 Insurance Authority. 2023. Conduct in Focus - Chatting about Chatbots and AI. (https://www.ia.org.hk/en/legislative_framework/circulars/reg_matters/files/Cir_dd_12.05.2023_Eng. pdf). 37 People’s Bank of China. 2023. Guidance on Information Disclosure for Financial Applications Based on Artificial Intelligence Algorithms. (http://www.hbbill.com/uploadFiles/- 13/395/070/09/2c9081e489c0507d018cdeab565401fc.pdf). 38 Monetary Authority of Singapore. 2023. Emerging Risks and Opportunities of Generative AI for Banks, A Singapore Perspective. (https://www.mas.gov.sg/-/media/mas-media-library/ schemes-and-initiatives/ftig/project-mindforge/emerging-risks-and-opportunities-of-generative-ai-for-banks.pdf). 39 Financial Conduct Authority. 2024. AI Update. (https://www.fca.org.uk/publication/corporate/ai-update.pdf). Generative A.I. in the Financial Services Space 51
to the information provided to consumers. These principles are relevant for firms using A.I. responsibly and safely in financial services. Notably, the Consumer Duty imposes a broad obligation to act in good faith, characterised by honesty and fair, open dealings with retail consumers. Additionally, the Consumer Duty includes rules on consumer understanding, which focus on meeting the information needs of retail customers and enabling them to make effective, timely, and well-informed decisions. • US: The ‘Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile’ issued by the NIST recommends that organisations consider disclosing the use of GenA.I. to end-users in appropriate contexts. This disclosure is suggested to be thoughtfully tailored, taking into account several key factors: the purpose and objective of the disclosure, the specific context in which the GenA.I. is being used, the likelihood and severity of any associated risks, the characteristics of the intended audience, and the optimal frequency of such disclosures. These considerations help ensure that users are informed in a transparent and meaningful way without causing unnecessary confusion or information overload. As transparency and disclosure principles evolve across various jurisdictions, solution providers and financial institutions must adjust to meet new regulatory expectations. These regulations are designed to protect user rights and promote responsible A.I. usage by ensuring that users are well-informed about how A.I. systems are used. 4.5. Conclusion It is imperative for financial institutions to remain informed about these regulatory updates, as they provide guidance on suggested practices required for ongoing innovation efforts, particularly for those operating on a regional or global scale. Keeping updated on these regulations ensures that organisations can effectively adapt and comply, maintaining their competitive edge in an increasingly complex regulatory environment. Staying ahead of the curve is equally critical for the public sector. By continuously revisiting and updating existing regulatory frameworks and incorporating global suggested practices, where appropriate, the public sector can establish effective policies that not only drive innovation but also protect the interests of the broader ecosystem. 52 Generative A.I. in the Financial Services Space
5.1. GenA.I. Governance Structure Establishing a robust governance structure is essential for the successful deployment of GenA.I. solutions at any financial institution, ensuring that the technology is used both correctly and responsibly. Taking into consideration the regulatory standards and supervisory guidelines outlined across major jurisdictions in Section 4, including the recent circular on GenA.I. published by the HKMA40, a range of key measures should be adopted by financial institutions to establish robust GenA.I. governance (see Figure 27). Figure 27: GenA.I. Governance Structure Source: Regulatory disclosures, Quinlan & Associates analysis GENERATIVE A.I. GOVERNANCE STRUCTURE • Establish an accountability framework to ensure oversight and risk management • Ensure appropriate explainability to make A.I.-driven decisions understandable to users • Filter inappropriate contents during data collection and model development to ensure the fairness of outputs • Conduct fairness assessments using detection and quantification tools to identify and address discriminatory bias • Handle personal data in accordance with regulations to protect privacy and ensure informed consent is obtained • Adopt security measures throughout the lifecycle including monitoring and audits to ensure system integrity • Ensure transparency about the role and use of A.I. in applications by disclosing the purpose, context of data usage, limitations, associated risks, and implications of these models Global Standards The board and senior management… remain accountable for all the GenA.I.-driven decisions and processes • Establish an appropriate committee under the governance, oversight, and accountability framework • Ensure appropriate explainability of the GenA.I. models • Adherence to the consumer protection principles with clear scope definition and proper policies and procedures for customer-facing GenA.I. applications • Put in place control measures and proper validation of GenA.I. models • Adopt “human-in-the-loop” approach Ensure GenA.I. models produce objective, consistent, ethical, and fair outcomes for customers • Comply with applicable laws, including those on discrimination, to avoid unfair bias or disadvantageous outputs • Consider… anonymising certain data categories, deploying comprehensive and fair representation datasets of the population, and removing bias during the validation and review processes • Provide customers with the option to opt out of using GenA.I. and request human intervention… or channels… to request for review Authorised institutions should implement effective protection measures to safeguard customer data • Comply with the Personal Data (Privacy) Ordinance if personal data are collected and processed by GenA.I. applications • Consult the Office of the Privacy Commissioner for Personal Data’s recommendations and good practices • Consider “privacy by design” and collecting and storing only the minimum amount of data • Ensure a clear and understandable request for consent Provide appropriate transparency on GenA.I. applications through proper, accurate, and understandable disclosure • Disclose the use of GenA.I. and associated risks to customers • Set up a mechanism for customers to enquire and request reviews, ensuring accessible and fair handling • Explain data types used and factors affecting the model where appropriate • Carry out appropriate education to enhance consumers’ understanding • Communicate in a clear and simple-to understand-manner… on the use, purpose, and limitations HKMA Circular REGULATORY PRINCIPLES Governance & Accountability Fairness Data Privacy & Protection Transparency & Disclosure • Governance & Accountability: Financial institutions should establish a robust governance, oversight, and accountability framework to use GenA.I. solutions. The framework should define clear roles and responsibilities across the development lifecycle, guide thorough risk assessments with ongoing monitoring, and put in place rigorous incident tracking and response mechanisms. The board and senior management ultimately remain accountable for decisions made using GenA.I., which must comply with consumer protection principles, corporate values, and ethical standards. Moreover, financial institutions need to ensure an appropriate level of explainability of the GenA.I. solutions and validate the solutions before launch. Appropriate policies and procedures should also be in place to guarantee responsible use. During the early stage of deploying GenA.I. applications, "human-in-the-loop" approach should also be adopted (i.e., having human to retain control in the decision-making process). 40 Hong Kong Monetary Authority. 2024. Consumer Protection in respect of Use of Generative Artificial Intelligence. (https://www.hkma.gov.hk/media/eng/doc/key-information/guidelinesand-circular/2024/20240819e1.pdf). 54 Generative A.I. in the Financial Services Space
• Fairness: GenA.I. models must produce objective, consistent, ethical, and fair outcomes. Financial institutions should comply with applicable laws, consider customers’ financial capabilities and needs, and appropriately weigh all relevant variables to build a robust model. Unfair bias or disadvantage must be avoided through techniques like anonymisation, fair representation, and bias adjustments. Customers should be given the option to optout and request human intervention during the early stage of deploying GenA.I. applications. Rigorous adversarial testing should be conducted to identify vulnerabilities and protect against potential manipulation. • Data Privacy & Protection: Effective data protection measures must be implemented to safeguard customer information. Financial institutions should embed data protection in the product and system design. Consent should be obtained with a clear understanding before the collection and use of personal data. Continuous monitoring and auditing of A.I. systems are crucial to ensure cybersecurity, ongoing compliance, and system integrity, with rigorous data governance practices and secure-bydesign principles to minimise vulnerabilities and protect against malicious attacks. • Transparency & Disclosure: Financial institutions should provide an appropriate level of transparency around the adoption, nature, usage, risks, and limitations of the GenA.I. solution. End-users should be able to enquire about and request reviews of the system. They should also receive adequate support with accessible and fair complaint handling. GenA.I. service providers should explain the types of data used and factors behind A.I.-driven decisions, enhancing consumer understanding through appropriate education. Communications should be clear and simple to understand, enabling customers to interpret the outputs and build trust. A well-defined governance structure is essential for ensuring clear oversight and accountability throughout GenA.I. initiatives. Such structure must explicitly delineate the roles and responsibilities of all stakeholders, including project managers, Information Technology (IT) teams, and business leaders. It should also outline mechanisms for effective decisionmaking, comprehensive risk management, and efficient conflict resolution. Several financial institutions we interviewed have already implemented GenA.I. governance committees, uniting key stakeholders to thoroughly review GenA.I. initiatives. These committees provide early insight into innovations and facilitate feedback on relevant risks and recommended actions. One institution underscored the importance of backtesting GenA.I. solutions for both internal and external GenA.I. models before deployment, while another global bank highlighted the need for automated, continuous monitoring throughout the solution’s lifecycle. In addition to internal governance, several institutions stressed the importance of a collaborative governance structure with technology providers. Technology providers echoed this sentiment, emphasising their risk-based approach to GenA.I. governance and their commitment to working with clients to establish a clear governance framework to collectively oversee GenA.I. initiatives. 5.2. Deployment Value Chain Anchored by a robust governance framework from the outset, organisations can start their GenA.I. deployment process that is aligned with the organisation’s broader strategic objectives, helping to keep the initiative on track and within scope, ultimately facilitating adoption of the technology across the value chain: (1) pre-deployment, (2) deployment, and (3) post-deployment (see Figure 28). Generative A.I. in the Financial Services Space 55
Figure 29: Pre-deployment Phase Source: Quinlan & Associates analysis GENERATIVE A.I. GOVERNANCE STRUCTURE PRE-DEPLOYMENT DEPLOYMENT POST-DEPLOYMENT • Ongoing Monitoring – Output Management – Solution Performance Monitoring – Compliance Monitoring • Training on GenA.I. • Marketing to the Public • Business Case Development • • Proof-of-Concept
Business Case Development Identifying the problem is the first step in developing a business case. Financial institutions need to understand the nature of the issue specific to their business operations and its significance relative to industry and market metrics. A quantitative statement that clearly relates to the top and bottom lines will help define a measurable, trackable, and time-sensitive problem statement, laying the foundation for both business and technology goals. Establishing specific key performance indicators is also recommended as a detailed point of reference. With a clear and quantified objective, financial institutions can further investigate the underlying causes of the issue. This may involve examining both macro factors (e.g., industry trends, headwinds, and tailwinds) and market factors (e.g., changes in market share and the forces affecting demand and supply). The findings should ultimately help determine whether the problem is actionable and worth addressing financially. Building a business case for GenA.I. often starts by identifying specific tasks that require significant time commitments but have limited outcome impact, such as processing or reviewing large volumes of information to generate insights. Compared to other technology solutions on the market, both the problem statement and benefits of the solution output for GenA.I. solutions are generally intuitive to be quantified and contextualised. Proof-of-Concept Once the business case is successfully built, financial institutions can initiate the PoC process to ideate, validate, and develop a prototype. The PoC stage is essential as it mitigates development risks and informs future iterations, laying the foundation for successful deployment. As the first step of the PoC, financial institutions should set the direction of the GenA.I. concept by considering the following three key elements: (1) user interface / user experience, (2) model design, and (3) capability acquisition approach. • User Interface (UI) / User Experience (UX): Based on the problem statement defined during the development of the business case, the UI should be designed with end-users in mind, prioritising accessibility and intuitiveness. As outlined by the Open Web Application Security Project (OWASP)42, financial institutions can design user-friendly interfaces that incorporate warnings about potential inaccuracies and clearly labelled generated content, allowing users to make informed decisions about the reliability of the data. Feedback from potential end-users should be actively gathered and integrated into the solution to refine and enhance the overall experience. A user-centric approach during the PoC phase ensures higher adoption rates and user satisfaction when the solution is fully deployed at scale. • Model Design: There are two types of GenA.I. models that financial institutions may consider: (1) pre-trained models and (2) customised models. The former offers a faster deployment option and can be cost-effective but may not fully address distinct business needs or provide a unique competitive edge. The latter, while more resource-intensive and timeconsuming to develop, can be tailored to meet unique challenges and deliver more precise outcomes. The decision on which model to use should consider the organisation’s specific use cases, available expertise, and desired level of customisation. While pre-trained, many GenA.I. models allow adjustment to a range of parameters, such as temperature, sampling methods and context-window size. Depending on the use cases, financial institutions can explore different combinations of parameters to better control outputs as well as resource consumption. Based on our interview findings, many financial institutions choose pre-trained models augmented with their internal knowledge base, achieving a balance between rapid deployment and tailored functionality for specific needs through augmentation or adaptation approaches such as RAG or Low-Rank Adaptation (LoRA). Other key considerations from the interviews include whether the GenA.I. model supports multiple languages, given that most financial institutions operate on a regional or global scale. 42 Open Web Application Security Project. 2023. OWASP Top 10 for LLM Applications. (https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/ OWASP-Top-10-for-LLMs-2023-slides-v1_1.pdf). Generative A.I. in the Financial Services Space 57
• Capability Acquisition Approach: Financial institutions should decide between developing the GenA.I. solution in-house or partnering with an external technology vendor. Developing the solution in-house offers greater control over the development process and allows for customisation to meet specific business needs. However, this approach demands substantial resources and expertise, as training GenA.I. models can be time-consuming and resource-intensive. In contrast, partnering with an external vendor can provide access to specialised skills and expedite the development process, though it may limit customisation options and create vendor dependency. Most financial institutions that have adopted GenA.I. solutions choose to partner with mature technology providers to leverage their expertise and reduce research and development costs. In these vendor arrangements, financial institutions should extend the controls to supplier management. This includes conducting proper due diligence to ensure that the vendor’s practices align with the institution’s organisational standards and setting clear GenA.I. guidelines for them, as outlined in the ISO / IEC 42001:2023. Once the direction is set, then financial institutions should investigate business risks to navigate the inherent complexities of innovation while maintaining business continuity and safeguarding their long-term success. A proactive risk management approach assesses potential business risks and develops corresponding contingency plans. • Business Risk Assessment: The adoption of new technology often comes with risks, especially in the case of GenA.I., due to its innovative nature. OWASP has identified several vulnerabilities in its Top 10 for LLM applications framework, including insecure output handling and over-reliance. In the context of GenA.I. deployment, these risks stem from an over-dependence on A.I. generated outputs without sufficient validation or oversight, leading to unintended data leaks or flawed decisionmaking. This is particularly critical in clientfacing applications, where errors or failures could damage the trust and reputation of an organisation. From our interviews, financial institutions have already implemented internal procedures to prevent over-reliance on GenA.I. and have developed appropriate m i t i g a t i o n s t r a t e g i e s . T h e s e i n c l u d e incorporating a thorough human review process before any GenA.I. outputs are used and continuously monitoring system logs to ensure accuracy. • Business Contingency Planning: Contingency planning during the PoC stage involves preparing for potential setbacks or failures that could occur during deployment. This includes developing backup plans for critical business functions and alternative solutions for when issues arise. Effective contingency planning ensures that the financial institution can quickly respond to unexpected challenges, maintaining business continuity and minimising the impact on operations. With sufficient preparation, financial institutions can then conduct a feasibility check before carrying out the PoC, an important step in identifying potential roadblocks upfront and determining if the project is truly worth pursuing. To evaluate whether the proposed solution has garnered enough resources and time, financial institutions can review resource requirements and lay out a deployment timeline. • Resource Requirements: It is important for financial institutions to identify the necessary (1) human resources, (2) supporting hardware, and (3) capital required to execute GenA.I. initiatives. GenA.I. solutions typically consume more energy and computing power than other technology solutions, making precise resource planning even more critical. Furthermore, financial institutions should consider the resource implications of maintaining traditional or opt-out channels that some customers may prefer even after adopting GenA.I. solutions. Supporting both GenA.I. and legacy systems may require additional resources, potentially escalating costs and causing unexpected delays. Effective resource planning helps identify these challenges early, ensuring initiatives are delivered within the allocated resources and aligned with expectations. • Deployment Timeline: Establishing a realistic deployment timeline is critical for managing expectations and ensuring that the PoC stays on schedule. The timeline should outline key 58 Generative A.I. in the Financial Services Space
GENERATIVE A.I. GOVERNANCE STRUCTURE PRE-DEPLOYMENT DEPLOYMENT POST-DEPLOYMENT • Ongoing Monitoring – Output Management – Solution Performance Monitoring – Compliance Monitoring • Training on GenA.I. • Marketing to the Public • Business Case Development • • Proof-of-Concept
All six layers must be carefully considered for the GenA.I. solution’s overall functionality, efficiency, and security. Neglecting any of these layers can lead to compatibility issues, data integrity problems, communication breakdowns, and potential security vulnerabilities, which can undermine the success of the deployment. • Application Layer: Most financial institutions have already adopted a wide range of technology applications, such as business intelligence and management information systems, alongside with GenA.I. solutions once they are adopted. On top of ensuring accessibility and intuitiveness as part of the UI / UX design during the PoC stage, financial institutions should also consider how the GenA.I. solution is integrated into the overall suite of applications. • Integration Layer: Implementing appropriate middleware solutions, such as application programming interfaces (APIs) and data integration platforms, is the key to unlocking the full potential of GenA.I. solutions. APIs enable seamless communication between GenA.I. solutions and other supporting layers, Figure 31: Architecture Design Source: Palo IT, Quinlan & Associates analysis Application Layer Application Layer Customer Applications Business Intelligence Management Information Systems Data Sharing Services GenA.I. Solutions Integration Layer APIs Data Integration Platform Storage Layer Curated Data Cleaned Data Dashboards Modeling Catalogue Lineage Streaming Data Data Warehouse Data Analytics Data Governance Data Lake Ingestion Layer Extract, Transform, Load Stream Processors Event Processors Data Loader Real-time Streaming System Core Processing System Data Sources Layer Databases Legacy Systems SaaS Applications Enterprise App. Files Web Services Security Layer Security while data integration platforms ensure that data fed into GenA.I. models is secure, consistent and compatible. • Storage Layer: When considering the storage layer for a GenA.I. solution, financial institutions should decide whether to host the solution on-premises or use a cloud-based storage infrastructure to accommodate the large volumes of data and processing required. Hosting the solution on-premises provides greater control over data and security but may require significant investment in hardware and maintenance and may have limitations on scalability. In contrast, a cloud-based solution offers scalability, flexibility, and lower infrastructure costs, although it may raise concerns about data privacy and compliance, particularly in the highly regulated financial services industry. Based on our interviews, most financial institutions are currently adopting GenA.I. solutions on-premises with no connection to the internet, as many use cases are still in the testing phase that requires a high degree of control. They are also monitoring for further regulatory clarity regarding the use of GenA.I. before scaling up these use cases to 60 Generative A.I. in the Financial Services Space
ensure compliant adoption of the technology. Lastly, financial institutions should establish strict data governance policies to maintain data compatibility, as well as regulatory compliance, which will support data migration and the longterm maintenance required to ensure the storage effectively supports GenA.I. performance. • Ingestion Layer: To handle high volumes of diverse data from various sources, such as market, transaction, and client data, financial institutions should implement powerful data streaming and processing systems that feed into the storage. These systems must be carefully stress-tested to determine whether they can handle the computational demands required GenA.I. solutions without disrupting ongoing operations. • Security Layer: Ensuring data privacy is of paramount importance when deploying a GenA.I. solution, especially in financial institutions where sensitive client information may be involved. Data privacy measures should include encryption of data both in transit and at rest, as well as strict access controls to prevent unauthorised access. Financial institutions can also explore advanced encryption techniques, such as homomorphic encryption, which allows data to remain encrypted even while being processed by GenA.I. models, eliminating the need for decryption during computations. With regards to access, financial institutions can customise authorisations using OAuth2 and API keys, as recommended by OWASP. By establishing comprehensive protocols for data privacy, which should be guided by the GenA.I. governance structure, financial institutions can protect customer trust and avoid legal repercussions associated with inadvertent sensitive information disclosures and data breaches. Technology Risk Assessment When considering the architecture design for GenA.I. initiatives, financial institutions should rigorously identify technology-specific risks to develop corresponding risk management plans. A thorough risk assessment helps identify potential issues, vulnerabilities, and points of failure that could arise during deployment and scaling. This ensures that financial institutions can create contingency plans to minimise the likelihood and impact of adverse events, thereby protecting both technological and financial investments and supporting the long-term success of the GenA.I. solution. This process involves identifying a broad spectrum of potential risks, encompassing system incompatibilities, data security vulnerabilities, performance bottlenecks, and evolving threats specific to GenA.I. systems, such as data poisoning, prompt injections, and model jailbreaks. These risks, highlighted in frameworks like the OWASP Top 10 for LLMs, can introduce significant vulnerabilities if left unaddressed. For instance, data poisoning attacks can corrupt a model's training dataset, leading to compromised outputs, while prompt injections and jailbreaking can manipulate the model's behaviour, bypassing its safety mechanisms. Additionally, the integration of third-party content into GenA.I. systems, such as through RAG architectures, presents another layer of risk, as personal data leaks and unauthorised data access can occur from contextdriven vulnerabilities. To mitigate these risks, continuous monitoring—such as through intrusion detection systems (IDS) and real-time anomaly detection—is crucial for detecting suspicious activities before they cause harm. Furthermore, LLM red-teaming and penetration testing should be considered to proactively identify vulnerabilities in the model and supporting infrastructure. Red-teaming, particularly in an openended format, enables testers to explore a wide range of potential harms beyond predefined attack vectors, uncovering blind spots in the system’s security posture. This approach allows for the documentation of previously unknown risks, such as hate speech, toxic outputs, hallucinations, and privacy violations, including the unintentional leakage of personally identifiable information (PII) from training data. By iterating on a list of harms identified through these tests, financial institutions can continually refine their risk management strategies and strengthen their defences. Moreover, application-layer threats often require a different red-teaming focus, as tool-based vulnerabilities (e.g., SQL injections, privilege escalations, or hijacking) are more likely to occur once the model is embedded in operational environments. Generative A.I. in the Financial Services Space 61
Both white-box and black-box testing should be employed. White-box testing can uncover deep, structural weaknesses in the model, such as model poisoning or access to PII, while black-box testing is better suited to simulate real-world attack scenarios, revealing unexpected behaviours in how the model interacts with external systems. Technology Contingency Planning In addition to proactive risk identification, financial institutions should engage in technology contingency planning, which can be both pre-emptive and reactive. Pre-emptive measures, such as alwayson firewalls, data encryption, and real-time anomaly detection systems, aim to address risks before they materialise. However, given the complexity of GenA.I. systems, reactive contingency plans must also be in place. These plans, developed in response to risk assessments, should include backup solutions, such as data recovery systems, alternative workflows, and incident response protocols. This is particularly critical in addressing application-layer threats, which often manifest after the model has been integrated into broader systems. Issues like indirect prompt injections, data exfiltration, and unauthorised access to APIs or databases may arise in real-world usage scenarios, making it essential for these plans to cover not only model failures but also broader system disruptions. Finally, financial institutions should ensure that their contingency plans and mitigations are regularly tested through performance testing, stress testing, and load testing. This iterative process helps validate that backup systems and security measures function effectively when needed. As part of this ongoing risk management cycle, institutions should continue conducting guided red-teaming to probe for known harms, while remaining vigilant for new threats that may emerge. Solution Performance Testing Prior to full-scale deployment, performance testing is essential to verify that the GenA.I. solution meets operational standards. This testing evaluates the solution’s ability to handle the expected volume and complexity of prompts, while maintaining accuracy, ethics, and relevance under real-world conditions. It also assesses the system’s resilience to potential disruptions or unexpected scenarios. The results guide financial institutions in validating that the solution aligns with their objectives and operational demands. If any weaknesses are found, an iterative testing process allows for targeted adjustments, ensuring the solution operates consistently and with high quality before being widely implemented. Additionally, stress testing and load testing are critical in ensuring the solution’s robustness. Stress testing pushes the system beyond its typical capacity, simulating extreme conditions like high query loads or infrastructure outages to identify breaking points and assess recovery capabilities. This helps ensure the system can operate effectively in high-pressure scenarios, protecting operational stability and the client experience. Meanwhile, load testing measures how well the system performs under expected and peak usage, assessing its ability to maintain response times and accuracy at scale, taking into consideration the considerable amount of computational power required to operate the GenA.I. solution. These tests help institutions identify potential bottlenecks and optimise resources, ensuring the GenA.I. solution can scale efficiently as demand grows. Lastly, GenA.I. solutions should be thoroughly tested and validated under pre-defined scenarios to ensure that key risk areas identified during the technology risk assessment stage (e.g., hate speech, toxic outputs, hallucinations, and privacy violations) are adequately addressed. This approach helps identify potential risk incidents arising from GenA.I.-powered operations, enabling financial institutions to deploy these solutions safely and responsibly. Conclusion Throughout the solution’s technical design, risk management, and performance testing, successful system integration plays a pivotal role. This involves embedding the GenA.I. solution seamlessly into existing business workflows while ensuring adherence to cybersecurity protocols, data privacy policies, and regulatory requirements. A smooth and secure deployment positions financial institutions to fully leverage the potential of novel GenA.I. technologies, enabling them to enhance operational efficiency, achieve business objectives more effectively, and deliver superior services to their end clients. 62 Generative A.I. in the Financial Services Space
Figure 32: Post-deployment Phase Source: Quinlan & Associates analysis GENERATIVE A.I. GOVERNANCE STRUCTURE PRE-DEPLOYMENT DEPLOYMENT POST-DEPLOYMENT • Ongoing Monitoring – Output Management – Solution Performance Monitoring – Compliance Monitoring • Training on GenA.I. • Marketing to the Public • Business Case Development • • Proof-of-Concept
• Compliance Monitoring: Ongoing compliance monitoring is critical for identifying issues, preserving system integrity, and ensuring the continued safe and responsible operation of deployed solutions. Closely tracking inputs and outputs allows for the detection and mitigation of emerging biases or unintended discriminatory impacts over time, guaranteeing the responsible and ethical use of GenA.I. to secure public trust and maintain the solution’s long-term viability. Training on GenA.I. To fully activate GenA.I. solutions, financial institutions should equip intended end-users with the necessary knowledge and skills to fully capitalise on these technologies. Training will not only familiarise users with the solution but also increase their confidence, enhancing the overall effectiveness of the solution and leading to better outcomes for the institutions. • Training on the General Understanding of GenA.I.: Financial institutions should educate users on what GenA.I. is, how it works at a high level, and what its benefits and limitations are. This foundational understanding will help users grasp the overall concept of the solution and recognise the risks associated with its use. • Training on Specific GenA.I. Solution Usage Methods: Each GenA.I. solution should come with tailored training for end-users, particularly for more complex and customised internal solutions. Training formats should vary based on the audience. For example, customer-facing GenA.I. solutions may include short instructional videos integrated into the UI, enabling rapid understanding. For internal solutions, financial institutions can look to provide in-person training sessions, online video tutorials, and user manuals. Marketing to the Public Lastly, financial institutions should consider sharing their progress in GenA.I. adoption to enhance their public perception and market proposition. Emphasising the commitment to continuously adhere to regulatory principles through a robust governance structure may effectively communicate the organisation’s dedication to corporate social responsibility and the public’s interests. Financial institutions can announce their use of GenA.I. through various channels, such as in-app notifications, website banners, and press releases on news websites. This public communication can showcase the organisation's commitment to innovation and its proactive approach to integrating the latest technology for the benefit of both employees and clients. Conclusion The responsibilities associated with technology development extend beyond successful deployment, requiring continuous effort and commitment from the organisation. Regular monitoring of performance and compliance is key to ensuring the responsible and ethical use of GenA.I. solutions. Training should focus on enhancing end-user confidence in using these solutions, creating a supportive environment for ongoing adoption. Transparent public communication can further build trust and showcase a financial institution’s dedication to innovative yet accountable technology deployment for the benefit of all stakeholders. 5.3. Feedback Loop One of the key recurring considerations across the deployment value chain is that collecting feedback from the end-user is very important for successfully deployment to ensure smooth operation and continuous improvement but also drives wider adoption within the organisation. The feedback loop consists of three key steps: (1) feedback collection, (2) feedback analysis, and (3) feedback implementation (see Figure 33). • Feedback Collection: During the predeployment phase, financial institutions should establish a channel for intended end-users to provide initial feedback, ensuring the solution’s accessibility and intuitiveness. Once the solution reaches the PoC stage, it is essential to include a feature at the UI level that allows end-users to give feedback on both the overall performance of the solution and the quality of its outputs. The financial institutions we interviewed understand the importance of collecting feedback and have implemented features that enable end-users to rate the GenA.I. solution on metrics such as response speed, relevance, and accuracy. On the back-end financial institutions must track the 64 Generative A.I. in the Financial Services Space
logs generated by the GenA.I. solution, allowing the monitoring team to report significant errors, such as biased responses, so they can be promptly addressed to prevent larger negative impacts. • Feedback Analysis: Collected feedback should be regularly aggregated, cleansed, and analysed to assess both the strengths and weaknesses of the GenA.I. solution. This process helps identify patterns and underlying causes, which are essential for developing future improvement plans. • Feedback Implementation: Based on the analysis collected, GenA.I. solutions should be regularly updated according to improvement plans that build on top of user feedback, with ongoing collaboration between engineers, product managers, and end-users to ensure that new versions effectively address the identified issues. A robust feedback implementation mechanism should be in place to ensure effective and ongoing incorporation of feedback into the GenA.I. solution, such as through backFigure 33: Feedback Loop Source: Quinlan & Associates analysis PRE-DEPLOYMENT DEPLOYMENT POST-DEPLOYMENT Feedback Analysis Feedback Implementation Feedback Collection 3 2 1 Feedback Collection Implement feedback mechanisms in the user interface, such as rating buttons for performance evaluation and options for reporting significant errors to facilitate prompt corrective actions 1 Feedback Analysis Analyse the collected feedback to identify the strengths and weaknesses of the GenA.I. solution, recognise performance patterns, and understand the underlying causes 2 Feedback Implementation Utilise the insights gained from the analysis to update the GenA.I. solution, addressing the identified issues and implementing enhancements to improve overall performance and user experience 3 end prompt engineering, output filtering, or model augmentation / adaptation. In accordance with ISO / IEC 42001:2023, having these activities or mechanisms in place will enable organisations to improve the effectiveness and performance of their system – an essential element for certification. 5.4. Conclusion Guided by a robust governance structure, the adoption of GenA.I. solutions in financial institutions requires thorough consideration at both the organisational and solution levels across all stages of deployment. A t h o r o u g h i m p a c t a s s e s s m e n t o f t h e s e considerations, coupled with proactive planning, can significantly smoothen the deployment process. By doing so, financial institutions can not only mitigate potential risks but also unlock GenA.I.’s full potential, driving innovation, achieving desired business outcomes, and ultimately rendering better end-user experiences. Generative A.I. in the Financial Services Space 65
6.1. Product Launch In the initial phase, financial institutions explore emerging A.I. models, architectures, and training techniques to evaluate their potential for upcoming projects. Given the rapid evolution of A.I. technologies, comprehensive R&D is required to ensure that GenA.I. solutions are innovative, functional, scalable, and aligned with industrywide needs. However, the complexity and resource demands of this phase underscore the need for robust support schemes to facilitate successful product launches. Hong Kong’s public and private sectors have responded by providing or committing to numerous initiatives to support this process. To promote the development of Hong Kong’s A.I. ecosystem, the HKSAR Government has allocated HKD 3 billion in the 2024-25 budget for a three-year A.I. Subsidy Scheme. This initiative supports local universities, R&D centres, government departments, and A.I.-related enterprises in leveraging the A.I. Supercomputing Centre (AISC) at Cyberport, which is set to reach 3,000 petaFLOPS (equivalent to processing 10 billion images per hour) in capacity by early 2026. Part of the scheme will also be directed towards enhancing the security of the AISC and attracting global A.I. talent and enterprises to the city. To oversee this initiative, the HKSAR Government appointed the A.I. Funding Scheme Committee in August 2024. Public-private partnerships have also been established to create a favourable product launch environment, enhancing R&D infrastructure and expanding the A.I. talent pool. For example: • In October 2018, the HKAI Lab, a non-profit initiative funded by the Alibaba Hong Kong Entrepreneurs Fund and SenseTime, and supported by HKSTP, was established to help A.I. companies scale their operations. The lab offers a flagship 12-month Accelerator Programme, allowing participants to access high-performance computing resources, Alibaba’s machinelearning platform, and technical support from leading A.I. solution providers. Additionally, the programme provides financial support, advisory services, and valuable networking opportunities. • In August 2022, Alibaba Cloud and HKUST partnered to launch a joint talent development programme focused on data analytics, cloud computing, and A.I., which includes handson workshops, seminars, and internship opportunities, providing students with practical experience at Alibaba Cloud. • In May 2024, Cyberport and Cisco signed the Memorandum of Understanding (MoU) that aims to enhance A.I. networks and cybersecurity in Hong Kong. As part of this collaboration, the two entities will create an A.I. lab at Cyberport to improve A.I. network technologies and drive innovation. • In June 2024, the HKIC invested in SmartMore, a home-grown A.I. firm, to accelerate technological advancements. SmartMore plans to establish an A.I. Research Institute and collaborate with local universities to offer Master’s and Doctoral programmes in A.I., building a pipeline of highly skilled professionals to drive future innovations. • In July 2024, HKUST and the Alibaba Group signed an MoU that outlines their plans to create a Joint Lab on Big Data and Artificial Intelligence in the next three years, focusing on researching emerging technologies such as GenA.I. The collaborative efforts of the HKSAR Government, quasi-government agencies, and private sector organisations are instrumental in advancing A.I. in Hong Kong. Through targeted financial support, comprehensive talent development programmes, and strategic joint research ventures, these measures ensure that researchers and enterprises have access to essential resources needed to develop GenA.I. solutions. Importantly, many of these support schemes alleviate concerns raised by institutions about upfront costs and resource needs, facilitating long-term innovation. Generative A.I. in the Financial Services Space 67
6.2. Product Promotion Effective deployment and promotion are crucial to the success of GenA.I. solutions post product launch. Hong Kong FinTech Week is one of Asia’s largest and most influential flagship Fintech events, spotlighting cutting-edge developments, including A.I. In 2023, the event featured over 300 speakers, 540 sponsors and exhibitors, and attracted more than 30,000 attendees, with 5 million views from over 90 economies. The event includes exhibitions, keynote speeches, panel discussions, workshops, networking opportunities, and business matchmaking sessions. The 2024 Hong Kong FinTech Week is set to take place in late October, with a forum dedicated to A.I. and Advanced Tech. Another large-scale event is the InnoEx, which showcases innovative solutions aligned with emerging global technology trends. The 2024 event featured 458 exhibitors from 13 countries and attracted over 39,000 buyers, with A.I. & Robotics among the top trending topics. Like Hong Kong FinTech week, the event provides an invaluable platform for institutions to promote their A.I. solutions and engage with a global audience. Most recently, the HKMA’s FiNETech2 event gathered over 300 professionals from the banking, securities, and insurance sectors, as well as representatives from the government and industry associations, to explore the applications of A.I. and GenA.I. in risk management, anti-fraud, customer service, and process transformation. 14 A.I. providers showcased diverse, innovative solutions through booth exhibitions and demonstration sessions. Experts from academia and industry also shed light on GenA.I.’s impact on A.I.-driven digital experiences, highlighting associated benefits and risks. Large-scale events not only provide a venue for showcasing innovations but also play a crucial role in the GenA.I. commercialisation process by fostering valuable connections and dialogue with industry leaders, potential partners, and end-users. Participation in these events also allows institutions to stay informed about the latest developments and trends in the evolving GenA.I. landscape, ensuring their solutions remain aligned with evolving market needs, crucial for driving sustained commercial success. 68 Generative A.I. in the Financial Services Space
In collaboration with other financial regulators including the SFC, the IA and the MPFA, the HKMA will continue to develop and refine policies that promote responsible technological innovation. Initiatives, such as the GenA.I. Sandbox, are only the beginning. These efforts are designed to foster a secure and controlled environment where financial institutions in Hong Kong can confidently explore and adopt advanced A.I. technologies. Through proactive collaboration and open communication between the public and private sectors, the HKMA will continue to support Hong Kong’s position as one of the world’s leading international financial hubs. We believe that by working together, we can achieve a future where financial institutions not only benefit from the advantages of GenA.I. but also contribute to a responsible, sustainable, and innovative financial ecosystem. 70 Generative A.I. in the Financial Services Space
• Encoder-decoder models: Models that use encoders to process and transform input text into a representation and decoders to generate the corresponding output text. • Encoder-only models: Models that encode the input text into a fixed-length representation, capturing contextual information for further processing or analysis. • Feed-forward mechanism: The process where the input data passes through multiple layers of a neural network, with each layer performing calculations and applying distinct weights to the inputs. • Generative Artificial Intelligence: A category of A.I. that excels at generating novel and innovative outputs across various domains by utilising generative models. • Graphic Processing Units: Specialised hardware accelerators that utilise numerous smaller, highly efficient processing cores to process data in parallel, making them particularly effective for tasks such as graphics rendering and complex computations. • Large Language Model: A type of generative models that can produce contextually relevant language and code outputs, leveraging vast amounts of training data to understand and generate text. • Model architectures: Design configurations and structural frameworks of A.I. models that dictate how they process information and generate outputs, influencing their performance and capabilities. • Nodes: Individual computation units within an A.I. model, responsible for processing data and contributing to the overall functionality of the network. • Parameters: Metrics that determine how input signals are transformed as they propagate through the network, including weights that regulate the strength of connections and biases to adjust the output independently of the input. • Processing core: Units that retrieve instructions from memory in the form of digital signals, decode them, and execute computations and logical functions using logical gates. • Prompt: A query or request for specific output, serving as an instruction to an application interface powered by an LLM. • Proof-of-Concept: A demonstration or prototype that is created to validate an idea, concept, or theory, helping organisations make informed decisions about moving forward with a project. • Reinforcement data: D a t a u s e d f o r reinforcement learning. • Reinforcement training: A training method in which models interact with their environment, receiving rewards for desirable actions and penalties for undesirable ones, allowing for iterated refinement and improvement in task performance over time. • Retrieval-augmented generation: An approach that enables an A.I. model to access data beyond its original training corpus, integrating external, real-time information to generate more accurate, relevant, and up-to-date responses. • Self-attention: The mechanism that enables a model to evaluate the importance of each word in a sentence relative to every other word. • Semantic meaning / understanding: The meaning of words, phrases, and sentences in a language. • Sparse models: Models where only a small fraction of parameters is non-zero, meaning that most of the parameters are effectively unused or set to zero to improve computational efficiency and interpretability. • Supervised training: A training method in which the model receives labelled training data where the correct output is already known so the model can learn to map inputs to their corresponding outputs. • Tensor Processing Units: A.I.-specific accelerators that are designed to optimise complex computations involved in training and running A.I. models. • Transformers: The standard architecture for building LLMs that leverages mechanisms like self-attention to process data in parallel, allowing for efficient training and effective handling of sequential information. • Unsupervised training: A training method where the model autonomously explores a dataset to identify underlying patterns and structures without the use of predefined outputs or labels. 72 Generative A.I. in the Financial Services Space
8.3. List of Reference • Cyberspace Administration of China, the National Development and Reform Commission, the Ministry of Education, the Ministry of Science and Technology, the Ministry of Industry and Information Technology, the Ministry of Public Security, and the National Radio and Television Administration: Interim Measures for the Administration of Generative Artificial Intelligence Services (2023) • Digital Policy Office of the Hong Kong Government: Ethical Artificial Intelligence Framework (2024) • European Data Protection Board ChatGPT Taskforce: Report of the Work Undertaken by the ChatGPT Taskforce (2019) • European Securities and Markets Authority: Public Statement on the Use of Artificial Intelligence in the Provision of Retail Investment Services (2024) • European Parliament and the Council of the European Union: Artificial Intelligence Act (2024) • European Union Agency for Cybersecurity: Multilayer Framework for Good Cybersecurity Practices for AI (2023) • Financial Conduct Authority: AI Update (2024) • High-Level Expert Group on Artificial Intelligence: Ethics guidelines for trustworthy AI (2019) • Hong Kong Academy of Finance & Hong Kong Institute for Monetary and Financial Research: Artificial Intelligence in Banking (2020), Artificial Intelligence and Big Data in the Financial Industry (2021) • Hong Kong Monetary Authority: Consumer Protection in respect of Use of Generative Artificial Intelligence (2024), High-level Principles on Artificial Intelligence (2019), Consumer Protection in respect of Use of Big Data Analytics and Artificial Intelligence by Authorized Institutions (2019), Reshaping Banking with Artificial Intelligence (2019) • Infocomm Media Development Authority and Personal Data Protection Commission: Model Artificial Intelligence Governance Framework Second Edition (2020) • Infocomm Media Development Authority: Model AI Governance Framework for Generative AI: Fostering a Trusted Ecosystem (2024) • Information Commissioner’s Office and The Alan Turing Institute: Explaining Decisions Made with AI (2022) • Information Commissioner’s Office: Generative AI: Eight Questions that Developers and Users Need to Ask (2023) • Insurance Authority: Conduct in Focus - Chatting about Chatbots and AI (2023) • Intellectual Property Department: Copyright and AI, Public Consultation Paper (2024) • Monetary Authority of Singapore: Emerging Risks and Opportunities of Generative AI for Banks A Singapore Perspective (2023) • National Cyber Security Centre: Guidelines for Secure AI System Development (2023) • National Technical Committee 260 on Cybersecurity: Basic Security Requirements for Generative Artificial Intelligence Service (2024) • National Institute of Standards and Technology: Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (2024) • N a t i o n a l N e w G e n e r a t i o n A r t i f i c i a l I n t e l l i g e n c e G o v e r n a n c e S p e c i a l i s t Committee: Ethical Norms for New Generation Artificial Intelligence (2021) • Office for Artificial Intelligence and Department for Science, Innovation & Technology: A Pro-innovation Approach to AI Regulation (2023) • Office of the Government Chief Information Officer: Ethical Artificial Intelligence Framework (2023) • Office of the Privacy Commissioner for Personal Data: Artificial Intelligence: Model Personal Data Protection Framework (2024), Guidance on the Ethical Development and Use of Artificial Intelligence (2021) • People’s Bank of China: Guidance on Information Disclosure for Financial Applications Based on Artificial Intelligence Algorithms (2023) • Personal Data Protection Commission: Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems (2024) • The White House: Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence (2023) Generative A.I. in the Financial Services Space 73
8.4. Acknowledgements This paper has greatly benefitted from the contributions of various external collaborators. We thank the Insurance Authority, the Mandatory Provident Fund Schemes Authority, the Hong Kong Institute for Monetary and Financial Research, various divisions and departments of the Hong Kong Monetary Authority, including the Communications Division, the Banking Supervision Department, the Banking Conduct Department and the Fintech Facilitation Office for their comments and suggestions. We would also like to thank Quinlan & Associates and KPMG China for coordinating and facilitating interviews with various market participants, including technology providers, banks, securities, and insurance firms, and for their support in the research and drafting of this paper. We wish to extend our gratitude to Amazon Web Services Hong Kong Limited, Bank of China (Hong Kong) Limited, Bank of Communications (Hong Kong) Limited, Citibank (Hong Kong) Limited, FIL Investment Management (Hong Kong) Limited, Hang Seng Bank, Limited, Hongkong and Shanghai Banking Corporation Limited (The), HSBC Life (Asia) Limited, J.P. Morgan Securities (Asia Pacific) Limited, JPMorgan Chase Bank, National Association, Microsoft Hong Kong Limited, Moody’s Asia Pacific Ltd, OneDegree Hong Kong Limited, PAO Bank Limited, Standard Chartered Bank (Hong Kong) Limited, and Zurich Insurance (Hong Kong) for their inputs for this paper. 74 Generative A.I. in the Financial Services Space
More like this from HKMA
HKMA published 11 documents in the last 30 days. We email you each new one the day it's published.